Payments are not enabled in this release.

Trust & Safety

Privacy Notice

TribeRide is live, and we keep improving it. Priced-gathering value flow is modeled, but payment execution, provider setup, settlement, refund handling, and payout remain switched off. The policies linked from this page are the versions in effect.

v0.4 · 2026-09-19 · P202_PRIVACY_POLICY_2026-09-19_v0.4.md

The English version governs; any translation is provided for convenience.

P202 Privacy Policy · 隐私政策

1. Purpose · 目的

This policy explains what information TribeRide collects, why, who it is shared with, how long it is kept, and what choices you have. It applies to the TribeRide platform and is posted to satisfy the California Online Privacy Protection Act (CalOPPA).

中文概要:说明平台收集什么信息、为何收集、与谁共享、保留多久、用户有何选择;本政策的发布本身即为满足加州 CalOPPA 的公示义务。

2. Information We Collect · 我们收集的信息

CategoryExamplesWhen collected
Accountname, email, password credentialaccount creation
Profiledisplay name, locale, visibility settingsuser-provided, editable
Activity recordsscenes published/joined, holds, confirmations, cancellations, no-show review recordsas you use the platform
Payment-relatedamount, currency, payment status, payment-intent reference, refund/dispute status. Card numbers are collected by Stripe, never by the platform.at checkout
Verificationa capability-type selection and a short free-text note. No verification document or image upload exists today; no verification document is stored by the platform.only when you apply for verification
User-content mediaphotos/images you attach to activities, messages, or Memory items. Uploaded images are scanned for content-safety before publication (§4, §9). Audio clips kept on your private Memory Wall are not automatically reviewed and are never published.when you upload
Communicationsmessages within coordination flows, reports, support requestsas sent
Device & logsIP address, browser type, access timestamps, error logsautomatically
Push notification token (mobile app, optional)the Expo push token for your device and its platform, stored with your account only if you turn on notifications in the app. This release only registers the token for future plan and account notifications; it sends none, and the token is never used for marketingyou (by turning on notifications)
Phone number (optional)the mobile number you ask to verify, and whether it has been verifiedonly when you verify a phone number
Sign-in with Google or Apple (optional)the email address and sign-in identifier Google or Apple returns; from Google, your basic profile (name and profile picture); from Apple, your name if you choose to share it. Apple may give us a private relay email address instead of your own. We never receive your Google or Apple passwordonly if you choose to sign in with Google or Apple
Source (attribution) recordsthe kind of event (opening a shared link, viewing an activity's page — whether or not you are signed in, starting or finishing sign-up, signing in, entering an activity's room, sharing a link), whether it happened on the website or in the iOS or Android app, when it happened, the activity, share-link code or merchant listing involved, and the source labels carried by the link you used (campaign tags such as utm_source, a channel tag, a referral code). Your account ID is recorded only for an activity view while you are signed in, for entering an activity's room, for sharing a link, and for finishing sign-up or signing in; opening a shared link, and a view by a visitor who is not signed in, carry no account ID at all. No IP address, browser or device user agent, page URL, precise location, or anonymous visitor ID is recorded in any of these records, and no cookie is set for themautomatically, when one of these events happens
Consent recordswhich policy version you accepted, when, in which flowat each consent point

Notice at collection: at each collection point the platform states, in the flow itself, what is collected and the purpose.

中文概要:收集账户、资料、活动记录、支付相关(卡号只由 Stripe 收集,平台永不接触)、验证(仅能力类型选择 + 短说明,验证环节当前无文件/图片上传、不存储任何验证文件)、用户上传的图片媒体(附加到活动/消息/Memory 的照片,发布前会经内容安全扫描,见 §4、§9)、沟通、设备日志、手机号(仅在验证手机号时)、Google/Apple 登录返回的邮箱与登录标识(Google 另含姓名与头像,Apple 仅在你选择分享时含姓名,Apple 可能提供隐私中转邮箱;平台从不接触你的 Google/Apple 密码)、来源归因记录(事件类型——打开分享链接、查看活动页面(无论是否登录)、开始或完成注册、登录、进入该页的房间、分享链接;网页或 iOS/Android、时间、所涉页面/分享链接代码/商户条目、链接携带的来源标签如 utm_source、渠道标签、推荐码;仅在登录状态的上述查看、进入房间、分享链接以及完成注册、登录时记账户 ID,打开分享链接与未登录访客的查看不记任何账户标识;任何此类记录都不记 IP 地址、浏览器或设备 UA、页面 URL、精确位置或匿名访客标识,也不为此设置 cookie)、同意记录等类别;每个收集点在流程内就地告知收集内容与目的。

3. How We Use Information · 使用目的

  • Operate the coordination runtime: matching, holds, confirmations, records of who committed to what.
  • Process payments and deposits via Stripe; correlate payment facts to activity records.
  • Verify identity/capability where you request host or verified status.
  • Safety: reviewing reports, incidents, no-show disputes, enforcing policies.
  • Content safety: images you upload are screened for prohibited content by an automated content-moderation service (§9) before they are shown to others.
  • Source attribution: first-party records of which links and channels bring people to TribeRide and its activities (§2), used to understand how people find the platform. They are not used for advertising, are not sold or shared for advertising, and are separate from the optional analytics in §10.
  • Legal compliance: tax reporting duties, lawful requests, dispute records.
  • Service protection and improvement: debugging, abuse prevention, and — only with your opt-in consent — aggregate analytics (§10).

We do not use your information for third-party advertising and do not perform cross-site tracking.

中文概要:用途限于协同运行、支付处理(经 Stripe)、身份验证、安全审查、内容安全扫描(经 §9 服务商)、来源归因(了解人们经由哪些链接与渠道来到平台,不用于广告,独立于 §10 的可选分析)、法律合规、服务保护与改进;聚合分析仅在用户主动同意后启用;不用于第三方广告,无跨站跟踪。

4. User Content · 用户内容

Content you publish (scene descriptions, profile, reviews) may be visible to other users. You retain your rights; the platform processes and displays content as needed to provide the service. Think before you publish — activity listings are public to the community.

Images you upload (activity photos, message attachments, Memory items) are sent to our content-safety provider, AWS (Amazon Rekognition), which analyzes each image for prohibited content before it is published (§9). The image bytes are transmitted to AWS solely for this automated moderation check; AWS acts as a data processor and does not use your images for its own purposes.

中文概要:发布内容对社区可见;用户保留权利,平台仅在提供服务所需范围内处理与展示;公开发布前请自行斟酌。上传的图片(活动照片、消息附件、Memory)会先发送至内容安全服务商 AWS(Amazon Rekognition) 做违规内容自动检测后才发布;图片字节仅用于该自动审核,AWS 作为数据处理方、不将图片用于自身目的。

5. Sensitive Information: Verification · 敏感信息:验证

Verification today collects only your selection of a capability type and a short free-text note (up to 500 characters). There is currently no document or image upload flow for verification, and the platform stores no verification document. (Separately, images you upload to activities, messages, or Memory items are content-safety scanned as described in §4 and §9.)

  • the note is collected only on your explicit submission, for the stated verification purpose only;
  • access restricted to the review function; never public, never shared for marketing;
  • Planned (not yet implemented): if a document-upload verification flow is later added, submitted identity/capability documents will be treated as sensitive — collected only on explicit submission, access-restricted, and retained no longer than 90 days after the decision and then deleted, keeping only the fact and tier of the decision.
  • host payout/KYC documents are collected by Stripe directly under Stripe's privacy policy; the platform stores only the account reference and derived status flags (e.g., "charges enabled"), never bank or KYC documents.

中文概要:当前验证仅收集一个能力类型选择 + 一段不超过 500 字的说明文本,验证环节目前无文件/图片上传流程,不存储任何验证文件(另:上传到活动/消息/Memory 的图片会按 §4、§9 做内容安全扫描)。说明文本仅在主动提交时收集、仅审查职能可见。Planned(尚未实现):若日后新增文件上传验证流程,提交的身份/能力文件将按敏感信息处理(仅主动提交时收集、仅审查可见、决定后 90 天删除只留结果)。主办的银行/KYC 资料由 Stripe 直接收集,平台只存账户引用与状态标志。

6. Sharing · 信息共享

The platform does not sell personal information and does not share it for cross-context behavioral advertising. Information is shared only:

  • with other users, as inherent to coordination (e.g., a Host sees who joined; participants see the Host's profile);
  • with service providers processing on our behalf (§9);
  • for legal reasons: valid legal process, tax reporting, protecting rights and safety;
  • in a business transfer, with notice.

中文概要:不出售个人信息、不做跨站行为广告共享;仅在协同必需(主办与参与者互见必要信息)、服务商代处理、法律要求、业务转移(有通知)四种情形共享。

7. Retention · 保留期限

DataRetention
Account & profilelife of account; after a deletion request, removal is processed as a separate later step — the processing window is confirmed by the operator before removal — except records below
Value/ledger records (payments, refunds, disputes)retained as append-only facts for 7 years, for tax and audit purposes
Verification documentsper §5
Consent recordsduration of account + 7 years, matching the payment-record retention above
Logs90 days rolling

Deletion requests: honored except where law or dispute/tax records require retention; residual records are minimized.

中文概要:账户资料随账户存续;删号请求提交后,清除作为后续单独步骤处理,处理时限由运营方在执行清除前确认;支付/账本事实作为只追加记录保留 7 年;日志滚动 90 天;法律或争议要求保留的记录除外。

8. Your Rights and Choices · 用户权利

You may: access and correct your profile in-app; request a copy of your data; request deletion (subject to §7); withdraw analytics consent at any time (§10); close your account.

Requests: privacy@triberide.online. We respond within 45 days and do not discriminate for exercising rights. California users receive at minimum the rights CalOPPA/applicable law provide; if the platform later meets CCPA/CPRA thresholds, this policy will be upgraded (§13).

中文概要:可访问、更正、导出、删除、撤回分析同意、注销;请求发至 privacy@triberide.online,45 天内答复,行权不受歧视。

9. Service Providers · 服务商

ProviderRoleNotes
Stripepayment processing; host onboarding, KYC, tax formscardholder data and host banking data live at Stripe, not the platform
Supabasedatabase, authentication, and file storage infrastructuredata processor; uploaded images are stored here
AWS (Amazon Rekognition)automated image content-safety moderationreceives the bytes of images you upload solely to check them for prohibited content; data processor, retains no copy for its own use
TwilioSMS phone-number verification (delivered via Supabase)active: when you ask to verify a phone number, that number is sent to Twilio (through Supabase) so it can deliver a one-time verification code by text message
SendGrid (Twilio)delivery of account emails (sent by Supabase Auth)account emails such as sign-up confirmation, sign-in links, and password resets are delivered through SendGrid; it receives your email address and the content of those emails, which include one-time sign-in links
Google, Appleoptional sign-in ("Sign in with Google" / "Sign in with Apple")only if you choose it: you sign in on Google's or Apple's own page or sheet, so they learn that you are signing in to TribeRide, and they return to us (through Supabase Auth) the details listed in §2
Vercelhosting; optional analytics/speed metricsanalytics load only after opt-in (§10)
Expo (EAS Update)delivery of mobile-app updateseach time the mobile app launches it checks Expo for an update, sending a random identifier created for that app install, the app's platform, runtime version, and current update identifiers; Expo also receives your device's IP address with that request. If the app hit a fatal error, the error details (cut to 1,024 characters) are sent with the next update check

Each provider maintains its own privacy terms and processes data on the platform's behalf under its terms; providers are service providers/processors, not recipients to whom the platform sells or shares personal information (§6, §11). Any future provider — monitoring, for example — is added to this list before it is enabled.

中文概要:服务商为 Stripe(支付/KYC/税表——卡与银行数据在 Stripe 侧)、Supabase(数据库/认证/文件存储——上传图片存于此)、AWS(Amazon Rekognition,图片内容安全自动审核——仅接收上传图片字节做违规检测、不留存自用)、Twilio(短信手机号验证,经 Supabase 交付——已启用:你请求验证手机号时,该号码经 Supabase 发送至 Twilio,用于以短信发送一次性验证码)、SendGrid(Twilio 旗下,投递 Supabase Auth 发出的账户邮件——注册确认、登录链接、重置密码等;接收你的邮箱地址与邮件内容,内容包含一次性登录链接)、Google 与 Apple(可选登录——仅在你选择时:你在 Google 或 Apple 自己的页面/弹层登录,它们因此知道你在登录 TribeRide,并经 Supabase Auth 向平台返回 §2 所列信息)、Vercel(托管+可选分析,仅在同意后加载)、Expo(EAS Update,移动 App 更新下发——App 每次启动向 Expo 检查更新,发送为该次安装随机生成的标识、平台、运行时版本与当前更新标识,Expo 同时收到设备 IP 地址;若 App 曾发生致命错误,下一次检查更新时附带错误信息,截断至 1,024 个字符);各服务商均作为代平台处理数据的服务商/处理方,而非平台出售或共享个人信息的对象(见 §6、§11);未来新增服务商(例如监控)须先补录本表。

10. Analytics Consent Gate · 分析同意闸

Default is essential-only: no analytics, no cookies for tracking. Vercel Analytics / Speed Insights (anonymous, aggregate, no advertising, no cross-site tracking) load only if you choose "Accept analytics." You can change your choice anytime; the choice is stored locally and versioned so policy changes re-prompt. The first-party source records described in §2 and §3 are separate from this choice: the platform keeps them itself, sets no cookie for them, and records no IP address, user agent, or page URL in them.

中文概要:默认"仅必要"——不加载任何分析、无跟踪 cookie;只有用户主动选择"接受分析"才加载匿名聚合的 Vercel Analytics/Speed Insights;可随时更改,政策变更会重新询问。§2、§3 所述的第一方来源归因记录独立于此项选择:由平台自行保存,不为此设置 cookie,也不记录 IP 地址、UA 或页面 URL。

11. Do Not Sell or Share · 不出售/不共享声明

The platform does not sell or share personal information as those terms are defined in the CPRA, and therefore does not currently offer a "Do Not Sell or Share" link. If practices ever change, the link and an opt-out will be added first.

中文概要:平台不进行 CPRA 定义下的"出售/共享",故当前无需"请勿出售或共享"链接;若做法改变,先加链接与退出机制。

12. Children · 儿童

The platform is not directed to children under 18 and does not knowingly collect information from anyone under 18. Suspected underage accounts are removed.

中文概要:平台不面向 18 岁以下人群,不明知收集未成年人信息;发现即删除。

13. CCPA/CPRA Trigger Monitoring · 触发监测

At current scale (~1,000 users) the platform likely does not meet CCPA/CPRA business thresholds. The owner monitors: annual gross revenue ($25M+), personal information of 100k+ CA consumers/households, or 50%+ revenue from selling/sharing PI. On approaching any threshold, this policy is upgraded to full CCPA/CPRA compliance (notice at collection, rights portal, metrics reporting).

中文概要:当前规模大概率未触发 CCPA/CPRA;车主持续监测三项阈值(营收 $25M / 10万加州消费者 / 出售共享占收入50%),临近即升级本政策。

14. Security · 数据安全

Reasonable safeguards: encryption in transit, row-level security on the database, deny-by-default write paths (all writes via server authority), no card data on platform systems. No system is perfectly secure; users should protect their own credentials. Breach notification per applicable law to privacy@triberide.online.

中文概要:传输加密、数据库行级安全、默认拒绝的写入路径、平台不存卡数据;无法保证绝对安全;数据泄露按适用法律通知 privacy@triberide.online。

15. Updates · 政策更新

Material changes are announced to signed-in users with an in-product notice that links to the updated policy (per P201 §10). Version history is retained.

中文概要:重大变更以产品内通知告知已登录用户,并附更新后政策的链接(依 P201 §10);版本历史留存。

Contact · 联系方式: privacy@triberide.online · Bladeback Inc — registered address · 注册地址: 8 The Grn Ste A, Dover, DE 19901, USA; office and mailing address · 办公/通信地址: 10876 Pine Cir, Truckee, CA 96161, USA


Last reviewed by the site operator.

Back to home