Privacy Policy
Your privacy matters to us. TripMate is built to help travellers plan journeys, connect with guides and travel agencies, manage budgets and organise trips. This Privacy Policy explains what information we collect, why we collect it, how it is protected and the choices you have regarding your information.
Privacy at a glance: TripMate does not sell your personal information. We collect only the information reasonably required to operate, secure and improve the platform.
On this page
1. Introduction
TripMate respects the privacy of travellers, guides, travel agencies and other users of our platform.
This Privacy Policy explains how TripMate collects, uses, stores and protects information when users access or use our website and its features.
By using TripMate, users acknowledge the practices described in this Privacy Policy.
2. Information We Collect
Account information
When users create or manage an account, TripMate may collect:
- Name
- Email address
- Phone number, if provided
- City
- Date of birth, if provided
- Profile photograph
- Account and profile preferences
Travel & platform information
Depending on the features used, we may process information associated with:
- Trips
- Itineraries
- Travel preferences
- Budgets
- Expenses
- Saved destinations
- Enquiries
- Guide booking requests
- Agency enquiries
- Quotations
- Reviews and ratings
- Collaborative trip information
Technical & security information
TripMate may process limited technical information necessary for security and reliable operation, including:
- IP address
- Login timestamps
- Login attempts
- Session information
- Security and abuse-prevention records
IP address logging
TripMate records the IP address your device connects from alongside security-relevant events: signing in, failed sign-in attempts, and actions taken by administrators. This is kept as a security record, so that unauthorised access or misuse can be identified and investigated, and so that repeated failed sign-ins can be rate-limited.
IP addresses are not used to track your browsing, build an advertising profile, or determine your precise location. They are visible only to TripMate administrators, and are retained as described in section 8.
3. How We Use Your Information
Information may be used to:
- Create and manage user accounts
- Provide TripMate features
- Display trips, itineraries and budgets
- Process enquiries and booking requests
- Connect travellers with guides and agencies
- Enable collaborative trip planning
- Remember user preferences
- Provide relevant recommendations
- Maintain platform security
- Prevent spam, fraud and abuse
- Moderate reviews and reports
- Provide customer support
- Maintain administrative and security records
- Improve reliability and user experience
TripMate does not sell users' personal information.
4. Guide & Agency Verification
TripMate may request verification information or documents when someone registers as a guide or travel agency.
- Verification documents are used for verification and platform safety.
- They are accessible only to authorised verification and administrative personnel.
- Verification documents are not displayed publicly on profiles.
- Only appropriate verification status or approved public profile information is visible to other users.
7. Data Storage & Security
TripMate uses reasonable technical and organisational safeguards to protect the information it holds. Measures in place include:
- Passwords stored using secure bcrypt hashes
- Passwords are never stored in readable plain text
- HttpOnly session cookies that browser scripts cannot read
- Remember-me tokens stored only as hashes, so a leaked database cannot be replayed
- Uploaded files renamed and type-checked against their actual contents
- Script execution disabled in upload directories
- Login attempts and suspicious activity may be rate-limited or temporarily restricted
No internet-based system can guarantee absolute security, but TripMate uses reasonable safeguards designed to reduce unauthorised access, misuse and disclosure.
8. Data Retention
Information is retained only for as long as reasonably required to:
- Provide the service
- Maintain account functionality
- Resolve disputes
- Prevent fraud or abuse
- Maintain legitimate platform records
- Meet applicable legal requirements
Security and activity logs
Security records — including IP addresses, sign-in timestamps, failed sign-in attempts and administrative actions — are kept for up to 24 months, after which they are deleted. They are held for this period so that security incidents can still be investigated some time after they occur.
When an account is deleted, information that is no longer required is deleted or anonymised where reasonably possible.
Some records connected to bookings, reviews, reports or other users may need to remain in anonymised or limited form to preserve the integrity of those records.
9. Your Privacy Choices
Depending on your account, you may:
- Edit your profile information
- Update travel preferences
- Remove optional profile information where supported
- Disable personalised recommendations where available
- Request information about your stored personal data
- Request correction of inaccurate information
- Request deletion of your account
- Contact TripMate regarding privacy concerns
You can manage most of this yourself from your Profile and Preferences pages. For anything else, the Contact page reaches our support team.
10. Children's Privacy
TripMate is not intentionally designed to collect personal information from children in violation of applicable law.
If TripMate becomes aware that personal information has been collected in circumstances where parental or guardian consent is legally required, appropriate steps may be taken to remove or appropriately handle that information.
11. Third-Party Services
TripMate may contain links to third-party websites or services, such as travel agencies, guides or other external resources.
TripMate is not responsible for the privacy practices of independently operated third-party websites. Users should review the privacy policies of external services before providing personal information to them.
12. Changes to This Policy
This Privacy Policy may occasionally be updated to reflect:
- Platform changes
- New features
- Security improvements
- Operational changes
- Applicable legal requirements
When the policy changes, the "Last updated" date shown at the top of this page is revised. Material changes are communicated appropriately where necessary.
Questions about your privacy?
If you have questions about this Privacy Policy, your personal information, or would like to request access, correction or deletion of your information, please contact TripMate through the existing Contact or Support system.
Contact TripMate →