Legal

Privacy Policy

Last updated · 14 February 2026.

1. Introduction

TripSynco is a curated hotel-booking service based in Sheridan, WY, USA. This policy explains what personal data we collect, why we collect it, how long we keep it and the rights you have over it. By using the site you agree to this policy.

You can reach the data controller at hello@tripsynco.com.

2. Data we collect

Account & booking data — name, email, phone number, guest details, dates of stay, room selection, special requests, and the booking reference and status.
Payment metadata — a transaction reference from our payment processor. We do not store card numbers, CVVs or any other payment credentials — those are handled by our PCI-DSS Level 1 payment processor.
Communications — enquiries, support messages and WhatsApp opt-in status.
Site analytics — page views, device type, approximate location (city-level), referrer and interaction events, collected with IP anonymisation.

3. How we use it

To confirm and deliver your booking, generate voucher and invoice PDFs, send you post-booking updates by email and WhatsApp, provide guest support before, during and after your stay, comply with legal and tax obligations, and (with your explicit opt-in) send you our monthly editorial newsletter.

4. Legal bases

We rely on contractual necessity for booking-related processing, legal obligation for tax and consumer-law record-keeping, legitimate interests for security, fraud prevention and product analytics, and consent for marketing and non-essential cookies.

5. Cookies

We use strictly-necessary cookies (Supabase authentication session), privacy-friendly analytics cookies (Google Analytics 4 with IP anonymisation) and no third-party advertising cookies.

6. Sharing your data

We share data only with:
  • The property you're booking with, for delivery of the stay.
  • Our PCI-DSS compliant payment processor, for processing your payment.
  • Our transactional email provider, for booking confirmations and receipts.
  • Our WhatsApp messaging provider, for booking-related updates.
  • Our database and authentication host.
  • Our legal, tax and accounting advisors, where required.
We do not sell personal data or share it with third parties for their own marketing.

7. International transfers

Some of our processors may process data outside India. Where they do, they operate under standard contractual clauses or equivalent safeguards.

8. Data retention

Booking data is retained for seven years to comply with Indian tax and consumer-protection rules. Newsletter data is kept until you unsubscribe. Support conversations are kept for two years unless a longer period is required by law.

9. Your rights

You can request a copy of the data we hold on you, ask for corrections, ask us to delete your account (subject to legal retention rules), or withdraw consent for marketing. Write to hello@tripsynco.com with your request. We will respond within 30 days.

10. Security

We use HTTPS everywhere, encrypted database storage, per-user access controls, and server-side signature verification for all payment events. Passwords are hashed; we never see them in plain text.

11. Children

Our services are not directed at children under 18 and we do not knowingly collect data from them.

12. Changes to this policy

We may update this policy from time to time. Continued use of the service after an update constitutes acceptance of the revised policy.

13. Contact

Any questions about this policy or your data can go to hello@tripsynco.com.