Security at a glance
A quick summary of how we approach protecting your account and your travel records. Each point is covered in more detail further down this page.
Data Protection
Sensitive details in your travel records — confirmation numbers, addresses, traveler names — are encrypted at the database level, on top of the access controls that already limit who can see your account's data.
Secure Access
Signing in is protected by a password stored as a salted, one-way hash we never see in plain form, with an optional second factor. You can review and sign out of other active sessions at any time.
Encryption
Traffic between your browser and Past the Hedge is encrypted over HTTPS. Backups of stored information are encrypted before they ever leave our server.
Privacy
There's no analytics or advertising tracking on this site, and the application itself doesn't log your IP address. Your travel data is never sold.
Infrastructure
Past the Hedge runs on established, professionally managed hosting and network infrastructure. We deliberately don't publish architecture details here — that information helps an attacker more than it helps a customer.
Monitoring & Response
We track application errors and background job failures, and rate-limit the public forms most likely to attract automated abuse. If something looks wrong, we investigate it.
How we protect your information
A closer look at the practices behind the summary above.
Data in transit
Your browser and our servers communicate over HTTPS, so information you send — including anything you type into a form — is encrypted along the way.
Data at rest
Sensitive fields in your booking records, and account-security secrets like your two-factor key, are encrypted in the database rather than relying on application logic alone. Passwords are never stored in a form that could be read back — only a salted, one-way hash.
Access controls
Your travel records are scoped to your account. If you choose to share a trip with a household member, that access is explicit and opt-in, and can be limited — hiding prices, confirmation numbers, or traveler names from what's shared.
Data minimization
We aim to collect and retain only what's needed to build and maintain your itinerary. There's no advertising or analytics tracking, and a forwarded confirmation email exists to build (and, if needed, later correct) your itinerary — not for any other purpose.
Account security
From Account Settings, you can change your password, turn on two-factor authentication with backup codes, link or unlink a Google sign-in, and sign out of sessions on other devices.
Secure development
Security is a consideration throughout ongoing development, not an afterthought. The account-security actions worth protecting most carry additional request-forgery protections, and the forms most exposed to automated abuse — sign-in, password reset, sign-up — are rate-limited.
Privacy & data handling
Past the Hedge exists to turn your travel confirmations into an organized, permanent record, which means it necessarily handles information about where you've been and where you're going. We collect only what's needed to do that: your account credentials, the passport countries and travel companions you choose to enter, and the bookings you forward or add.
That information is used to build and display your itinerary back to you — not to profile you, sell to advertisers, or share beyond what a feature you actually use requires.
You're in control of most of it directly: edit or delete a booking, remove a passport country, or disconnect a linked Google account any time from Account Settings, which also lets you export a full copy of your data or delete your account outright.
This section summarizes our approach. The Privacy Policy is the authoritative, detailed source for exactly what's collected, why, and how it's handled — read it for the full picture.
Your travel information
Past the Hedge is built around a simple idea: forward a booking confirmation to a private address unique to your account, and it becomes a permanent, organized entry in your itinerary. Because that means real confirmation emails pass through the service, it's worth being direct about how they're treated.
The content of a forwarded email is used to extract your itinerary's details and is otherwise handled as your data — not analyzed for advertising, not sold, and not used to train third-party AI models beyond the real-time processing needed to read it. The original message is kept as-is, so if a detail is ever parsed incorrectly, it can be corrected without asking you to dig up and re-forward it.
Access to that content follows the same account-scoped rules as the rest of your data. For the complete detail, see the Privacy Policy.
Third-party services
Running Past the Hedge means relying on a small number of outside service providers for specific tasks — for example, Stripe for Premium subscription billing. Each is given only the information it needs to do its job, never more.
We don't currently publish a standalone subprocessor list; the Privacy Policy names the categories of third party involved and what each one sees. If you need that information for a business or procurement review, contact us and we're happy to help.
Security practices
Broader detail on specific areas of our security program, at a level appropriate for a public page — what we protect and why, not a blueprint of how it's built.
Application security
Data protection
Access management
Privacy
Infrastructure security
Vulnerability management
Business continuity
Third-party risk
Incident response
Found a security issue?
If you believe you've found a security vulnerability affecting Past the Hedge, we want to hear about it. Email us at security@pastthehedge.com with what you found and how to reproduce it, and we'll review it and follow up. Please avoid accessing, modifying, or downloading data that isn't yours while investigating — reach out first and we can help you verify it safely. We don't currently run a formal bug bounty program, but we appreciate responsible, good-faith reports and will treat them accordingly.
Our approach to compliance
Past the Hedge doesn't currently hold formal certifications like SOC 2 or ISO 27001 — those are significant undertakings we haven't pursued at this stage, and we'd rather say so plainly than imply otherwise. We're committed to protecting user information and to evaluating our practices against applicable privacy and security expectations as the service grows. If a specific certification or compliance question matters to how you'd use Past the Hedge, contact us.
Reliability
Past the Hedge doesn't yet publish a dedicated public status page or uptime statistics. If you're having trouble reaching the service, or something looks wrong with your account, contact us and we'll look into it.
Documentation & resources
- Privacy Policy — what's collected, why, and where it goes.
- Travel guidance sources — how Past the Hedge selects and presents travel-readiness information.
- Terms of Use — the terms for using Past the Hedge.
- Status page — not currently available. Availability questions go to security@pastthehedge.com.
- Security contact — security@pastthehedge.com.
This page was last reviewed 30 August 2026.
