Privacy Policy

Last updated: August 2026 (draft)

This is a draft policy prepared ahead of TrainMate's soft launch. It has not been reviewed by a lawyer, and jurisdiction-specific details (data protection law, registered business entity, a formal data-retention schedule) are not yet finalized. Do not treat this as final legal coverage.

This Privacy Policy explains what information TrainMate collects, how we use it, and the choices you have.

1. Information we collect

Account information: name, email, and city, if you provide one.

Booking and contact activity: bookings you make, requests you post, and contact actions (phone/WhatsApp/email clicks) on a provider's page.

Reviews: the rating and text you submit for a completed booking.

Technical information: your IP address (used for rate-limiting abuse and in our security audit trail) and a single session cookie that keeps you signed in.

2. How we use it

To operate your account, process bookings, and let providers respond to your requests and contact attempts.

To keep the platform secure — rate-limiting repeated requests and maintaining an internal audit log of account and booking actions.

To send you transactional email (booking updates, claim decisions, password reset, email verification). We don't send marketing email today.

3. Cookies

TrainMate uses one functional, httpOnly session cookie to keep you signed in. We don't use third-party advertising or analytics trackers today.

4. Sharing your information

When you book a provider or submit a contact request, the provider sees the information needed to fulfil it (e.g. your name and contact details for a confirmed booking). A provider never sees your email or phone number through the User Request Marketplace feed before you choose to accept a response.

We don't sell your personal information, and we don't share it with third parties for their own marketing purposes.

5. Data retention

We retain account and booking data for as long as your account is active, plus a reasonable period after for legal, security, and audit purposes. A formal retention schedule is still being finalized.

6. Your rights

You can request access to, correction of, or deletion of your personal information by contacting us through the Contact page.

7. Children

TrainMate isn't directed at children, and account creation requires being old enough to form a binding contract in your jurisdiction.

8. Security

Passwords are hashed (Argon2id), never stored in plain text. Session cookies are httpOnly and transmitted only over HTTPS in production.

9. Changes to this policy

We may update this policy as the platform develops. Material changes will be reflected by an updated "Last updated" date on this page.

10. Contact

Questions about this policy, or a request about your data? Reach out via the Contact page.