Privacy policy
Last updated: July 2026.
1. Data controller
The service is operated by the publisher of TripMyWeek (see the legal notice). For any question or request regarding your data: contactme@tripmyweek.fr.
2. Data we collect
- Account: email, first name, last name, phone (optional except email), password.
- Public profile: the nickname you choose and/or an initials acronym, and your chosen avatar.
- Itineraries: the criteria you enter and the itineraries you save.
- Community content: your ratings and comments.
- Verification & security: if enabled, a temporary email code (valid 15 min); optional 2FA secret.
- Technical: error logs and an anti-abuse usage counter.
3. Purposes and legal bases
- Provide the service (generate/save itineraries, community space) — performance of the contract.
- Secure access, prevent abuse and fraud, moderate content — legitimate interest.
- Email verification, when enabled — legitimate interest / your request.
4. Public content and visibility
Saved itineraries may appear publicly in the community showcase, and your ratings/comments are visible to other members. In all cases you are identified only by your nickname or an initials acronym — never by your real name or email. Do not share personal or sensitive data in itineraries or comments.
5. Automated moderation
Free-text comments may be screened by a keyword filter and by an AI classifier to detect insults, spam or personal data. Only the comment text and a technical identifier are sent for this check — never your name or email. This screening does not produce legal effects concerning you; a comment can be reviewed on request.
6. Recipients and processors
- An AI provider, which receives your travel criteria (to generate an itinerary) or comment text (to moderate it).
- The hosting provider and, if configured, an email (SMTP) provider.
- Public map/weather/photo services: OpenStreetMap, Open-Meteo, Wikimedia Commons.
We never sell your data. Some providers may process data outside the EU, under appropriate safeguards.
7. Security
Sensitive fields (name, email, phone, itineraries) are encrypted at rest (AES-256-GCM); passwords are stored hashed (bcrypt) and never in clear; access is over HTTPS. Optional 2FA adds a one-time code at login.
8. Retention
Account and community data are kept while your account exists. Deleting your account removes your data and your saved itineraries, ratings and comments. Technical logs are purged regularly.
9. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, object to and port your data. Write to contactme@tripmyweek.fr. You may also lodge a complaint with your data-protection authority (in France, the CNIL). Hosting takes place within the European Union.
10. Cookies
Only strictly necessary cookies are used: a session cookie (to keep you logged in), and small preference cookies for your language and light/dark theme. No advertising or third-party tracking cookies.
11. Minors
The service is not intended for children under 15 without the consent of a legal guardian.