Privacy Policy
What we collect,
and what we don’t.
Last updated July 7, 2026.
What we collect
- Account basics. Email, phone (optional), and a display name.
- Profile. Photos, bio, birthday, city, gender, and whatever else you choose to share.
- Verification. Legal name and, at higher tiers, documents you upload for identity / education / occupation / asset checks. Documents stay in a private storage bucket only the review team can see.
- Reservations & payments.Which events you’ve booked, what you paid, and Stripe’s payment metadata (we never see your full card number).
- Messages. Chats with other members and with us. We store them so you can go back and read them.
- Anonymous usage analytics.Page views, clicks, and referrer. See “analytics” below.
What we don’t collect
- Your full credit card number (Stripe holds that).
- Your location in real time. We ask what city you’re in; we don’t track where you are right now.
- Data from your device outside this app.
How we use it
- Match you with events, trips, and other members.
- Verify you and keep the club honest.
- Send transactional email (confirmations, reminders).
- Improve the product — anonymously wherever we can.
Who we share it with
A short list of vendors, all of which are contractually bound to protect your data:
- Supabase— database + auth
- Stripe— payments
- Resend— transactional email
- Vercel— hosting + anonymized web analytics
For trips, we pass your contact info to the specific partner agency you registered interest with. Nothing else, and never to third-party marketers.
Analytics
We use Vercel Web Analytics to understand what people click. It doesn’t use third-party cookies and doesn’t build cross-site profiles of you. If your browser sends the Do Not Track header we respect it.
Your rights
You can see, edit, and download the data we hold on you at any time by asking. You can delete your account, and with it your profile, photos, and messages, from your account settings. We keep a minimal audit trail (payments, refunds, moderation) for legal reasons.
Security
Traffic is TLS-encrypted end to end. Verification documents sit in a locked-down bucket. Payments go directly to Stripe. We don’t use SMS 2FA (which is easily hijacked) — logins go through email one-time codes.
Contact
Privacy questions? privacy@bondly.love.