Legal

Privacy Policy

Effective: September 3, 2026 · Last updated: September 3, 2026

This policy describes what Zups collects, how we use it, who we share it with, and the choices you have. If something changes materially, we will update this page and update the "Last updated" date above.

Zups is operated by James Zupa ("Zups", "we", "us"). Questions about this policy can go to jameszupa@zupstravel.com.

Summary

1. Information we collect

Before you create an account

When you first open the app to go through onboarding, Zups creates a temporary anonymous session on our backend so your onboarding choices (for example, your typed home city and travel preferences) can persist before you register. If you complete signup, that anonymous session is upgraded into your registered account and the onboarding choices become part of it.

Account and profile information

Content you create

Photos and media

If you upload a photo (for your profile or a postcard), the photo is stored on Zups' backend infrastructure so we can display it back to you and, if you share the postcard into a Community you have joined, to other members of that Community. Zups does not send your uploaded photos to advertising networks or booking partners.

Home base — no GPS

Zups needs to know your "home airport" to plan trips from it. You choose this manually — you type a city name, Zups looks it up against OpenStreetMap's public geocoder to find the nearest airports, and you pick one. Zups stores the city name and 3-letter airport code. Zups does not store latitude/longitude, and Zups does not ask your device for your GPS location. The iOS Location permission dialog does not appear in the app.

How you use the app (product analytics)

Zups records first-party product-interaction events — for example, opening a trip idea, saving a trip, starting to plan, or tapping a booking link. This helps us understand which content is useful and which is not. These events are stored in Zups' own backend, linked to your account. Zups does not send them to Amplitude, Mixpanel, PostHog, Google Analytics, Segment, Facebook, or any other third-party analytics vendor. There is no third-party analytics SDK in the app.

Booking handoff records

When you tap a "book with" link inside Zups, we log the fact that you clicked it — including origin, destination, and dates — so we can understand what people are trying to book. If a partner completes a booking, they may send us a delayed confirmation (see "Booking partners" below). No credit card, passport, or personal booking detail is ever sent through Zups — you complete the booking on the partner's website.

Support communications

If you email us, we keep the email so we can respond.

What Zups does not collect

2. How we use your information

We do not use your information for advertising, retargeting, profiling, or sale to data brokers.

3. Location — clear statement

Zups does not obtain your precise location from your device. The iOS Location permission prompt does not appear in the Zups app. The only "location" data associated with your account is the home city label and 3-letter airport code you chose during onboarding. You can change this in Settings at any time.

4. Who we share information with

Zups uses a small number of trusted service providers to operate. Each receives only what they need to do their job.

ProviderWhat they do for ZupsWhat they receive
Supabase Database, authentication, storage, edge functions (our primary backend) Everything you save in Zups: account, profile, trips, postcards, journal, product events.
Apple Sign in with Apple Apple's own identifier for you. If you use Apple's private-relay email, we receive the relay address, not your real email.
Google Continue with Google (OAuth) Google's own identifier for you and the email associated with your Google account.
Expo (EAS) Mobile app builds and over-the-air updates App bundles and update channels — no user data.
OpenStreetMap Nominatim Converts a city name you type into approximate coordinates so we can suggest nearby airports The city string you typed and a generic "ZupsApp" User-Agent. No account identifier.
Google Routes API Ground transit routing between cities you've added to a trip Origin and destination city references. No account identifier. Query is made from our servers, not your device.
Compensated affiliate providers (Kiwi.com via Travelpayouts, Expedia) Provide flights and accommodations you can book. Zups may earn a commission on qualifying bookings, at no extra cost to you. Zups is not the seller. The trip parameters needed to pre-fill the provider's search — origin, destination, dates, number of adults — plus Zups' affiliate marker. See Affiliate Disclosure.
Other external providers (Hostelworld, Rome2Rio, GetYourGuide, Viator, and individual ferry operators for certain island routes) Provide additional accommodations, ground transport, routing information, and experiences you can plan or book. Zups is not the seller and does not currently earn a commission from these links. The trip parameters needed to pre-fill the provider's search — origin, destination, dates, number of adults.
fal.ai (server-side only) Generates editorial images used inside the app Text prompts written by us — no user data.

We do not share your information with advertisers, data brokers, marketing platforms, or any party not listed above.

Booking partner data — what actually gets sent

When you tap a "book flights", "find hotels", "browse experiences" or similar link, Zups opens the partner's website with a URL that includes: the trip context (origin, destination, dates, adult count) and our affiliate marker. Zups also includes a random identifier used solely so the partner can tell us if a booking eventually completes. This random identifier is not your Zups account ID or email — it's a separate opaque token stored server-side. We do not send your name, email, Apple identifier, or precise location to booking partners.

Once you land on the partner's website, the partner's own privacy policy governs what happens next — including any cookies they set, any account you create with them, and any booking you make.

5. Sign-in methods

You can create or sign into a Zups account using any of the following:

When you delete your Zups account (see below), and if you originally signed in with Apple, Zups attempts to revoke Apple's authorization so the link between your Apple ID and the deleted Zups account is severed. If you later sign into Zups with the same Apple ID, Apple treats it as a brand-new user and you get a fresh, empty account.

6. Postcard and profile visibility

Every Zups account is private by default. This is enforced by Zups' backend access rules, not just by the app's user interface:

7. User-generated content, reporting, and moderation

You control the content you create. Zups supports reporting and blocking so other members of a Community can flag content they find objectionable:

8. Deleting your account

You can delete your Zups account from inside the app:

Settings → Danger Zone → Delete Account → confirm twice.

When you delete your account, Zups:

What is retained after deletion, and why: Zups keeps aggregate booking-handoff and booking-link-click records — rows that log which trip context led to which partner click. Before these records are retained, your account identifier is removed from them, so they are no longer associated with your Zups account. Zups keeps them to understand which trip ideas convert into booking attempts, in aggregate, and for partner attribution. These records are retained in a form no longer associated with your Zups account, and they still contain the trip-context fields already in the row (origin, destination, dates, partner).

Authentication server logs held by our infrastructure providers (records that a login happened, tokens issued, etc.) are retained by those providers under their own retention policies and are not directly controllable by Zups.

If you'd rather delete your account by email — for example if you can't get into the app — write to jameszupa@zupstravel.com from the email associated with your account (or from your Apple-relay email) and we will process it manually.

9. Data retention

We keep your account data for as long as your account exists. If you delete your account, we delete it as described above. If you become inactive but don't delete your account, we keep your data so it's ready when you come back.

Support emails are kept for as long as needed to help you, then discarded.

10. Data location

Zups' primary backend (Supabase) currently runs in the United States. If you use Zups from outside the US, you're consenting to your data being processed there. Apple, Expo, and our booking partners operate globally.

11. Minimum age

Zups is not intended for anyone under the age of 16, and we do not knowingly collect data from anyone under 16. If you believe someone under 16 has created a Zups account, email us and we will delete it.

12. Your choices and rights

See Manage Your Data for the practical how-to.

13. Security

We use standard industry practices: TLS for data in transit, database access controls on the Zups backend, and industry-standard authentication (Sign in with Apple, Google OAuth, or email with password or one-time link). No system is perfectly secure. If you find something concerning, email jameszupa@zupstravel.com.

14. Changes to this policy

If we change this policy materially, we'll update the "Last updated" date at the top and, for meaningful changes, notify active users inside the app or by email.

15. Contact

Get in touch

Zups
Email: jameszupa@zupstravel.com

For account deletion, privacy questions, or data requests, please use the email above.