Trust & Safety
Privacy Notice — Pilot
This is a staging pilot of TribeRide — a preview, not a production service, public marketplace, or finished product. Priced-scene value flow is modeled, but payment execution, provider setup, settlement, refund handling, and payout remain Owner-gated. These are pilot-stage disclosures; final versions are being prepared.
P202 Privacy Policy · 隐私政策
1. Purpose · 目的
This policy explains what information TribeRide collects, why, who it is shared with, how long it is kept, and what choices you have. It applies to the TribeRide platform and is posted to satisfy the California Online Privacy Protection Act (CalOPPA).
中文概要:说明平台收集什么信息、为何收集、与谁共享、保留多久、用户有何选择;本政策的发布本身即为满足加州 CalOPPA 的公示义务。
2. Information We Collect · 我们收集的信息
| Category | Examples | When collected |
|---|---|---|
| Account | name, email, password credential | account creation |
| Profile | display name, locale, visibility settings | user-provided, editable |
| Activity records | scenes published/joined, holds, confirmations, cancellations, no-show review records | as you use the platform |
| Payment-related | amount, currency, payment status, payment-intent reference, refund/dispute status. Card numbers are collected by Stripe, never by the platform. | at checkout |
| Verification | a capability-type selection and a short free-text note. No document or image upload exists today; no verification document is stored by the platform. | only when you apply for verification |
| Communications | messages within coordination flows, reports, support requests | as sent |
| Device & logs | IP address, browser type, access timestamps, error logs | automatically |
| Consent records | which policy version you accepted, when, in which flow | at each consent point |
Notice at collection: at each collection point the platform states, in the flow itself, what is collected and the purpose.
中文概要:收集账户、资料、活动记录、支付相关(卡号只由 Stripe 收集,平台永不接触)、验证(仅能力类型选择 + 短说明,当前无文件上传、不存储任何验证文件)、沟通、设备日志、同意记录八类;每个收集点在流程内就地告知收集内容与目的。
3. How We Use Information · 使用目的
- Operate the coordination runtime: matching, holds, confirmations, records of who committed to what.
- Process payments and deposits via Stripe; correlate payment facts to activity records.
- Verify identity/capability where you request host or verified status.
- Safety: reviewing reports, incidents, no-show disputes, enforcing policies.
- Legal compliance: tax reporting duties, lawful requests, dispute records.
- Service protection and improvement: debugging, abuse prevention, and — only with your opt-in consent — aggregate analytics (§10).
We do not use your information for third-party advertising and do not perform cross-site tracking.
中文概要:用途限于协同运行、支付处理(经 Stripe)、身份验证、安全审查、法律合规、服务保护与改进;聚合分析仅在用户主动同意后启用;不用于第三方广告,无跨站跟踪。
4. User Content · 用户内容
Content you publish (scene descriptions, profile, reviews) may be visible to other users. You retain your rights; the platform processes and displays content as needed to provide the service. Think before you publish — activity listings are public to the community.
中文概要:发布内容对社区可见;用户保留权利,平台仅在提供服务所需范围内处理与展示;公开发布前请自行斟酌。
5. Sensitive Information: Verification · 敏感信息:验证
Verification today collects only your selection of a capability type and a short free-text note (up to 500 characters). There is currently no document or image upload flow, and the platform stores no verification document.
- the note is collected only on your explicit submission, for the stated verification purpose only;
- access restricted to the review function; never public, never shared for marketing;
- Planned (not yet implemented): if a document-upload verification flow is later added, submitted identity/capability documents will be treated as sensitive — collected only on explicit submission, access-restricted, and retained no longer than 90 days after the decision and then deleted, keeping only the fact and tier of the decision.
- host payout/KYC documents are collected by Stripe directly under Stripe's privacy policy; the platform stores only the account reference and derived status flags (e.g., "charges enabled"), never bank or KYC documents.
中文概要:当前验证仅收集一个能力类型选择 + 一段不超过 500 字的说明文本,平台目前无文件/图片上传流程,不存储任何验证文件。说明文本仅在主动提交时收集、仅审查职能可见。Planned(尚未实现):若日后新增文件上传验证流程,提交的身份/能力文件将按敏感信息处理(仅主动提交时收集、仅审查可见、决定后 90 天删除只留结果)。主办的银行/KYC 资料由 Stripe 直接收集,平台只存账户引用与状态标志。
6. Sharing · 信息共享
The platform does not sell personal information and does not share it for cross-context behavioral advertising. Information is shared only:
- with other users, as inherent to coordination (e.g., a Host sees who joined; participants see the Host's profile);
- with service providers processing on our behalf (§9);
- for legal reasons: valid legal process, tax reporting, protecting rights and safety;
- in a business transfer, with notice.
中文概要:不出售个人信息、不做跨站行为广告共享;仅在协同必需(主办与参与者互见必要信息)、服务商代处理、法律要求、业务转移(有通知)四种情形共享。
7. Retention · 保留期限
| Data | Retention |
|---|---|
| Account & profile | life of account + 30 days after deletion request, except records below |
| Value/ledger records (payments, refunds, disputes) | retained as append-only facts for 7 years, for tax and audit purposes |
| Verification documents | per §5 |
| Consent records | duration of account + 7 years, matching the payment-record retention above |
| Logs | 90 days rolling |
Deletion requests: honored except where law or dispute/tax records require retention; residual records are minimized.
中文概要:账户资料随账户存续,删号后 30 天清除;支付/账本事实作为只追加记录保留 7 年;日志滚动 90 天;法律或争议要求保留的记录除外。
8. Your Rights and Choices · 用户权利
You may: access and correct your profile in-app; request a copy of your data; request deletion (subject to §7); withdraw analytics consent at any time (§10); close your account.
Requests: privacy@triberide.online. We respond within 45 days and do not discriminate for exercising rights. California users receive at minimum the rights CalOPPA/applicable law provide; if the platform later meets CCPA/CPRA thresholds, this policy will be upgraded (§13).
中文概要:可访问、更正、导出、删除、撤回分析同意、注销;请求发至 privacy@triberide.online,45 天内答复,行权不受歧视。
9. Service Providers · 服务商
| Provider | Role | Notes |
|---|---|---|
| Stripe | payment processing; host onboarding, KYC, tax forms | cardholder data and host banking data live at Stripe, not the platform |
| Supabase | database and authentication infrastructure | data processor |
| Vercel | hosting; optional analytics/speed metrics | analytics load only after opt-in (§10) |
Each provider maintains its own privacy terms. Any future provider — email, monitoring — is added to this list before it is enabled.
中文概要:服务商为 Stripe(支付/KYC/税表——卡与银行数据在 Stripe 侧)、Supabase(数据库/认证)、Vercel(托管+可选分析,仅在同意后加载);未来新增服务商须先补录本表。
10. Analytics Consent Gate · 分析同意闸
Default is essential-only: no analytics, no cookies for tracking. Vercel Analytics / Speed Insights (anonymous, aggregate, no advertising, no cross-site tracking) load only if you choose "Accept analytics." You can change your choice anytime; the choice is stored locally and versioned so policy changes re-prompt.
中文概要:默认"仅必要"——不加载任何分析、无跟踪 cookie;只有用户主动选择"接受分析"才加载匿名聚合的 Vercel Analytics/Speed Insights;可随时更改,政策变更会重新询问。
11. Do Not Sell or Share · 不出售/不共享声明
The platform does not sell or share personal information as those terms are defined in the CPRA, and therefore does not currently offer a "Do Not Sell or Share" link. If practices ever change, the link and an opt-out will be added first.
中文概要:平台不进行 CPRA 定义下的"出售/共享",故当前无需"请勿出售或共享"链接;若做法改变,先加链接与退出机制。
12. Children · 儿童
The platform is not directed to children under 18 and does not knowingly collect information from anyone under 18. Suspected underage accounts are removed.
中文概要:平台不面向 18 岁以下人群,不明知收集未成年人信息;发现即删除。
13. CCPA/CPRA Trigger Monitoring · 触发监测
At current scale (~1,000 users) the platform likely does not meet CCPA/CPRA business thresholds. The owner monitors: annual gross revenue ($25M+), personal information of 100k+ CA consumers/households, or 50%+ revenue from selling/sharing PI. On approaching any threshold, this policy is upgraded to full CCPA/CPRA compliance (notice at collection, rights portal, metrics reporting).
中文概要:当前规模大概率未触发 CCPA/CPRA;车主持续监测三项阈值(营收 $25M / 10万加州消费者 / 出售共享占收入50%),临近即升级本政策。
14. Security · 数据安全
Reasonable safeguards: encryption in transit, row-level security on the database, deny-by-default write paths (all writes via server authority), no card data on platform systems. No system is perfectly secure; users should protect their own credentials. Breach notification per applicable law to privacy@triberide.online.
中文概要:传输加密、数据库行级安全、默认拒绝的写入路径、平台不存卡数据;无法保证绝对安全;数据泄露按适用法律通知 privacy@triberide.online。
15. Updates · 政策更新
Material changes are announced in-app and trigger re-consent where required (per P201 §10). Version history is retained.
中文概要:重大变更应用内公告并按需重新同意;版本历史留存。
Contact · 联系方式: privacy@triberide.online · bladeback Inc, 10876 Pine Cir, Truckee, CA 96161, USA
Pilot draft — last reviewed by the site operator.
Back to home