TripAgit(이하 "서비스")는 이용자의 개인정보를 소중히 다루며, 아래와 같이 개인정보를 수집·이용·보관합니다. 이 방침은 서비스의 실제 데이터베이스 구조(schema.sql)와 실제로 호출하는 외부 서비스 목록을 근거로 작성되었습니다.
| 항목 | 수집 시점 | 비고 |
|---|---|---|
| 이메일 주소, 계정 식별자 | Google 로그인 시 | 비밀번호는 저장하지 않습니다(Google OAuth만 사용) |
| 여행 제목·날짜·메모·예산 | 여행 생성/편집 시 | |
| 일정 장소명·주소·좌표·시간·메모 | 일정 입력 시 | 장소 검색은 Google Places API를 거칩니다 |
| 지출 금액·통화·항목명·메모·결제자·분담 내역 | 지출 입력 시 | |
| 체크리스트 항목·담당자 | 체크리스트 입력 시 | |
| 바우처 제목·예약번호·날짜·링크 | 바우처 입력 시 | 예약 확인번호 등 민감할 수 있는 정보가 포함됩니다 |
| 비상연락처 이름·전화번호 | 비상연락처 입력 시 | 서비스 이용자가 아닌 제3자의 정보 — 아래 3항 참고 |
| 동행자 역할·초대 이메일 | 동행자 초대 시 | 제3자의 정보일 수 있음 |
| 코멘트 작성자 이름(자유 입력)·본문 | 코멘트 작성 시 | 로그인 없이도 작성 가능(비인증) |
| 피드백 본문·연락처(선택)·페이지 경로·언어·브라우저 정보·IP 해시 | 의견 보내기 이용 시 | IP는 원문이 아닌 해시로만 저장(스팸 방지 목적) |
| 접속 IP, User-Agent | 모든 접속 시 | 호스팅 사업자(Cloudflare)의 표준 서버 로그, Cloudflare Web Analytics를 통해 집계될 수 있음 |
이 서비스는 이용자 본인이 아닌 사람의 정보를 이용자가 직접 입력하는 기능이 있습니다.
이 정보를 입력하는 이용자는 해당 제3자로부터 정보 제공에 대한 동의를 받을 책임이 있습니다. 서비스는 해당 제3자에게 별도로 동의를 요청하지 않습니다. 이 항목은 이용약관에도 동일하게 안내되어 있습니다.
여행 일정(언제, 어디로 떠나는지)은 단순한 취향 정보가 아니라 "그 기간 동안 자택이 비어 있다"는 사실을 드러낼 수 있는 정보입니다. 서비스는 이 점을 고려해 다음과 같이 접근 범위를 최소화합니다.
share_token)는 추측이 불가능한 임의의 문자열이며, 이 링크를 아는 사람은 누구나 열람할 수 있는 "소지자 인증" 방식입니다 — 아래 6항의 재발급 기능으로 이 링크를 무효화할 수 있습니다.이용자가 계정을 유지하는 동안 위 정보를 보관합니다. 이용자가 직접 여행/항목을 삭제하면 즉시 삭제되며, 계정을 삭제하면 아래 6항의 절차에 따라 소유한 모든 여행과 하위 데이터가 영구 삭제됩니다. 다른 사람의 여행에 남긴 코멘트는 삭제 시 완전히 지우지 않고 작성자 표시만 "삭제된 사용자"로 대체합니다(대화 맥락 보존 목적).
장소 검색에 사용하는 Google Places 데이터(이름·주소·좌표)는 Google 약관에 따라 30일 이상 저장되면 배경에서 자동으로 최신화됩니다.
| 권리 | 서비스 내 위치 |
|---|---|
| 내 데이터 열람·정정 | 각 화면에서 직접 수정 |
| 내 데이터 내려받기(이동권) | 대시보드 우측 상단 "설정" → 데이터 내보내기 |
| 계정 및 내 데이터 삭제 | 대시보드 우측 상단 "설정" → 계정 삭제 |
| 공유 범위 축소·공유 중단 | 여행 상세 화면의 "공유 링크" 팝오버 — 공유 범위 토글 끄기 또는 링크 재발급(기존 링크 무효화) |
위 기능으로 해결되지 않는 요청은 아래 13항의 연락처로 문의해주세요.
서비스는 개인정보를 판매하거나 광고 목적으로 제3자에게 제공하지 않습니다. 다만 서비스 운영을 위해 아래 외부 서비스에 데이터의 일부가 전달됩니다. 이 서비스들은 대부분 미국 등 국외에 서버를 두고 있어 개인정보가 국외로 이전될 수 있습니다.
| 제공받는 자 | 제공 항목 | 목적 |
|---|---|---|
| Supabase | 위 1항의 모든 저장 데이터, 로그인 정보 | 데이터베이스, 인증 [Supabase 프로젝트 리전을 확인해 입력하세요] |
| Cloudflare | 접속 IP·User-Agent, 페이지 조회(Web Analytics) | 호스팅, CDN |
| Google(Maps/Places API) | 검색어, 좌표 | 지도 표시, 장소 검색 |
| Google(로그인) | 이메일, 계정 식별자 | 로그인(OAuth) |
| Mapbox | 좌표 | 도보 이동시간 계산, 지도 장애 시 대체 표시 |
| OpenStreetMap(Nominatim) | 검색어, 좌표 | 장소 검색 장애 시 대체 검색 |
| Open-Meteo | 좌표, 날짜 | 날씨 정보 |
| open.er-api.com | 통화 코드 | 환율 정보 |
| Wikidata · Wikimedia Commons | 도시명 | 여행 커버 사진 |
| Wikipedia | 도시명, 좌표 | 여행지 정보 검색 |
| Google Fonts · jsDelivr | 접속 IP(글꼴/라이브러리 파일 요청) | 디자인 자산 제공 |
이 표는 실제 코드가 접속을 허용한(CSP) 외부 호스트를 기준으로 작성되었습니다. 새로운 외부 서비스가 연동되면 이 표도 함께 갱신합니다.
서비스는 지도 표시와 장소 검색에 Google Maps Platform을 사용합니다. Google 지도 관련 서비스 이용에는 다음이 함께 적용됩니다.
서비스는 광고·추적 목적의 쿠키를 사용하지 않습니다. 브라우저에 저장되는 정보는 전부 서비스 이용에 반드시 필요한 것들입니다.
| 저장소 | 내용 |
|---|---|
| localStorage | 테마·언어 선택, 마지막으로 본 여행의 오프라인 스냅샷 |
| sessionStorage | 로그인 없이 체험하는 게스트 모드의 임시 데이터(서버로 전송되지 않음) |
| Supabase 인증 토큰 | 로그인 상태 유지 |
| Service Worker 캐시 | 오프라인에서도 앱이 열리도록 하는 정적 파일 저장(개인정보 미포함) |
이 외에 Cloudflare(호스팅사)가 Web Analytics를 통해 방문 통계를 집계할 수 있습니다 — 쿠키를 사용하지 않는 방식으로 알려져 있으나, 정확한 동작은 Cloudflare의 정책을 따릅니다.
서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 이를 인지한 상태로 만 14세 미만 아동의 개인정보를 의도적으로 수집하지 않습니다.
이 방침이 개정되는 경우 서비스 내 공지 또는 이 페이지의 개정일 갱신을 통해 알려드립니다.
개인정보 관련 문의는 [email protected]으로 연락해주시거나, 서비스 내 "의견 보내기"를 이용해주세요.
TripAgit (the "Service") takes your personal data seriously and collects, uses, and retains it as described below. This policy is written directly from the service's actual database schema (schema.sql) and the actual list of external services it calls.
| Item | When collected | Notes |
|---|---|---|
| Email address, account identifier | Google sign-in | We never store passwords (Google OAuth only) |
| Trip title, dates, notes, budget | Creating/editing a trip | |
| Itinerary place name, address, coordinates, time, notes | Adding an itinerary item | Place search goes through the Google Places API |
| Expense amount, currency, item name, notes, payer, split | Adding an expense | |
| Checklist item, assignee | Adding a checklist item | |
| Voucher title, confirmation number, date, link | Adding a voucher | May include sensitive booking confirmation numbers |
| Emergency contact name, phone number | Adding an emergency contact | Data about a third party, not the account holder — see section 3 |
| Companion role, invited email | Inviting a companion | May be third-party data |
| Comment author name (free text), body | Posting a comment | Can be posted without logging in (unauthenticated) |
| Feedback message, optional contact, page path, language, browser info, IP hash | Using the feedback form | The IP itself is never stored, only a hash (for spam prevention) |
| Access IP, user agent | Every visit | Standard server logs from our hosting provider (Cloudflare); may be aggregated via Cloudflare Web Analytics |
Some features let you enter information about a person other than yourself.
If you enter this kind of information, you are responsible for getting that person's consent to share it. The Service does not separately request consent from that third party. The same notice appears in our Terms of Service.
An itinerary (when and where you're traveling) is not just a preference — it can reveal that your home will be empty during a specific window of time. We minimize exposure accordingly:
share_token) is an unguessable random string — anyone who has the link can view the trip ("possession is access"). Section 6 below lets you reissue it to invalidate the old link.We retain the data above for as long as your account exists. Deleting a trip or item yourself deletes it immediately. Deleting your account (see section 6) permanently deletes every trip you own and all of its underlying data. Comments you've left on someone else's trip are not deleted outright when you delete your account — the author name is replaced with "deleted user" instead, to preserve the conversation for other participants.
Google Places data used for search (name, address, coordinates) is automatically refreshed in the background if it's more than 30 days old, per Google's terms.
| Right | Where in the app |
|---|---|
| View / correct your data | Edit directly on each screen |
| Download your data (portability) | Dashboard → Settings → Export my data |
| Delete your account and data | Dashboard → Settings → Delete account |
| Narrow or stop sharing | Trip detail screen → "Share link" popover — turn off a share-scope toggle, or reissue the link to invalidate the old one |
For anything not covered by the above, contact us at the address in section 13.
We do not sell your personal data or share it with third parties for advertising. To operate the Service, however, portions of your data are sent to the external services below. Most of these are based outside Korea, so your data may be transferred internationally.
| Recipient | Data shared | Purpose |
|---|---|---|
| Supabase | All stored data from section 1, login information | Database, authentication [confirm and fill in your Supabase project region] |
| Cloudflare | Access IP, user agent, page views (Web Analytics) | Hosting, CDN |
| Google (Maps/Places API) | Search queries, coordinates | Map display, place search |
| Google (Sign-In) | Email, account identifier | Login (OAuth) |
| Mapbox | Coordinates | Walking-time estimates; fallback map if Google is unavailable |
| OpenStreetMap (Nominatim) | Search queries, coordinates | Fallback place search |
| Open-Meteo | Coordinates, dates | Weather information |
| open.er-api.com | Currency codes | Exchange rates |
| Wikidata / Wikimedia Commons | City name | Trip cover photos |
| Wikipedia | City name, coordinates | Destination info lookup |
| Google Fonts / jsDelivr | Access IP (font/library file requests) | Design assets |
This table is derived directly from the external hosts our code is actually allowed to reach (via Content Security Policy). It's updated whenever we connect to a new external service.
We use Google Maps Platform for map display and place search. The following apply alongside this policy:
We do not use cookies for advertising or tracking. Everything stored in your browser is required for the Service to function.
| Storage | Contents |
|---|---|
| localStorage | Theme/language choice, an offline snapshot of the last trip you viewed |
| sessionStorage | Temporary data for the no-login guest mode (never sent to our servers) |
| Supabase auth token | Keeping you signed in |
| Service worker cache | Static files cached so the app opens offline (no personal data) |
In addition, Cloudflare (our hosting provider) may aggregate visit statistics via Web Analytics — reportedly cookieless, though the exact behavior follows Cloudflare's own policy.
The Service is not directed at children under 14, and we do not knowingly collect personal data from children under 14.
If this policy changes, we'll let you know via an in-app notice or by updating the revision date on this page.
For privacy questions, reach us at [email protected] or use "Send feedback" inside the app.