Privacy Policy
Last updated: August 6, 2026
This policy describes what Tineris collects when you use the service, why, and the rights you have over it. Tineris is operated from the EU, and this policy is written to meet GDPR obligations for anyone we serve.
What we collect
Account data. Authentication is handled by Clerk. We receive your email address, name (if provided), and an authentication identifier — we never see or store your password.
Trip data. Anything you enter into Tineris — trip names, destinations, dates, bookings, and expenses — is stored in our Postgres database, hosted by Supabase.
Place search data. When you search for a place while adding a booking, your query is sent to the Google Places API to return results. We request only the fields we display; we do not request or store place ratings.
Map data. Trip map views are rendered by Mapbox, which receives the coordinates needed to draw the map and may log standard request metadata (such as IP address) as part of serving map tiles.
Booking data.When you book a flight or a stay, we send what the airline or property requires to complete it, through our travel provider Duffel. For flights that is each traveller's title, given and family name, date of birth, gender as recorded by the carrier, contact email and phone number, any frequent-flyer number you enter, and — where the airline requires one — passport or other identity-document details. For stays it is each guest's name, plus a contact email and phone number. Duffel passes this on to the airline or property, who then hold it as their own record of your reservation under their own privacy terms.
Payment details.Card details are entered into a form hosted by Duffel and its payment security provider Evervault, and go directly to them. They are never sent to, seen by, or stored on Tineris's servers. Running the 3-D Secure check your bank may require loads a script from Evervault into the page under Duffel's account. We keep only the booking reference and the amount charged.
Booking emails. When you book, pay for, change or cancel something, we send a confirmation to your account email address through our email provider Resend, who deliver it on our behalf. The message contains your booking reference and the details of what you booked, and we keep a copy of it alongside a record of whether it was delivered, so we can tell you what we sent and send it again if it did not arrive. These are transactional messages about bookings you made; we do not send marketing email.
Why we collect it
Solely to run the product: to authenticate you, to store and display your trips, to show place search results and maps when you ask for them, and — when you book — to complete the reservation you asked us to make and to give you a record of it afterwards. We do not use your data for advertising, and we do not sell it to anyone.
Who we share it with
The processors named above — Clerk, Supabase, Google Places, Mapbox, Duffel, Resend and, through Duffel, Evervault — each acting under their own data processing terms and only to the extent needed to provide the feature they support.
Bookings are different in kind, and worth stating plainly: an airline or property you book with is not our processor. They receive your traveller details to hold your reservation and become responsible for that data in their own right, under their own privacy policy. We cannot delete a reservation record on your behalf from their systems.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
How long we keep it
Trip data is kept for as long as your account exists. If you delete your account, we delete your trip data along with it, except where we're required to retain records by law.
Booking records — what was booked, with whom, for how much — are kept while your account exists, since they are the receipt for a payment you made. Deleting your Tineris account does not cancel a booking or remove it from the airline's or property's systems.
Place details returned by Google — a name, an address, coordinates and opening hours — are cached on our servers for at most seven days and then deleted, so a place you look at twice is not fetched twice.
Your rights
If you're in the EU, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at privacy@tineris.com.
Cookies
We use only the session cookie Clerk sets to keep you signed in. We don't run analytics or advertising cookies today — if that changes, this page and the relevant consent flow will change first.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page and, where required, notify you directly.
Questions? Reach us at privacy@tineris.com or see our Terms.