TripFlair holds your family's trips, photos, and plans. Here's exactly how we protect them — in plain language, because trust shouldn't require a law degree.
Every layer of TripFlair runs on platforms that pass rigorous, annual third-party security audits. Think of these as the passport stamps our infrastructure has earned.
Where your trips and account live. Every record is encrypted at rest with AES-256 and in transit with TLS.
Serves TripFlair over HTTPS everywhere, with audited infrastructure and annual penetration testing.
Your card details go straight to our payment partner and never touch TripFlair's servers. We couldn't see your card number if we tried.
These certifications belong to our infrastructure partners and cover the platforms TripFlair is built on. We pair them with our own application-level protections below.
Your itineraries, memories, and brochures belong to you. Download your trip data or export print-ready PDFs any time — no lock-in, no hoops.
Ask us to delete your account and we remove your trips, memories, and personal data from our systems. Gone means gone.
We work with a short, published list of service providers — database, hosting, payments, email, maps, weather, and AI — each bound by their own security commitments. The full list lives in our Privacy Policy.
If you believe you've found a security vulnerability in TripFlair, we want to hear from you — quickly and directly. Email security@tripflair.net and we'll respond promptly. We're grateful to researchers who help keep family memories safe.