Triploft Privacy Policy
Last Updated: June 15, 2026
This policy explains, in plain terms, what information Triploft collects, how we use and share it, and the choices you have. Triploft is a product of LH2 Holdings LLC (“Triploft,” “we,” “us,” or “our”), a travel platform connecting travel advisors, agencies, suppliers, and travelers. It covers triploft.ai, our mobile apps, and the services we provide through them (the “Services”), and it’s part of our Terms and Conditions.
Using the Services means you understand this policy. Your state may give you extra rights — see “Your U.S. State Privacy Rights” below. If you don’t agree with this policy, please don’t use Triploft.
When We’re the Controller vs. the Processor
For the information we collect about our own users and visitors — account, billing, usage, and marketing data, for example — we decide how and why it’s used, which makes us the “controller” (a “business,” under U.S. state laws).
But when a Travel Advisor or Agency uses Triploft to manage information about their Traveler clients (we call this “Customer Data”), we’re acting as their “processor” (or “service provider”) — they’re the controller, and we handle that data on their instructions. That work is covered by their instructions and by the “Data Processing Terms for Business Customers” section below, not by the rest of this policy. If you’re a Traveler wondering how an advisor or agency uses your information, reach out to them directly.
What We Collect
What we collect depends on who you are. We get it from you directly, automatically as you use Triploft, and from third parties.
From advisors and agencies: name, email, phone, business name and address, login details, financial details (commissions, fees, payment method, banking info), marketing and usage data, and the Traveler client information you enter (which we treat as Customer Data, above).
From travelers: name, email, phone, address, login details, date of birth, passport and government-ID details, loyalty info, travel preferences, trip details, and the payment details used to approve bookings with suppliers.
From suppliers: name, business contact details, login details, and information about offerings.
Automatically: device and log data (IP address, device IDs, browser), how you use the Services, approximate or precise location where you allow it, and data from cookies and similar tech (below).
From others: identity-verification and fraud-prevention partners, analytics providers, accounts you choose to link (like email or calendar), and public sources.
We also collect information when you contact support, take a survey, or engage with our marketing.
The Categories We Collect, at a Glance
Here’s a quick summary of the categories of personal information we’ve collected in the last 12 months, why, and who we share each with. The specifics are described above.
| Category (examples) | Why we collect it | Who we share it with |
|---|---|---|
| Identifiers and contact info (name, email, phone, address, login details, IP and device IDs) | Run and secure the Services; talk with you; marketing | Service providers |
| Government and sensitive IDs (date of birth, passport and government-ID details) | Run the Services and support bookings; verify identity | Only service providers that need it (hosting, identity verification) — not AI providers or advertisers |
| Payment and financial info (payment method, tokenized card details, billing, commissions) | Process payments, subscriptions, and payouts | Payment and tokenization providers (Stripe, IXOPAY) |
| Commercial info (subscriptions, transactions, bookings, trip details) | Run the Services | Service providers |
| Usage and device info (browser, pages viewed, interactions, analytics) | Operate, analyze, and secure the Services | Service providers |
| Location (approximate or precise, when you allow it) | Power location features | Service providers |
| Photos and videos you upload | Run the Services | Service providers |
| Preferences and inferences (like travel preferences) | Personalize and improve the Services | Service providers |
| Anything else you choose to send us (like support messages) | Help and respond to you | Service providers |
How We Use It
We use the information we collect to:
- run, maintain, and secure the Services, and set up and manage accounts;
- process transactions and send confirmations, invoices, and related messages;
- personalize, analyze, and improve Triploft and build new features, including our AI features;
- talk with you, provide support, and send service messages;
- send marketing (subject to your choices);
- power and improve our AI features through third-party model providers, without sending them government-ID or payment data (see “AI at Triploft” below);
- detect and prevent fraud, abuse, and security problems; and
- meet our legal obligations and enforce our Terms.
Cookies, Analytics, and Ads
We and our providers use cookies, pixels, SDKs, and similar tools (“Cookies”) to run the Services, remember your preferences, measure how things perform, and support analytics and advertising.
Analytics. We use tools like Google Analytics and Mixpanel to see how people use Triploft. You can opt out of Google Analytics with Google’s browser add-on.
Marketing. We do not currently sell or share your personal information for cross-context behavioral (targeted) advertising. If we begin using advertising or remarketing tools that do so, we’ll update this policy, disclose it here, and provide the opt-out the law requires (including honoring Global Privacy Control signals).
You can manage Cookies in your browser and through the Digital Advertising Alliance and Network Advertising Initiative opt-out tools.
There’s no agreed industry standard for “Do Not Track” (DNT) browser signals, so we don’t currently respond to them. If we ever begin selling or sharing data for targeted advertising, we’ll honor Global Privacy Control signals as the law requires.
Who We Share It With
We share information with:
- Service providers and sub-processors — vendors acting for us, including cloud hosting (such as AWS, Google Cloud, or Microsoft Azure), payments and card tokenization (Stripe, Inc. and IXOPAY), analytics (Google Analytics, Mixpanel), email and SMS delivery (such as SendGrid and Twilio), and AI model providers (such as OpenAI and Anthropic) behind our AI features.
- Other users and partners — as needed to deliver the Services, like sharing details among an advisor, their agency, and a traveler to coordinate a trip.
- Advisors and authorities — our lawyers, accountants, auditors, and insurers, and law enforcement or others where the law requires, to enforce our Terms, or to protect people’s rights and safety.
- In a business deal — if we’re involved in a merger, acquisition, financing, or asset sale, information may transfer as part of that.
We only share Customer Data as the relevant advisor or agency instructs or as described in “Data Processing Terms for Business Customers” below.
AI at Triploft
Some features use AI, including third-party large language model providers such as OpenAI and Anthropic, to power things like AI-assisted itineraries and content, automated import, and chat or copilot tools. We send these providers only the information a feature actually needs — for example, destinations, dates, and trip preferences. We do not send government-ID or passport information, or payment-card data, to our AI providers. We use these providers under enterprise terms that prohibit them from using your or your clients’ data to train their general models, and we don’t sell that data or use it for advertising. AI output can be wrong — you’re responsible for checking it, as our Terms explain.
How Long We Keep It
We keep information for as long as we need it to run the Services, meet legal, tax, and regulatory duties, resolve disputes, and enforce our agreements. How long depends on why we collected it, how sensitive it is, and what the law requires. When we no longer need it, we delete, de-identify, or anonymize it, and we may keep de-identified or aggregated data indefinitely. For example:
- account and profile data — while your account is active and a reasonable time after;
- payment and billing data — as long as we need it for your transaction or subscription, plus any legally required period;
- usage and device data — as long as we need it to run and secure the Services;
- support messages — as long as we need them to help you and keep reasonable records; and
- de-identified or aggregated data — indefinitely.
How We Protect It
We use reasonable administrative, technical, and physical safeguards to protect personal information. No system is perfectly secure, though, so we can’t promise absolute security. Keep your login details private — that part’s on you.
Children
Triploft isn’t meant for anyone under 16, and we don’t knowingly collect information from anyone under 16. We also don’t knowingly “sell” or “share” the information of anyone under 16. If you think someone under 16 gave us information, contact us and we’ll take appropriate steps to delete it.
Where We Process Information
We’re based in the United States and process and store information here and in other countries where we or our providers operate. If you use Triploft from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data-protection rules than your home country.
Your Choices
- Account info — review and update certain details in your settings.
- Marketing — unsubscribe from marketing emails via the link in them, and reply STOP to marketing texts; service messages continue.
- Cookies — manage them through your browser and the industry opt-out tools above.
- Access, deletion, correction — ask us to access, delete, or correct your information as described below.
Your U.S. State Privacy Rights
Depending on where you live (including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws), you may have some or all of these rights, subject to verification and legal limits:
- to know and access the information we’ve collected about you and how we use and share it;
- to delete information we collected from you;
- to correct inaccurate information;
- to get a copy of your information in a portable, machine-readable format;
- to opt out of the “sale” or “sharing” of your information and of targeted/cross-context advertising;
- to limit how we use sensitive information; and
- to not be treated differently for exercising these rights.
California (CCPA/CPRA). Over the past 12 months we’ve collected the categories described in “What We Collect” (including identifiers, contact and account data, commercial and financial data, internet and usage activity, geolocation, and, for some users, government identifiers like passport details), from the sources and for the purposes described in this policy. We disclose information to service providers for business purposes. We do not sell your personal information, and we do not share it for cross-context behavioral (targeted) advertising.
Opting out of sale/sharing. Because we don’t currently sell or share your personal information, there’s nothing to opt out of today. If that ever changes, we’ll add a clear opt-out (including a “Do Not Sell or Share My Personal Information” control and Global Privacy Control honoring) and update this section. You can always reach us at support@triploft.ai.
Sensitive information. We use sensitive information (like login credentials and, for travelers, government-ID details) only to run and secure the Services and for other legally permitted purposes — not to draw inferences about you.
Making a request. Email support@triploft.ai (or write to us at the address below). We’ll verify your identity first and respond within the time the law requires. You can use an authorized agent (subject to verification). If we say no, you can appeal by replying to our response, and you can also contact your state attorney general.
California “Shine the Light.” California residents can ask about our disclosures of personal information to third parties for their direct marketing; email support@triploft.ai.
Data Processing Terms for Business Customers
This section kicks in when a Travel Advisor or Agency (“Customer”) uses Triploft to handle information about their Traveler clients (“Customer Data”). It’s part of our Terms and serves as our data processing agreement for that activity. The Customer is the controller/business and is responsible for giving every required notice and getting every consent and legal basis for the Customer Data they put in. In short:
- we process Customer Data only to run and support the Services, on the Customer’s instructions — never for our own separate purposes;
- as a CCPA “service provider,” we won’t sell or share Customer Data, and won’t use, keep, or disclose it for anything other than providing the Services or outside our direct relationship with the Customer, except as the law allows;
- we keep reasonable safeguards (see “How We Protect It”) and use the sub-processor categories listed in “Who We Share It With,” holding them to similar obligations and staying responsible for them;
- we’ll reasonably help with verified data-subject requests about Customer Data and will tell the Customer without undue delay about a confirmed breach affecting it; and
- when things end, we’ll delete or make Customer Data available to export as described in “How Long We Keep It,” other than de-identified or aggregated data and anything we must keep by law.
Liability under these data processing terms is subject to the liability cap in our Terms. If you need a separate signed data processing agreement for procurement or compliance, email support@triploft.ai and we’ll provide one.
Changes to This Policy
We may revise this policy over time. If we make material changes, we’ll let you know by posting a notice, emailing you, or another method the law allows. The “Last Updated” date above shows when we last revised it.
Contact Us
Questions about this policy or your privacy, or want to exercise a right? Reach us at:
LH2 Holdings LLC (d/b/a Triploft)
Attn: Privacy Team
312 West 2nd Street
Casper, WY 82601
Email: support@triploft.ai