Splitide (“the app”, “we”, “us”) helps groups split trip and group expenses fairly. This policy explains what we collect, why, how it's protected, and the rights you have. Our guiding principle is simple: we collect only what the app needs to work, and nothing for advertising or tracking.
Who is responsible
The data controller is the operator of Splitide, based in Serbia. For any privacy question, data request, or complaint, contact us at splitide@proton.me. We answer privacy requests within 30 days.
What we collect
- Account: your email address and a display name — either from Google sign-in or entered when you register with email and password. Passwords are never stored by us in readable form; they are handled and hashed by our authentication provider.
- Trips: trip names, the member names you add, the currency, and an optional trip photo.
- Payments: amounts, descriptions, dates, who paid, and how each expense is split between members.
- Activity: a log of actions (an expense added, marked paid, or a trip settled) shown to the members of that trip so everyone stays in sync.
- Notifications: if you enable push notifications, a device token that lets us deliver alerts about your trips. You can turn this off in your device settings at any time.
- Technical: a login token, your theme preference, and a local cache of your trips are stored on your own device so the app opens instantly and works offline.
We do not collect your location, contacts, or advertising identifiers, and we do not use third-party analytics, advertising, or cross-site tracking of any kind.
Why we use it (legal basis)
We process this data to provide the service you asked for — creating trips, splitting costs, and sharing them with the people you invite (performance of a contract, GDPR Art. 6(1)(b)). Push notifications are sent on the basis of your consent (Art. 6(1)(a)), which you can withdraw at any time. Currency conversion uses an anonymous public rate lookup that does not include any of your personal data.
Where it's stored & who processes it
We rely on a small set of trusted infrastructure providers who act as our processors, each under their own data-processing terms:
- Supabase — stores your account, trips, payments and activity in a Postgres database, and handles sign-in (authentication). This is where your data lives.
- Google Firebase — hosts the web app (Hosting) and delivers push notifications (Cloud Messaging).
- Google Sign-In — used only if you choose to sign in with your Google account, to confirm your identity.
Access to your data is protected by row-level security rules so that only you and the members you invite to a trip can read it. Currency rates are fetched from a public exchange-rate API.
Sharing
We never sell your data and we never share it for advertising. The trips and payments you create are visible only to the accounts you invite to that specific trip. We share data solely with the infrastructure providers listed above, only as needed to run the app, and where we are legally required to do so.
Retention
We keep your data for as long as your account is active. You can delete individual payments and trips at any time, or delete your entire account and all data you own from the in-app account menu. When you delete your account, your profile and the trips you own are permanently removed. Local data cached on your device is cleared when you sign out.
Your rights
Under the GDPR and similar laws you have the following rights, most of which you can exercise directly in the app (account menu → Export my data / Delete account):
- Access & export — download all your trips and payments as a CSV file.
- Rectify — edit your name, trips, and payments.
- Erase — permanently delete your account and the trips you own.
- Object & restrict — contact us to object to or limit certain processing.
You also have the right to lodge a complaint with your local data-protection authority.
Security
Data is transmitted over encrypted connections (HTTPS/TLS) and stored by our providers with encryption at rest. Access is restricted by per-user, per-trip security rules. No online service can be guaranteed to be 100% secure, but we take reasonable steps to protect your information.
International transfers
Our providers may process data on servers located outside your country, including outside the EU. Where that happens, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Children
Splitide is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Changes
We may update this policy from time to time; material changes will be reflected here with a new “Last updated” date. Continued use of the app after a change means you accept the updated policy.
Contact
Questions or requests? Email splitide@proton.me.