Trust & Security

Your travel data deserves to be protected.

Past the Hedge operates this service and takes the security and privacy of your travel information seriously. This page explains, in plain language, the safeguards and practices we use to help protect it — and how to reach us if you have a security question or a concern to report.

Report a security concern Read the Privacy Policy

No. 01 · Overview

Security at a glance

A quick summary of how we approach protecting your account and your travel records. Each point is covered in more detail further down this page.

Data Protection

Sensitive details in your travel records — confirmation numbers, addresses, traveler names — are encrypted at the database level, on top of the access controls that already limit who can see your account's data.

Secure Access

Signing in is protected by a password stored as a salted, one-way hash we never see in plain form, with an optional second factor. You can review and sign out of other active sessions at any time.

Encryption

Traffic between your browser and Past the Hedge is encrypted over HTTPS. Backups of stored information are encrypted before they ever leave our server.

Privacy

There's no analytics or advertising tracking on this site, and the application itself doesn't log your IP address. Your travel data is never sold.

Infrastructure

Past the Hedge runs on established, professionally managed hosting and network infrastructure. We deliberately don't publish architecture details here — that information helps an attacker more than it helps a customer.

Monitoring & Response

We track application errors and background job failures, and rate-limit the public forms most likely to attract automated abuse. If something looks wrong, we investigate it.

No. 02 · In Detail

How we protect your information

A closer look at the practices behind the summary above.

Data in transit

Your browser and our servers communicate over HTTPS, so information you send — including anything you type into a form — is encrypted along the way.

Data at rest

Sensitive fields in your booking records, and account-security secrets like your two-factor key, are encrypted in the database rather than relying on application logic alone. Passwords are never stored in a form that could be read back — only a salted, one-way hash.

Access controls

Your travel records are scoped to your account. If you choose to share a trip with a household member, that access is explicit and opt-in, and can be limited — hiding prices, confirmation numbers, or traveler names from what's shared.

Data minimization

We aim to collect and retain only what's needed to build and maintain your itinerary. There's no advertising or analytics tracking, and a forwarded confirmation email exists to build (and, if needed, later correct) your itinerary — not for any other purpose.

Account security

From Account Settings, you can change your password, turn on two-factor authentication with backup codes, link or unlink a Google sign-in, and sign out of sessions on other devices.

Secure development

Security is a consideration throughout ongoing development, not an afterthought. The account-security actions worth protecting most carry additional request-forgery protections, and the forms most exposed to automated abuse — sign-in, password reset, sign-up — are rate-limited.

No. 03 · Privacy

Privacy & data handling

Past the Hedge exists to turn your travel confirmations into an organized, permanent record, which means it necessarily handles information about where you've been and where you're going. We collect only what's needed to do that: your account credentials, the passport countries and travel companions you choose to enter, and the bookings you forward or add.

That information is used to build and display your itinerary back to you — not to profile you, sell to advertisers, or share beyond what a feature you actually use requires.

You're in control of most of it directly: edit or delete a booking, remove a passport country, or disconnect a linked Google account any time from Account Settings, which also lets you export a full copy of your data or delete your account outright.

This section summarizes our approach. The Privacy Policy is the authoritative, detailed source for exactly what's collected, why, and how it's handled — read it for the full picture.

No. 04 · Your Inbox

Your travel information

Past the Hedge is built around a simple idea: forward a booking confirmation to a private address unique to your account, and it becomes a permanent, organized entry in your itinerary. Because that means real confirmation emails pass through the service, it's worth being direct about how they're treated.

The content of a forwarded email is used to extract your itinerary's details and is otherwise handled as your data — not analyzed for advertising, not sold, and not used to train third-party AI models beyond the real-time processing needed to read it. The original message is kept as-is, so if a detail is ever parsed incorrectly, it can be corrected without asking you to dig up and re-forward it.

Access to that content follows the same account-scoped rules as the rest of your data. For the complete detail, see the Privacy Policy.

No. 05 · Third Parties

Third-party services

Running Past the Hedge means relying on a small number of outside service providers for specific tasks — for example, Stripe for Premium subscription billing. Each is given only the information it needs to do its job, never more.

We don't currently publish a standalone subprocessor list; the Privacy Policy names the categories of third party involved and what each one sees. If you need that information for a business or procurement review, contact us and we're happy to help.

No. 06 · Practices

Security practices

Broader detail on specific areas of our security program, at a level appropriate for a public page — what we protect and why, not a blueprint of how it's built.

Application security
Security is considered throughout the development and maintenance of Past the Hedge, not bolted on afterward. We use automated tools to help identify known vulnerabilities in the open-source components the application depends on.
Data protection
Sensitive fields in your travel records are encrypted at the database level, in addition to the access controls already built into the application.
Access management
Access to your data is scoped to your account by default. Sharing anything with another account — a household member, a link to an upcoming trip — is an explicit, opt-in action you take, with control over exactly what's visible.
Privacy
We collect what's needed to run the service and nothing more. There's no advertising or analytics tracking anywhere on the site.
Infrastructure security
The application runs on established, professionally managed hosting and network infrastructure, with network-level protections in front of it. We describe this at a high level deliberately: infrastructure specifics are more useful to an attacker than to a customer.
Vulnerability management
We use automated scanning to help identify known vulnerabilities in the software this application depends on, and address what we find as part of ongoing maintenance.
Business continuity
Stored information is backed up regularly, encrypted before it leaves our server. We periodically test that a backup can actually be restored — not just that one exists.
Third-party risk
Before relying on an external service provider, we consider what information it would need access to and limit that to what the specific task actually requires.
Incident response
If we identify or are made aware of a security issue, we prioritize investigating and addressing it. See “Found a security issue?” below for how to reach us.
No. 07 · Report a Concern

Found a security issue?

If you believe you've found a security vulnerability affecting Past the Hedge, we want to hear about it. Email us at security@pastthehedge.com with what you found and how to reproduce it, and we'll review it and follow up. Please avoid accessing, modifying, or downloading data that isn't yours while investigating — reach out first and we can help you verify it safely. We don't currently run a formal bug bounty program, but we appreciate responsible, good-faith reports and will treat them accordingly.

Email security@pastthehedge.com
No. 08 · Compliance

Our approach to compliance

Past the Hedge doesn't currently hold formal certifications like SOC 2 or ISO 27001 — those are significant undertakings we haven't pursued at this stage, and we'd rather say so plainly than imply otherwise. We're committed to protecting user information and to evaluating our practices against applicable privacy and security expectations as the service grows. If a specific certification or compliance question matters to how you'd use Past the Hedge, contact us.

No. 09 · Reliability

Reliability

Past the Hedge doesn't yet publish a dedicated public status page or uptime statistics. If you're having trouble reaching the service, or something looks wrong with your account, contact us and we'll look into it.

No. 10 · Resources

Documentation & resources

This page was last reviewed 30 August 2026.