Security
Last updated July 16, 2026
Planning a trip means trusting us with your group's details. Here's how we protect them, in plain language. Security is ongoing work, not a finish line — this page describes our current practices and we'll keep improving them.
Passwordless sign-in
There are no passwords to steal or reuse. Organizers sign in with a single-use magic link sent to their email that works once and expires in an hour. If a link isn't used, it simply stops working.
Invite-only access
While we're in beta, organizer sign-in is limited to an approved list of email addresses, so random sign-ups can't reach the app.
Guests without accounts
The people you invite take part through a long, unguessable invite link — they never create an account or a password. You can revoke an invite link at any time, which immediately cuts off access through it.
Encryption & reputable infrastructure
- All traffic is encrypted in transit (HTTPS).
- We run on established providers — Vercel (hosting), Neon (managed database), Resend (email), and Cloudflare — each with their own security programs.
- Sign-in sessions use secure, HTTP-only cookies.
We collect little, and take no payments
MerryGo doesn't process payments and never asks for card or financial information, so there's no payment data to protect. We collect only what's needed to plan your trip, and we don't sell your data. See our Privacy Policy.
Reporting a vulnerability
If you believe you've found a security issue, please tell us at hello@merrygo.app before disclosing it publicly. We appreciate responsible disclosure and will work with you to confirm and fix genuine issues quickly.