Privacy Policy

Last updated: 16 August 2026

This policy explains what personal data we process when you use Resa (resa-travel.app), why we process it, where it is stored and which rights you have under the EU General Data Protection Regulation (GDPR) and German data protection law.

1. Controller and contact

Resa is operated jointly by two private individuals. Both are joint controllers within the meaning of Art. 26 GDPR and have agreed that data subject requests can be addressed to either of them at the contact address below.

Joshua Böer
Heerstraße 62
56179 Vallendar
Germany

Till Felix Rincke
Am Hang 14
53343 Wachtberg
Germany

Email for all privacy matters and data subject rights: info@resa-travel.app

We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG.

2. What data we process

Account data. Your email address, your first name, a password hash if you choose to set a password, the initials and colour used for your avatar, and a flag showing whether you have completed the introduction.

Trip content. Everything you and your group add to a trip: trip name, destination, travel dates, invite code, an optional trip photo, your membership in a trip, accommodation, travel and activity cards including links, prices, times and locations, your votes, the transport options you join, and your comments.

Technical data. When you open the app, our hosting and backend providers record connection data such as your IP address, date and time, the requested resource, browser type and operating system in server logs.

Data stored on your device. We use browser local storage (not advertising cookies) to keep you signed in, to remember an invite or a vote you started before signing in, and to remember that you have seen the introduction. This storage is strictly necessary to provide the service you requested, so no consent banner is required under § 25(2) TDDDG. We do not use analytics, advertising or tracking technologies.

3. Purposes and legal bases

Providing your account and the shared trip board — performance of a contract, Art. 6(1)(b) GDPR.

Sending sign-in links, sign-up confirmations and password reset emails — performance of a contract, Art. 6(1)(b) GDPR.

Security, abuse prevention and stability — legitimate interests, Art. 6(1)(f) GDPR. Our interest is to keep the service available and to protect it and its users from attacks and misuse; we only use log data for this purpose and do not build user profiles from it.

Optional features you actively trigger — uploading a trip photo, requesting a link preview, searching for a place or looking up a flight number: Art. 6(1)(b) and Art. 6(1)(f) GDPR.

4. Visibility inside the app

Resa is a shared planning tool. Everything you add to a trip — your name, avatar, cards, prices, votes and comments — is visible to all members of that trip. Please only add information you are comfortable sharing with your group.

Trips are joined through an invite link or an eight-character code. Anyone who holds that link or code can open the invite page, see the trip name, destination and dates, and join the trip. Treat invite links as confidential. Administrators can close a trip so that no further members can join.

5. Hosting, database and backend

Frontend hosting. The website and application are hosted on the infrastructure of Lovable, which also operates the content delivery network and keeps short-lived server logs of requests (see technical data above).

Database, authentication, file storage and email. The backend runs on a managed Supabase environment provided through Lovable. The provider acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR and processes personal data only according to our instructions.

Concretely, your data is stored as follows:

  • Authentication system: email address, the hash of your password if you set one, session and refresh tokens, sign-in timestamps and confirmation status. Passwords are never stored in plain text.
  • PostgreSQL database: your profile, trips, trip memberships, accommodation/travel/activity cards, votes, transport participation and comments.
  • Object storage: trip photos you upload are stored in a dedicated storage bucket (trip-images); images are resized in your browser before upload.

Access control. All database tables are protected by row-level security: a row can only be read or changed by users who are members of the corresponding trip, and profile data is limited to the people you share a trip with. Administrative access to the backend is restricted to the two controllers named above.

Storage location and transfers. The backend is operated in a data centre in the European Union. Where a provider or one of its sub-processors processes data outside the EU/EEA — for example for support or monitoring — such transfers are safeguarded by the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR together with additional technical measures such as encryption in transit and at rest. You can request a current overview of processors from us at any time at info@resa-travel.app.

6. Third-party services we contact for you

The following services are called by our server, not by your browser. They therefore do not receive your IP address or any device data.

  • OpenStreetMap Nominatim (OpenStreetMap Foundation) for place suggestions while you type a destination. Only the search term is transmitted.
  • AeroDataBox via RapidAPI for looking up a flight by its number. Only the flight number and the date are transmitted.
  • Link previews. When you paste a link into a card, our server — not your browser — opens that page to read its title and preview image. The operator of the linked site sees our server, not you. We strip common tracking parameters from stored links.

Transactional email. Sign-in links, confirmations and password resets are sent from our domain notify.resa-travel.app through the email service integrated in our backend. The email contains your address and the requested link; delivery metadata is logged for troubleshooting.

7. Retention and deletion

We store your account data for as long as your account exists, and trip data for as long as the trip exists. When a trip is deleted, its cards, votes, participation entries and comments are deleted with it.

You can leave a trip at any time in the app. To delete your account and all associated personal data, write to info@resa-travel.app; we will erase the data without undue delay unless a statutory retention obligation applies.

Server logs held by our hosting and backend providers are kept only for a short period (usually a few days up to 30 days) for security and troubleshooting purposes and are then deleted or anonymised.

8. Your rights

Under the GDPR you have the right to:

  • access your personal data (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability in a machine-readable format (Art. 20),
  • object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21), and
  • withdraw any consent you have given, with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise these rights, contact info@resa-travel.app.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, place of work or the place of the alleged infringement. The authorities responsible for us are the State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate and the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

9. No automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR, and we do not run advertising, tracking or analytics cookies.

10. Changes to this policy

We update this policy when the service or the legal situation changes. The current version is always available at resa-travel.app/datenschutz with the date of the last update shown above.

This text describes how Resa currently processes personal data. It is provided for transparency and does not constitute legal advice; we recommend a review by a lawyer before relying on it commercially.