TripBase Logo

Privacy Policy

Effective date: May 1, 2026

This policy explains what personal data Cricket Traveling LTD (“Tripbase,” “we,” “us,” or “our”) processes when you visit tripbase.com, create an account, request a personalized travel guide, sign up for our newsletter, purchase a guide, or otherwise interact with our services (together, the “Services”). It also explains your rights and how to exercise them.

Cricket Traveling LTD is the controller of your personal information for the purposes of the EU General Data Protection Regulation (“EU GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and the Israeli Privacy Protection Law, 5741–1981 (the “PPL”). We are registered in Israel.

If you have any questions about this policy or want to exercise a privacy right, contact us at [email protected].

1. Quick summary

  • Who we are: Cricket Traveling LTD, an Israeli company that operates tripbase.com.
  • What we collect: account details (name, email, password), Google sign-in profile if you use it, travel preferences you give us when you ask for a guide, payment information you provide to our payment processor, newsletter sign-ups, feedback, and standard technical data such as IP address and browser type.
  • Why we collect it: to provide and improve the Services, send you the guides and emails you ask for, take payment for paid features, prevent abuse, and comply with the law.
  • Who we share it with: a small number of vetted sub-processors that help us run the site (listed in section 5). We do not sell your personal information.
  • Your rights: you can ask to access, correct, export, or delete your data. Email [email protected].

2. Information we collect

2.1 Information you give us directly

  • Account details. When you create an account, we collect your name, email address, and a password. Passwords are stored only as salted PBKDF2-SHA512 hashes — we never store, see, or transmit your password in clear text.
  • Google sign-in profile. If you choose “Sign in with Google,” Google sends us your name, email address, profile image URL, and a unique Google account identifier so we can create or link your Tripbase account.
  • Profile data and avatar. An optional display name and profile image you provide on your account page.
  • Travel-guide form input. When you request a personalized guide, we collect the inputs you submit, including your email address, destination(s), travel dates, party size, budget, and free-text preferences. These are used to generate your guide and are transmitted to our AI provider as described in section 5.
  • Saved destinations and trips. Items you save, trips you create, and travel companions you add to a trip.
  • Venue feedback. Ratings, comments, and suggestions you submit about venues featured on the site.
  • Newsletter sign-up. Your email address, and the date you subscribed.
  • Payment information. When you purchase a guide or other paid feature, payment is handled by Stripe. Your card number is entered directly into Stripe’s elements and is never received or stored by Tripbase. We retain a Stripe payment-intent identifier, the amount, the email address used at checkout, and the product purchased.
  • Correspondence. If you email us or fill in a contact form, we keep the message and your email address so we can reply and for our records.

2.2 Information collected automatically

  • Server logs. Our edge middleware records your IP address, the URL you requested, your browser’sUser-Agent string, and standard HTTP headers. We use these to operate the site, debug errors, and detect bots and abuse.
  • Product analytics. We use PostHog (EU region) to measure how the Services are used. PostHog records page views, clicks on key features, the path you took through the site, and a pseudonymous distinct-user identifier stored as a cookie and in browser local storage. If you sign in or submit certain forms, PostHog associates your subsequent events with your email address so we can understand the journey of authenticated users.
  • Approximate location. We may infer the country or city you are visiting from at the IP-address level. We do not collect GPS coordinates.
  • Cookies and local storage. See section 6.

2.3 Information from third parties

  • Google. If you use Google sign-in, Google sends us the profile data you authorize.
  • Stripe. Stripe sends us metadata about successful and failed payments (status, amount, last-four digits, country of card issuer).
  • Brevo. Our email provider sends us delivery, open, and click events for emails we send you, which we use to measure engagement and to suppress sending to addresses that bounce.

3. How we use your information

The table below sets out the purposes for which we process personal information and the legal basis we rely on under the EU and UK GDPR. For users in Israel, all processing is carried out in accordance with the PPL and your consent to this policy when you use the Services.

PurposeCategories of dataLegal basis (EU/UK GDPR)
Create and operate your account; authenticate youEmail, password hash, Google profile, account IDPerformance of a contract (Art. 6(1)(b))
Generate the personalized travel guide you requestedGuide-form input, emailPerformance of a contract (Art. 6(1)(b))
Take payment for paid featuresEmail, Stripe payment-intent ID, purchase metadataPerformance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c))
Send transactional email (guide ready, receipts, password reset)Email, name, related contextPerformance of a contract (Art. 6(1)(b))
Send the newsletterEmailConsent (Art. 6(1)(a)) — you can unsubscribe at any time
Measure usage; improve the ServicesAnalytics events, IP-derived country, distinct-user ID, email when signed inLegitimate interests in understanding and improving the Services (Art. 6(1)(f))
Detect, prevent, and investigate abuse, fraud, and security incidentsIP, User-Agent, account data, request logsLegitimate interests in protecting the Services and other users (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable
Respond to your enquiries and support requestsEmail, name, message contentsLegitimate interests in supporting our users (Art. 6(1)(f))
Comply with legal obligations and respond to lawful requestsAs required by the requestLegal obligation (Art. 6(1)(c))
Defend or establish legal claimsAs requiredLegitimate interests (Art. 6(1)(f))

We do not use your data to make decisions about you that have a legal or similarly significant effect on you, and we do not use it for any form of automated profiling beyond ranking destinations and content for relevance.

4. AI-assisted features

Some features — including personalized guide generation, destination chat, and content suggestions — are powered by large-language-model providers, principally Anthropic (Claude). When you use those features, the input you submit (for example, the contents of a guide-request form) is transmitted to the provider so it can generate a response. We instruct providers under contract not to retain your input for model training, but you should not enter information you would not want a third-party processor to handle.

Destination imagery shown on the site is generated using OpenAI’s image models from non-personal destination metadata only; no user-supplied personal data is sent to image-generation providers.

We previously published a read-only Model Context Protocol (MCP) connector that let AI assistants such as ChatGPT and Claude query Tripbase’s public travel data. That connector is currently disabled while we add authenticated access, so no data flows through it. It was read-only and wrote nothing back to Tripbase; it received only the parameters of each request (for example, a destination slug or a passport country code) and returned public destination data, and we did not use it to collect or store the contents of your AI conversations. If it returns, this policy will be updated before it is switched back on.

5. Sharing and sub-processors

We do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising. We disclose data only to the categories of recipients described below.

5.1 Service providers we rely on

The following processors handle personal data on our behalf:

ProviderPurposeData categoriesRegion
RailwayApplication hosting and managed Postgres databaseAll personal data we storeEU / US (depending on deployment region)
Google LLCOAuth sign-in (“Sign in with Google”)OAuth profile (name, email, image, account ID)US
Stripe Payments Europe Ltd. / Stripe, Inc.Payment processingPayment card data (controlled by Stripe), email, billing country, amountEU / US
Brevo (Sendinblue)Newsletter and transactional email; email engagement eventsEmail address, name, message contents, open/click eventsEU
PostHog Inc.Product analytics (EU instance)Pseudonymous distinct-user ID, page-view and click events, IP-derived country, email when signed inEU
Anthropic, PBCAI-assisted guide and chat generation (Claude API)Guide-form contents and chat messages you submitUS
OpenAI, L.L.C.AI image generation for destination artDestination metadata only — no user PIIUS
Google Places APIServer-side venue and place enrichmentPlace identifiers and search terms (no user PII)US
ApifyServer-side review enrichmentPlace identifiers (no user PII)EU
Viator (Tripadvisor)Affiliate tour and activity catalogSearch parameters such as destination, dates, traveler countsUS / EU
KayakAffiliate hotel and flight searchSearch parameters such as origin, destination, datesUS / EU
DuffelServer-side flight and stay searchSearch parameters such as origin, destination, datesEU / US

Each of these providers is bound by a written data-processing agreement and may only process your personal data on our instructions and for the purposes set out above.

5.2 Affiliate hand-offs

When you click an affiliate link to book a flight, hotel, tour, car, or other travel product, you are taken to the partner’s own website and the partner becomes the controller of any personal information you provide to them. Their privacy policy will govern that interaction. We may receive a commission, and we may receive aggregated reporting from the partner about whether your click resulted in a booking, but we do not receive your booking details unless you separately give them to us.

5.3 Other disclosures

  • Legal compliance. We may disclose personal information where required by applicable law, court order, or other lawful request from a public authority, including authorities outside your country of residence.
  • Protection of rights. We may disclose information when we believe in good faith that it is necessary to protect our rights, your safety, the safety of others, or to investigate fraud or misuse.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your information may be transferred to a successor entity, subject to the protections of this policy.

6. Cookies, local storage, and tracking

We use a small number of first-party and service-provider cookies and browser-storage entries. The list below reflects what the Services actually set today.

Name / patternTypePurposeLifetime
authjs.session-token / __Secure-authjs.session-tokenStrictly necessary cookieStores your encrypted Auth.js session JWT so you stay signed inSession / up to 30 days
authjs.callback-url, authjs.csrf-tokenStrictly necessary cookieSign-in flow security and post-login redirectSession
ph_* (PostHog distinct-id and session)Analytics cookie + local storagePseudonymous identifier for product analytics; allows us to count unique visitors and stitch sessionsUp to 1 year
tripbase.newsletterPopup.*Local storageRemembers which newsletter pop-up variant you saw, when you last dismissed it, and whether you have already subscribedUntil cleared by you
rk_consentStrictly necessary cookieStores your consent preferences from the cookie banner (together with an anonymous consent ID) so we do not show it on every visitUp to 1 year
rk_geoStrictly necessary cookieTwo-letter country code derived from your IP address, used only to decide whether the consent banner must be shown before analytics may run24 hours

We present our own consent banner on first visit where consent is required. It lets you accept all cookies, reject non-essential cookies, or pick categories individually. We keep a minimal log of consent decisions (an anonymous consent ID, the choice, the time, and a country code, with no IP address and no account linkage) as proof of consent. You can change or withdraw your choices at any time via the “Cookie settings” link in the footer of every page; withdrawing removes the cookies those tools have set. In addition, you can:

  • block or delete cookies via your browser settings (note that this will sign you out and may break some functionality);
  • turn on your browser’s “Do Not Track” or “Global Privacy Control” signal — we treat these as a request to disable analytics; or
  • email [email protected] and we will suppress analytics for your account.

7. International data transfers

We are based in Israel and our primary infrastructure is hosted in the EU. Some of the providers listed in section 5 (notably Google, Stripe, Anthropic, OpenAI, and PostHog where the US instance is used) process data in the United States. Where personal data of users in the EEA, the UK, or Switzerland is transferred outside its country of origin to a country that has not been recognized by the European Commission as providing an adequate level of data protection, we rely on appropriate safeguards, including:

  • the European Commission’s Standard Contractual Clauses (with the UK addendum where applicable),
  • certifications under the EU–US Data Privacy Framework (and its UK extension and Swiss-US bridge) where the recipient is certified, and
  • the European Commission’s adequacy decision for Israel for transfers from the EEA to Israel.

You can request a copy of the safeguards we rely on by emailing [email protected].

8. How long we keep your information

  • Account data. Kept for the life of your account. If you ask us to delete your account, we delete or anonymize your account data within 30 days, except where we need to keep records to meet a legal obligation, resolve a dispute, or prevent fraud (in which case we restrict access to that data and delete it when the obligation ends).
  • Generated guides and saved trips. Kept for the life of your account.
  • Payment records. Kept for as long as required by tax, accounting, and consumer-protection law — typically seven years.
  • Newsletter subscription. Kept until you unsubscribe; after that, we keep a suppression record of your email address so we do not contact you again.
  • Server logs. Up to 90 days.
  • Analytics events. Retained per our PostHog instance settings, currently up to 12 months at the event level and longer in aggregated form.
  • Support correspondence. Up to 24 months from the last contact.

9. Your privacy rights

Depending on where you live, you have some or all of the rights below. To exercise any of them, email [email protected] from the email address associated with your Tripbase account, or from any address you can show belongs to you. We will respond within the time limit required by the applicable law (one month under the EU/UK GDPR, 45 days under the CCPA, generally 30 days under the PPL).

9.1 If you are in the EEA, the UK, or Switzerland (GDPR / UK GDPR)

  • Access — obtain a copy of the personal data we hold about you and information about how we process it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure (“right to be forgotten”) — ask us to delete personal data we no longer need or that we hold on the basis of your consent.
  • Restriction — ask us to limit how we use your data while we resolve a query.
  • Portability — receive a copy of the data you gave us in a structured, machine-readable format, and have it transmitted to another controller.
  • Objection — object to processing we carry out on the basis of legitimate interests (including analytics) or for direct marketing.
  • Withdraw consent — where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint with your local data protection authority. For the UK, this is the Information Commissioner’s Office; in Ireland, the Data Protection Commission; in France, the CNIL; in Germany, your state authority. We would, however, appreciate the chance to address your concerns first.

Because we have no establishment in the EU or the UK, we have not appointed an Article 27 representative; if this changes we will update this policy.

9.2 If you are in California (CCPA / CPRA)

You have the right to (1) know what personal information we have collected about you and how we have used and disclosed it; (2) request deletion of personal information; (3) request correction of inaccurate personal information; (4) opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising; (5) limit the use of sensitive personal information; and (6) be free from retaliation for exercising any of these rights. We do not sell or share personal information for cross-context behavioral advertising and we do not knowingly collect or process “sensitive personal information” as defined under the CPRA.

The personal-information categories we collect, by reference to the CCPA enumeration, are: identifiers (name, email, account ID, IP address); customer-records information (account profile); commercial information (purchases); internet/network activity (page views, clicks); approximate geolocation (IP-derived country); and inferences drawn from the above (such as content recommendations). We retain each category for the period described in section 8.

You may designate an authorized agent to make a request on your behalf. We will require the agent to provide signed proof of authority and may contact you to verify.

9.3 If you are in Israel (PPL)

Under sections 13 and 14 of the Israeli Privacy Protection Law, you have the right to inspect personal data we hold about you in our database and to request that inaccurate data be corrected or deleted. Email [email protected] with a clear description of the data you want to access or correct, and we will reply within 30 days. The Privacy Protection Authority within the Israeli Ministry of Justice supervises compliance with the PPL and you can contact it at gov.il/en/departments/the_privacy_protection_authority.

10. How we keep your data secure

We use industry-standard security controls, including:

  • TLS (HTTPS) for all data in transit;
  • salted PBKDF2-SHA512 password hashing — we never store cleartext passwords;
  • stateless, signed JSON Web Token sessions handled by Auth.js (NextAuth);
  • payment-card data scoped to Stripe, which is PCI-DSS Level 1 certified;
  • access controls, least-privilege database roles, encrypted backups, and infrastructure on Railway with managed network isolation;
  • bot and abuse detection at the edge based on User-Agent and request-pattern heuristics.

No system is perfectly secure. If you become aware of a vulnerability or believe your account has been compromised, please email [email protected].

11. Children

The Services are intended for adults. We do not knowingly collect personal information from children under 16 (or under 13 in the United States as defined by COPPA). If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it.

12. Marketing communications

We send you promotional email only if you opt in to our newsletter or if we have a recognized legal basis (such as a soft opt-in for users of a paid product, where the law allows it). Every promotional email contains an unsubscribe link, and you can also unsubscribe at any time by emailing [email protected]. Unsubscribing does not stop transactional email about your account, purchases, or guide deliveries, which are necessary to provide the Services.

13. Third-party links

tripbase.com links to third-party websites (booking partners, information sources, social platforms). We are not responsible for the privacy practices of those websites. Read their policies before providing them with personal information.

14. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date at the top of this page and take reasonable steps to notify you — for example, by emailing account holders or showing a notice on the site — before the changes take effect. Non-material changes (clarifications, typo fixes) will be reflected by an updated effective date only.

15. Contact us

Cricket Traveling LTD
Registered in Israel
Privacy contact: [email protected]
General contact: [email protected]