Legal
Privacy Policy
Effective August 25, 2026
TripLedger is a personal travel ledger operated by Pianosa Labs LLC. This notice explains what information we handle, why we handle it, and the choices you have.
Who we are
Pianosa Labs LLC is the controller of personal information processed through TripLedger. Our address is 30 N Gould St, STE R, Sheridan, WY 82801, USA. Questions and privacy requests can be sent to privacy@tripledger.app.
What we collect
- Account: your name, email, password credential, role, and Terms acceptance.
- Travel ledger: journeys, dates, times, locations, transport, stays, expenses, loyalty accounts, participants, and notes you add.
- Shared ledgers: traveler names and travel details, members, invitations, and permissions.
- Connections and security: sessions, IP address, browser and device details, API keys, OAuth grants, MCP usage, and security events.
- Payments and messages: purchase, refund, and Stripe customer references, plus service-email delivery information. We do not store full card numbers.
- Optional analytics and diagnostics: website visits, product events, performance details, and error reports when those tools are enabled.
Please do not put passport numbers, payment-card numbers, health information, or other highly sensitive information in free-text fields.
Why we use it
- Run your account, ledgers, calculations, exports, billing, and MCP connections.
- Calculate residency and Schengen results from your travel records.
- Process purchases and refunds, prevent abuse, and investigate failures.
- Send account, security, and service messages.
- Improve TripLedger through optional analytics and feedback you choose to send.
Where the GDPR or UK GDPR applies, we rely on performance of our contract for the core service; legitimate interests for security, fraud prevention, support, and limited diagnostics; consent for optional analytics and promotional email; and legal obligations for tax, accounting, and lawful requests.
Shared ledgers
You may add other travelers or invite people to a ledger. Make sure you have permission to add their information. Ledger owners control the shared ledger. Closing a member account does not erase traveler records that remain in somebody else’s ledger. Contact us if privacy rights and shared-ledger records conflict; we will review the circumstances.
Who helps us run TripLedger
We share information with providers only as needed for their work:
- Cloudflare for hosting, delivery, security, Turnstile, and logs.
- PlanetScale for managed PostgreSQL infrastructure.
- Stripe for checkout, payments, tax tooling, and refunds.
- Loops for transactional email and lifecycle messages.
- Sentry for error and performance diagnostics.
- DataFast for optional marketing-site and help-center analytics and attribution.
- PostHog for optional in-app product analytics.
- UserJot for feedback. Its widget loads only after you choose Leave feedback; we then send your account ID, name, and email so we can respond.
We may also disclose information to professional advisers, authorities when legally required, or a buyer in a business transaction with appropriate safeguards. We do not sell personal information or share it for cross-context behavioral advertising.
Cookies and analytics
Necessary cookies and local storage keep you signed in, secure the service, remember interface choices and your active ledger, and store your analytics preference. DataFast handles marketing-site and help-center analytics; PostHog handles app analytics. Where prior consent is required, they stay off until you accept. Change your choice at any time here or through Analytics preferences in the app settings.
Where information is processed
We are based in the United States, and our providers may process information in the United States and other countries. Where required, we use recognized transfer safeguards offered by our providers, including adequacy decisions, the EU-US Data Privacy Framework, or standard contractual clauses.
Retention and deletion
- Account and ledger information stays while the account or shared ledger is active.
- Confirmed deletion removes your live account, your owned ledger, its members’ access, and your memberships in other ledgers. It does not delete traveler records in ledgers owned by somebody else.
- Deleted information may remain temporarily in restricted backups until normal rotation completes.
- Providers keep security, email, diagnostic, and analytics records for their configured periods while reasonably needed.
- Terms acceptance stays with your account. We and Stripe may keep payment, refund, and tax records for up to 7 years, or longer where required.
Your choices and rights
In Settings, you can export your account and owned ledger or permanently delete them. Deletion is immediate and cannot be reversed. To request access, correction, export, restriction, objection, assisted deletion, or another privacy right, email privacy@tripledger.app or support@tripledger.app. We may verify your identity. Where applicable, we aim to respond within one month, and you may complain to your local data-protection authority.
Security
We use encrypted network connections, access controls, secure authentication cookies, credential revocation, and service monitoring. No online service can promise absolute security.
Children
TripLedger is for people aged 18 or older. We do not knowingly collect personal information from children. Contact us if you believe a child has created an account.
Changes
This policy is a notice, not a contract you must repeatedly accept. We update it as TripLedger changes and update the effective date above. If a change materially affects your rights, we will notify account holders by email or in the service.
Contact
Pianosa Labs LLC
30 N Gould St, STE R
Sheridan, WY 82801, USA
privacy@tripledger.app