Maintained by the Pinphy team

The Pinphy Trust Centre

Your trips hold flights, addresses, photos and the people you travel with. This page explains, in plain English, how we protect that information, who else touches it, and how to reach us.

Last reviewed August 4, 2026

How we protect your data

Your trips are yours

Every trip, place, photo and expense is scoped to your account. Database-level row security rules decide what each request may read or write, so another traveller cannot reach your data even if they guess an ID. Collaborators see a trip only after you invite them, and only at the role you grant (owner, editor or viewer).

Shared responsibility

Pinphy operates Pinphy on Lovable Cloud. The platform provides managed hosting, the database, authentication and encrypted storage; we design the access rules, decide what data is collected and answer your privacy requests. You keep your password and devices secure and choose who you invite to a trip.

This page is maintained by Pinphy to answer common security and privacy questions about Pinphy. It describes the controls we have enabled today — it is not an independent audit or certification.

Security practices

  • Least privilege by default: every table starts locked and is opened only by an explicit policy.
  • Role-based access control for the admin console, with separate moderator, admin and super-admin permissions.
  • Server-side checks on every privileged action — the browser is never trusted to decide what you may do.
  • Secrets and API keys live in server-side configuration, never in the app bundle.
  • Automated security scanning of the database rules and dependencies as part of our release process.
  • Admin actions are written to an audit log with actor, action and timestamp.
  • Regular dependency updates to pick up upstream security fixes.
  • Sensitive third-party calls (maps, weather, AI, payments) are proxied server-side so keys stay private.

Pinphy does not currently hold a third-party certification such as SOC 2 or ISO 27001, and we do not claim regulatory compliance beyond the commitments written in our policies.

Encryption

  • In transit: every connection to Pinphy uses HTTPS with TLS; plain HTTP is redirected.
  • At rest: the managed database, file storage and backups are encrypted on disk by the hosting platform.
  • Passwords are never stored in readable form — they are salted and hashed by the authentication service.
  • Trip photos and travel documents are held in private storage buckets and served through short-lived signed links.

We do not offer end-to-end encryption: trip content must be readable by the service to power search, sharing, route optimisation and AI features.

Authentication

  • Sign in with email and password, Google or Apple — your choice.
  • Sessions use short-lived access tokens that refresh automatically and can be revoked by signing out.
  • Passwords are checked against known-breach lists where enabled, and can be reset by email at any time.
  • You can review your active devices and recent sign-in history from your account settings.
  • Collaboration invitations are role-scoped, and trip owners can remove access instantly.

Data storage

What we store

Your account profile, trips and itineraries, saved places and notes, budgets and expenses, packing lists, bookings, photos and travel documents you upload, collaboration and activity records, and subscription status. Payment card details are never stored by Pinphy.

Retention & deletion

Data is kept while your account is active. You can export everything, delete an individual trip, or delete your account from your privacy and data settings — deletion runs after a short grace period, after which content is removed from live systems and ages out of encrypted backups.

Third-party services

ServiceWhat it doesWhat it can see
Lovable Cloud (Supabase)Database, authentication, file storage and realtime syncAccount details, trips, places, photos and documents you upload
StripeSubscription payments and invoicingBilling email and payment metadata — card numbers never reach Pinphy
Google Maps PlatformPlace search, place details, geocoding and routingSearch terms and coordinates for the places you look up
AI providers via the Lovable AI GatewayTrip assistant, destination guides and trip storiesThe trip context you send to an AI feature; not used to train models
Weather & currency data providersForecasts and exchange rates shown on your tripsDestination coordinates and currency codes only

We never sell your personal information. Optional cookies for analytics, performance and marketing run only with your consent — .

System status

Live

Checking services…

    Checks run live from your browser against our services.

    Security updates

    • Fixes ship continuously — there is no version for you to install; the web app and PWA update on next load.
    • Dependencies are scanned and patched on an ongoing basis, with critical issues prioritised.
    • Database access rules are re-scanned whenever the schema changes.
    • If an incident ever affects your personal data, we will notify affected travellers and the relevant regulator as required by law.

    Material changes to how we handle data are published in the Legal Centre with a version number and date.

    Report a security issue

    Found a vulnerability? Please report it privately before disclosing it publicly. Include the affected URL or screen, the steps to reproduce, and what you were able to access. We aim to acknowledge reports within two business days and will keep you updated while we investigate.

    • Please do not access, modify or delete other travellers' data while testing.
    • No denial-of-service, spam or social-engineering testing.
    • We will not pursue legal action against good-faith research that follows these rules.
    security@pinphy.app

    Privacy & legal contact

    Privacy contact

    Access, correction, deletion and marketing questions. Most requests can be self-served instantly in your privacy and data settings; otherwise we respond within 30 days.

    privacy@pinphy.app

    Legal contact

    Terms, copyright, law-enforcement requests and commercial agreements with Pinphy.

    legal@pinphy.app
    Support: hello@pinphy.app
    Abuse: abuse@pinphy.app
    Copyright: copyright@pinphy.app