PRIVACY
What TabiTabi knows about you.
TabiTabi is a trip planner. This policy explains what it holds about you, why, who else can see it, and how to make it stop — in the same plain language as the rest of the app.
In effect from 1 August 2026.
Who is responsible
TabiTabi is operated by Piraeus Technology LLC, a company formed in New Jersey, United States. Under the UK and EU GDPR we are the controller of the personal data described below.
For anything in this policy — a question, a request, a complaint — write to piraeustechnology@gmail.com.
We have not appointed a representative in the EEA or the UK. We rely on the exemption for processing that is occasional, low risk, and does not involve large-scale special-category or criminal-offence data. We will revisit that position before those facts change.
What TabiTabi collects
Nothing at all, until you act. You can open TabiTabi, explore the example trip it comes with, and close it again without signing in. Anything you change there is written to your own browser and is never sent to us.
When you sign in
Signing in with Google, with Apple, or through an email link creates an account record held by Firebase Authentication. It contains:
- your email address — if you sign in with Apple and choose to hide it, we receive only Apple's private relay address, and that is all we ever see;
- the display name and profile photo your provider supplies, where it supplies them;
- an account identifier, plus the times you signed in.
What you tell us about yourself
Your account profile holds a nickname, a home country, and a count of countries you have visited. All three are optional, all three are yours to change or clear, and the count is a number you type — not anything TabiTabi observed or inferred.
What you plan
A trip is whatever you put in it: a title, destinations, dates, a base currency, notes, the names you give your travel companions, the itinerary, and the expenses with their amounts and currencies. When you pick a place from a suggestion rather than typing it freely, the trip also stores that place's Google identifier and its coordinates so the map can draw a pin.
Account-linked trip metadata
Signed-in trips also carry the account identifiers of members, each member's role and expense-editing grant, the account link on a claimed traveler, and the account identifier that created each traveler, itinerary item, and expense. Signed-in records also carry current and previous revision identifiers and record timestamps. Invite records hold the trip title, the access they grant, the identifier and name of the traveler they seat, and when they were created; a join receipt holds the invite identifier and the time that account joined.
Companions' names are what you choose to type. A traveler on a trip is a label you write. Nothing obliges it to be anyone's legal name, and TabiTabi does not ask for a companion's email, phone number, or date of birth anywhere.
Technical data
TabiTabi is served by Firebase App Hosting. Google keeps request and runtime logs — including IP addresses, timestamps, requested routes, and failures — and exposes aggregate operational measurements such as request counts, error rates, bandwidth, and resource use. Server failures are also available through Cloud Error Reporting. We use this operational information only to run, secure, and troubleshoot the service, not to follow people or analyze product behaviour. Place suggestions, Maps features, and the exchange-rate lookup are direct browser requests governed by the services described below.
What TabiTabi does not collect
This list is short and deliberate, and it is worth stating plainly because so many travel apps do the opposite:
- No product analytics and no tracking. TabiTabi includes no analytics, advertising, attribution, session-replay, or product error-reporting SDK. We do not use App Hosting's operational logs and aggregate service measurements to profile you, follow your activity, or analyze how people use product features.
- No advertising, and no sale of data. We do not sell, rent, or share your personal information, and we do not run advertising or profiling of any kind.
- No device location. TabiTabi never asks your browser or phone for your location. The coordinates it stores belong to places you picked, not to you.
- No payment details. TabiTabi takes no payments and books nothing. The amounts in your budget are numbers you typed.
- No contacts, photos, calendar, or files. TabiTabi does not browse or read those parts of your device. On-device data it reads is limited to the storage described below.
Why we hold it, and on what legal basis
For people in the UK and the EEA, the GDPR requires us to name a lawful basis for each purpose. Ours are:
- To provide the service you asked for — holding your trips, syncing them to your devices, and sharing them with the companions you invite. Legal basis: performance of our contract with you (Art. 6(1)(b)).
- To sign you in and keep the account secure — verifying your identity and preventing abuse. Legal basis: contract, and our legitimate interest in a service that is not trivially abused (Art. 6(1)(f)).
- To answer you — replying to a request or a complaint. Legal basis: legitimate interest, and our legal obligation where the request is a rights request (Art. 6(1)(c)).
We do not rely on consent for any of it, because none of it is optional decoration on the service — which also means there is no consent to withdraw, only an account to delete.
Who else can see your trips
The people you invite. Sharing a trip is done with a link. Anyone who opens that link while signed in to TabiTabi becomes a member of that trip, and members see everything in it: destinations, dates, notes, the itinerary, traveler names, every expense, and the account-linked metadata described above. Because members receive whole Firestore documents, they can use those identifiers to attribute a traveler, itinerary item, or expense to the account that created it. A signed-in holder of an invite link can see its trip-title, access summary, and the name of the one traveler the link seats before joining; the owner can also see invite records and join receipts. Treat a trip link like a key — send it only to the people you mean to travel with, and remove a member from the trip when you no longer want them to have it.
The people who administer TabiTabi. There is no ordinary operator-facing reader of trip content, and we do not inspect trips as part of running the product. Project administrators can technically access Firestore data through Firebase and Google Cloud administration tools. We use that access only to service a deletion request, investigate a security incident, or comply with a legal obligation.
Processors and independent services. Firebase processes account, trip, and hosting data for us under Google Cloud's data-processing terms. Google and Apple act under their own terms when you choose them as an identity provider, and Google acts as an independent controller for Maps Platform. The public exchange-rate service receives only the narrow request described below.
Nobody else, unless the law compels it. We will disclose data if we are legally required to — a valid court order, for instance — and to establish or defend a legal claim. We do not use administrative access for any broader purpose.
The services behind TabiTabi
These Google services process data on our instructions so TabiTabi can operate:
- Google (Firebase Authentication) — Verifies who you are when you sign in with Google, with Apple, or through an email link, and holds the account record behind that sign-in. Their policy.
- Google (Cloud Firestore) — Stores the trips of signed-in accounts and syncs them between the devices of everyone on a trip. Their policy.
- Google (Firebase App Hosting) — Serves the site. Google keeps request and runtime logs, including IP addresses and timestamps, and exposes aggregate request counts, error rates, usage metrics, and server failures through Cloud Error Reporting. Their policy.
The following companies are independent controllers for the listed interactions. They decide how to handle the data they receive under their own terms and privacy policies:
- Google (Google Sign-In) — Handles the Google account sign-in you choose and supplies the basic account details used by TabiTabi. Google receives the sign-in request and associated device and network data. Their policy.
- Apple (Sign in with Apple) — Handles the Apple account sign-in you choose. TabiTabi requests name and email; Apple receives the sign-in request and associated device and network data, and may supply a private relay address. Their policy.
- Google Maps Platform — Provides place suggestions, map rendering, and Google Maps search and directions pages. Depending on what you use, Google receives typed or stored itinerary and place text, place identifiers, destination-derived location bounds, stored map and marker coordinates, IP address, and device and request data. Google may use and retain that data under its own terms, including to provide and improve Google products and services. Their policy.
- Google (Gemini API) — Generates the draft plans in a trip's Ideas tab, and only when you ask for one. Google receives the destination you picked from the trip's own destination list, the number of days, and the travel-style choices you selected — party, interests, pace, spending level, and whether to suggest a start time for each stop — plus the month of the trip when it has a start date. It does not receive your trip's name, notes, itinerary, expenses, travelers, account identifier, or email. TabiTabi uses the free tier of this service, on which Google may use the submitted content and the generated response to improve Google products and services. Their policy.
One other public service receives a narrow lookup request:
- ExchangeRate-API — Supplies the reference rate suggested for a foreign-currency expense. Receives the trip's base-currency code and your IP address; TabiTabi sends no other trip content or account data. Its terms.
TabiTabi uses Google Maps. Place suggestions, the trip map, and Google Maps search and directions links are Maps Platform features. Autocomplete can send the text in the field and location bounds derived from the trip's stored destinations; the map sends its stored map and marker coordinates; and search or directions links put stored itinerary text and place identifiers into a Google URL. Those requests also carry ordinary network and device data such as an IP address. We do not send your browser's or phone's own location. Your use is subject to the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy, which are incorporated into this policy by reference. Google may use and retain Maps request data under those terms, including to provide and improve Google products and services. Google Maps is contacted when you request place suggestions, open a trip map, or follow a Maps search or directions link.
TabiTabi uses Google Gemini for the Ideas tab. A trip's Ideas tab turns a few fixed choices into a draft day-by-day plan. It is never automatic: nothing is sent until you press the button, and the tab has no free-text prompt box, so the only thing you can send is a set of options and one destination picked from this trip's own destination list. That request carries the destination, the number of days, your party, interest, pace and spending selections, whether you asked for start times, and the month of the trip when it has a start date. It does not carry your trip's name, notes, itinerary, expenses, travelers, account identifier, or email address, and the request is not labelled with who sent it. Like every other request it also carries ordinary network data such as an IP address. TabiTabi uses the free tier of this service, and on that tier Google may use what is sent and what comes back to improve Google products and services, under the Google Privacy Policy and the Gemini API Additional Terms of Service. Suggestions are generated text and can be wrong or out of date; nothing is added to your trip until you save it yourself.
Where your data is stored
Accounts and trips are held in Google Cloud data centres in the United States, and the site is served from there. If you are in the UK or the EEA, using TabiTabi means your personal data is transferred to the United States.
Those transfers rest on Google's certification under the EU-US and UK-US Data Privacy Frameworks and, where they apply, the European Commission's Standard Contractual Clauses, which Google incorporates into its terms. The rights described below are yours whichever side of that transfer your data sits on.
How long it is kept
- Trips stay until deleted. Deleting a trip removes it for every member — it takes a typed confirmation, and it is permanent.
- Your account and profile stay until you ask us to delete them. When we complete that request, we delete trips you own before removing the profile and authentication account so a shared trip is never left with a dead owner.
- Trips saved in your browser are under your control, not ours. Clearing your browser's site data for TabiTabi removes them, and we never had a copy.
- Infrastructure logs and metrics are kept by Google on its own retention schedule, which is described in its documentation.
Deletion inside a shared trip has one honest limit: content you added to a trip someone else owns is part of that trip's record, and deleting your account does not reach into their plan and unpick it. Ask the trip's owner to remove the trip, or remove your entries before you go.
Your rights
If you are in the UK or the EEA, the GDPR gives you the right to ask for a copy of your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. You can edit your own profile inside the app. A trip owner can edit or delete that trip and manage its members. An editor can edit itinerary items and traveler labels, but a non-owner can delete only the itinerary items and travelers that account created. Expense access is separate: the owner or a member explicitly given expense-editing access can edit expenses, and a non-owner can delete only expenses that account created.
For requests the app does not provide — an export of everything we hold, or deletion of the account itself — write to piraeustechnology@gmail.com. We answer within 30 days. We will ask you to write from the address on the account, because handing your trips to someone who merely claims to be you would be the worse failure.
You may complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority where you live or work. We would rather you told us first, but that is your choice and not a condition.
If you are in the United States
Several states give residents rights to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information, and we do not process it for targeted advertising or profiling — there is nothing to opt out of. The access, correction, and deletion routes above are open to you on the same terms, whichever state you live in.
What is stored on your device
TabiTabi sets no advertising or analytics cookies, and there is nothing here to consent to — the following storage is used to make the app work:
- Trip data, in your browser's local database for local-only use — including the signed-out example and trips kept from earlier versions — and in Firestore's browser cache when signed in, so account trips work offline.
- Your sign-in session, stored by Firebase Authentication so you are not asked to sign in on every visit.
- A cached exchange-rate response, so a day of budgeting does not re-fetch the same rates repeatedly.
- A pending email-link address, stored as plain text after a sign-in link is sent so the same browser can finish signing in. It is removed after a successful sign-in; if the link is never completed, it remains until another request overwrites it or you clear TabiTabi's site data.
- Your per-trip Ideas draft and last suggestion, kept for the signed-in account and browser tab where you used Ideas so that refreshing the page does not discard it and spend another day's suggestion to get it back. It holds the form choices and returned itinerary, including its display-only reasons, plus the account and trip identifiers, destination options, dates, and date mode needed to check that the suggestion still fits the trip. It is removed when you leave or delete the trip or sign out, and otherwise discarded when you close the tab. Suggestions are not added to your trip unless you add them.
- Retired import records, written by earlier versions that copied trips planned in this browser into an account. TabiTabi no longer does that and no longer writes these, but a browser that held them still does. The older per-account flag contains your Firebase account identifier; the later per-trip ledger also contains identifiers for trips copied or confirmed already present in the account. Both remain until you clear TabiTabi's site data.
Google Maps may set storage of its own when it loads, under Google's policy rather than ours. Clearing site data for TabiTabi in your browser removes everything TabiTabi stores there — including any trips saved only in that browser.
Security
Your trips are protected by rules enforced on Google's servers, not merely by the app on your screen: an app account can read a full trip only if it is a member. Before joining, a signed-in person who holds the secret invite link can read the invite's trip-title, access summary, and the name of the one traveler it seats. The administrative access described above is governed separately. The rules are tested on every change to them. Traffic is encrypted in transit, and data is encrypted at rest by Google Cloud. We never handle a password — sign-in is delegated to Google, Apple, or a one-time email link.
No service is perfectly secure, and we would rather say so than imply otherwise. If you find a weakness, please write to piraeustechnology@gmail.com — we would genuinely like to know.
Children
TabiTabi is not intended for children. You must be at least 13 to use it, or at least 16 in the EEA and the UK where local law sets that threshold. We do not knowingly collect personal data from a child below that age; if you believe a child has created an account, write to piraeustechnology@gmail.com and we will delete it.
Changes to this policy
If TabiTabi starts doing something this policy does not describe, the policy changes first. We will update the date at the top, and for any change that materially affects your rights we will tell you in the app before it takes effect — not quietly, and not after the fact.
Contact
Piraeus Technology LLC. Email piraeustechnology@gmail.com.