Privacy Policy
Last updated: August 18, 2026
Background
Performance Marketing Group Limited (“TripCrane,” “we,” “us,” or “our”) understands that your privacy matters and that you care how your information is used and shared online. We collect only what the service needs, we do not sell it, and this page sets out exactly what we hold and why.
This Privacy Policy applies to our use of any data we collect in relation to your use of the TripCrane website and subscriber app. Please read it and make sure you understand it. Your acceptance is deemed to occur on your first use of the site. If you do not agree with it, please stop using the site.
This policy should be read together with our Terms of Service.
1. Definitions
- Account: the subscriber account required to use the watch, alert and preference features of the service.
- Alert: an email we send you when a trip on your list clears the settings you saved.
- Cookie: a small text file placed on your device by our site or by one of the providers named in section 10.
- GDPR: Regulation (EU) 2016/679, and the UK GDPR as retained in UK law, applying to visitors in the European Economic Area and the United Kingdom.
- Isle of Man Data Protection Law: the Data Protection Act 2018 (Isle of Man) and the GDPR and LED Implementing Regulations 2018, which govern us as an Isle of Man company.
- Personal Data / Personal Information: any information relating to an identified or identifiable person.
- Sensitive Personal Information: as defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and analogous state laws. See section 6.
- Site: tripcrane.com and its subdomains, including the subscriber app.
- U.S. State Privacy Laws: the CCPA/CPRA and comparable laws including the Virginia CDPA, Colorado Privacy Act, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA and Florida Digital Bill of Rights.
2. Information about us
The Site is owned and operated by, and the data controller for all Personal Data collected through it is:
Performance Marketing Group LimitedRegistered in the Isle of Man, company number 016728V
4 Christian Road
Douglas
Isle of Man, IM1 2SD
Email: support [@] tripcrane.com
Phone: +1 888 308 9229
3. Scope: what this policy covers
This policy covers your use of the Site only. It does not extend to any website we link to. Our alerts and pages link out to airlines, hotels, online travel agencies and our hotel booking partner, and once you follow one of those links you are on that company's site under that company's privacy policy. We have no control over how they collect, store or use your data, and we recommend you check their policies before providing information to them.
4. What data we collect
Some data is collected automatically (see section 10 on cookies). The rest you give us yourself. Depending on how you use the Site we may collect some or all of the following:
Identifiers and contact information
- Your name, where you or our payment processor provide it
- Your email address
- Your country of residence and, for tax purposes, the billing country our payment processor reports to us
Your trip preferences
- The destinations, dates and date flexibility you want watched
- Your home or departure airport
- Your budget, cabin and comfort preferences
- Your passport country, used only to check visa requirements for the trips we show you (see section 6)
Service activity
- Which alerts we sent you, when, and whether you opened them or clicked a booking link
- Which watches and on-demand trip checks you have used, and your remaining allowance or alert credits
- Support correspondence you send us
Billing information
- Your subscription tier, its status, renewal dates, and the identifier our payment processor assigns you
- We do not receive or store your card number, expiry date or security code. Those go to our payment processor and never reach our servers.
Technical and usage information, collected automatically
- IP address, approximate location derived from it (country or region level), browser and device type, operating system
- Pages requested, referring URL, time and date of each request, and standard server and security logs
- The advertising and analytics identifiers described in sections 9 and 10, including click identifiers passed to us by ad platforms such as Google's gclid and Meta's fbclid
- A first-party session cookie that keeps you signed in
5. How we use your data
- To provide the service. Creating and running your account, running your watches, checking prices, deciding whether a trip clears your settings, and sending you the alert.
- To bill you. Starting, renewing, changing and cancelling your subscription, applying alert credits you buy, and issuing refunds.
- To communicate with you. Your welcome email, sign-in links, alerts, service notices, and replies to your support messages.
- To keep the service safe. Detecting and preventing fraud, abuse, credential sharing and automated scraping, and protecting the Site from attack.
- To improve the service. Understanding which pages, features and alert types work, in aggregate.
- To measure our advertising. Understanding which ads and pages bring subscribers, as described in section 9.
- To meet our legal obligations. Tax, accounting and record-keeping duties, and responding to lawful requests.
We do not use your trip preferences, alert history or passport country to build advertising profiles, and we do not share them with any advertising platform.
6. Sensitive personal information
We do not ask for and do not want health data, financial account numbers, government identification numbers, precise geolocation, biometric data, or information about your race, ethnicity, religion, sex life or sexual orientation. Please do not send any of it to us.
One field needs calling out. We ask for your passport country so that visa notes in your alerts are correct for you. Under the CCPA/CPRA, citizenship information counts as Sensitive Personal Information, so we treat it that way: it is used solely to determine visa requirements for the trips we show you, it is never used to infer anything about you, it is never used for advertising or profiling, and it is never sold or shared. Under the GDPR it is not a special category of data, but we apply the same restriction to it regardless of where you live. You can leave it blank; your alerts will simply carry no visa note.
7. Legal bases for processing (EEA, UK and Isle of Man)
- Performance of a contract. Running your account, your watches and your alerts, and billing you, because that is the service you bought.
- Legitimate interests. Security, fraud prevention, service improvement, aggregate measurement, and defending legal claims. We balance these against your rights and use the least data that achieves the purpose.
- Consent. Non-essential cookies and the analytics and advertising technologies in sections 9 and 10, where consent is required in your jurisdiction. You can withdraw consent at any time.
- Legal obligation. Tax, accounting and other statutory record-keeping.
8. Do we share your data?
We do not sell your personal data for money. We share it only with the providers that run the service on our behalf, each under contract and each limited to what its job requires:
| Provider | What it does | What it receives |
|---|---|---|
| Gumroad | Payment processing as merchant of record | Your name, email, billing country and card details, which you give directly to them |
| Resend | Sends our email | Your email address and the contents of the email |
| Cloudflare | Hosting, content delivery and security | Your IP address and request data |
| Travel data providers | Flight and hotel price and availability lookups | Routes, dates and budgets only. Never your name, email or any account identifier. |
| Our hotel booking partner | Hosts the hotel pages our alerts link to | Only what your browser sends when you follow a link, under their own policy |
| Google, Meta, Mixpanel, Segment | Analytics and advertising measurement | Site usage and the identifiers in sections 9 and 10. Never your trip preferences or passport country. |
We may also disclose data where we are legally required to, where we need to establish or defend legal claims, or to protect the rights, property or safety of any person. If we are ever compelled to disclose your data, we will tell you unless the law forbids it.
9. Advertising and measurement
We advertise on Google and Meta, and we need to know which ads produce subscribers. To do that we use the following, mainly on our public marketing pages rather than inside your account:
- Google Tag Manager to load and manage the tags below. It is a container, not an analytics product in itself.
- Google Analytics for aggregate traffic and page performance.
- Google Ads conversion tracking and remarketing tags, which tell us that a click on one of our ads led to a page view or a subscription.
- Meta pixel and Conversions API for the same purpose on Facebook and Instagram.
- Mixpanel for product analytics: which pages, forms and features get used, and where people drop out.
- Segment as the pipeline that routes those events to the tools above so each tool does not need its own script.
What these receive is page and event data, cookie or device identifiers, IP address, and, for conversion matching, an identifier derived from your email address in hashed form. What they never receive is your trip preferences, your watch settings, your alert history or your passport country.
Under the CCPA/CPRA, disclosing identifiers to advertising platforms for cross-context behavioural advertising counts as sharing even though no money changes hands. We therefore treat it as sharing and honour opt-outs. See section 19 for how to opt out, and section 10 for the browser-level controls that apply.
10. Cookies and similar technologies
Cookies fall into two groups on our Site.
Strictly necessary
These make the Site work and cannot be switched off from within the Site. They include the first-party cookie that keeps you signed in, and Cloudflare's security cookies used to distinguish real visitors from automated traffic.
Analytics and advertising
These are the technologies in section 9, and they are the ones you get a choice about.
A short notice appears at the bottom of the page the first time you visit, with an Accept and a Decline button. If you are in a place where the law requires your prior consent, which includes the EEA and the United Kingdom, nothing in this group is loaded at all until you press Accept. Everywhere else these tags run from the first page view and Decline switches them off. Either way your choice is remembered on your own device, not in a cookie we read, and you can change it whenever you like with the Cookie choices link in the footer of every page.
If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as a Decline before you touch anything, no analytics or advertising tag is loaded, and we do not show you the notice to ask you to reconsider. You already answered.
| Set by | Purpose | Category |
|---|---|---|
| TripCrane | Keeps you signed in to your account | Strictly necessary |
| Cloudflare | Security, bot detection, load balancing | Strictly necessary |
| Google Tag Manager | Loads the tags below | Analytics and advertising |
| Google Analytics | Aggregate traffic measurement | Analytics |
| Google Ads | Conversion tracking and remarketing | Advertising |
| Meta | Conversion tracking and audience measurement | Advertising |
| Mixpanel | Product analytics and A/B testing | Analytics |
| Segment | Routes events to the tools above | Analytics and advertising |
You can also block or delete cookies in your browser settings, though the strictly necessary ones are required to stay signed in. The ad preference controls that Google and Meta each provide apply to their tags as well, independently of anything you choose here.
One limitation worth stating plainly: to know whether the consent rule applies to you we read your device's timezone, because these pages are static files with no server that sees where the request came from. It is a good proxy and not a perfect one. If you are in Europe on a device set to a non-European timezone, and you would rather nothing loaded before you chose, press Decline or send a Global Privacy Control signal and nothing will.
11. Communications: email, phone and text
We send service email only: your welcome email, sign-in links, your trip alerts, billing notices, and replies to your support messages. Alerts are the product, so they continue while your subscription is active; you can pause or delete your watches at any time, or cancel the subscription.
We do not run a marketing text message programme and we will not send you marketing SMS. We do not make marketing phone calls. The phone number in section 2 is for reaching us, not for us to reach you.
Any use of your email address beyond the service email described above would require a separate, explicit opt-in from you.
12. Data retention
- Account data and trip preferences: for as long as your account exists, then deleted within 30 days of closure or of a deletion request.
- Alert and activity history: for as long as your account exists, then deleted on the same basis.
- Support correspondence: up to 24 months after the matter is closed.
- Server and security logs: typically 30 to 90 days.
- Billing and tax records: retained by us and by our payment processor for as long as tax and company law require, which is generally six to seven years. This is a legal obligation and survives deletion of your account.
13. How and where we store your data
Your account data is stored on servers we control, protected by access controls, encryption in transit, and administrative access limited to those who need it. Sign-in uses single-use links sent to your email address rather than a stored password. No system is perfectly secure, and we cannot guarantee absolute security, but if a breach ever affects your data we will notify you and the relevant regulator as the law requires.
14. International data transfers
We are established in the Isle of Man. The Isle of Man holds an adequacy decision from the European Commission, and is treated as adequate by the United Kingdom, which means personal data can move from the EEA and the UK to us without additional safeguards.
Several of our providers are in the United States. Where data reaches them we rely on the appropriate safeguards for that transfer, which means Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable, or the provider's own certification under the EU-U.S. and UK-U.S. Data Privacy Framework where it participates. You can ask us which mechanism applies to a specific provider.
15. What happens if our business changes hands
If the business or any part of it is sold, merged or reorganised, your data may transfer to the new owner, who would be bound by this policy for the data they receive. We would tell members by email before any such transfer takes effect and before your data is used for any new purpose.
16. Your rights: the short version
Wherever you live, you can email us at support [@] tripcrane.com to ask what we hold about you, to correct it, to get a copy of it, or to have it deleted. We answer within 30 days and we never charge for it. We do not discriminate against anyone for exercising a privacy right, and using these rights will never change your price, your tier or your service.
17. Your rights under the GDPR, UK GDPR and Isle of Man law
If you are in the EEA, the UK or the Isle of Man you have the right to:
- be informed about how we use your data, which is what this policy is for;
- access your data and receive a copy;
- have inaccurate data corrected;
- have your data erased, subject to our legal retention duties;
- restrict how we process your data;
- data portability, meaning a copy in a commonly used machine-readable format;
- object to processing based on legitimate interests, and to object at any time to processing for direct marketing;
- withdraw consent at any time where we rely on consent;
- not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. See section 20.
You also have the right to complain to a supervisory authority. In the Isle of Man that is the Information Commissioner (inforights.im). In the UK it is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority for your country of residence. We would rather you came to us first at support [@] tripcrane.com so we can put it right.
18. Your U.S. state privacy rights
Depending on your state, you may have the right to know what personal information we collect and how we use and disclose it, to access and receive a copy of it, to correct it, to delete it, to opt out of its sale or sharing for cross-context behavioural advertising, to opt out of profiling in furtherance of decisions with legal or similarly significant effects, to limit our use of sensitive personal information, and to appeal a refusal.
To make it concrete for California:
- We do not sell personal information and we have not sold personal information in the preceding 12 months.
- We do share identifiers and internet activity with the advertising platforms in section 9 for cross-context behavioural advertising, which counts as sharing under the CPRA.
- Sensitive personal information: the only item we hold that qualifies is your passport country, used solely for visa notes, never for advertising or inference, and never sold or shared. We do not use sensitive personal information for any purpose that would trigger the right to limit.
- We do not knowingly sell or share the personal information of anyone under 16.
To opt out of sharing, or to exercise any of the rights above, email support [@] tripcrane.com with the word Privacy in the subject line, or use your browser's Global Privacy Control signal where it is available. We will verify your request against the email address on your account before acting on it. You may use an authorised agent, in which case we will ask for proof of their authority. If we refuse a request we will tell you why and how to appeal.
19. Automated decision-making and profiling
Our watch engine works automatically end to end. It compares live prices against the settings you saved, puts each candidate trip through four fixed checks, and sends the alert when all four pass or holds it when any of them fails. No person reviews an alert before it goes out.
None of this is a decision with a legal or similarly significant effect on you, which is the threshold that triggers the right in section 17 not to be subject to solely automated decision-making. What the engine decides is whether a trip is worth an email. We do not use automated decision-making or profiling for pricing, for credit, for eligibility, for anything that affects your rights, or to make any inference about you as a person.
20. Children's privacy
TripCrane is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, email support [@] tripcrane.com and we will delete it.
21. Changes to this policy
We may update this policy. The current version always lives at this page with the date at the top. If a change is material, members get an email before it takes effect, and where the law requires consent for the change we will ask for it rather than assume it.
22. Contacting us
For anything about your data, including any request under sections 16 to 18:
Performance Marketing Group Limited (company number 016728V)4 Christian Road, Douglas, Isle of Man, IM1 2SD
Email: support [@] tripcrane.com
Phone: +1 888 308 9229
Please write the email address in the normal way when you send to it. We display it like that here to keep the spam bots off it.