Privacy Notice
Last updated: 9 September 2026
About this Privacy Notice
This Privacy Notice explains what personal data Splitrip collects about you, how we use it, why each use is lawful, who we share it with, and the control you have over it.
Please read Section 1.3 first. Splitrip is a record-keeping and calculation tool. It never accepts, holds, escrows or transmits anyone's money. That single fact shapes most of what follows.
Splitrip is currently a pre-release product distributed to a limited group of testers. Some features described in this notice may change before general release, and we will update this page when they do.
Table of Contents
1. The Basics: Who We Are, Our Role, and Definitions
1.1 Who We Are
We are Splitrip, a product managed by Mobile Flow Ltd. Our offices are at Kiryat HaMada St 20, Jerusalem, Israel 9777600, and our company registration number is 517148722.
For any question about your privacy, or to exercise any right described here, contact us at privacy@splitrip.com or support@splitrip.com.
We are the controller of the personal data described in this notice.
1.2 Definitions
When we refer to the "App", we mean the Splitrip mobile application and any web view of a trip that we make available.
When we refer to the "Services", we mean the App and everything available through it, together with this website.
When we refer to "personal data", we mean information that identifies you directly or indirectly, including unique identifiers such as account identifiers, device identifiers and IP addresses.
A "trip" is the record you create in Splitrip: its name, dates, base currency, the people on it, the expenses logged against it, and the settlements recorded on it.
A "member" is a person listed on a trip's roster. A member may or may not have an account with us — see Section 2.3.
This Privacy Notice should be read together with our Terms of Use.
1.3 We Never Hold or Move Your Money
Splitrip is a record-keeping and calculation tool. It works out who owes whom, and by how much, from information you and the other people on your trip enter.
Splitrip does not accept, hold, escrow, transmit or process anyone's funds. It is not a bank, a payment service, a money transmitter or an escrow agent, and it has no connection to your bank account or your cards. When you record a settlement in Splitrip, you are recording a claim that a payment happened somewhere else, between you and another person. We do not verify, effect or guarantee that payment.
Because of this, we do not collect bank account numbers, card numbers or payment credentials in order to move money, and we never see the transfer itself.
2. Personal Data We Collect, How We Use It, and Why
Below is each category of personal data we process, what we do with it, and why. You are under no legal obligation to give us personal data, but some of it is necessary for the Services to work at all.
2.1 Sign-In Data, Including Anonymous Sign-In
Splitrip uses Firebase Authentication, a Google service.
Anonymous sign-in. The first time you open the App — and when you open a trip link — we create an anonymous Firebase identity for your device. This produces a pseudonymous account identifier (a "uid"). It is not linked to your name, email address or phone number, and you do not have to create an account to use Splitrip. We do this so that a person holding a share link can see a trip and add an expense without an account.
Signing in properly. If you later choose to create an account, you do so with Google Sign-In or Sign in with Apple. From that provider we receive an account identifier and, where the provider supplies it, your name and email address (Apple may supply a private relay address instead). When you sign in, your anonymous identity is upgraded in place: the same uid is kept, so the trips and expenses you created while anonymous stay attached to you.
How we use this data: to give you access to the Services, to attach your entries to you rather than to somebody else, to keep your data available across sessions and devices, to protect the Services against abuse, and to answer support requests.
2.2 Trip Data
The core of the Services is data you and your fellow travellers create. We store it in Google Cloud Firestore under our Firebase project. This is cloud storage, not local-only storage. The App also keeps an offline cache on your device so that you can read and add expenses with no signal, but that cache is a copy of a record that lives in the cloud.
Trip data includes:
- Trip details — name, destination label, start and end dates, base currency, whether the trip is a group or solo trip, an optional budget and an optional cover image.
- The roster — the display name of each member, an optional avatar, their role on the trip, their home currency, and whether they have claimed their place.
- Expenses — title, amount, currency, the exchange rate frozen onto that expense and its source, the local date and optional time of purchase, who paid, how it was split and each person's resolved share, an optional category, note, line items and charges.
- Settlements — who paid whom, how much, the method you selected, who asserted the payment and who acknowledged it.
- Provenance — for every row, who created it, where it came from (typed by hand, extracted from a receipt, parsed from text, imported), and a history of edits.
- Imported data — if you import a spreadsheet exported from another expense-splitting service, the rows in that file.
- Your itinerary and plan — the days, segments and plan items you add (flights, stays, activities and places), including any location or map pin attached to them.
- Saved places and links — places you save and links you keep from Instagram or TikTok, together with the preview details resolved for them (see Section 2.10).
- Shared lists and decisions — packing lists, checklists, ideas and group polls the trip builds together.
- Attachments — the receipt photographs and booking documents uploaded against expenses and plan items, which are held in Google Firebase Storage (see Section 2.4).
How we use this data: exclusively to provide the Services — to compute balances, settlement plans and totals, to show the trip to the people on it, and to keep the record auditable so a disputed figure can be traced back to its source. We do not use trip contents for advertising, and we do not sell them.
2.3 People Added by Someone Else
This section matters and we would rather state it plainly than bury it.
Splitrip is designed so that a trip organiser can add someone to a roster by name alone, without that person's email address, phone number, consent or knowledge, and can record expenses and financial obligations against that name. We call this a "ghost" member. It exists because collecting eight people's contact details at a restaurant table is the point at which groups give up on this kind of app.
If you have been added to a trip in this way, we may therefore hold a display name chosen by somebody else, together with amounts that person says you owe or are owed, without you having any account with us. That record is created by the trip organiser, not by us, and the accuracy of it is theirs.
If you believe you have been recorded on a trip and you want that entry removed or anonymised, contact us at privacy@splitrip.com. We will act on it — see Sections 8 and 9 for what we can and cannot do with a record that also forms part of other people's accounts of a shared trip.
2.4 Receipt and Booking Photographs, and AI Extraction
Splitrip lets you attach a photograph of a receipt to an expense, and a photograph or PDF of a booking confirmation (a flight, hotel, car hire, restaurant or tour) to a plan item. When you do, two separate things happen to that file, and it is worth keeping them apart.
The file is stored on your trip. Before a photograph leaves your device the App downsamples it to keep it small; the file is then uploaded to Google Firebase Storage and kept as an attachment on the trip, so that you and the other members can open it later. This is cloud storage, not local-only storage. A booking confirmation is often a PDF rather than a photograph, and PDFs are stored the same way. Access to these files is restricted to members of the trip by the same server-side rules that protect the rest of the trip. (An earlier version of this notice said receipt images were never stored on our servers; that is no longer accurate, and this section replaces it.)
The file is also sent to Google to be read. To save you typing, the image or PDF is transmitted from your device to our server function and from there to the Google Gemini API (the model identifier is pinned, and is currently gemini-3.7-flash), which reads it and returns structured fields — for a receipt: merchant, date, currency, line items, taxes, tips and service charges, and the literal text it read each number from; for a booking: the kind of booking, provider, reference, dates and times, origin and destination, address, an approximate map location, amount and currency. A receipt or booking may contain anything printed on it, including what you bought, where and when you were there, a booking reference, and in some cases partial card details printed by the merchant. Google processes the file as our service provider, subject to its own terms for that API, which are linked in Section 5.1. The extraction call itself does not retain the file; the copy that persists is the one stored on your trip, described above.
We keep a small usage counter — a per-day count of how many extractions each identity has requested — so that we can apply a fair-use limit. It contains no receipt or booking content.
The App asks for access to your camera and/or your photo library only so that you can supply a file; we do not otherwise browse your library. Nothing the model returns is written into your trip automatically: the extraction is shown to you first, every field is editable, and only your explicit confirmation moves it into the shared ledger or plan.
How we use this data: to store the receipt or booking on your trip, to turn it into an expense or a plan item you can check and confirm, and to enforce a usage limit.
If you would rather not send a file to a third party, do not use this feature — and if you would rather not store an image on the trip at all, do not attach one. Every expense and every plan item can be entered by hand, and entering it by hand is never restricted.
2.5 Typed Expense Text and Place Lookups
If you enter an expense in plain language — for example "dinner forty euros split me Ana and Tom, I paid" — that text is sent to the same Google Gemini API to be parsed into an amount, a description and the names you mentioned. So that the model can tell where a name ends and an ordinary word begins, the display names of the members on that trip are sent with it as a hint. No other trip data, and no account identity, is included. If you add an expense by speaking it, the speech is turned into text by your device and only that text — never the audio — is sent to us.
Deciding which member each spoken name refers to is then done in our own code, not by the model. An ambiguous name is returned to you as a question rather than resolved by a guess.
As with receipts, the result is shown to you for confirmation and is never saved directly.
Place lookups. When you name a place while planning — a hotel, a restaurant, a landmark — the App may send that short place name, and at most a neighbourhood or the name of your accommodation to disambiguate it, to the same Google Gemini API to get back candidate map locations. No account identity and no other trip data is included, and any location returned is shown to you to accept rather than saved automatically. This feature does not use Google Maps' Places service.
How we use this data: to save you typing, and to help you place things on a map — and only that.
2.6 Share Links and Join-by-Link Access
When you invite people to a trip, we mint a short share token for that trip and store it in a collection that is never readable by any client. Opening a link calls a server function, which validates the token and, if it is good, grants that device's identity access scoped to that one trip by way of a custom claim on the identity. We record how many times a token has been used, and a token can be revoked.
Anyone who holds the link can see the trip. Treat a trip link the way you would treat a shared document link: send it to your group, not to a public channel.
How we use this data: to let invited people reach the trip without an account, and to be able to cut off access if a link is misused.
2.7 Device, Log and Diagnostic Data
When your device talks to our servers, our infrastructure providers record ordinary technical data: IP address, timestamps, the operation requested, the result, and error diagnostics. Our server functions also write operational logs — for example, that a receipt extraction ran, for which account identifier, how long it took and how many fields the model declined to fill.
Upload diagnostics. When an attachment fails to upload, the App writes a small diagnostic record to a collection we use to debug a known upload problem on some devices. It records the trip and the internal storage path the file would have had (which includes the trip, the folder and the uploading identity), the size of the file in bytes, your device's operating system, and the error the upload returned. It does not contain the image itself or its contents. These records are temporary and are removed once the underlying problem is fixed.
Device permissions. Depending on the features you use, the App may ask for access to your camera (to photograph a receipt, a booking, or a friend's invite QR code), your photo library (to attach a file you have already saved), your microphone (to add an expense by speaking it, where that is offered), and your location. Where the App uses your location it does so on your device, only to centre the map on where you are; it does not record or share your location, and the map's "my location" marker is off by default.
How we use this data: to run and debug the Services, to detect and prevent abuse, and to keep the Services secure.
To be explicit about what we do not do: the current Splitrip App contains no third-party analytics SDK, no advertising SDK, no attribution SDK, no session-recording tool and no advertising identifier collection. We do not build advertising audiences and we do not profile you.
2.8 Contact Information
If you email us — including to ask for early access — we receive your email address, the content of your message and anything you choose to include in it.
How we use this data: to answer you, and where you asked to be told when Splitrip is released, to send you that one notification.
2.9 Payment Data
Splitrip does not currently charge for anything and does not process payments. If we introduce paid plans, they would be sold through the app marketplace you installed from (the Apple App Store or Google Play), and those marketplaces — not we — would process your payment details. We would receive only the fact and status of a purchase. We will update this notice before that happens.
Separately, and to repeat Section 1.3: Splitrip never processes the payments you make to each other.
2.10 Links You Save from Instagram and TikTok
Splitrip lets you save a place from a reel or a video — by sharing a link to the App, or by pasting one — so you can keep it with a trip. When you do, the App sends that link to our server function, which fetches the platform's own public preview ("oEmbed") for it: an Instagram link is looked up through Meta's Instagram oEmbed endpoint, and a TikTok link through TikTok's oEmbed endpoint. This returns the embed the platform itself provides — for TikTok, the caption and author; for Instagram, an embeddable block with no caption. The video itself is never downloaded, copied, re-hosted or transcribed by us.
To help turn what you saved into a place on your plan, the App may send the accompanying text — a TikTok caption, text you paste, or text read from a screenshot on your own device — to the Google Gemini API, which returns candidate place details grounded in that text. A screenshot you add is read on your device and is never uploaded; only the resulting text is sent. Instagram-derived data is not stored by us; basic TikTok preview details (caption and author) may be cached for up to about 30 days so a saved card still renders during a platform outage.
These lookups reach Meta (for Instagram) and TikTok in order to render what you asked to save; those platforms are governed by their own terms and privacy policies (see Section 5.1).
How we use this data: to render a preview of a place you chose to save, and to help file it against your trip.
2.11 Push Notifications
If you allow notifications, the App registers a push token for your device with Google Firebase Cloud Messaging and stores it under your account, along with which platform the device is (iOS or Android). We use it to send you notifications about your own trips — for example that another member added an expense, or a reminder you set — and such a notification carries the trip name and the relevant expense detail. The token is deleted when you sign out, and no token is stored if you do not grant notification permission. You can turn notifications off at any time in your device settings.
3. Data Shared With Other People by Design
Splitrip is a shared ledger. Sharing is the function, not a side effect, so it is worth being precise about who sees what.
Every member of a trip can see: the trip's details, the full roster and each member's display name and avatar, every expense on the trip including its amount, currency, date, category, note and who paid it, how each expense was split and each person's share, every settlement recorded, any receipt photograph or booking document attached to a row, the trip's shared plan and itinerary, the places and links saved to it, its packing lists, ideas and group decisions, and the provenance and edit history of every row — including which member created or changed it.
Expenses you mark as personal are not included in the group total and do not affect anyone's balance.
What we do not do: we do not publish your trips, we do not list them anywhere public, and we do not make them findable by search engines. A trip is reachable only by someone who has been given its link or added to it.
If you would prefer other members of a trip not to see something, do not enter it into that trip.
4. Our Marketing Activities
4.1 Email
If you contacted us to ask for early access, we will email you when there is something to install. You can stop this at any time by replying to any message or writing to support@splitrip.com, and we will delete your address.
If you become a user, we may need to send you administrative or service messages. Those are not marketing and you would continue to receive them.
4.2 No Advertising, No Audiences, No Cross-Context Behavioural Advertising
We do not show advertising in Splitrip. We do not collect advertising identifiers. We do not upload identifiers to advertising platforms, build advertising audiences, or share personal data for cross-context behavioural advertising. We do not sell personal data.
We never use the contents of your trips — your expenses, your balances, who you travel with, or a receipt photograph — for any advertising purpose whatsoever.
5. Sharing the Personal Data We Collect
5.1 Service Providers and Sub-Processors
We engage the providers below to operate the Services. Each receives only the personal data needed for its function, is bound by confidentiality obligations, and has undertaken to use the data only as we direct. We may update this list as our vendors change.
| Sub-Processor | Purpose | Privacy Policy |
|---|---|---|
| Google Firebase & Google Cloud | Authentication (anonymous sign-in, and Google/Apple sign-in); database (Cloud Firestore); file storage for receipt and booking images and PDFs (Cloud Storage for Firebase); push notifications (Firebase Cloud Messaging); remote configuration (Firebase Remote Config); serverless functions; and abuse prevention (Firebase App Check). This is where trip data and attachments are stored. | firebase.google.com/support/privacy |
| Google Gemini API (Google LLC) | Reading a receipt photograph, or a line of typed expense text plus the display names on that trip, and returning structured fields. See Sections 2.4, 2.5 and 11A. | policies.google.com/privacy · ai.google.dev/gemini-api/terms |
| Apple (TestFlight and the App Store) | Distributing the pre-release iOS build to testers, and any future purchases made on iOS. | apple.com/legal/privacy |
| Google Play | Distributing the Android build, and any future purchases made on Android. | policies.google.com/privacy |
| Meta Platforms (Instagram oEmbed) | Fetching the public preview for an Instagram link you save. See Section 2.10. | privacycenter.instagram.com/policy |
| TikTok | Fetching the public preview (caption and author) for a TikTok link you save. See Section 2.10. | tiktok.com/legal/privacy-policy |
| Google Maps (on Android) and Apple Maps (on iOS) | Displaying maps and placing pins. When a map is shown, the map provider for your platform receives the interaction needed to draw it. A fallback map draws only pins on a blank canvas and fetches no map tiles. | policies.google.com/privacy · apple.com/legal/privacy |
| Vercel | Hosting this website. Receives ordinary web request logs. | vercel.com/legal/privacy-policy |
We also read daily reference exchange rates published by the European Central Bank, through a public API. Only a date is sent. No personal data of any kind is transmitted in order to obtain a rate, and rates are fetched once a day by our server rather than by your device.
5.2 Change of Ownership
If we look to sell the company, liquidate assets or merge with another business, we may share personal data with interested parties as part of that transaction. Your personal data would remain subject to this Privacy Notice.
5.3 Law Enforcement and Legal Disclosure
We may share personal data with government agencies or other relevant parties, such as a law firm or an independent auditor: (i) where we believe disclosure is appropriate to protect our rights, property or safety or those of a third party; (ii) where required by law or court order; or (iii) as necessary to comply with a legal or regulatory obligation.
6. International Transfers
We are based in Israel and our infrastructure providers operate in countries other than your own, including the United States. When we transfer personal data internationally we do so in accordance with applicable law and require recipients to provide an adequate level of protection through appropriate contractual and security safeguards.
7. Security
We comply with industry standards and applicable law to keep your personal data secure. In particular:
- Access to trip data is enforced server-side by database security rules, not by the App. A client can only read a trip it is a member of, either through an account or through a link grant scoped to that single trip.
- Attachments in file storage are protected by the same membership check: a receipt or booking file can only be read by a member of the trip it belongs to.
- Share tokens are never readable by any client. Only our server function can exchange a token for access, which is what prevents anyone from enumerating their way into other people's trips.
- Server functions check a Firebase App Check attestation and sharply rate-limit calls that cannot present a valid one, so automated abuse from outside our own App is throttled.
- Ledger integrity is enforced at the database layer: amounts must be integers in minor units and every expense must carry the exchange rate frozen at the moment it was created. A broken or hostile client cannot corrupt the arithmetic.
- Expenses are soft-deleted and restorable rather than destroyed by a client, and trips cannot be deleted by a client at all.
No system is perfectly secure. The security of your data also depends on the security of your device and of any account you use to sign in.
8. Your Rights
Depending on the law that applies to you, you may have rights to access, correct, delete, port or restrict the personal data we hold about you, and to object to certain processing. Residents of U.S. states with comprehensive privacy laws should also read Annex A (Section 14); individuals covered by Israeli law should read Annex B (Section 15).
To exercise any right, contact privacy@splitrip.com. We may ask for reasonable evidence of your identity, or of your authority to act for someone else, before we act.
One honest limitation. A trip is a shared record. An expense you entered is also part of other people's account of what a trip cost and who owes whom, and deleting it outright would silently change other people's balances. Where you ask us to erase data that is entangled in a shared ledger in this way, we will normally disassociate and anonymise your identity from those entries rather than destroy the group's record — unless the applicable law requires otherwise, in which case we will follow the law. We will always tell you which we have done.
9. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described above. In deciding how long, we consider the amount, nature and sensitivity of the data, the potential harm from unauthorised access, the purpose it was collected for, and applicable legal requirements.
- Trip data is retained for as long as the trip exists. Trips are archived rather than deleted by the App, because the history is the point of the product. Ask us and we will delete or anonymise your part of it, subject to the limitation in Section 8.
- Receipt and booking files attached to a trip are stored in Firebase Storage and retained for as long as that trip exists, or until you delete the attachment. The separate copy sent to Google for extraction is not retained after the request completes.
- Extraction usage counters are retained only as long as needed to apply a fair-use limit.
- Saved-link previews from TikTok (caption and author) are cached for up to about 30 days; Instagram-derived data is not stored.
- Push tokens are retained while your device is registered and are deleted when you sign out.
- Upload diagnostic records are temporary and are removed once the underlying upload problem is fixed.
- Share tokens are retained while the invitation is live and can be revoked at any time.
- Exchange-rate snapshots contain no personal data and are retained indefinitely, because an expense's frozen rate must remain verifiable.
- Server logs are retained for a limited operational period by our infrastructure providers.
- Email correspondence is retained for as long as needed to handle your request and to keep a record of it.
We may retain personal data after we have finished using it where the law requires (for example for tax or audit purposes) or where there is a prospect of litigation. In such cases the same security measures apply.
For detail on retention periods for a particular category, write to privacy@splitrip.com.
10. Cookies and Similar Technologies
A cookie is a small piece of text stored on your device. Other technologies — web beacons, pixel tags, device identifiers — behave similarly, and for simplicity we refer to them all as cookies.
This website does not place analytics or advertising cookies. We do not run an analytics tag, an advertising pixel, a session recorder or a consent-gated tracker on splitrip.com. Our hosting provider may set strictly necessary cookies for security and load balancing.
In the App, we do not use advertising identifiers. Firebase Authentication stores a token on your device so that you stay signed in; that is necessary for the App to work and cannot be disabled while using the Services. If you enable notifications, a push token is also stored for your device so that we can deliver them (see Section 2.11).
Most browsers let you refuse or delete cookies. Doing so will not stop this website from working.
11. Third-Party Services
You may reach third-party services through the Services — for example, when you choose to settle a debt using a payment app you already have, we may hand you off to that app with an amount pre-filled. What happens after that is between you and that provider, governed by its terms and its privacy policy. We do not receive confirmation from it, and we take no responsibility for its performance.
11A. AI and Automated Processing
Several features rely on a third-party artificial-intelligence provider, Google, through the Gemini API:
- Receipt and booking extraction — the photograph or PDF you supply is sent to Google and read (Section 2.4).
- Natural-language expense entry — the sentence you typed, plus the display names of the members on that trip, is sent to Google and parsed (Section 2.5).
- Place lookups — a short place name, with at most a neighbourhood or accommodation name to disambiguate it, is sent to Google to get back candidate map locations (Section 2.5).
- Saved-link enrichment — a caption, text you paste, or text read from a screenshot on your device is sent to Google to suggest a place to save (Section 2.10).
Google acts as our service provider for these calls and is bound to use the data only to provide the feature to us.
We do not use AI to make any decision that produces a legal or similarly significant effect about you. Specifically:
- No AI output is written into the shared ledger without a person confirming it. Extractions are held separately and only an explicit human tap moves them into a trip.
- The model does not perform the arithmetic. Splits, balances, currency conversion and settlement plans are computed by our own code. A model may describe a figure it was given; it may not produce one.
- The model never decides who a person is. Matching a spoken name to a member of your trip is done deterministically in code, and an ambiguous name is returned to you as a question.
- We do not profile you and we do not score you.
12. Children
The Services are not directed at children. We do not knowingly collect personal data from anyone under the age of eighteen (18). If you become aware that someone under eighteen has used the Services without parental permission, please tell us immediately at privacy@splitrip.com and we will delete the data.
13. Changes to this Privacy Notice
We may update this Privacy Notice to keep it current with the law and with how we operate. Updates are posted on this page with the date they were published. Please check back from time to time. Splitrip is a pre-release product and its feature set is still moving, so this notice will change.
14. Annex A — U.S. State Privacy Rights
This annex describes additional rights that may apply if you are a resident of a U.S. state with a comprehensive consumer-privacy law. Sections 14.1 to 14.8 describe rights under California law; Section 14.9 describes rights for residents of other states. These rights apply only to the extent the relevant law applies to you and to our processing, and subject to that law's exceptions. To exercise any of them, contact privacy@splitrip.com. We may ask for reasonable evidence to verify your identity, or that you are an authorised agent, before acting.
14.1 Your Rights Under the CCPA, as Amended by the CPRA
If you are a California resident, and depending on the applicability of certain laws and exemptions, you may have the rights described below. We recommend you check the law or consult a lawyer to understand what applies in your case. For the purposes of this Annex, "personal data" has the meaning of "personal information" under the CCPA.
14.2 Right to Know
You may ask us to disclose, for the 12-month period preceding your request: the specific pieces of personal data we have collected about you; the categories collected; the categories of sources; the categories of third parties to whom we disclose it; the categories sold or shared, if any, and to whom; the categories disclosed for a business purpose and to whom; and our business or commercial purposes for collecting it.
14.3 Right to Delete
Subject to certain exceptions, you may ask us or our service providers to delete personal data we hold about you. Please read the limitation in Section 8 about entries that form part of a shared ledger.
14.4 Right to Correct
You may ask us to correct inaccurate personal data we maintain about you, taking into account its nature and the purposes of processing. Note that a figure another trip member entered about you is their assertion about a shared trip; we can correct our records, but we do not adjudicate disagreements between members about what was actually spent.
14.5 Do Not Sell or Share My Personal Information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We run no advertising in the Services, collect no advertising identifiers, and upload nothing to advertising platforms.
Because there is nothing to opt out of, we do not operate a "Do Not Sell or Share My Personal Information" mechanism. If that ever changes we will publish the link required by law, in the website footer and in the App, before the change takes effect. We honour Global Privacy Control (GPC) signals as a valid opt-out request in any event. If you would like written confirmation of our position, ask us at privacy@splitrip.com.
14.6 Limit the Use of My Sensitive Personal Information
We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use under the CCPA. We use it, where we hold any at all, only to provide the Services you asked for and for permitted business operations. For that reason we do not operate a separate "Limit the Use of My Sensitive Personal Information" mechanism. We do not infer characteristics about you, and we do not use the contents of your trips or your receipts for any purpose other than providing the Services.
14.7 Right to Non-Discrimination
You have the right not to be discriminated against for exercising any of your consumer privacy rights — including not being denied goods or services, or charged a different price or rate.
14.8 How to Exercise Your California Privacy Rights
Contact. Submit a verifiable request to privacy@splitrip.com. You may exercise your right of access twice in a 12-month period.
Verifiable requests. To exercise the right to know or the right to delete, your request must contain enough information for us to reasonably verify that you are the person whose data we collected, or an authorised agent of that person. Requests made from an account you control will be verified through that account.
Authorised agents. An agent may act for you. We may ask for reasonable evidence of your identity and the agent's identity, and for written authorisation, before complying.
The past 12 months. In the past 12 months we have disclosed the following categories for a "business purpose" (as defined in the CCPA): identifiers, internet or other electronic network activity information, and commercial information relating to the expenses you record — in each case to the sub-processors listed in Section 5.1, and to the other members of your own trips as described in Section 3. We have not sold or shared any personal information for cross-context behavioural advertising.
14.9 Your Rights Under Other U.S. State Privacy Laws
If you are a resident of a U.S. state with a comprehensive consumer-privacy law in effect — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA) and Montana (MCDPA), and other states with similar laws now in force (such as Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Indiana, Tennessee and Florida, and others as they take effect) — you may have the following rights, subject to the exceptions and limitations of the applicable law:
- Right to access or confirm whether we process your personal data, and to access it.
- Right to delete personal data we have collected about you.
- Right to correct inaccurate personal data we maintain about you.
- Right to data portability — to obtain a copy in a portable and, where technically feasible, readily usable format.
- Right to opt out of processing for targeted advertising, the sale of personal data, and certain profiling. We do none of these, so there is nothing to opt out of; we honour GPC signals regardless.
- Right to non-discrimination, and to appeal. You may not be treated differently for exercising these rights, and where the applicable law provides, you may appeal a refusal to act on a request.
To exercise any of these rights, contact privacy@splitrip.com. We will respond within the period the applicable law requires. If we decline your request you may, where the law allows, appeal by replying to our response.
15. Annex B — Your Rights Under Israeli Law
This annex applies to individuals whose personal data we process under the Israeli Protection of Privacy Law, 5741-1981 and its regulations (the "PPL"), as amended, and supplements the rest of this Privacy Notice.
15.1 Notice and Purposes of Processing
We collect and process personal data for the purposes described in Sections 2 to 5 — principally to provide the Services you ask for, to operate and secure them, to comply with legal obligations and to communicate with you. Some data is necessary to use the Services; where data is optional we say so. We determine the purposes and means of processing. Our contact details are in Section 16.
15.2 Right to Inspect and Correct
Under Sections 13 and 14 of the PPL you have the right to inspect the personal data we hold about you and to ask us to correct, amend or delete data that is inaccurate, incomplete, unclear or out of date. Contact privacy@splitrip.com. We may take reasonable steps to verify your identity, and we will respond within the periods the PPL requires. If we decline a correction request you may note your objection, and where applicable we will record that the data is disputed.
15.3 Direct Mailing (Sections 17C–17I of the PPL)
To the extent we use your contact details to send you messages about our own products, this may constitute "direct mailing" under the PPL. Where those rules apply: each message will indicate that it is direct mailing, identify us as the sender, and state your right to be removed; on request we will tell you the source from which we obtained your details; and you may at any time ask to be deleted from our direct-mailing database, which we will honour.
15.4 Transfers Outside Israel
We use service providers and store data on infrastructure located outside Israel, including in the United States (see Section 5.1). Where we transfer personal data outside Israel we do so in accordance with the PPL and its regulations on transfers abroad, and we require recipients to provide an adequate level of protection through appropriate contractual and security safeguards.
15.5 Complaints
If you believe your privacy rights have been infringed you may contact us at privacy@splitrip.com, and you may also contact the Israeli Privacy Protection Authority (PPA).
16. How to Contact Us
Splitrip is managed by Mobile Flow Ltd, Kiryat HaMada St 20, Jerusalem, Israel 9777600, company registration number 517148722.
- Privacy questions and rights requests: privacy@splitrip.com
- Everything else: support@splitrip.com