Privacy Policy
Last updated: August 2026 (draft)
This Privacy Policy explains what information TrainMate collects, how we use it, and the choices you have.
1. Information we collect
Account information: name, email, and city, if you provide one.
Booking and contact activity: bookings you make, requests you post, and contact actions (phone/WhatsApp/email clicks) on a provider's page.
Reviews: the rating and text you submit for a completed booking.
Technical information: your IP address (used for rate-limiting abuse and in our security audit trail) and a single session cookie that keeps you signed in.
2. How we use it
To operate your account, process bookings, and let providers respond to your requests and contact attempts.
To keep the platform secure — rate-limiting repeated requests and maintaining an internal audit log of account and booking actions.
To send you transactional email (booking updates, claim decisions, password reset, email verification). We don't send marketing email today.
3. Cookies
TrainMate uses one functional, httpOnly session cookie to keep you signed in. We don't use third-party advertising or analytics trackers today.
4. Sharing your information
When you book a provider or submit a contact request, the provider sees the information needed to fulfil it (e.g. your name and contact details for a confirmed booking). A provider never sees your email or phone number through the User Request Marketplace feed before you choose to accept a response.
We don't sell your personal information, and we don't share it with third parties for their own marketing purposes.
5. Data retention
We retain account and booking data for as long as your account is active, plus a reasonable period after for legal, security, and audit purposes. A formal retention schedule is still being finalized.
6. Your rights
You can request access to, correction of, or deletion of your personal information by contacting us through the Contact page.
7. Children
TrainMate isn't directed at children, and account creation requires being old enough to form a binding contract in your jurisdiction.
8. Security
Passwords are hashed (Argon2id), never stored in plain text. Session cookies are httpOnly and transmitted only over HTTPS in production.
9. Changes to this policy
We may update this policy as the platform develops. Material changes will be reflected by an updated "Last updated" date on this page.
10. Contact
Questions about this policy, or a request about your data? Reach out via the Contact page.
TrainMate