Privacy Policy
Last updated: June 2026
This Privacy Policy explains what personal data TastePass collects, why, and the choices you have. For any privacy question or data request, email support@tastepass.co.
1. Summary
We collect the minimum needed to build and deliver your itinerary and to run the service. We don’t sell your data. There is no advertising tracking.
2. What we collect
- Account and contact: your email address.
- Trip inputs: the details you enter to build an itinerary, destinations, dates, who’s travelling, where you’re staying, interests, budget, pace, and any special occasion.
- Purchase data: handled by Paddle (our Merchant of Record). We never see or store your full card details, Paddle does, as a PCI-DSS-compliant processor.
- Waitlist: if you join a city waitlist, your email and the city you asked about.
- Technical: standard security and operational logs our hosting keeps (IP, request metadata).
3. Why we use it
To create and deliver your itinerary, send transactional emails (purchase confirmation, your itinerary, and any launch notifications you asked for), provide support, prevent abuse and fraud, and meet our legal obligations.
4. AI processing
Your trip inputs are processed by AI models (via Anthropic’s API) to generate your itinerary. They are used to produce your trip and are not used to train third-party models. Venue data is verified via Google Places.
5. Who processes your data (sub-processors)
- Cloudflare, hosting, storage, security (USA / global).
- Anthropic, AI itinerary generation (USA).
- Google (Places / Maps), venue verification, photos, map links.
- Resend, transactional email (USA).
- Klaviyo, marketing and lifecycle email + waitlist notifications (USA / global).
- Paddle, payments and Merchant of Record (UK / global).
- Microsoft Clarity, privacy-friendly analytics: heatmaps and masked session recordings to see where the site can be improved. It masks page content and sensitive input by default and respects Do-Not-Track; it is not advertising tracking (USA / global).
We don’t sell or share your data for advertising.
6. Cookies
We use only what’s strictly necessary to run the site and remember your session and preferences. No advertising or cross-site tracking cookies.
7. Data retention
We keep your account, itineraries, and purchase records while your account is active and for a reasonable period after, or until you ask us to delete them, whichever comes first, subject to legal and accounting retention requirements (handled largely by Paddle for transactions).
8. Your rights
Email support@tastepass.co to access, correct, export, or delete your data, or to unsubscribe. If you’re in the EU/UK or California, you have the rights granted by GDPR, UK GDPR, and CCPA, and we honor them regardless of where you live.
9. International transfers
Your data may be processed in the USA and elsewhere by the providers above, under appropriate safeguards.
10. Security
We use encryption in transit (TLS) and reputable processors. No system is perfectly secure, but we take reasonable measures to protect your data.
11. Children
TastePass is not directed to children under 18, and we don’t knowingly collect their data.
12. Changes & contact
We may update this notice; the “Last updated” date will change. Questions or requests: support@tastepass.co.