Privacy Policy

Last Updated: September 2026

At LetsPackUp.com, we take your privacy seriously. This policy describes how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).

1. Data Controller

LetsPackUp.com (The "Service") is the data controller. You can contact us at privacy@letspackup.com regarding any data concerns.

2. Data We Collect

  • Account Data: Name, email address, and avatar image (via Google/Microsoft/Apple login).
  • Trip Data: Itineraries, expenses, and chat messages you create.
  • Location Data: If you enable location sharing, your GPS coordinates are shared with trip members in real-time.

3. How We Use Your Data

We use your data solely to provide the collaborative travel planning service. We do not sell your personal data to third parties.

4. Data Sharing

Your trip data is shared with the members of your trips. It leaves the platform only if you connect an AI assistant yourself — see 4.1 below. We use the following third-party services:

  • Authentication: Google, Microsoft, and Apple for secure login
  • Cloud Infrastructure: Hosted on secure servers in Germany
  • Maps: OpenStreetMap for map functionality
  • AI Assistants: Only if you connect one yourself. The trip content covered by the permissions you grant is sent to that assistant's provider — for example Claude or ChatGPT — which is your own chosen processor, not ours.

4.1 AI Assistants You Connect

LetsPackUp can be connected to an AI assistant you already use, so it can read your trips and help you plan them. Nothing is connected by default. A connection exists only after you sign in on our consent screen and tick the permissions you want to grant, and it covers only the trips you select there.

While a connection is live, the trip content covered by the permissions you granted is sent to the provider of the assistant you connected, each time you ask it about that trip. That provider handles the content under its own privacy policy and its own terms, as a processor you chose rather than one we engaged. We cannot see, control or delete what it keeps, so please read the privacy policy of the assistant you connect.

Permissions are granted one at a time on the consent screen, and none of them implies another:

  • Read the trips you select: itinerary, destinations, the map coordinates of the planned places, packing lists, expense amounts, availability and polls. This includes the booking details recorded on an itinerary item — the booking reference, the link and who it is booked with, the street address, access notes such as a door code, a contact phone number, required travel documents and the stated check-in and check-out times — the same details the app shows to everyone on the trip.
  • Add and edit content in those trips: activities, destinations, notes, map coordinates and time zones, packing items, availability, comments and votes in a poll. An assistant can also record a booking reference, door code, street address or contact phone number into the protected field that holds it, and can change one that is already there. Deleting is a separate permission.
  • Create a new trip for you. A trip an assistant creates is added to that connection automatically.
  • Permanently delete content from those trips: itinerary items, destinations, packing items, expenses and comments the assistant wrote itself, and — only while nobody else has ever joined it — a whole trip the assistant created for you. It can only delete things you added yourself or that it added for you, and there is no undo.
  • Read a trip's group chat, including replies. This is separate from sending, and it is the widest of these permissions: everything anyone has written in that chat, and everything written from then on, is sent to the assistant's provider. Your co-travellers are not asked and cannot revoke it — only you can.
  • Send a message to a trip's group chat as you, and start a poll there.
  • Invite someone to a trip by email.
  • List, add and delete your own documents in a trip — the file name, type and size only, never the contents of a file and never a download link — and read and add your own emergency contact. Another member's documents and another member's emergency contact are never reachable.

Some things are never sent to a connected assistant, at any permission level, and no setting turns them on:

  • Invite links and calendar feed links — anyone holding one could join your trip or read its entire itinerary without logging in.
  • Member email addresses and profile photos of the people you travel with.
  • Live location, and the emergency contacts of the people you travel with. Location sharing cannot be connected at all: the map coordinates of a planned stop are trip content and are covered by the read permission, but where anybody actually is never leaves the platform. Your own emergency contact is not on this list: it has its own permission above, which you tick or leave unticked.
  • Receipt files, document download links, and group chat links such as a WhatsApp or Telegram group invitation.

Booking details are not on that list, and this changed in September 2026. Until then, a booking reference, street address, door code, contact phone number or required document recorded on an itinerary item was never sent to a connected assistant. It now is, to any assistant you give the read permission to, because those details are ordinary trip content that LetsPackUp already shows to everyone on the trip, and withholding them only stopped your own assistant answering questions you can answer by opening the app. Two consequences are worth stating plainly. A booking reference together with the provider's name can be enough for someone to change or cancel that booking, and it now leaves the platform along with the rest of the trip. And your co-travellers wrote some of those details, so this is one more thing your connection exposes on their behalf. If that is not what you want, do not grant the read permission, or connect only the trips you are comfortable sharing. Free text has always worked this way: anything anyone types into an activity description, a note or a comment is trip content and is read by any assistant with that permission.

A trip is co-authored. The people you travel with write the activities, comments, notes and expenses your assistant reads, so connecting one exposes their contributions as well as yours. In this first version they are not told that you connected an assistant and cannot revoke your connection — only you can. Please consider whether the group would agree before connecting an assistant to a shared trip. Making a connection visible to everyone on the trip is the first change we intend to make here.

A chat message sent by a connected assistant is labelled "sent via" the app that sent it, so the other members can see it did not come from you directly. Because an assistant reads text other members wrote, an instruction hidden in a trip's content can in principle make it send such a message in your name. These messages are always labelled and strictly rate-limited, but that label is what the group has to go on, and we would rather say so plainly than leave it unsaid.

We store the connection itself: which app you connected, which permissions you granted, which trips it covers and when it was last used. That record appears in your data export and is deleted with your account. We also keep a usage log of every request a connected assistant makes — the name of the action, whether it succeeded, how long it took and which connection made it, never the content of the request or of your trip. The log is kept for 400 days and then deleted. Deleting your account removes the connection record at once; the usage log runs out on its own and no longer names anyone once the account is gone.

You can revoke a connection at any time under "Connect AI" in Profile & Settings. Revocation takes effect on that assistant's next request. It does not reach data the provider already received, so ask that provider to delete it on their side as well.

5. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: View and download all data we hold about you.
  • Correction: Update your profile information at any time.
  • Deletion: Request complete deletion of your account and data.
  • Portability: Export your data in JSON format.
  • Objection: Object to certain processing of your data.

6. How to Exercise Your Rights

You can exercise all of these rights directly from your account:

  • Click on your profile picture in the navigation bar to open Profile & Settings.
  • Under "Your Data", click "Download My Data" to export all your personal data as a JSON file.
  • Under "Delete Account", you can permanently delete your account and all associated data.

For any additional requests, contact us at privacy@letspackup.com.

7. Security

We implement security measures including encryption in transit and secure authentication. Data is stored in European data centers.

8. Contact Us

If you have any questions about this Privacy Policy, please contact us at:
privacy@letspackup.com

Related Legal Documents