Privacy Policy
Effective July 19, 2026. This policy explains how OneSpace Trips processes account, itinerary, and service data.
Data we process
- Account data: name, email address, optional phone number, avatar photo, and user identifier.
- Travel and search data: destination searches, dates, accommodation or starting points, must-see and excluded places, route preferences, saved routes, and offline plans. Search terms can be included in your synchronized app state.
- Customer support data: the contact email, category, and message you submit through the support form.
- Technical data: request time and status, IP address in hosting or security logs, and error or diagnostic information needed to operate and protect the service.
AI trip planning and explicit consent
Only after you explicitly agree before generating an itinerary, OneSpace Trips sends the destination, dates, trip length, daily hours, budget, transport, starting point, must-see and excluded places, interface language, and route preferences to OpenAI through a Supabase Edge Function to generate the itinerary. We do not send your account email, phone number, avatar, or password to OpenAI in this request. You may decline; in that case no trip data is sent and no AI itinerary is generated.
Processors and purposes
We use data to authenticate users, generate itineraries, verify places, synchronize saved routes, provide support, and protect the service. Supabase provides authentication, cloud data, and Edge Functions; OpenAI processes consented trip-planning requests; Google Maps, Apple Maps, or Amap may process user-selected place and route queries; Netlify hosts the website and server functions.
Avatar photos
Uploading an avatar is optional. A photo you select is compressed and stored in your Supabase user profile, linked to your account, and used only to display your avatar in OneSpace Trips. You can replace it or remove the associated profile through account deletion.
Retention, sharing, and tracking
We do not sell personal data or use it for cross-app tracking. Data is shared with service providers only where needed for the functions above. Account-linked travel and search data is kept while your account is active and is removed through the in-app account-deletion flow, except where retention is legally required. Support records and short-lived security, hosting, and diagnostic logs are retained only for support, fraud prevention, service reliability, or legal obligations, then deleted or de-identified under the applicable provider retention settings. Shared itinerary links do not include an account ID, name, email, phone number, avatar, or password.
Your choices
You can sign out or permanently delete your account in Profile. Deletion removes the Supabase Auth account, profile fields including the avatar, saved itineraries, and synchronized search and travel state that we are not legally required to keep. Support messages and provider backups or logs are removed under their applicable retention cycle. You may also decline AI processing and continue using non-AI pages.
Contact and changes
Send privacy questions to albert.jiang@onerspace.com or visit OneSpace Trips Support. We will update the effective date and provide an appropriate notice if this policy changes materially.