Legal

Privacy policy

There is very little to say here, which is the point.

Last updated

In short. No accounts, no advertising cookies, no cross-site tracking, and nothing you type into the tools ever leaves your device. We measure how many people read which page, using cookieless analytics that cannot identify you or follow you to another site. We do not sell or share personal data.

What we store on your device

KarismaTrip uses your browser’s local storage, not cookies. Local storage is not transmitted to us — it stays in your browser and we cannot read it remotely. We use it for:

WhatWhy
karismatrip-themeRemembers whether you chose light or dark
karismatrip:budget:v2Your budget calculator figures, so a refresh does not lose them
karismatrip:packing:*Your packing list settings and which items you have ticked
karismatrip:fx:*The last currency pair you converted

You can delete all of it at any time by clearing site data in your browser settings. Nothing breaks — the tools simply start fresh.

Offline storage

If your browser supports it, a service worker saves pages you have visited so that guides remain readable without a connection. This is a cache on your device. Clearing site data removes it.

What we do not do

  • No accounts. There is no sign-up, so we hold no email addresses, names or passwords.
  • No advertising or tracking cookies. None at all, which is why you have not been shown a cookie banner — under the ePrivacy rules, storage that is strictly necessary for a feature you asked for does not require consent.
  • No cross-site profiling. We do not use tracking pixels, fingerprinting, ad networks or data brokers. The one measurement we do run is described under Analytics above, and it cannot follow you off this site.
  • No selling data. We have nothing to sell and would not sell it if we did.

The Android app

The KarismaTrip Android app collects nothing. It contains no analytics library, no crash-reporting service and no advertising SDK, and it requests no advertising identifier. It declares three Android permissions, all of them the kind Android grants without asking you, and none of which can read anything about you: internet access, and the two network-state permissions the app framework uses to tell whether you are connected. Location, camera, microphone, contacts and file storage are explicitly blocked in the app’s manifest rather than merely left unused.

Three things are stored on your device and nowhere else:

  • Saved trips. Kept so a plan survives closing the app. We cannot read them, cannot restore them, and they do not follow you to another phone.
  • Your packing checklist ticks.
  • A cached copy of the destination list, so the discovery screen works without a connection.

Clearing the app’s data or uninstalling it deletes all of it. There is no server-side copy to ask us to delete, because we never receive one.

When you build a plan with a connection, the app sends the trip settings you entered — destination, dates, number of travellers, currency, travel style, interests — to this site so the server can fetch the weather, the exchange rate and the official entry guidance on your behalf. That request carries no account, no device identifier and no advertising ID, and nothing from it is stored once the plan is returned. The app can also build a plan entirely offline, in which case nothing is sent at all.

The app talks only to this site. It does not contact Open-Meteo, the FCDO or the European Central Bank directly — the server does that, which is what keeps your device out of those services’ logs.

Analytics

This section is about the website. The Android app has no analytics of any kind — see above.

We use Vercel Web Analytics to see which pages are read and roughly where readers come from. It is the reason we can tell that a guide is worth updating. It is deliberately the least invasive option we could find, and it works differently from the analytics you are used to:

  • No cookies and no local storage. Nothing is written to your device, which is why there is still no cookie banner.
  • No persistent identifier. Rather than tagging your browser, Vercel derives a temporary hash from the request itself. That hash is rotated daily and cannot be reversed, so you are a different anonymous visitor tomorrow and there is no profile to build.
  • No cross-site tracking. The measurement exists only within this site. It cannot follow you anywhere else, and it is not shared with advertisers or data brokers.

What is recorded is the page path, the referring page, and coarse technical facts — country, device type, browser and operating system. Not your IP address, not a name, not an account. The data is processed by Vercel Inc. as our processor; see the Vercel privacy policy.

The lawful basis is legitimate interest under UK GDPR and GDPR Article 6(1)(f): understanding which guides are useful, using the least identifying method available. If you would rather not be counted at all, any content or tracker blocker will stop it, and the site works exactly the same.

Server logs

Our hosting provider records standard technical logs for every request — IP address, timestamp, page requested, browser user-agent — as is necessary to operate any website and to defend it against abuse. These are retained for a short period by the provider and are not combined with anything else or used to build a profile of you.

The lawful basis for this, under UK GDPR and GDPR Article 6(1)(f), is legitimate interest: running a website securely and reliably.

Third-party services

Some content is fetched from external services. Where that happens on our server, those services see our server, not you. Two exceptions send a request from your browser:

Everything else — weather, exchange rates, visa guidance, guide text — is fetched server-side and cached, so your browser never contacts those providers.

If you write to us

There is no contact form on this site and nothing you type here is submitted anywhere. If you email the address below, we hold your message and address for as long as it takes to deal with it, and we use it only to reply. We do not add you to a mailing list.

Your rights

Under UK GDPR and GDPR you have rights of access, rectification, erasure, restriction, portability and objection. In practice we hold no personal data about you, so there is usually nothing to exercise them against — the data the tools create is already in your hands and you can delete it yourself.

If you have written to us and want that correspondence deleted, ask and we will. If you believe we have handled data improperly, you can complain to the Information Commissioner’s Office.

Children

This site is not directed at children and we knowingly collect no data from anyone. There is no account to create and no profile to build.

Changes

If this policy changes, the date at the top changes with it. If we ever begin collecting personal data — for example by adding a hosted contact form, or accounts to sync your saved trips between devices — this page will say so, and will say what changed.

Contact

Questions about privacy, or a request to delete correspondence: hasnainzeb.se@gmail.com. See also the terms and disclaimer.