Privacy Policy
Last updated: July 9, 2026
This policy explains what data Lazy Booking collects, why, and who it is shared with. The short version: we collect what's needed to plan and book your trips, we share it only with the services that make those bookings work, and we never sell it.
1. What we collect
- Account information — your name, email address, and sign-in details, managed by our authentication provider, Clerk.
- Trip and chat data — the messages you send our assistant, the trips it builds, and your stated preferences. Voice messages, if you use them, are transcribed and then handled like text messages.
- Passenger details — when you book, we collect the details travel providers require: passenger names, dates of birth, gender as it appears on ID, email, and phone number.
- Payment data — payments are processed by Stripe. Your card number goes directly to Stripe; we never see or store your full card number. We keep a payment reference so we can issue refunds.
- Usage data — basic product events (for example, “search run,” “checkout started”) and error reports, used to fix bugs and improve the product.
2. How we use it
- To plan trips and make bookings you request.
- To send transactional email: booking confirmations, hotel approval or cancellation notices, and airline schedule-change alerts.
- To provide support and process refunds.
- To detect abuse and keep the service secure.
- To understand usage and improve the product.
We do not sell your personal data or share it with advertisers.
3. Who we share it with
We share data only with the processors needed to run the service, each receiving only what its function requires:
- Duffel — our flight and hotel booking partner; receives passenger and stay details to create bookings with airlines and hotels, which also receive those details to fulfil your booking.
- Stripe — payment processing.
- OpenAI — powers the chat assistant; your conversation messages and trip context are sent to OpenAI to generate responses.
- Viator — activity search, when you explore things to do.
- Clerk — authentication and account management.
- Supabase — our database, storing trips and bookings.
- Vercel — hosting.
- SendGrid — transactional email delivery.
- Sentry — error monitoring.
- Upstash — rate limiting (stores hashed request counters, not message content).
4. Cookies
We use cookies for one thing: keeping you signed in (session cookies set by Clerk). We do not use advertising or cross-site tracking cookies.
5. Retention
Trip and booking records are kept while your account is active so you can access your travel history, and as required for financial record-keeping (for example, refunds and disputes). You can delete individual trips in the app. To delete your account and associated personal data, email us — see Section 7.
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. We honor these requests regardless of jurisdiction where we reasonably can: email odograsmussen@gmail.com and we will respond within 30 days. Note that data tied to a completed booking (for example, a ticketed flight) may need to be retained by the airline or hotel under their own policies.
7. Contact
Privacy questions or requests: odograsmussen@gmail.com
8. Changes to this policy
If we change this policy, we'll update the date at the top of this page and note material changes here. Significant changes that affect how your existing data is used will be announced by email.
