Privacy Policy
How we handle your data
Last updated: 16 May 2026. Drafted in plain language. Aligned with India's Digital Personal Data Protection Act, 2023 (DPDPA).
Who we are
Score My Trip (also referred to as "we", "us") is the data fiduciary for personal data collected through this product. If you have any privacy question or want to exercise your rights, write to scoremytrip@gmail.com. Our grievance officer contact is at the end of this policy.
What we collect and why
We collect the minimum data we need to run the audit and operate the product. Each item below names what is collected and the purpose it is collected for.
- Email address — collected only when you choose to save your audit to your history, sign in via magic link, or unlock a paid audit. Used to identify your audits, send the magic-link sign-in email, and contact you about your audit when needed.
- The travel package or plan you upload or paste — sent to our backend for structured extraction (a large language model parses it into fields) and for the deterministic rule audit. Used only to run your audit and to display it back to you.
- Notes you type in the agent-remarks, T&C paste, or quote fields — same treatment as the package text. Used only for your audit.
- Audit history (when you save an audit to your account) — stored on our backend so you can return to it, run follow-up audits, and see score deltas.
- IP address — used for rate limiting during our introductory free window (3 audits per IP per 24 hours, raised to 10 if you share Score My Trip with three friends via the share form) and for basic abuse protection. Not used to build a profile of you.
- Friend email addresses (only if you use the share form on a results page) — used once to send each of the three friends a single short share email, then discarded by our backend. We do not add them to a marketing list and we do not email them again unless they sign up themselves.
- Feedback you submit (thumbs up or down, optional comment) — used to improve the product. Stored against your audit so we can correlate feedback patterns with audit shape.
Who processes your data on our behalf
We use a small number of named service providers to operate the product. Each is bound by their own data-processing terms.
- Anthropic (United States) — runs the large language model that parses your uploaded package and writes the optional "travel-savvy take" summary. The package text is sent to Anthropic for processing under their data terms; they do not use it to train their models.
- Google Places (United States) — used to look up hotel coordinates for distance-to-city-center calculations.
- Resend (United States) — sends magic-link sign-in emails and share emails. Sees the recipient email and the message body.
- Railway (United States) — hosts our backend.
- Vercel (United States) — hosts the frontend you are reading right now.
Because these providers operate in the United States, your data is transferred outside India when it is processed. By using Score My Trip you consent to this cross-border transfer for the specific purposes above. We do not transfer your data to any jurisdiction the Indian government restricts.
How long we keep it
Different items have different retention periods.
- Audits saved to your account stay on our backend until you delete them or ask us to delete them.
- Audits run anonymously (without saving to history) live in your browser's local storage on your device, not on our backend.
- Magic-link tokens expire within 15 minutes of being issued and are one-time use.
- Friend email addresses entered in the share form are used only to send the one share email and are not retained.
- Feedback rows are retained until you ask us to delete them.
- Server logs (request paths, status codes, IP addresses for rate limiting) are retained for up to 90 days for abuse investigation and then rotated out.
Your rights under the DPDPA
You have the following rights with respect to your personal data. Write to scoremytrip@gmail.com to exercise any of them. We respond within seven working days and resolve the request within thirty.
- Right to access — a summary of what personal data we hold about you and how it has been used.
- Right to correction — correct any inaccurate or incomplete data.
- Right to erasure — delete your account and the audits associated with it. We may retain a non-identifiable subset for model improvement unless you ask us to purge that too, in which case we will.
- Right to grievance redressal — escalate any complaint about how we handle your data. See the grievance-officer section below.
- Right to nominate — nominate someone to exercise these rights on your behalf if you are incapacitated or deceased.
You can withdraw your consent at any time by writing to us. Withdrawing consent does not affect the lawfulness of processing we already did before you withdrew.
Children
Score My Trip is intended for users 18 years and older. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, write to scoremytrip@gmail.com and we will delete it.
Cookies and similar technologies
We use a single first-party session cookie to keep you signed in after you click a magic link. We do not use third-party analytics cookies and we do not run advertising trackers. Your browser may also use local storage to keep your most recent anonymous audit accessible after a page refresh; that data never leaves your device unless you explicitly save it to your account.
Security
We use HTTPS for all data in transit. Backend secrets are stored in our hosting provider's secret manager and never committed to code. Magic-link tokens are signed and time-bound. No security setup is perfect. If you suspect a breach, write to scoremytrip@gmail.com.
What we do not do
We do not sell your data. We do not rent your email to anyone. We do not maintain a public ranking of operators. We do not scrape aggregator sites on your behalf. We do not send marketing emails to addresses entered in the share form.
Changes to this policy
We will update this policy when the underlying data practice changes. Material changes will be announced at the top of the page and in a short note next to the "Last updated" date. We will not retroactively widen our use of data already collected without your fresh consent.
Grievance officer
The grievance officer for Score My Trip is the founder, reachable at scoremytrip@gmail.com. We acknowledge complaints within forty-eight hours and resolve them within thirty days. If you are not satisfied with our response you may approach the Data Protection Board of India once it is constituted under the DPDPA.
ScoreMyTrip · informational only