Privacy Policy
Last updated: 31 August 2026
This policy explains what personal data we process when you use Resa (resa-travel.app), why we process it, where it is stored and which rights you have under the EU General Data Protection Regulation (GDPR) and German data protection law.
1. Controller and contact
Resa is operated jointly by two private individuals. Both are joint controllers within the meaning of Art. 26 GDPR and have agreed that data subject requests can be addressed to either of them at the contact address below.
Joshua BöerHeerstraße 62
56179 Vallendar
Germany
Till Felix Rincke
Am Hang 14
53343 Wachtberg
Germany
Email for all privacy matters and data subject rights: info@resa-travel.app
We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG.
2. What data we process
Account data. Your email address, your first name, an optional profile picture, a password hash if you choose to set a password, the initials and colour used for your avatar, and a flag showing whether you have completed the introduction. We also record, in append-only form, which version of our terms of use you accepted and when. We keep that record to be able to demonstrate compliance with our accountability obligation under Art. 5(2) GDPR.
Trip content. Everything you and your group add to a trip: trip name, destination, travel dates, invite code, an optional trip photo, the group size, an optional home city including its coordinates, the vibes you pick and a rough daily budget, your membership in a trip, your own arrival and departure dates, accommodation, travel and activity cards including links, prices, times and locations, your votes, the transport options you join, and your comments. Locations you enter for an accommodation or an activity are converted into coordinates so that they can be shown on a map.
Technical data. When you open the app, our hosting and backend providers record connection data such as your IP address, date and time, the requested resource, browser type and operating system in server logs.
Data stored on your device. We use browser local storage (not advertising cookies) to keep you signed in, to remember an invite or a vote you started before signing in, and to remember that you have seen the introduction. This storage is strictly necessary to provide the service you requested, so no consent banner is required under § 25(2) TDDDG. We do not use advertising cookies, third-party analytics tools or cross-site tracking. We do measure the use of our own service; this is described in the section "Reach measurement and internal statistics" below, and it includes a random identifier stored on your device.
3. Purposes and legal bases
Providing your account and the shared trip board — performance of a contract, Art. 6(1)(b) GDPR.
Sending sign-in links, sign-up confirmations and password reset emails — performance of a contract, Art. 6(1)(b) GDPR.
Security, abuse prevention and stability — legitimate interests, Art. 6(1)(f) GDPR. Our interest is to keep the service available and to protect it and its users from attacks and misuse; we only use log data for this purpose and do not build user profiles from it.
Optional features you actively trigger — uploading a trip photo, requesting a link preview, searching for a place or looking up a flight number: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
4. Visibility inside the app
Resa is a shared planning tool. Everything you add to a trip — your name, avatar, cards, prices, votes and comments — is visible to all members of that trip. Please only add information you are comfortable sharing with your group.
Trips are joined through an invite link or an eight-character code. Anyone who holds that link or code can open the invite page, see the trip name, destination and dates, and join the trip. Treat invite links as confidential. Administrators can close a trip so that no further members can join.
5. Hosting, database and backend
Frontend hosting. The website and application are hosted on the infrastructure of Lovable, which also operates the content delivery network and keeps short-lived server logs of requests (see technical data above).
Database, authentication, file storage and email. The backend runs on a managed Supabase environment provided through Lovable. The provider acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR and processes personal data only according to our instructions.
Concretely, your data is stored as follows:
- Authentication system: email address, the hash of your password if you set one, session and refresh tokens, sign-in timestamps and confirmation status. Passwords are never stored in plain text.
- PostgreSQL database: your profile, trips, trip memberships, accommodation/travel/activity cards, votes, transport participation and comments; push notification delivery addresses and preferences, the terms-of-use consent log, marketing-link click records, and cached currency exchange rates.
- Object storage: photos you upload are stored in dedicated storage buckets — cover photos for a trip and photos on accommodation cards, and separately your profile picture. Images are resized in your browser before they are uploaded. Access is restricted in the same way as the rest of your data: trip and card photos can only be retrieved by members of that trip, and your profile picture only by people you share a trip with.
Access control. All database tables are protected by row-level security: a row can only be read or changed by users who are members of the corresponding trip, and profile data is limited to the people you share a trip with. Administrative access to the backend is restricted to the two controllers named above.
Storage location and transfers. The backend is operated in a data centre in the European Union. Where a provider or one of its sub-processors processes data outside the EU/EEA — for example for support or monitoring — such transfers are safeguarded by the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR together with additional technical measures such as encryption in transit and at rest. You can request a current overview of processors from us at any time at info@resa-travel.app.
6. Third-party services we contact for you
The following services are called by our server, not by your browser. They therefore do not receive your IP address or any device data.
- Google Places (Google Ireland Limited) for place suggestions while you type a destination or a location, and to turn a picked place into coordinates. Only the search term, and where useful the trip destination as a rough search area, is transmitted from our server.
- AeroDataBox via RapidAPI for looking up a flight by its number. Only the flight number and the date are transmitted.
- Link previews. When you paste a link into a card, our server — not your browser — opens that page to read its title and preview image. The operator of the linked site sees our server, not you. We strip common tracking parameters from stored links.
Transactional email. Sign-in links, confirmations and password resets are sent from our domain notify.resa-travel.app through the email service integrated in our backend. The email contains your address and the requested link; delivery metadata is logged for troubleshooting.
6a. Maps (Google Maps)
The Stay and Plans tabs can show a map. It stays closed by default and nothing is requested from Google until you open it. When you open the map, your browser contacts Google Maps directly and Google receives your IP address, device and browser data, and may set cookies or similar identifiers. Your choice to keep the map open or closed is stored locally on your device.
Legal basis: your consent (Art. 6(1)(a) GDPR), given by opening the map; you can withdraw it at any time by closing the map again. Data may be transferred to Google LLC in the USA on the basis of the EU standard contractual clauses. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details: policies.google.com/privacy.
Coordinates we obtain for a place are cached with the entry for up to 30 days and then refreshed or dropped, so nothing from Google stays with us indefinitely.
6b. Reach measurement and internal statistics
We measure how Resa is used so that we can improve it. This happens entirely within our own service. We do not use third-party analytics tools, we do not run advertising, and we do not combine your data with data from other apps or websites.
Marketing links. Links we post on social media point to short addresses such as resa-travel.app/go/instagram. When such a link is opened, we record the name of the source, the time, the browser and operating system string, and a shortened IP address in which the last block has been removed. A random identifier is stored in your browser so that we can recognise repeat visits from the same device. If you create an account in the same browser afterwards, the name of the source is attached to your profile once, so that we can see which channel a sign-up came from. It is never changed afterwards.
Usage statistics. For signed-in users we store the time of the last visit and whether it happened in the installed app, a mobile browser or a desktop browser. From this we calculate aggregate figures such as active users, trips created and how many people use the installed app. These figures are only ever viewed in aggregate form by the two controllers named above.
Legal basis: legitimate interests, Art. 6(1)(f) GDPR. Our interest is to understand how our service is used and to develop it further. We do not build behavioural profiles, we do not use this data for advertising, and we do not pass it on to third parties. You can object at any time on grounds relating to your particular situation under Art. 21 GDPR by writing to info@resa-travel.app.
Retention: click records from marketing links are deleted after 12 months. The last-visit information is overwritten with each visit and is deleted together with your account.
6c. Push notifications
You can switch on notifications about your trips — for example when somebody joins, when something is added, or when a vote is waiting for you. Notifications are off until you actively turn them on.
When you enable them, we store a delivery address for the device you are using: on the web a push endpoint provided by your browser vendor together with the associated encryption keys, and in the iOS app a device token issued by Apple. We store your notification preferences alongside it and link both to your account, so that a message reaches the right person on the right device.
Sending a notification means transmitting it to the push service of your browser vendor or device manufacturer. For the iOS app this is the Apple Push Notification service, operated by Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, and Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland. These providers receive the delivery address and the content of the notification in order to deliver it. Data may be transferred to the USA on the basis of the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Legal basis: your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time with effect for the future by switching notifications off in the app settings, or by withdrawing the permission in your device settings. The stored delivery address is deleted when you do.
6d. The Resa iOS app
Resa is also available as an app for iPhone. The app loads the same application as the website and processes personal data in the same way as described in this policy. In addition, it can receive native push notifications (see above) and open invitation and sign-in links directly instead of in a browser.
If you install the app from the App Store, Apple processes your download and, where applicable, your Apple Account data as its own controller. We have no influence over this and no access to it. Apple provides us only with anonymous aggregate statistics, such as download and usage figures, from which we cannot identify individual people. Information on Apple's own data processing is available at apple.com/legal/privacy.
7. Retention and deletion
We store your account data for as long as your account exists, and trip data for as long as the trip exists. When a trip is deleted, its cards, votes, participation entries and comments are deleted with it.
You can leave a trip at any time in the app. To delete your account and all associated personal data, write to info@resa-travel.app; we will erase the data without undue delay unless a statutory retention obligation applies. When your account is deleted, any stored push delivery addresses and notification preferences are removed with it. The terms-of-use consent log is kept for the statutory limitation period as evidence of compliance, after which it is also deleted.
Server logs held by our hosting and backend providers are kept only for a short period (usually a few days up to 30 days) for security and troubleshooting purposes and are then deleted or anonymised.
Feedback and bug reports. When you send us feedback from inside the app, we process the text you write, an optional screenshot you attach, and technical context collected automatically: the page you were on, the trip id if you were inside a trip, your browser and device string, the window size, the app build version and the time. We use this solely to understand and fix the problem or to assess your idea (Art. 6(1)(f) GDPR, our legitimate interest in a working product; for the optional screenshot, your consent under Art. 6(1)(a) GDPR, given by choosing to attach it). Screenshots are deleted automatically 14 days after the report is closed, and in any case 90 days after it was sent. The report text itself is kept while we work on it and for as long as it is useful as a record of a change; feature requests you post to the public board remain visible to other signed-in users with your upvote until we remove them.
8. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability in a machine-readable format (Art. 20),
- object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21), and
- withdraw any consent you have given, with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise these rights, contact info@resa-travel.app.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, place of work or the place of the alleged infringement. The authorities responsible for us are the State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate and the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
9. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. We do not use advertising cookies, cross-site tracking or third-party analytics services. How we measure the use of our own service is described in the section "Reach measurement and internal statistics" above.
10. Changes to this policy
We update this policy when the service or the legal situation changes. The current version is always available at resa-travel.app/privacy with the date of the last update shown above.