Privacy Policy
Last updated: 9 October 2026
This policy explains what personal information TripMoor collects, why, who we share it with and the choices you have. TripMoor is operated from Australia and handles personal information under the Australian Privacy Act 1988 and its Australian Privacy Principles, and, for people in the European Economic Area and the United Kingdom, under the GDPR.
1. What we collect
- Account: your email address, and the sign-in session your browser keeps.
- Trips: what you tell us about a trip (the request, your answers and messages, dates, who is travelling, pace and budget), the plans we make, places you save, your packing and to-do lists, countries you mark in your atlas and leave you plan.
- Bookings: the booker's and guests' names, email and phone number, the hotel, dates, price and status. Payment cards are entered directly with our booking partner's payment service; we never receive card numbers.
- Booking confirmations you add: the text, screenshots or PDFs, used only to read the booking and not kept afterwards.
- Technical information: your IP address and the country and region it indicates, browser and device details, and request logs needed to run and secure the service.
- Preferences kept in your browser: language, passport, currencies, guest numbers and similar settings.
Needs you tell us about so we can plan around them, such as food you don't eat for religious or health reasons, allergies or limited mobility, may be sensitive information. We use them only to plan and change your trip, and by telling us you consent to that use. You can remove them from your trip at any time.
2. How we use it
- To plan and change your trips, answer your questions and keep your history.
- To search for, book and manage hotels you choose.
- To sign you in and keep your trips and bookings on your account.
- To set sensible defaults, such as your passport country, currency and public holidays, from where you seem to be. You can change any of them.
- To keep TripMoor secure, prevent abuse and fix problems.
- To understand, in aggregate, how TripMoor is used and improve it.
- To meet legal, tax and accounting obligations.
We don't sell your personal information, we don't show advertising, and we don't use advertising or cross-site tracking cookies.
Under the GDPR our legal bases are: performing our contract with you (planning, bookings, your account); our legitimate interests (security, defaults, improving the service), balanced against your rights; your consent where we ask for it; and legal obligations.
3. Artificial intelligence
Your trip requests, messages and the current plan are sent to AI model providers to write and change plans, read booking confirmations you add, understand your messages and match place names. We don't send your email address or account details with these requests. The providers process this content to return a result and may keep it for a limited time under their own terms.
AI output can be wrong. A person at TripMoor may look at requests and results when investigating a problem you report or to improve quality.
4. Who we share it with
We use service providers for parts of TripMoor. Each gets only what it needs for its part:
- Sign-in and account services: your email address and sign-in records.
- Hosting, content delivery and security services: technical information such as your IP address, and cookieless traffic statistics.
- AI model providers: trip content, as described above.
- Our hotel booking partner and its payment processor: what is needed to quote, book, charge and cancel a stay. For a booking, the hotel receives the guest names and contact details it needs.
- Map and weather services: places and dates, to show maps, routes and forecasts. The map loads in your browser, so the map provider receives your IP address.
- Place search services: searches about places to visit and eat, built from your trip (for example, a dish and a neighbourhood), never with your identity.
We may also disclose information when the law requires it, to protect people's safety or our rights, or to a buyer if TripMoor's business is transferred, in which case this policy continues to apply.
5. Overseas processing
Our providers may store or process information outside Australia, including in the United States, member states of the European Union, and other countries where they or their subcontractors operate. We choose providers that protect information, and for transfers out of the EEA or the UK we rely on safeguards such as the European Commission's standard contractual clauses where these apply.
6. Cookies and browser storage
TripMoor uses your browser's local storage to keep you signed in and to remember preferences such as language and currency. Our hosting provider may set strictly necessary security cookies to tell people from bots. Our traffic statistics use no cookies and do not track you across sites. Clearing your browser storage signs you out and resets your preferences.
7. How long we keep it
- Your account and trips: until you delete them or ask us to delete your account.
- Bookings: for as long as needed to provide the stay and then as long as tax, accounting and consumer law require (generally up to 7 years).
- Booking confirmations you add: not kept after they are read.
- Security and request logs: for a short period, normally no longer than 30 days, unless needed to investigate a problem.
8. Your choices and rights
You can ask us to access, correct, export or delete your personal information, and you can withdraw consent you gave. People in the EEA and the UK can also object to or restrict our processing. Email support@tripmoor.com; we may need to confirm it's you, and we will answer within 30 days.
If you're unhappy with how we handled your information, contact us first. In Australia you can then complain to the Office of the Australian Information Commissioner (oaic.gov.au); in the EEA or the UK, to your data protection authority.
9. Security
We use encrypted connections, access controls and reputable providers to protect your information. No system is perfectly secure; if a breach is likely to cause you serious harm, we will tell you and the regulator as the law requires.
10. Children
TripMoor is for people aged 18 and over. We don't knowingly collect information from children. A child's name may appear in a booking or plan made by an adult travelling with them; contact us if you think we hold a child's information we shouldn't.
11. Changes to this policy
We will update this policy when what we do changes, and tell you in the app or by email before a significant change takes effect.
12. Contact
TripMoor, Australia. Privacy questions and requests: support@tripmoor.com.