Privacy Policy

Last updated: July 14, 2026

This Privacy Policy explains how Kapua (“Kapua”, “we”, “us”) collects, uses, and protects personal data when you use our website and application (the “Service”). It is written to address the EU/UK GDPR and the California CCPA/CPRA. Kapua is currently in beta; we keep this policy consistent with what the Service actually does and will update it as the Service evolves.

Who we are (Controller)

Kapua is operated by an individual sole operator based in Slovenia, who is the controller of personal data processed through the Service. You can reach us about privacy at privacy@kapua.io. Because we are established in the EU, an Article 27 representative is not required, and we have not appointed a Data Protection Officer as our processing does not require one.

Data we collect

  • Account data you provide: name, email address, password (stored only as an Argon2id hash), and optional profile photo.
  • Trip & content data: the trips, options, votes, comments, expenses, checklists, chat messages, and post-trip memories you and your group create.
  • Billing data: your plan and subscription status. Card details are handled entirely by our payment processor (Stripe) — we never see or store full card numbers.
  • Location text you enter: place names you add to options are sent to a mapping service to look up coordinates for the map.
  • Receipt images (optional, Pro): if you use receipt scanning, the photo you upload is sent to an AI provider to extract the line items, then the result is stored with your trip.
  • Technical & security data: IP address and device/browser information seen by our servers, and security-activity logs (sign-ins, security events) used to operate and protect the Service.
  • Cookieless analytics: aggregate usage statistics (pages visited, referring domain, language, and whether you’re on mobile or desktop). We do not store your IP address for analytics; visitors are counted with a daily-rotating, irreversible hash, and raw analytics rows are deleted after 90 days. See “Cookies”.

How and why we use data (purposes & GDPR legal bases)

  • Provide and secure the Service, authenticate you, and run your trips — performance of a contract (Art. 6(1)(b)).
  • Process payments and manage subscriptions — contract and legal obligation (Art. 6(1)(b), (c)).
  • Send transactional/service emails (verification, password reset, invitations, security alerts) — contract and our legitimate interests (Art. 6(1)(f)).
  • Send optional product emails — only with your consent (Art. 6(1)(a)); you can opt out at any time from your notification settings.
  • Understand aggregate, cookieless usage to improve the Service and prevent abuse — legitimate interests (Art. 6(1)(f)).
  • Maintain security, prevent fraud/abuse, and keep audit logs — legitimate interests and legal obligation.

Sharing and processors

We do not sell your personal data and we do not use advertising trackers. We share data only with service providers (“processors”) acting on our behalf under contract:

  • Hetzner Online GmbH (Germany, EU) — cloud hosting and database.
  • Stripe — payment processing for paid plans.
  • Resend — delivery of transactional emails.
  • Google — AI processing of receipt images you upload for the optional Pro receipt-scan feature.
  • OpenStreetMap / Nominatim — geocoding place names you enter, for the map.
  • Open-Meteo — weather forecasts for your trip destination.

Analytics is first-party and self-hosted — no third-party analytics provider is involved. We may also disclose data to comply with law, enforce our terms, or protect rights and safety, and in connection with a business transfer (with notice where required).

International transfers

Our hosting is in the EU. Some processors (e.g. Stripe and Google) may process data in the United States or other countries. Where we transfer personal data outside the EEA/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Contact us for details.

Retention

  • Account & trip content: kept while your account is active; deleted or anonymized when you delete your account (self-service in Settings).
  • Security/audit logs: up to 365 days.
  • Cookieless analytics: raw rows deleted after 90 days.
  • Billing records: retained as required by tax and accounting law.

Your rights (EU/UK – GDPR)

If you are in the EEA or UK, you have the right to:

  • access your data and obtain a copy (portability);
  • rectify inaccurate data and complete incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict or object to processing;
  • withdraw consent at any time (without affecting prior processing);
  • lodge a complaint with your supervisory authority (in Slovenia, the Information Commissioner / Informacijski pooblaščenec).

You can export and delete your data directly from your profile settings, or by emailing privacy@kapua.io. We respond within the timeframes required by law (generally one month under the GDPR).

Your rights (California – CCPA/CPRA)

If you are a California resident, you have the right to:

  • know what personal information we collect and how it’s used and shared;
  • access, delete, and correct your personal information;
  • opt out of the “sale” or “sharing” of personal information (we do neither), and limit use of sensitive personal information;
  • not be discriminated against for exercising your rights.

We do not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise your rights, use your profile settings or email privacy@kapua.io; you may use an authorized agent. We will verify your request before acting on it.

Cookies

We use only strictly necessary cookies: a session cookie to keep you signed in and a CSRF-protection token. Our analytics is cookieless — it sets no cookies and stores no IP address — so no cookie-consent banner is required. If we ever introduce non-essential cookies, we will ask for your consent first.

Security

We use technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS), hashed passwords (Argon2id), hashed tokens at rest, access controls, rate limiting, and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and regulators of breaches where required by law.

Children

The Service is not directed to children under 16 (or the applicable age of digital consent), and under 13 in the United States. We do not knowingly collect their data; if you believe a child has provided us data, contact privacy@kapua.io and we will delete it.

Changes to this policy

We may update this policy from time to time. For material changes we will provide notice (e.g. by email or in-app) and update the “Last updated” date above.

Contact

Privacy questions or requests: Kapua, privacy@kapua.io (Slovenia).

Privacy Policy · Kapua