Privacy policy
How TrustTrip uses personal data and your choices.
TrustTrip processes personal data for one purpose family: operating a trustworthy shared-travel platform. This policy explains in plain language what we collect, why we collect it, how long we keep it, and the rights you can exercise.
Our data principles
Three principles guide data processing on TrustTrip. First, purpose limitation means data is used to operate accounts, bookings, payments, safety, fraud prevention, and support, not for unrelated resale. Second, access controls are designed to restrict internal access by role and operational need. Selected sensitive operations generate audit records. Third, proportional retention means records are kept as long as needed for the service, legal obligations, and dispute resolution, then removed or anonymized.
What we process and why
Account and identity
Name, email, date of birth, phone verification status, language preference, profile photo when you add one, and role-specific profile fields. Drivers additionally provide verification documents (licence, vehicle, insurance) reviewed during onboarding. Those verification files are stored privately and encrypted at rest. Purpose: account security, eligibility, and trust.
Trips, bookings, and location
Published routes, schedules, seat reservations, booking history, and trip messaging tied to confirmed shared travel. When you choose to share live location for a trip, we process that location so members on that trip can coordinate boarding. Purpose: operating shared travel and keeping a reliable record when something goes wrong.
Vehicle and media
Vehicle details and photos that drivers upload for their profile or trip presentation (including a public vehicle cover when provided). Purpose: helping passengers recognize the right vehicle and supporting driver eligibility.
Payments
Billing contact details and payment metadata (amounts, status, references) processed through our payment provider. TrustTrip does not store full card numbers. Purpose: secure checkout, refund reviews, and accounting obligations.
Session, security, and abuse prevention
Session identifiers, IP address, browser or device information such as user agent, security events, captcha results, and abuse-prevention signals. Purpose: maintaining sessions, protecting accounts, limiting automated abuse, and investigating security incidents.
Trust signals and notifications
Reliability and trust-point activity tied to your account, plus in-app, email, and SMS notices about trips, bookings, and account events when those channels are enabled. Purpose: operating trust features and keeping you informed. For SMS-specific terms, see SMS notifications below.
Support, chat, and safety
Support conversations (including guest chat when you use it), contact details used to continue a guest support session, trip messaging, attachments you send, reports, and policy events (cancellations, no-shows, reviews). Purpose: helping you, maintaining support continuity, enforcing community rules, and keeping reliability signals accurate.
Driver verification documents
When you apply as a driver, TrustTrip collects verification documents such as your licence, vehicle registration, and insurance proof so our review team can confirm eligibility.
These files are stored in private storage and encrypted at rest with AES-256. Access is limited to authorized TrustTrip reviewers for verification and compliance. They are not published as public profile media.
SMS notifications
TrustTrip sends SMS only for account security and shared-travel activity. We do not send promotional or marketing SMS campaigns.
We do not share mobile numbers with third parties for their own marketing.
Message types include one-time verification codes for phone identity, password reset, and password change. They also include booking and payment updates such as confirmation or a payment issue, and trip updates for passengers and drivers such as driver live on the map, trip cancellation, and a new booking alert for drivers.
You consent to one verification SMS when you enter your mobile number and select Send code or the equivalent labeled button. We send a code only after that action. This request does not turn on recurring SMS. Password recovery offers email or SMS, so SMS is not the only path.
You consent to recurring transactional SMS when you turn on SMS in Account settings. These messages are sent to your verified account number and relate to account, booking, payment, and trip activity.
Frequency is event-driven only. Volume depends on your activity.
Message and data rates may apply.
You can turn off recurring SMS in Account settings under Notifications. Text STOP to block all SMS to your number. TrustTrip will not send another SMS while that block remains active, including a verification code you request. Reply START or UNSTOP to +1 (438)-797-7202 to enable SMS again.
For support, visit https://trusttrip.ca/resources/contact.
Sharing and processors
With other members, we share only what is needed to organize and complete the trip: your public profile, meeting points, and trip messaging. All other personal information stays private and is protected with industry-standard encryption and security controls. We also use service providers for hosting, payment processing, communications, security, captcha, and related platform operations. Information may be disclosed to professional advisers, regulators, law enforcement, or other authorities when required or permitted by law. TrustTrip does not sell personal data.
Your rights in Canada
Under applicable Canadian privacy laws, including PIPEDA and, where they apply, Quebec’s private-sector privacy rules such as Law 25, you may have rights to access and correct your personal information, to ask how it is handled, and to withdraw consent where processing relies on consent.
To exercise a right or ask a privacy question, contact support through the documented channels. We handle requests according to the laws that apply to your situation. If you are not satisfied with the response, you may contact the relevant privacy authority.
Changes to this policy
We may update this policy as the product and applicable law evolve. Material changes are communicated before they take effect. This page always reflects the current published version.