Skip to content

Legal

Security

The short version: encryption in transit, trip data scoped to invited members, and — by design — no financial accounts to protect, because we never connect to any.

Data protection

All traffic is encrypted in transit (TLS). Passwords are hashed with a modern algorithm and never stored in plain text.

Access control

Trip content is visible only to that trip’s members. Joining requires the trip’s code or invite link, and members can be removed by the trip creator.

Administrative access to production systems is restricted and logged.

The smallest attack surface

TripSync holds no payment credentials, no bank links and no UPI handles. The most sensitive thing in a trip is the trip itself — and it is shared only with the people you chose.

Reporting a vulnerability

Found something? Email hello@tripsync.app with details. We read every report and respond as fast as a small team honestly can.

Pre-launch draft. This describes how TripSync is designed to work and will be reviewed by counsel before public launch — the principles above won’t change.