Privacy Policy

Last updated: July 2026

Welcome to Mai Trip! Your privacy is fundamental to us. This Privacy Policy transparently explains how we collect, use, store, and protect your personal data when you use our mobile application and website (joinmaitrip.com), in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).

1. Data Controller

The Data Controller is Mai Trip. For any clarification, exercise of your rights, or information regarding the processing of your personal data, you can contact us at our dedicated email address:

info@joinmaitrip.com

2. Types of Data We Collect

We collect different categories of personal data to provide and improve our services:

  • Registration and Account Data: Name, email address, profile picture (if uploaded), and encrypted login credentials securely managed via Google Firebase Authentication.
  • Travel and Planning Data: Destinations, travel dates, created itineraries, stops, notes, saved places, and users invited to collaborate on trips.
  • Shared Expenses Data: Amounts entered, currency, expense description, payer, and expense split among group members.
  • Technical and Usage Data: IP address, device type, operating system, system logs, anonymous device identifiers, and Firebase Cloud Messaging (FCM) tokens for push notifications.
  • Transaction Data: Token purchase history and Premium subscription status. Transactions are processed directly through the Apple App Store or Google Play Store via RevenueCat. Mai Trip does not collect or store your credit card or bank details.
  • Location Data (Geolocation): With your explicit consent provided through your mobile operating system, we may process your geographic location to suggest nearby attractions and places.
  • Ad Consents: In the free version of the mobile app, with your prior consent (CMP consent banner and App Tracking Transparency prompt on iOS), Google AdMob may process advertising identifiers to serve relevant ads.

3. Purposes and Legal Bases for Processing

We process your personal data based on the following legal conditions (Art. 6 GDPR):

  • Performance of Contract (Art. 6.1.b GDPR): To allow you to register an account, create and share itineraries, calculate shared expenses, and use app features.
  • User Consent (Art. 6.1.a GDPR): For sending push notifications, real-time geolocation, and serving personalized ads in the free app.
  • Legitimate Interest (Art. 6.1.f GDPR): To ensure IT security, prevent fraud or abuse, and optimize server performance.
  • Legal Obligation (Art. 6.1.c GDPR): To comply with legal, accounting, and tax obligations arising from in-app transactions.

4. Generative AI Transparency (EU AI Act & GDPR)

Mai Trip uses advanced generative Artificial Intelligence models (Google Gemini AI via Cloud Functions) to generate custom travel itineraries and suggest stops.

Text prompts sent to the AI provider contain exclusively travel preferences (destination, duration, travel style) and do NOT include direct personally identifiable data. AI providers process data solely to generate the requested itinerary and do not train public models on your personal data.

AI-generated recommendations and itineraries are purely supportive and informative and do not constitute automated decisions producing legal effects (pursuant to Art. 22 GDPR).

5. Data Recipients and Sub-processors

To provide its services, Mai Trip uses selected third-party technical partners acting as GDPR-compliant Data Processors:

  • Google Cloud / Firebase: Cloud infrastructure for authentication, database (Firestore), hosting, and push notifications.
  • Google Gemini API: Artificial intelligence service for itinerary processing.
  • RevenueCat Inc.: Management and validation of subscription status and token purchases.
  • Google AdMob: Ad network for the free version of the app (subject to consent).
  • Apple Inc. & Google LLC: App distribution platforms and in-app payment handling.

6. Data Transfers Outside the EU

Some of our service providers (e.g. Google, RevenueCat) are located in the United States. Data transfers outside the European Economic Area (EEA) occur strictly under GDPR safeguards, via the EU-U.S. Data Privacy Framework (DPF) or European Commission Standard Contractual Clauses (SCCs).

7. Data Retention and Deletion

Your personal data is retained for as long as your account remains active. You can request complete deletion of your account and associated data at any time via the profile settings in the mobile app or by emailing info@joinmaitrip.com. Permanent deletion from active databases occurs within 30 days.

8. Your Rights (Art. 15-22 GDPR)

Under the GDPR, you have the following rights:

  • Right of Access: Obtain confirmation of data processing and receive a copy of your personal data.
  • Right to Rectification: Request correction or updating of inaccurate data.
  • Right to Erasure ('Right to be Forgotten'): Request deletion of your personal data.
  • Right to Restriction: Request restriction of processing under certain conditions.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object & Revoke Consent: Object to processing or withdraw previously granted consent at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority.

9. Privacy Contacts

To exercise any of your rights or for privacy questions, email us anytime at:

info@joinmaitrip.com