1. Information you provide
- account details such as name, email address, avatar, currency, and preferences;
- trip dates, destinations, itineraries, activities, places, notes, and map locations;
- accommodation and transport details, including optional booking, room, seat, contact, and Wi-Fi information;
- budgets, expenses, currencies, payment-method descriptions, and optional receipt links;
- packing items and uploaded travel documents, including optional document numbers and expiry dates;
- emails used for account invitations or the public waitlist; and
- text, URLs, and trip context submitted when you request an AI feature.
2. Information handled automatically
Supabase authentication uses session cookies so signed-in pages can identify the current user. DayFlow also stores a secure referral and campaign-attribution cookie named df_attribution for up to 30 days when relevant campaign parameters are present.
The application includes Vercel Analytics and records product events such as feature usage, usage limits, checkout starts, purchase entitlements, and campaign attribution.
3. Information stored on your device
To support offline use, DayFlow saves selected trip, itinerary, place, stay, transport, budget, document-metadata, and packing snapshots in browser local storage. Pending offline edits can also be queued there, while the service worker caches app pages and static assets.
This browser-stored data can remain on the device after logout until the browser's site data is cleared. Take extra care on shared or public devices.
4. How the current product uses information
- to create and secure accounts and keep shared-account data synchronized;
- to display, save, and restore trip plans, including supported offline workflows;
- to provide requested map, place, route, and AI features;
- to enforce plan access and feature-usage limits;
- to create Stripe checkout sessions and record payment entitlements;
- to send waitlist confirmations, purchase confirmations, and account invitations; and
- to understand campaign performance and operate the service.
5. Services used by DayFlow
- Supabase for authentication, database, realtime synchronization, and file storage;
- Vercel for hosting and analytics;
- Stripe for hosted checkout and payment processing;
- Google Maps and Google Places for maps, locations, and place details;
- Google Gemini for AI features requested by the user; and
- Resend for transactional email when that provider is configured.
Stripe hosts the payment form; DayFlow stores entitlement and checkout identifiers, not the full card details entered on Stripe's checkout page.
6. Collaboration and public sharing
Members of the same DayFlow account can access shared account and trip information. A tokenized public trip link can be opened without signing in by anyone who receives the active link.
The current public snapshot can include trip names and dates, destinations, day and activity details, addresses, locations, room information, transport numbers, terminal or gate information, and free-form notes. It excludes stored areas such as budgets, uploaded documents, accommodation Wi-Fi passwords, and confirmation codes, but users should still review notes and itinerary details before sharing a link.
7. Current controls
Current product controls allow an account owner to remove an invited member and allow a trip owner to revoke a public share link. A complete account-deletion, export, or privacy-request workflow is not documented in the current product.
8. Details awaiting owner confirmation
A complete production privacy notice still requires confirmed decisions about:
- the legal controller or operator identity, postal address, and privacy contact;
- applicable legal bases and any required cookie or analytics choices;
- specific retention and deletion periods for each data category;
- how users request access, correction, export, deletion, restriction, or objection;
- minimum-age and children's privacy rules;
- processing regions, international transfers, and relevant safeguards;
- formal security, incident-notification, and complaint procedures; and
- a reviewed provider or subprocessor list and change-notification process.
Until those details are confirmed and reviewed, this page describes current technical handling and should not be read as a complete jurisdiction-specific privacy notice.