← Back to home

Privacy Policy

Last updated: 26 August 2026

Who we are

Family Travel Command Centre ("we", "our", "us") is a trip-planning tool built for families. Our website is tripcommandhq.com. If you have questions about this policy, contact us at support@tripcommandhq.com.

What we collect

We only collect information you provide directly:

  • Account information — your email address when you sign up or log in.
  • Trip data — destination, dates, traveller details, booking information, packing lists, and budget entries you enter into the app. This data is stored against your account and used solely to power your trip planning.
  • Travel documents — passport, visa and travel insurance details you choose to record (e.g. document numbers, expiry dates, policy numbers), plus any scans, certificates or policy files you upload for them.
  • Emergency and medical information — emergency contacts and medical/medication notes you choose to enter for your trip.
  • Waitlist submissions — your email address if you join the early access list.
  • Payment information — handled entirely by Stripe. We do not store card numbers or payment credentials on our servers.

How we use your information

  • To provide and operate the Family Travel Command Centre service.
  • To send transactional emails (sign-in links, password resets, booking confirmations).
  • To send a short series of trip-planning emails after you sign up — a welcome note and, if it looks like your setup has stalled, a few practical nudges and an offer of help. You can turn these off at any time from Account settings or the unsubscribe link in any of them; doing so never affects sign-in links, password resets or other account and security emails.
  • To notify early-access waitlist members when features launch.
  • To process payments via Stripe.
  • If you choose to use AI-assisted booking extraction, to send the booking text or image you submit to our AI processor so it can pull out flight, hotel or other booking details for you (see "AI-assisted booking extraction" below).

We do not sell your data. We do not use your trip data for advertising.

Travel documents, emergency and medical information

Passport, visa and insurance details, and any emergency contact or medical/medication notes you enter, are saved against your account like the rest of your trip data.

Document files (scans, certificates, policy documents you upload against a Passport, Visa or Insurance record) are stored in Supabase Storage, with file metadata in our Supabase database, and are only accessible to you, the trip owner — they are not shown to anyone you share or review a trip with.

Emergency contacts and medical/medication notes are treated as ordinary trip data, not as owner-only files: if you share a trip or someone opens it in review mode, they can see these details too. Only record what you're comfortable sharing with the people you give trip access to.

AI-assisted booking extraction

Family Travel Command Centre offers an optional feature to help you add bookings faster by extracting flight, hotel and other details automatically. This only happens when you choose to use it — it is not applied to your trip data generally.

  • If you paste or type booking text for extraction, that text is sent to Anthropic (maker of the Claude AI models) to identify the booking details.
  • If you upload a booking screenshot (PNG/JPEG) for extraction, that image is sent to Anthropic for the same purpose.
  • If you upload a PDF booking confirmation, the PDF itself is parsed server-side within FTCC to pull out text — it is not sent to Anthropic. If that extracted text is then run through AI-assisted extraction, the text (not the original PDF file) is sent to Anthropic at that point.

Anthropic handles content sent through this feature under its API/commercial privacy terms. See anthropic.com/legal/privacy for details.

Third-party services

  • Supabase — authentication, database and file storage hosting. Your account, trip data, document metadata and uploaded document files are stored on Supabase infrastructure. See supabase.com/privacy.
  • Anthropic — AI-assisted booking extraction. Only used when you choose to extract a booking from pasted text or an uploaded image, as described above. See anthropic.com/legal/privacy.
  • Stripe — payment processing. See stripe.com/privacy.
  • Vercel — hosting and delivery. See vercel.com/legal/privacy-policy.
  • Google Maps Platform (Places API) — for Hotel bookings, we look up the property's official website and phone number using Google's Places API so we can show you a direct way to contact or visit your hotel. We send the hotel's name and the address you provided to Google to find a match. We never send Google any other trip, traveller, or account data. We store the Google place identifier for the property we matched, so we don't have to repeat the full name-and-address search every time — this identifier can occasionally change on Google's side, so we may need to re-match a property from time to time. Any other information Google returns (website, phone number) is fetched fresh each time it's needed and is never stored in our database. See policies.google.com/privacy and Google Maps Platform Terms of Service.

Cookies and local storage

We use browser local storage to save your trip data when using the demo without an account. We use session cookies for authentication. We do not use advertising cookies or third-party tracking pixels.

We also use first-party product analytics, hosted on our own servers, to understand how people find and use the service — for example, which page led you here and whether you completed key steps like creating a trip. If you arrive via a marketing link, we record the campaign tags in that link (such as source and campaign name) using local storage, so we can tell which campaigns are working. We do not sell this data, we do not share it with advertising networks, and we do not use your trip data (destinations, dates, bookings, documents, or any of the information described above) for this measurement — only anonymous product and campaign-tag events.

Data retention

Your account and trip data is retained while your account is active. You can request deletion of your data at any time by emailing support@tripcommandhq.com. We will process deletion requests within 30 days.

Your rights

You have the right to access, correct, or delete the personal data we hold about you. To exercise any of these rights, contact us at support@tripcommandhq.com.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

Questions or concerns? Email us at support@tripcommandhq.com.