Legal
Privacy Policy
Last updated October 9, 2026
Giro helps you plan trips. This policy explains what personal information we collect, why, who we share it with, and the choices you have. We follow the principles of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
1. What we collect
When you create an account
- Your name and email address.
- Your password, stored only as a salted, one-way hash. We can't see it.
- Optional preferences: home currency and home airport.
When you use Giro
- Trips: destinations, dates, party size, budget, interests, notes, and any edits you make.
- Group trips: who is on a trip and their role, votes on activities, and shared expenses (amount, description, who paid and who it's split between). These are visible to everyone on that trip.
- Travel DNA: a taste profile derived from what you swap, remove, book and vote on. You can view and reset it on your account page.
- Partner clicks: when you follow a booking link, we record which partner, the trip, an estimated trip value, the time, and your account if you're signed in. This is how we earn and reconcile commissions.
- Security data: your IP address, used to limit repeated sign-in, sign-up and reset attempts. These records are deleted within about a day.
When you don't sign in
Trips, preferences and packing checklists are kept in your browser's local storage on your device. They aren't sent to us unless you create an account, at which point they move into it.
What we don't collect
We don't take payments or store card details; bookings happen on our partners' sites. We don't collect your precise location, and we don't sell personal information.
2. Why we use it
- To provide Giro: planning, saving and syncing trips, group features, and account emails (confirmation, password reset, invites you send).
- To personalise suggestions using your Travel DNA.
- To keep Giro secure and prevent abuse.
- To measure which partners are useful and to earn commissions that keep Giro free.
- To improve the product, using aggregated information wherever possible.
We only use your information for these purposes, or for others you consent to or that the law permits.
3. Giro AI
If you turn on Giro AI, the trip details you enter (destinations, dates, party size, budget, interests, must-sees, things to avoid, and notes) are sent to Anthropic, our AI provider, to generate your itinerary. Please don't put sensitive personal information (such as health details) in notes. Giro AI is optional; the standard planner runs without it.
4. Who we share it with
We use trusted service providers to run Giro. They may only use your information to provide their service to us:
- Vercel: website hosting, and anonymous visit statistics (pages viewed, referrer, country and device type) collected without cookies.
- Neon: database hosting.
- Anthropic: Giro AI, only when you use it.
- Resend: sending account and invite emails.
- Open-Meteo and Frankfurter: weather forecasts and exchange rates. We send only a city or location and currency codes, never your personal information.
- Wikipedia, Wikimedia Commons and OpenStreetMap: place history, photos, coordinates and map tiles. Our server looks up place names; map tiles load in your browser, so OpenStreetMap sees your IP address, as any website you visit would.
Travel partners. When you follow a booking link, you leave Giro for the partner's site (e.g. Booking.com, Expedia, Airbnb, Google Flights). The link includes your search details (destination, dates, party size, currency) and, for some partners, a click reference code, but not your name or email. The partner's own privacy policy applies from there.
Other members of your trips can see your name, votes and the expenses you add on those trips.
We may also disclose information if required by law, or to protect the safety, rights or property of our users or the public.
5. Where your information is stored
Our service providers store and process information in the United States, so it may be accessible to authorities there under U.S. law.
6. Cookies and local storage
We use one essential cookie, giro_session, to keep you signed in. We don't use advertising or third-party tracking cookies. Your browser's local storage holds trips (when signed out), your Travel DNA and packing checklists. Partner sites may set their own cookies after you visit them.
7. How long we keep it
We keep your account information until you delete your account. Deleting it (Account → Delete account) permanently removes your profile, the trips you own (including for other members of those trips), your trip memberships, votes, expenses you paid, and sessions. Partner click records are kept for commission reconciliation, but are no longer linked to you. Our database provider may hold encrypted backups for a short period before they expire.
8. Your choices and rights
- Access and correction: view and edit your profile on the account page, or ask us for a copy of your information.
- Deletion: delete your account at any time from the account page.
- Withdraw consent: stop using Giro AI, reset your Travel DNA, or delete your account.
- Complaints: contact us first. You can also complain to the Office of the Privacy Commissioner of Canada.
9. Security
We protect your information with encrypted connections (HTTPS), hashed passwords and session tokens, access controls on trips, and rate limits on sensitive actions. No system is perfectly secure, so please use a unique password.
10. Age
You must have reached the age of majority in your province or territory to create an account. Adults may include children on trips they plan.
11. Changes
If we make material changes to this policy, we'll update the date above and, where appropriate, let you know by email or in the app.
12. Contact
Questions or requests about privacy: hello@girotrips.com.