Draft — not yet reviewed by a lawyer. This previews upcoming policy language; it is not final or binding.
Privacy policy
Draft updated 2026-08-15 · Version 2026-08-15-draft
Who is responsible for your data
Cairn is provided by Cairn City, a Dutch eenmanszaak registered under KVK 42104444, VAT ID NL003291428B51. Cairn City is the data controller for the personal data described in this draft. Its visiting address is shielded in the Dutch Business Register. Contact hello@cairn.city.
What we collect
Depending on how you use Cairn, we may process your name and contact details; account, member and invitation information; trip dates and details; itinerary items, chat messages, announcements and attendance; expenses, payment and refund references; uploaded documents, photos and receipts; places, map pins and approximate location you choose to share; notification subscriptions; support and security records; and device, browser, usage, analytics and error information. Stripe handles payment-card details; Cairn City does not receive complete card details. Optional information is voluntary unless we explain that it is needed for a feature or legal requirement.
Where the data comes from
We receive personal data from you, from organizers and other members of groups you join, from your browser or device when you use a feature, and from service providers that return operational events such as payment, email-delivery, authentication and error information.
Why we process it, and on what basis
We process data to provide and support the service and Trip Pass you request (contract); meet tax, accounting and other legal duties (legal obligation); secure, maintain, troubleshoot and improve the service and understand aggregate use (our legitimate interests, balanced against your rights); and use optional device capabilities or send optional notifications when you choose or permit them. We do not sell personal data, use it for third-party advertising or act as a data broker.
What your group can see
Cairn is a shared group service. Members of a trip can see the profile name, trip contributions and other group content made available within that trip. Organizers may manage membership and shared trip information. Before adding information about someone else, make sure you are entitled to share it and avoid adding sensitive information that the group does not need.
Who we share it with
Depending on the features you use, recipients can include other members of your trip and providers that support Cairn: Supabase for authentication, databases and storage; Vercel for hosting and analytics; Stripe for payments and refunds; Resend for email; PostHog for product analytics; Sentry for error monitoring; Anthropic when you use an AI-assisted feature; Geoapify, OpenStreetMap and Wikimedia services for place and map information; Unsplash for selected imagery; and browser or platform providers for web push. We may also disclose data when legally required or to protect rights and security. These recipients do not receive personal data from us for their own advertising.
International transfers
Some providers may process personal data outside the European Economic Area. Where the GDPR requires it, the transfer must rely on an applicable safeguard, such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where appropriate. Provider locations and safeguards can change, so they are reviewed as part of our processor management.
How long we keep it
We keep account and trip data while needed to provide the service and then delete or de-identify it under the account-deletion process below. Payment, refund and invoice records that form part of our Dutch business administration are generally retained for at least seven years. Security, support, analytics and provider logs are kept for limited periods based on their purpose and configured retention. We may retain specific data longer when required by law or needed to establish, exercise or defend legal claims.
Your rights
Depending on the circumstances, the GDPR gives you rights to access, correct, delete, restrict or receive your personal data, and to object to processing. Where processing relies on consent, you can withdraw it without affecting earlier processing. To make a request, use available account controls or email hello@cairn.city. We may need to verify your identity. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent supervisory authority.
Analytics
Cairn uses Vercel Analytics and PostHog to understand service performance and feature use. PostHog's browser configuration uses memory-only persistence rather than a persistent browser identifier, while server-side product events may use a stable account identifier so events can be associated with an account. Analytics is not used for advertising or cross-site tracking. Our legal and consent posture depends on the live configuration and applicable ePrivacy rules and will be verified before this draft is published.
Cookies and local device storage
Cairn uses strictly necessary cookies for functions such as authentication and security. The app can also use local browser storage, IndexedDB, service-worker caches and web-push subscription data to remember preferences, support passkeys, keep selected trip information available offline and deliver notifications you enable. We do not use marketing or advertising cookies. Clearing browser data may remove offline information and local preferences.
Deleting your account
You can request deletion in Profile. The request is scheduled for completion after 30 days and can be cancelled during that period. Deletion is blocked while you organize active trips with other members; first transfer or delete those trips as the product instructs. On completion, Cairn removes your account identity, contact details, private documents and profile data. Shared group history needed by remaining members, such as expenses and chat, is de-linked from your account rather than silently removed. Trips you organize alone are deleted. Records that must be kept for tax, legal or security reasons remain only for the required period.
AI and automated decisions
Optional AI-assisted features may help extract or categorize information you submit. Cairn does not use automated processing to make decisions that produce legal or similarly significant effects about you. Review AI-assisted results before relying on them.
Children
Cairn is not directed to children under 16 and we do not knowingly allow them to create an account. If you believe a child under 16 has provided personal data, contact us so we can investigate and take appropriate action.
Security
We use technical and organizational measures intended to protect personal data, including access controls, encrypted connections and service monitoring. Some document content can be encrypted in the browser for trip members when that feature is enabled, but not all Cairn data is end-to-end encrypted. No service can promise absolute security.
Changes to this policy
We will update this page when our processing or this notice materially changes and identify the current version and date above. Where required, we will provide additional notice or ask for permission before a change takes effect.
Contact
Questions about this draft, your personal data or a privacy request can be sent to hello@cairn.city.