TripMeet Privacy Policy
Effective date: 2026-10-02Version: —Last updated: —
Draft for review — not final. This version describes our current data practices. It should be reviewed by qualified legal counsel before we begin public promotion. The English version is the governing version of this policy; translations are provided for convenience. (Open items: see the checklist at the end.)
Effective Date: 2026-10-02
1. Overview
This Privacy Policy explains how TripMeet ("TripMeet," "we," "us," or "our") collects, uses, and protects information about you when you use our website and services (the "Services"). It applies to everyone who visits or uses the Services, whether or not they create an account.
"Personal information" means any information relating to an identified or identifiable individual. If you are located in the EEA, UK, or Switzerland, the EU General Data Protection Regulation (GDPR) and equivalent national laws apply, and this policy describes your rights under those laws. If you are a California resident, the CCPA/CPRA may also apply.
2. Information We Collect
Information you provide to us
- Account data: your email address and a password (stored only in encrypted/hashed form). You may also sign in through a third-party provider (Google, Apple, or Facebook); in that case we receive your email address and basic profile information from that provider.
- Profile data: your display name (nickname), username (e.g.
@alex.travel), gender, date of birth, and a short bio — each of which you can choose to show or hide (see Section 7). - Photos: your profile picture and cover image, and any photos you upload as part of content you post.
- Activity and order data: when you book or host an experience/activity — participant details, dates, quantities, amounts, order status, and the associated experience. If you host, we may also collect payout account details you provide to receive funds.
- Content you post: reviews and ratings, replies, and (where available) posts and photo albums ("User Content").
- Support data: messages and attachments you send us through the support/ticket system.
- Preferences: your interface language, currency, theme, and city.
Payment information: payments are processed by our payment providers (currently Stripe for card payments and Antom for other supported methods). We do not store your full card number — card details are handled by the provider. We receive limited transaction information (such as the amount, status, and a provider reference).
Information we collect automatically
- Usage data: pages visited, features used, clicks, and referring site, collected via cookies and similar technologies — see our Cookie Policy.
- Device and log data: IP address, browser type and version, operating system, language settings, and approximate location derived from your IP address (see Section 4).
- Analytics data: where you consent, aggregated behavioral data collected by our analytics provider (Google Analytics 4).
3. How We Use Your Information
We use your personal information to:
- create and maintain your account and authenticate you;
- provide the Services — browse experiences, book, pay, host, and receive payouts;
- display and let you manage your profile and the content you post;
- localize the Services (language, currency, city) and show relevant content;
- send service and transactional messages (order confirmations, status changes, security notices);
- keep the Services secure and prevent fraud, abuse, and violations of our Terms;
- understand how the Services are used and improve them (analytics, subject to consent);
- comply with legal obligations and respond to lawful requests.
We do not sell your personal information.
4. Location and IP Address
To offer a sensible default city, our server derives an approximate location from your request IP address. We process the IP through a geographic lookup (a self-hosted/offline database), cache the result using a hashed IP with a short lifetime, and do not store your plaintext IP in our business logs. You can change your city at any time.
5. Signing in with Google, Apple, or Facebook
You may sign in using a third-party account. When you do, that provider shares limited information with us (typically your email address and basic profile information), and we use it only to create and secure your TripMeet account.
Google user data. If you sign in with Google, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We access only your basic Google profile (name, email address, and profile image) made available through the sign-in scope.
- We use it solely to authenticate you and to create and maintain your account (display your name/email within the Services).
- We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide the sign-in feature or as required by law.
- We do not use Google user data to train or improve generalized AI/ML models.
6. How We Share Your Information
- Service providers that help us operate the Services — cloud hosting and storage, content delivery, email delivery, payment processing, content moderation, AI translation, and analytics. They receive only what they need and are bound by contract to protect it.
- Other users: information you choose to make public (your display name, username, photos, bio, reviews, and public activity) is visible to others as you configure it.
- Hosts/participants: when you book, the host (and, for hosting, the relevant participants) sees the information needed to fulfill the booking.
- Legal reasons: where required by law or legal process, or to protect the rights, safety, or property of TripMeet, our users, or the public.
- Business transfer: in a merger, acquisition, or sale of assets, subject to this policy.
7. Your Choices and Public Visibility
- Field-level privacy: you can control whether individual profile fields (e.g. your activity history, follows/followers) are publicly visible. When a field is turned off, it is not returned by the Services at all.
- You can edit most profile fields directly in your account.
- You can manage cookies and analytics consent at any time (see the Cookie Policy).
8. Legal Bases for Processing (EEA/UK)
- Performance of a contract: providing the account, booking, payment, and hosting features you request.
- Legitimate interests: security, fraud prevention, service improvement, and analytics where consent is not required — balanced against your rights.
- Consent: analytics/marketing cookies and optional communications, which you may withdraw at any time.
- Legal obligation: where we must retain or disclose information to comply with law.
9. International Data Transfers
We operate from the United States and use service providers in other countries. Where we transfer personal information from the EEA/UK to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. You can request a copy of the relevant safeguards from us.
10. Data Retention
We keep personal information for as long as your account is active and for a reasonable period afterwards where needed for legal, accounting, tax, or security purposes (for example, order and payment records for statutory periods, and to prevent fraud). When you request deletion, we delete or anonymize your personal information within 30 days, except where we must retain it to comply with law or resolve open disputes.
11. Your Rights
Subject to applicable law, you have the right to: access your personal information; correct it; delete it; restrict or object to certain processing; portability (receive a machine-readable copy); withdraw consent at any time; and lodge a complaint with your local data protection authority. California residents have additional rights under the CCPA/CPRA (including the right to know and to opt out of certain sharing; we do not sell personal information).
To exercise these rights, contact us at privacy@mytripmeet.com. We respond to verified requests within 30 days.
12. Children
The Services are not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
13. Security
We use appropriate technical and organizational measures — including password hashing, encryption in transit (HTTPS), access controls, and rate limiting — to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new effective date and, where appropriate, notified to you. Where required, we will ask you to re-consent.
15. Contact Us
TripMeet is operated by Pegasus International Travel INC., 700 Lavaca St, Ste 1401, Austin, TX 78701, USA.
- Privacy questions: privacy@mytripmeet.com
- General/support: support@mytripmeet.com
If you are in the EEA/UK, you may also contact the relevant supervisory authority.
待确认(发布前必须补 / 或需法务复核)
| 项 | 状态 |
|---|---|
| 生效日期 / 运营实体 / 注册地址 / 经营国 / 时限 | ✅ 已按 Texas 注册证书填(2026-10-02:Pegasus International Travel INC. · 700 Lavaca St, Ste 1401, Austin, TX 78701, USA) |
| 最低年龄 | 已填 16,按实际市场确认 |
| 加州用户 | 若触达,CCPA/CPRA 条款可再展开 |
| EU 代表(GDPR Art. 27) | ⏳ 当前市场 = 美国优先,是否设立待决策(登记于 [上线中心 C-15](../../../launch/README.md));若面向欧盟推广而无欧盟实体则必须指定 |
| 法务复核 | ⏳ 对外推广前必做(v2) |