TripDeck Privacy Policy
Effective date: August 27, 2026 Last updated: August 27, 2026
TripDeck is operated as a sole proprietorship by Christopher S. Dye, based in Waverly, Illinois, United States ("TripDeck," "we," "us," or "our"). This Privacy Policy explains what data TripDeck collects, how we use it, and — most importantly — where your trip data actually lives.
The short version: TripDeck stores your trip content in your own cloud storage (Google Drive, OneDrive, or Dropbox). We do not keep copies of your trip reports, business cards, contacts, or engagement notes on our servers.
1. Who we are
- Operator: Christopher S. Dye, sole proprietor
- Location: Waverly, Illinois, United States
- Contact for privacy questions: [email protected]
- Website: https://gettripdeck.com
If you have any question, complaint, or request about your data, email us at the address above. We respond within 30 days.
2. What TripDeck does, in one paragraph
TripDeck turns business trips — trade shows, expos, site visits, customer meetings — into finished trip reports. You capture business cards, dictate notes, and TripDeck generates a polished report you can send to your team. The design assumption underneath everything is that you own your trip data. TripDeck writes reports and captured artifacts to a folder inside your own cloud storage. When you disconnect the app or delete your account, your data stays where it was — in your storage — and we no longer have any way to reach it.
3. What data we collect and where it lives
TripDeck data falls into two categories: a small amount of account data on our servers, and everything else in your own storage.
3a. On TripDeck's servers (minimal)
We store only what we need to sign you in and connect you to your storage:
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account identifier, sign-in, service emails | Until you delete your account |
| Password hash (bcrypt) | Sign-in verification. We never store or see your actual password. | Until you delete your account |
| First and last name (optional) | Personalization in the app UI | Until you delete your account |
| Chosen storage provider (e.g. "Google Drive") | Knowing where to write your data | Until you disconnect storage |
| OAuth refresh token for your storage provider | Writing files to your storage on your behalf | Until you disconnect or revoke access |
| The Google Drive / OneDrive / Dropbox folder ID we created for you | Knowing where in your storage TripDeck's folder lives | Until you disconnect or delete account |
| Account creation and last-login timestamps | Security, abuse prevention | Until you delete your account |
We do not store: your trip reports, business card scans, contact records, engagement notes, dictated audio, extracted text, company profile content, or any other trip artifact. Those live entirely in your storage.
3b. In your own cloud storage (everything else)
When you connect Google Drive, OneDrive, or Dropbox, TripDeck creates a folder named /TripDeck inside your account and writes everything there:
- Trip reports — the finished PDFs and structured data we generate for each trip
- Business card scans — images and extracted contact fields
- Contact records — the people you met, their affiliations, follow-up status, your notes
- Engagement notes — audio and transcripts from site walkthroughs, plus generated engagement reports
- Company profile — the description of your company that TripDeck uses to write reports in your voice
- Trip metadata — dates, locations, attendees
These files are yours. You can open them directly in your storage provider without TripDeck involved. If you cancel your subscription or delete your TripDeck account, this folder stays in your storage untouched.
3c. What we access, briefly, in flight
To generate a trip report or scan a business card, TripDeck reads the relevant files from your storage folder into memory, processes them (using AI services described in Section 5), and writes the output back. We do not retain copies of these files after processing completes. Server logs may briefly record file identifiers and timestamps for debugging, retained for no more than 30 days.
4. Google user data (Drive scope specifically)
TripDeck requests one Google OAuth scope: https://www.googleapis.com/auth/drive.file
This scope grants access only to files and folders that TripDeck creates in your Drive or that you explicitly open with TripDeck. TripDeck cannot see, read, or list any other file in your Google Drive. This is a hard technical limit enforced by Google, not a promise from us.
How TripDeck uses Google user data:
- Create the /TripDeck folder in your Drive on first connection
- Write trip reports, business card images, and JSON records into that folder
- Read those same files back when you view them in the TripDeck app
How TripDeck does NOT use Google user data: - We do not transfer your Drive data to any third party except AI processing services strictly needed to fulfill your requests (see Section 5) - We do not use your Drive data to train AI models - We do not use your Drive data for advertising - We do not sell, rent, or trade your Drive data - Humans at TripDeck do not read your Drive data. The only case where we would look at file content is if you specifically send it to us to resolve a support issue, and only then with your written permission.
TripDeck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Third-party services we use
TripDeck routes data through a small number of services strictly to deliver the product:
| Service | What it processes | Why |
|---|---|---|
| Your chosen storage provider (Google Drive / OneDrive / Dropbox) | Trip files, contacts, reports | Where your data lives |
| OpenAI (or equivalent LLM provider) | Business card text, dictated notes, generated report text | Business card OCR, transcription, report generation. Data is not used to train their models under our API terms. |
| Cloudflare | HTTP traffic to gettripdeck.com | Hosting, DNS, DDoS protection |
| A payment processor (Stripe, when subscriptions launch) | Your billing information | Charging for paid plans. TripDeck never sees or stores your card number. |
We do not share your data with any other party. We do not use analytics services that identify individual users (no Google Analytics, no session recording tools).
6. How we protect your data
- All connections to TripDeck use HTTPS (TLS 1.2 or newer)
- Passwords are hashed with bcrypt before storage. We cannot recover your password if you forget it.
- OAuth refresh tokens are encrypted at rest
- Only Christopher S. Dye has administrative access to TripDeck's servers
- The
/TripDeckfolder in your storage is protected by the same access controls as the rest of your Google/Microsoft/Dropbox account
Security is a moving target. If you spot something that concerns you, email [email protected] and we will respond quickly.
7. Your rights
Depending on where you live, you may have specific rights under law (GDPR if you're in the EEA, CCPA/CPRA if you're in California, etc.). TripDeck honors these rights globally as a matter of policy — you do not need to be in a particular jurisdiction to exercise them:
- Access — request a copy of the account data we hold about you
- Correction — ask us to fix inaccurate account data
- Deletion — delete your TripDeck account and all associated server-side data
- Export — because your trip data lives in your own storage, you already have it. Nothing to export from us.
- Revoke storage access — disconnect Google/Microsoft/Dropbox from TripDeck at any time from the app, or revoke access directly in your storage provider's account settings
- Object to processing or restrict processing — email us
- File a complaint — with your local data protection authority if you're in the EEA
Email [email protected] for any of these. No fee, no forms — just ask.
8. Data retention and deletion
- Account data: kept until you delete your account. Deletion is immediate and covers everything in Section 3a.
- Server logs: 30 days
- OAuth tokens: revoked immediately when you disconnect storage or delete your account
- Files in your storage: untouched. If you want them deleted, delete the
/TripDeckfolder in your storage provider.
To delete your account, sign in to TripDeck and use Settings → Delete Account, or email [email protected].
9. Children
TripDeck is a business tool. It is not directed at anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, email us and we will delete it.
10. International transfers
TripDeck is operated from the United States. If you use TripDeck from outside the U.S., your account data (Section 3a) will be transferred to and processed in the U.S. Your trip data (Section 3b) stays wherever your storage provider stores it — for most European users, that is a data center within the EU, controlled by Google, Microsoft, or Dropbox, not by us.
11. Changes to this policy
We'll update this policy when TripDeck's data practices change. Material changes will be announced by email to your account address at least 14 days before they take effect. The "Last updated" date at the top always reflects the current version.
12. Contact
- Email: [email protected]
- Postal: Christopher S. Dye, Waverly, Illinois, United States (mailing address available on request)
We aim to respond within 5 business days. Complex requests may take up to 30 days.