Effective Date: 10-05-2025
Tripdeo.com (“Tripdeo,” “we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect information about buyers (clients) and sellers (gig providers) on our marketplace.
1) Information We Collect
-
Account Data: Name, email, phone, password (hashed), country.
-
Profile & Business Data (Sellers): Display name, bio, skills, portfolio links; KYC/KYB documents where required (e.g., passport/ID, selfie, business registration, tax IDs, proof of address).
-
Transactions: Orders, invoices, payout details; payment tokens via PCI-DSS compliant processors.
-
Usage & Device Data: IP address, device/browser info, referral pages, session logs, crash/diagnostic data.
-
Communications: In-app messages, support tickets, dispute correspondence, email preferences.
-
Cookies/Similar Tech: Session cookies, analytics, fraud-prevention identifiers.
2) How We Use Your Information
Lawful purposes only:
-
Create/manage accounts; enable listings, bookings, messaging.
-
Verify identities/businesses (KYC/KYB) and meet AML/CTF obligations.
-
Process payments, payouts, refunds, chargebacks, and taxes.
-
Detect/prevent fraud, abuse, spam, and security incidents.
-
Personalize content, recommendations, and improve UX.
-
Handle support, disputes, and policy enforcement.
-
Comply with legal/regulatory requirements and cooperate with lawful requests.
3) GDPR / CCPA Legal Bases & Rights
-
Legal Bases: Consent; Contract; Legitimate Interests (security, service improvement, fraud prevention); Legal Obligation (e.g., AML/CTF, tax).
-
Your Rights: Access, correction, deletion, portability, restrict/object to processing, and withdraw consent (where applicable).
-
CCPA/CPRA: Right to know, delete, correct, and opt-out of sale/share of personal information. We do not sell personal information.
-
-
How to exercise: Email support@tripdeo.com. We may verify your request and identity.
4) Opt-Outs & Preferences
-
Unsubscribe links in marketing emails.
-
Manage cookie preferences via browser settings and (where available) our cookie banner.
-
You can opt out of non-essential analytics/marketing cookies; essential cookies are required for the service.
5) KYC/KYB Documents (Sellers)
-
Purpose: Identity verification, compliance with AML/CTF, sanctions screening, and risk controls.
-
Storage: Encrypted at rest and in transit; access strictly role-based and logged.
-
Retention: Kept only as long as necessary for compliance and platform safety (typically 5–10 years after account/payout closure, subject to applicable law).
-
Deletion: Where permitted by law, we delete or irreversibly pseudonymize/anonymize upon expiry of legal retention periods.
6) Data Sharing (No Sale of Personal Information)
We do not sell personal data. We share only with:
-
Payment & Payout Partners: Card processors, banks, PSPs (for payments, payouts, refunds, chargebacks).
-
Verification/Compliance Partners: KYC/KYB, sanctions/PEP screening, fraud-risk services.
-
Service Providers: Hosting, cloud storage, analytics, communications, support tools—bound by confidentiality and data-processing terms.
-
Authorities/Regulators: When required by law, court orders, or to enforce our Terms, protect rights, safety, or security.
7) International Transfers
We may transfer data across borders. Where required, we use safeguards such as Standard Contractual Clauses (SCCs) or equivalent lawful mechanisms.
8) Data Security
-
Encryption in transit (HTTPS/TLS) and at rest for sensitive fields.
-
Network and application firewalls, access controls, least-privilege, logging/monitoring, and periodic audits.
-
Vendor due diligence and DPAs with processors.
9) Data Retention & Deletion
-
Retained only for as long as needed for the purposes outlined or to meet legal obligations (e.g., tax/AML records).
-
On valid request, we delete or anonymize data not subject to mandatory retention.
10) Cookies & Tracking
-
Essential Cookies: Authentication, security, core features.
-
Analytics/Performance: Measure usage and improve features.
-
Marketing (where used): With consent (where required).
Manage via browser settings and (where available) our cookie banner.
11) Children’s Privacy
Tripdeo is not intended for individuals under the age of 18. We do not knowingly collect data from minors.
12) Third-Party Links
Links to third-party sites/services have their own privacy practices. We are not responsible for their policies.
13) Changes to This Policy
We may update this Policy. We’ll post the new version with an updated “Last Updated” date. Material changes may be notified via email or dashboard notice.
14) Contact & Requests
For privacy questions or to exercise your rights:
Email: support@tripdeo.com
If you are in the EU/UK and require our DPO or EU/UK representative details, contact support@tripdeo.com and we’ll provide them as applicable.