naistripbeta

Privacy Policy

Last updated: June 6, 2026

Your privacy is important to us. It is our policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website naistrip.com and other sites we own and operate.

This Privacy Policy applies to all users of naistrip.com worldwide. Jurisdiction-specific provisions (for the European Economic Area, United Kingdom, California, Canada, and Australia) are included as Addenda at the end of this document and apply in addition to the common provisions below for residents of those regions.

In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.

1. Information We Collect

1.1 Information you provide

We may ask for personal information when you register an account, generate a travel plan, or contact us. The information we voluntarily collect from you today is limited to:

  • Email address and basic profile information (name, profile picture) — when you register an account via Google Sign-In or contact us by email.
  • Travel preferences — destinations, dates, points of interest and similar inputs you submit to generate an itinerary.

1.2 Information automatically collected

When you visit our website or use our services, our servers automatically log basic technical data, including:

  • IP address and basic network metadata.
  • Browser type and version, device type, and operating system.
  • Pages visited, time and date of visit, and time spent on each page.
  • Error data if you encounter technical issues while using the service.

This information is collected primarily for security, rate limiting, abuse prevention, and to improve our service.

1.3 Information we do not collect

We do not collect phone numbers, payment information, precise geolocation, sensitive personal information, or biometric data. If we begin collecting additional categories in the future, we will update this Privacy Policy accordingly and, where required by law, obtain your consent before doing so.

1.4 Anonymous vs registered use

You can use naistrip.com to generate travel itineraries without creating an account. When you use the service anonymously, we collect only the automatically generated technical data described in section 1.2 (IP address, browser metadata, error logs); your generated itineraries are processed in memory and are not stored on our servers.

When you register an account using Google Sign-In, we additionally collect: (i) your email address; (ii) basic profile information that Google shares with us upon your consent (typically name and profile picture); and (iii) the itineraries you choose to save to your account. This allows us to provide registered-user features such as saving and managing travel plans across devices.

Certain features of naistrip.com (such as saving and retrieving travel plans) require a registered account. Account creation is voluntary and not required to try the core itinerary-generation functionality.

2. How We Use Your Information

We may use the information we collect for the following purposes:

  • To provide and operate the core features of the service (generating travel itineraries, saving plans, account management).
  • To communicate with you regarding your account, service updates, or support requests.
  • To detect, prevent, and respond to fraud, abuse, security incidents, and violations of our terms.
  • For analytics, troubleshooting, and improvement of our website and services.
  • To comply with legal obligations and respond to lawful requests from authorities.

Personal information will not be further processed in a manner that is incompatible with these purposes.

3. Lawful Bases for Processing

Where required by applicable data protection law, we rely on one or more of the following lawful bases to process your personal information:

  • Consent — where you have given us specific consent (for example, to subscribe to marketing communications). You may withdraw your consent at any time using the facilities we provide; withdrawal does not affect processing that has already taken place.
  • Performance of a contract — where processing is necessary to provide the service you have requested (for example, to generate a travel plan after you submit your preferences).
  • Legitimate interests — where processing is necessary for our legitimate interests in operating, securing, and improving the service, provided those interests are not overridden by your rights and freedoms.
  • Compliance with the law — where processing is necessary to comply with a legal obligation we are subject to.

4. Third-Party Service Providers

We rely on a small set of third-party service providers strictly necessary to operate the service:

  • Firebase (Google LLC) — used to manage user authentication (including Google Sign-In), data storage, and application hosting. See Firebase Privacy and Security and Google Privacy Policy.
  • Google Gemini (Google LLC) — used to generate AI-powered travel suggestions and trip content. Prompts and related data may be processed by Google LLC. See Google Privacy Policy.
  • Google Maps Platform (Google LLC) — used to display maps, geocode destinations, and retrieve place photos.
  • Microsoft Clarity (Microsoft Corporation) — used for analytics, including session recordings and heatmaps, to help us understand and improve how visitors use our website. This service is only activated with your consent. See Microsoft Clarity Privacy Documentation and Microsoft Privacy Statement.
  • getterms.io — used to manage cookie consent on the website.

We may also disclose personal information to courts, tribunals, regulatory authorities, and law enforcement officers as required by law, or to an entity that acquires (or to which we transfer) all or substantially all of our assets and business.

4.1 Analytics Services Requiring Consent

The following table summarizes third-party analytics services that only run after you provide your consent through our cookie consent manager:

ServiceProviderCategoryConsent Required?
Microsoft ClarityMicrosoft CorporationAnalyticsYes — records sessions and heatmaps

5. International Transfers

The personal information we collect is stored and processed in the United States of America, where our infrastructure providers (Google Firebase, Google Cloud, Google Gemini) maintain their facilities.

The United States may not have the same level of data protection as the country in which you initially provided the information. When we transfer your personal information internationally, we perform those transfers in accordance with the requirements of applicable law and, where required, rely on appropriate safeguards such as Standard Contractual Clauses ("SCCs") issued by the EU Commission, together with the UK International Data Transfer Addendum for transfers from the United Kingdom, or other valid mechanisms recognised by competent supervisory authorities.

6. How Long We Keep Your Information

We keep your personal information only for as long as we need to, in accordance with this Privacy Policy. For example, if you have provided us with personal information as part of creating an account, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for our purposes, we will delete it or make it anonymous by removing all details that identify you.

If you delete your account, we will delete your personal information within 30 days of the deletion, unless we are required to retain it longer for compliance with a legal, accounting, or reporting obligation, or for archiving purposes in the public interest, scientific or historical research, or statistical purposes.

7. Security

When we collect and process personal information, and while we retain this information, we protect it within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use, or modification.

Although we will do our best to protect the personal information you provide to us, no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security. You are responsible for selecting any password and its overall security strength, and for keeping any credentials associated with your account secure and confidential.

8. Cookies

We use cookies to operate our website, remember your preferences, and understand how visitors use our site. Cookie consent is managed through our consent management system powered by getterms.io. For detailed information on the cookies we use, please refer to our Cookie Policy.

Analytics services such as Microsoft Clarity, which records sessions and generates heatmaps, are only activated after you provide your consent through the consent manager described above (see Section 4.1).

Most browsers allow you to refuse or disable cookies through their settings. Note that some browsers offer a "Do Not Track" feature; at this time we do not respond to "Do Not Track" signals, but we adhere to the standards described in this Privacy Policy and only collect and process personal information lawfully and transparently.

9. Children's Privacy

We do not aim any of our products or services directly at minors and we do not knowingly collect personal information from them. The applicable minimum age depends on your country of residence:

  • United States: 13 years of age (in accordance with COPPA).
  • European Union (general): 16 years of age (in accordance with the GDPR). Some EU member states have lowered this threshold — for example, Spain sets a minimum age of 14.
  • United Kingdom: 13 years of age (in accordance with the UK GDPR).
  • All other countries: 13 years of age, or the minimum age required by applicable local law, whichever is higher.

If you are below the applicable minimum age in your country, you must not use our services or provide us with any personal information. If we become aware that we have inadvertently collected personal information from a user below the applicable minimum age, we will delete that information promptly. If you believe we may have collected such information, please contact us at hello@naistrip.com.

10. Your Rights

Subject to applicable law and the conditions described in each Jurisdiction Addendum below, you have the following rights with respect to your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Rectification — request correction of inaccurate or incomplete information.
  • Deletion — request that we delete the personal information we hold about you, subject to legal exceptions.
  • Portability — receive a copy of the personal information you provided to us in a structured, machine-readable format.
  • Restriction — ask us to restrict the processing of your personal information in certain circumstances.
  • Objection — object to processing based on our legitimate interests or for direct marketing.
  • Withdrawal of consent — withdraw any consent you previously gave us, at any time.
  • Complaint — lodge a complaint with the supervisory authority in your region (see Section 13).
  • Non-discrimination — we will not discriminate against you for exercising any of your rights over your personal information.

To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframes required by applicable law. We do not charge a fee for responding to access or rectification requests.

11. Business Transfers

If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy.

12. External Links

Our website may link to external sites that are not operated by us. We have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices. Please review the privacy policy of any third-party site you visit.

13. Supervisory Authorities

If you believe your data protection rights have been violated and you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your region:

RegionSupervisory Authority
Spain / European UnionAgencia Española de Protección de Datos (AEPD) — aepd.es
United KingdomInformation Commissioner's Office (ICO) — ico.org.uk
CanadaOffice of the Privacy Commissioner of Canada (OPC) — priv.gc.ca
AustraliaOffice of the Australian Information Commissioner (OAIC) — oaic.gov.au
United States (California)California Privacy Protection Agency (CPPA) — cppa.ca.gov

14. Changes to This Policy

We may change this Privacy Policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this Privacy Policy, we will post the changes here at the same link by which you are accessing this Privacy Policy. Changes will take effect 30 days after publication on this page.

If the changes are significant, or if required by applicable law, we will contact registered users by email with the new details and links to the updated policy.

If required by law, we will obtain your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.

15. Contact Us

For any questions or concerns regarding your privacy, you may contact us using the following details:

Identity: Jaime Alonso Fernández
Address: Avda Fisterra 95, 15004 A Coruña, Galicia, Spain
Email:hello@naistrip.com


Addendum A — European Economic Area (GDPR)

This Addendum applies in addition to the common Privacy Policy for users residing in the European Economic Area.

Data Controller

The GDPR distinguishes between organisations that process personal information for their own purposes ("data controllers") and organisations that process personal information on behalf of others ("data processors"). With respect to the personal information you provide to us through naistrip.com, the Data Controller is:

Jaime Alonso Fernández
Avda Fisterra 95, 15004 A Coruña, Galicia, Spain
hello@naistrip.com

International Transfers

Personal data transferred from the EEA to the United States is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, or other safeguards permitted under Articles 45–49 of the GDPR.

Your Rights Under the GDPR

In addition to the rights listed in Section 10, you have the right to:

  • Lodge a complaint with the Agencia Española de Protección de Datos (AEPD) or another EEA supervisory authority.
  • Request restriction of processing under Article 18 of the GDPR.
  • Object to processing based on legitimate interests under Article 21 of the GDPR.
  • Be informed of any automated decision-making with legal or similarly significant effects (we do not currently engage in such automated decision-making).

Addendum B — United Kingdom (UK GDPR)

This Addendum applies in addition to the common Privacy Policy for users residing in the United Kingdom.

Data Controller

With respect to the personal information you provide to us through naistrip.com, we are the Data Controller. Our identity and contact details are provided in Section 15.

International Transfers

Personal data transferred from the United Kingdom to the United States is protected by Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum, or by other safeguards permitted under the UK GDPR (Article 46) and the Data Protection Act 2018.

Your Rights Under the UK GDPR

In addition to the rights listed in Section 10, you have the right to:

  • Lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority — ico.org.uk.
  • Submit a Data Subject Access Request (DSAR); the statutory deadline for fulfilment is 30 calendar days from receipt.
  • Be informed of any automated decision-making with legal or similarly significant effects (we do not currently engage in such automated decision-making).

Addendum C — California (CCPA / CPRA)

This Addendum applies in addition to the common Privacy Policy for residents of California.

Notice of Collection

In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA / CPRA:

  • Identifiers, limited to email address, name, and IP address (the name is collected only from registered users who sign in with Google).
  • Internet activity, limited to your interactions with our service (requests sent to our servers, error logs, pages visited).

We do not collect phone numbers, payment information, precise geolocation, or sensitive personal information.

No Sale or Sharing of Personal Information

We do not sell or share personal information for cross-context behavioural advertising. We do not offer financial incentives in exchange for the collection, sale, or retention of personal information.

Your California Rights

In addition to the rights listed in Section 10, California residents have the right to:

  • Right to Know — request the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
  • Right to Delete — request deletion of the personal information we collected from you, subject to legal exceptions.
  • Right to Correct — request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing — not applicable, as we do not sell or share personal information.
  • Shine the Light (Civil Code §1798.83) — request information regarding the manner in which we share certain personal information with third parties for their direct marketing purposes. To make this request, contact us with "Request for California privacy information" in the subject line. You may make this request once per calendar year.

Addendum D — Canada (PIPEDA)

This Addendum applies in addition to the common Privacy Policy for residents of Canada.

Scope of Personal Information

Under PIPEDA, "Personally Identifying Information" (PII) is interpreted broadly. Any references to personal information in this Privacy Policy are intended as equivalent to PII under PIPEDA.

Compliance with the Ten Principles of Privacy

This Privacy Policy is designed to comply with PIPEDA's ten fair information principles: Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use/Disclosure/Retention, Accuracy, Safeguards, Openness, Individual Access, and Challenging Compliance.

Right of Access

You may request access to the PII we hold about you in writing using the contact details in Section 15. We do not charge a fee for responding to access requests. We will respond within 30 days of receipt of your request, except where the time limit is extended under PIPEDA.

Complaints

You may also contact the Office of the Privacy Commissioner of Canada:

30 Victoria Street
Gatineau, QC K1A 1H3
Toll Free: 1.800.282.1376
priv.gc.ca

Addendum E — Australia (Privacy Act)

This Addendum applies in addition to the common Privacy Policy for residents of Australia.

Australian Privacy Principles (APPs)

This Privacy Policy is intended to be consistent with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).

International Transfers

Where the disclosure of your personal information is subject to Australian privacy laws, you acknowledge that some third parties may not be regulated by the Australian Privacy Act. If any such third party engages in any act or practice that contravenes the Australian Privacy Principles, it would not be accountable under the Privacy Act, and you may not be able to seek redress under that Act.

Complaints

You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC)oaic.gov.au.