← TripSmasher

Privacy policy

Last updated: August 25, 2026

1. Introduction

This Privacy Policy describes how TripSmasher collects, uses, stores, and protects its users’ information.

TripSmasher is a tool for specialized travel agents. It allows selectively capturing hotel, flight, transfer, and other service offers from wholesaler and OTA sites (via a Chrome extension), gathering them into shared team (agency) quotes, building options (manually or with AI assistance), and exporting or sharing them with the passenger (PDF and/or native share, e.g. WhatsApp).

Hereinafter, TripSmasher is called “the Service”, including the website, dashboard, API, and Chrome extension. By using the Service, you accept the practices described in this document.

We commit to processing personal data responsibly and in accordance with Argentine Personal Data Protection Law No. 25.326 (PDPA) and equivalent rules in force in Latin American countries where the Service operates.

2. Data we collect

We collect only the data needed to operate the Service.

2.1 Account and session data

  • Email address, name, and, if you sign in with Google, profile image.
  • Password (stored hashed/encrypted; never in plain text) if you register with email.
  • Web session data: IP address and browser user agent (security and authentication).
  • Extension auth tokens, stored in Chrome local storage (`chrome.storage`) on your device.

2.2 Team and configuration data

  • Team (agency) name, logo (if uploaded), contracted or free plan, and memberships (roles: owner / member).
  • Invitations: invitee email and name, who invited, and link status (valid, accepted, or revoked).
  • Preferences: default active team and active quote in the extension.
  • Team commercial agreements: markup by provider and service type (percentage, fixed amount, or none).

2.3 Quote operational data

Quote content is loaded by the agent. It may include:

  • Title, recipient, number of adults / children / infants and children’s ages.
  • Quote status (in progress, sent, closed, archived).
  • Agency clients (when using the clients module): name, phone, email, and notes you enter.
  • Pool candidates (hotels, flights, transfers): prices, currency, dates, occupancy, cancellation policies, itineraries, stops, transfer details, and other fields extracted or edited by you.
  • Options and line items: variant dates, markup, and sell prices.
  • Who captured or edited each element (user audit).

This data is agency content. We do not use it for advertising or sell it to advertisers.

2.4 Selective capture data

When you enable capture mode in the extension and click a block on the page (a hotel card, an itinerary, etc.):

  • The content script takes an HTML fragment of the chosen element (and, if applicable, the expanded detail of that same selection: it does not crawl the listing or the whole site).
  • That HTML, together with the page URL and capture metadata, is sent to our servers for automatic analysis (structured extraction).
  • We may keep the original HTML transiently or associated with the candidate, for re-analysis, error correction, or support.

We do not capture background browsing. There is no crawler, mass scraper, or per-provider extractors. Only what you explicitly send is processed.

2.5 Automated processing data (AI)

  • Usage records for analysis and assisted option building (e.g. operation volume, for plan limits).
  • Content sent to language models (converted HTML, prompts you write, pool candidates) is processed to extract or propose structure. See section 4.

2.6 Communications

  • Messages you send via the contact channel (email or others we indicate on the site).
  • Transactional Service notices (security, terms changes, invitations if email sending is added later).

3. How we use your data

We use your personal data for the following purposes:

  • Providing and improving the Service: authentication, teams, collaborative quotes, capture, analysis, option building, PDF, and share.
  • Associating each capture and edit with the active team and quote.
  • Showing real-time updates to those who have the same quote open.
  • Measuring aggregated usage for plan limits and operations.
  • Sending Service-related communications (not third-party advertising).
  • Complying with legal obligations.

We do not use your data for third-party advertising or sell it to advertisers.

4. Artificial intelligence

Part of the Service uses language models (for example via providers such as Groq, Google Gemini, or equivalents, sometimes through a gateway). Current purposes:

  • Extracting structured data (hotel, flight, transfer) from HTML you capture.
  • Proposing option builds from prompts or presets you choose.

That content is sent to AI providers for processing. We do not control third-party models. You can and should edit prices, text, and conditions: extraction may contain errors.

We do not use your quote content to train our own public-facing models. Whether a third-party provider retains or uses data to train its models is governed by that provider’s policies. We choose providers and configurations oriented to API / production use, not public training, to the extent the provider’s contract allows.

The Service does not invent rates as a source of truth: the valid price is the provider’s; TripSmasher only organizes what was captured and what the agent corrects.

5. Chrome extension — permissions and scope

The extension requests broad host permissions (`http://*/*` and `https://*/*`) because agents work across many wholesalers and OTAs, and there is no closed domain list.

That does not mean we read everything you browse. In practice:

  • The picker (highlight and capture) activates only when you turn capture mode on.
  • HTML is taken only from the element you choose with a click.
  • We store in `chrome.storage` what the session needs (tokens, active team/quote, local preferences).
  • The extension talks to our authenticated API; it does not publish HTML to public third-party webhooks.

Typical additional technical permissions: `storage`, `tabs`, `sidePanel`, `windows`, `contextMenus` (side panel, active tab, context menu).

If you uninstall the extension, local Chrome data is removed per browser behavior; data already sent to the server remains on the account / team until deletion is requested or performed.

6. Sharing data with third parties

We do not sell or rent personal data. We may share limited information with:

  • Google — sign-in (OAuth). We do not access Drive, Gmail, or Calendar.
  • AI providers — extracting or proposing data from HTML and prompts you send.
  • Hosting and infrastructure — Vercel (web/API and files such as logos), PostgreSQL database, object storage.
  • Pusher — real-time events when a quote is open (e.g. “a candidate was added”).
  • Upstash — short-lived queues and/or cache (e.g. recent option-building chat history, with TTL).
  • Payment processors — when paid plans exist (the provider will be indicated in billing; today the initial plan is free).
  • Authorities — when required by law or court order.

Any processor accessing data must treat it for the purposes of this Policy and applicable law.

Members of the same team see quotes and the pool under product rules (in the MVP, work is collaborative at team level; the default list may show “mine”). The team owner is responsible for whom they invite.

7. Google — sign-in

Google access is limited to authentication. This means:

We do not use Google Drive, Gmail, Calendar, or other restricted APIs. This Policy complies, as applicable to Sign-In, with Google’s user data rules.

8. PDF, clipboard, and WhatsApp (native share)

You may export quotes or options to PDF or share them via the system’s native mechanism (Web Share, clipboard, or a `wa.me`-style link).

  • TripSmasher does not operate a WhatsApp Business channel, does not read your chats, and does not send messages on your behalf automatically.
  • When you share, content leaves our Service to the app you choose. That app has its own policies (Meta/WhatsApp, email client, etc.).
  • You are responsible for not including data you should not send to the passenger or third parties.

9. Storage and security

Data is stored on servers with reasonable technical and organizational measures: encryption in transit (TLS/HTTPS), password hashing, access control by account and team, and tokens for the extension.

No Internet system is 100% secure. If you suspect unauthorized access, write to us immediately at hola@tripsmasher.co.

10. Data retention

We retain data while the account or team is active or as needed to provide the Service (history, plan limits, archived quotes or soft-deleted quotes).

  • Assisted option-building cache history may expire within hours (e.g. 24 h).
  • If you delete a team (owner confirmation), soft delete applies; data may be kept for a reasonable time for integrity, backups, or law.
  • If you request account deletion, we will proceed within a reasonable period, unless law requires retaining certain information.

In the MVP there is no immediate physical deletion of quotes from the UI (archive / soft delete yes).

11. Your rights

Under applicable law, you may:

  • Access personal data we hold about you.
  • Rectify inaccurate or outdated data.
  • Request erasure (“right to be forgotten”).
  • Object to certain processing.
  • Request data portability.

To exercise them: hola@tripsmasher.co. The team owner should coordinate requests affecting the whole agency or other members’ data.

12. Cookies and similar technologies

We use technical and session cookies needed to authenticate the web dashboard and run the Service. We do not use third-party advertising cookies without consent.

The extension uses Chrome local storage, not third-party site cookies, for its session.

You may reject cookies in the browser; that may prevent web sign-in.

13. Minors

The Service is aimed at professionals. It is not intended for anyone under 18. We do not knowingly collect minors’ data. If you believe a minor has provided us data, tell us so we can delete it.

Passenger data (names, children’s ages on a quote) is entered by the agent in a professional role; the agent is responsible for having a lawful basis to process their clients’ data.

14. Changes to this Policy

We may update this Policy. We change the “last updated” date and, if the change is significant, we will notify you by email or with a notice in the Service.

15. Contact

Questions or exercise of rights: hola@tripsmasher.co.