MyTripWallet
Features App Who for? Pricing Business Get the app
Get the app

Privacy Policy

Version: August 2026

  1. Privacy at a glance
  2. Controller
  3. Hosting
  4. Website access data
  5. Account and sign-in
  6. Trips, documents and shared trips
  7. E-mail
  8. Purchases through the App Store
  9. Storage on the device
  10. Advertising in the app
  11. Push messages in the app
  12. Retention and deletion
  13. Your rights
  14. Changes to this policy

1. Privacy at a glance

MyTripWallet manages the documents of a trip. Two different kinds of data arise in the process, and the roles differ between them:

  • Your account data and trip content — everything that arises because you use MyTripWallet. For this we are the controller within the meaning of the GDPR.
  • Third-party data you enter — fellow travellers, clients of a travel agency or people shown on uploaded documents. For this you are the controller; we process it solely on your behalf.

Without an account the data never leaves the device. We use no analytics or tracking services, no social media plugins and no newsletter systems; there is no profiling and no automated decision-making. In the free tier the app shows advertising (see below). Data is not sold to third parties.

2. Controller

Centric Software International Ltd.
M. Karl
20-22 Wenlock Road, N1 7GU London, England
E-mail: [email protected]

Full details in the imprint.

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

Legal bases

We process personal data on the basis of Art. 6(1)(b) GDPR (performance of the user contract, see Terms), Art. 6(1)(f) GDPR (legitimate interest in secure, trouble-free operation), Art. 6(1)(c) GDPR (statutory retention obligations for payments) and, where consent has been given, Art. 6(1)(a) GDPR. Consent given can be withdrawn at any time with effect for the future.

SSL/TLS encryption

This site and all interfaces of the service are delivered exclusively over an encrypted connection (recognisable by https:// in the address bar). Data transmitted cannot therefore be read by third parties.

3. Hosting

MyTripWallet runs on a server in a data centre within the European Union. All application data — accounts, trips, uploaded documents and receipts, and the shares between accounts — is held on that server. No content delivery network is used; fonts, icons and scripts are also delivered from our own server and not loaded from external hosts.

4. Website access data

When a page is requested, your browser transmits technically necessary information that the server records in log files:

  • the address requested, date and time of the request
  • the amount of data transferred and the HTTP status code
  • browser type and version, operating system
  • the referring page, where transmitted
  • IP address

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in secure operation and the defence against attacks. This data is not merged with other data sources. Logs are deleted after 30 days at the latest, unless they are needed to investigate a specific case of abuse.

To fend off automated attacks we store the IP address of suspicious requests in a block list for a limited time.

Contacting us

If you write to us by e-mail, we process your details in order to handle the enquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) or (f) GDPR. Messages remain with us until the purpose ceases to apply and no statutory retention periods stand in the way.

5. Account and sign-in

An account is needed only for syncing, sharing and backup. In doing so we process:

  • e-mail address and, where given, name and profile picture
  • the password — solely as a non-reversible hash, never in plain text
  • a session identifier by which the app recognises you on each request
  • the tier booked and the confirmation status of the account
  • timestamps of creation and last change
  • time-limited identifiers for the confirmation e-mail and for resetting the password

The legal basis is Art. 6(1)(b) GDPR. The account is valid for MyTripWallet only. Other applications of the provider maintain separate accounts with their own records, even for the same e-mail address; no comparison takes place between them.

The app's PIN lock is checked exclusively on the device; the PIN is not transmitted to us.

6. Trips, documents and shared trips

When syncing with the server (from the Premium tier upwards) the following is held there:

  • trips with name, period, destination and notes
  • entries per trip: tickets, bookings, receipts, links and tasks with their details
  • uploaded files and images (ticket PDFs or photographed receipts, for instance)
  • for shared trips, which account sees which trip in which role
  • in client management, the client records you create

The legal basis is Art. 6(1)(b) GDPR. For personal data of third parties that you enter, you are the controller; we process it on your documented instructions (Art. 28 GDPR) and provide a data processing agreement on request. Each account's files reside in a directory of its own; permission is checked on every request.

If you share a trip, the invited accounts see its content. A share can be revoked at any time; copies already saved by other accounts (an exported PDF, for instance) cannot be recalled.

7. E-mail

The service sends e-mail only in response to an event: confirmation of registration, password reset, invitation to a shared trip and notices about the account. Dispatch is handled by the provider's mail server. There is no advertising or newsletter mailing.

8. Purchases through the App Store

Purchases and subscriptions are processed through the Apple App Store. You enter the payment details with Apple; they never reach our server. From Apple we receive only the confirmation of which tier is unlocked for your device or App Store account, and we store that status with your account.

The legal basis is Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR for retention under commercial and tax law. Apple's privacy notices apply in addition.

9. Storage on the device

The app stores data in the device's local storage. Without an account it stays there exclusively:

  • trips, entries and attachments (IndexedDB)
  • the session (account identifier, session identifier, display name) and the PIN lock
  • the chosen language, the light/dark setting and the view last opened

Receipt recognition (OCR) and the generation of the itinerary PDF run entirely on the device; no images or texts are transferred to us or to third parties in the process. The legal basis is Art. 6(1)(b) GDPR. Signing out and clearing the app data removes these entries.

10. Advertising in the app

In the free tier the iOS app shows an advertising banner at the bottom of the screen. It is delivered through Google AdMob (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). In doing so Google processes device data such as the device's advertising identifier, the IP address and coarse location in order to select ads and to enable billing and abuse detection.

The legal basis is Art. 6(1)(f) GDPR (funding the free tier); where personalised advertising or access to the advertising identifier requires consent, that consent is obtained through the operating system prompt and can be withdrawn there at any time (Settings > Privacy & Security > Tracking). The advertising identifier can also be reset or switched off in the system settings.

From the first paid tier onwards the banner disappears entirely; no connection to AdMob is then established. There is no advertising in the browser.

11. Push messages in the app

If you allow notifications, the operating system generates, via Firebase Cloud Messaging (Google Ireland Limited), a device identifier that we assign to your account so we can send you notices about dates and shared trips. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time in your device settings; the stored device identifier is then no longer used and is removed when the account is deleted. There are no push messages in the browser.

12. Retention and deletion

  • Account data — until you delete the account.
  • Trips, entries and files on the server — until you delete them or your account. We do not delete them on our own initiative.
  • Data held only on the device — until you delete it or remove the app; it is not restored afterwards if no sync was running.
  • Access logs — after 30 days at the latest.
  • Purchase records — for the statutory retention periods, as a rule six to ten years.

You delete your account yourself in the app. All trips, documents, receipts and tasks are removed from the server and the account is deactivated. The action cannot be reversed. Accounts with other applications of the provider are unaffected.

13. Your rights

You have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the processing (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on a legitimate interest (Art. 21). Consent given can be withdrawn at any time with effect for the future.

Please contact [email protected]. If another account has shared a trip with you, please address questions about the content entered there to that account first — it is the controller for that data.

Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement.

14. Changes to this policy

We adapt this policy when the service or the legal situation changes. The version published here at the time applies. In the case of substantial changes we additionally inform account holders in the application or by e-mail.

MyTripWallet Imprint Terms Privacy Disclaimer Help

Help & guide