Privacy Policy

Last updated: June 6, 2025 · Terms of Service

This policy explains what data TribeTrip collects, for what purpose, and how you can exercise your rights. If you have any questions, contact us at legadevel@gmail.com.

1. Data Controller

The data controller for personal data collected through the TribeTrip app is the individual developer who owns the application, domiciled in Spain.

Contact: legadevel@gmail.com

2. Data We Collect

DataPurposeLegal basis
Email address and display nameAccount identificationPerformance of a contract (Art. 6.1.b GDPR)
Profile photo (optional)Visual identification among trip membersConsent (Art. 6.1.a GDPR)
Trip data (destination, dates, members)Core app functionalityPerformance of a contract
Expenses and settlementsBalance calculation between participantsPerformance of a contract
Device token (FCM)Sending push notificationsConsent
Preferred languageApp and notification localizationLegitimate interest (Art. 6.1.f GDPR)
Technical logs (Firebase)Service stability and securityLegitimate interest

TribeTrip also supports anonymous use: in this mode, your activity is not linked to any email address. Anonymous data is deleted when you convert or delete your account.

3. Use of Data

We use your data exclusively to:

We do not sell, rent, or share your data with third parties for commercial purposes.

4. Data Processors

TribeTrip uses the following third-party services that act as data processors:

International transfers of data to Google are covered by the Standard Contractual Clauses adopted by the European Commission.

5. Data Retention

We retain your data for as long as you maintain an active account. When you delete your account from the app (Settings → Delete Account), we permanently erase:

Data related to shared trips (expenses, settlements) that affects other users may be retained in anonymized form to preserve the integrity of those trips' history.

6. Your Rights

Under the GDPR you have the right to:

To exercise any of these rights, contact us at legadevel@gmail.com. We respond within a maximum of 30 days.

If you believe our processing is not compliant with the GDPR, you may lodge a complaint with the Spanish Data Protection Authority (AEPD) at www.aepd.es.

7. Security

We apply appropriate technical and organizational measures to protect your data: encrypted communications (TLS), database security rules that restrict access to your own data and trips you are part of, and authentication via Firebase Auth.

8. Children

TribeTrip is not directed at children under 16 years of age. If you become aware that a minor has provided us with personal data without parental consent, please contact us so we can delete it.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes through an in-app notice or by email. The date of the last update is always shown at the top of this document.