Draft — not publishable yet. Placeholders below must be filled and the whole
document reviewed before any external tester sees it. PRD §12 requires a real privacy policy on
a verified domain first.
Privacy
Last updated: [DATE]
Trip Tracker reads your email inside your own Google account. Your messages are never
transmitted to us, and we have no ability to read them.
How it works
Setup places a Google Sheet in your Drive containing a script. That script runs under your own
Google authorization, in Google's infrastructure, not ours. When you ask for a search, it reads
matching booking emails, extracts the details, and sends only those details to our
service so your phone can display them.
We do not hold credentials for your Google account. We cannot initiate a scan. We cannot read
an email you have not asked us to extract from.
What we receive and keep
- Booking details: type, title, provider, confirmation code, dates, times, and location.
- The Gmail message ID of each booking, so re-scanning updates rather than duplicates it, and
so the app can link back to the original message in your own Gmail.
- A pairing token identifying your account. It is random and contains nothing about you.
- Sender domains of emails we failed to parse — the domain only, never content — so we know
which providers to support next.
What we never receive
- Message bodies, subjects, attachments, or any email that is not a booking.
- Your Google password or any Google credential.
- Your contacts, calendar contents, files, or anything outside the bookings you request.
Third parties
- Cloudflare hosts the service and its database. [Region
and retention to be stated.]
- OpenStreetMap / Nominatim converts addresses to map coordinates. A booking's
address is sent to resolve it; nothing identifying you is included.
- Google hosts the script and your email. Their terms govern that
relationship, not ours.
- [QR code generation currently uses a third-party image service, which receives
the pairing token. To be replaced with client-side generation before launch — do not ship
this policy until that is resolved or disclosed.]
Calendar reminders
If enabled, the script writes reminder events into your own Google Calendar at scan time. Those
events are created by your script in your calendar; we do not read your calendar.
Removing your data
- Revoke the script's access at
myaccount.google.com/permissions.
It stops immediately, without involving us.
- Delete the Sheet from your Drive to remove the script entirely.
- Email [CONTACT ADDRESS] to have stored booking details deleted.
[Response time to be stated.]
Changes
If this policy changes in a way that affects what we receive or keep, we will say so here and
date it. [Notification method to be decided.]
Contact
[CONTACT ADDRESS] · [LEGAL ENTITY OR INDIVIDUAL NAME] · [JURISDICTION]
← Back