Privacy policy
Last updated: 11 June 2026
This policy explains what personal data The Puzzle Trip("we", "us") processes, why, and your rights under the EU General Data Protection Regulation (GDPR). We are the data controller for the data described here.
Data we process
- Search and trip data you enter (origins, destinations, dates, travelers) — used to return results and build your trip.
- Account data (email address), only if you create an account — used to save trips and send the emails you opt into.
- Trip content (the pieces you add) — saved so you can return to your puzzle, including anonymous trips identified by a random share link.
- Technical data — privacy-friendly, aggregate analytics with no cross-site tracking and no advertising cookies.
How we use it
- To provide search results and assemble and save your trips.
- To send price alerts and trip emails you have opted into (double opt-in).
- To measure, in aggregate, which features are useful and improve the product.
Our legal bases are performance of a service you request, your consent (for marketing emails and non-essential cookies), and our legitimate interest in running and improving a secure service.
Partners and transfers
When you click Book, we redirect you to a travel partner. From that point the partner's own privacy policy applies. We share only the search context needed to open the relevant page, plus our affiliate marker. We never share your payment details — we never collect them.
We use Supabase (database/auth, EU region) and Resend (email) as processors, and a privacy-friendly analytics provider. Where data is processed outside the EEA, appropriate safeguards are in place.
Retention
We keep trip and account data while your account is active or your trip link is in use, and delete or anonymize it on request. Aggregate analytics contain no personal identifiers.
Your rights
You can request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent at any time. Email hello@thepuzzletrip.com. You may also lodge a complaint with your local data protection authority.
Operator note: replace this with your registered legal entity name, address and DPO/contact details before going live.