Travelify

Privacy Policy

Last updated: July 13, 2026

Draft pending legal review. Not a substitute for advice from a qualified attorney.

1. Overview

This policy describes how Travelify handles personal information for two groups: Hosts (our customers, who run trips) and Travelers (the Host's customers, who book trips). For Traveler data, the Host is the controller and Travelify acts as a processor on the Host's behalf. The service is not directed to children; you must be at least 18 to use it.

2. What we collect

  • Hosts: name, email, organization details, and authentication data (via Clerk).
  • Travelers — booking: name, email, phone, and the booking details you provide when reserving a trip.
  • Travelers — trip intake (when you provide it): date of birth, gender, nationality, emergency contact, dietary needs, flight details, and passport number. This information is collected so your Host can run the trip. Sensitive fields (such as passport number) are encrypted at rest (see §5).
  • Payment: card details are collected and stored by Stripe. Travelify never sees or stores full card numbers.
  • Usage: basic product analytics and error telemetry (via PostHog) to operate, secure, and improve the service. This may use cookies or similar local storage.

3. How we use it

To provide the service: render Host sites, process bookings and payments (including scheduled installment charges you authorize), send transactional emails (booking confirmations, receipts, payment reminders), provide trip rosters and required travel details to your Host, and secure and improve the platform. We do not sell personal information.

4. Sub-processors

We share data with these service providers strictly to operate the platform:

  • Stripe — payment processing
  • Clerk — Host authentication
  • Supabase (Postgres) — application database
  • Cloudflare — media storage (R2) and DNS
  • Resend — transactional email
  • PostHog — product analytics & error monitoring
  • Vercel — application hosting

5. Data security

Data is encrypted in transit (HTTPS). Sensitive Traveler PII (such as passport numbers) is additionally encrypted at rest. Traveler data is isolated per Host at the database level so one Host cannot access another's data. Card data is handled by Stripe and never stored on Travelify's servers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Retention & your rights

We retain personal information for as long as needed to provide the service and to meet legal and financial obligations. Depending on your location you may have rights to access, correct, delete, or port your data, or to object to certain processing. Travelers should contact the relevant Host (the data controller); Hosts can contact us directly. We will assist Hosts in responding to their Travelers' requests as their processor.

7. International

Travelify is operated from the United States; if you access the service from elsewhere, your information may be processed in the U.S. [Cross-border transfer mechanisms (e.g. SCCs) and specific GDPR/CCPA disclosures to be confirmed with counsel.]

8. Contact

Privacy questions: privacy@travelify.sharkfins.xyz.