PlanFolks Privacy Policy

Effective Date: [Insert Effective Date] Last Updated: [Insert Last Updated Date]

Legal Review Notice: This document is a production-quality draft prepared for PlanFolks' MVP launch. Bracketed placeholders (e.g., company legal name, registered office, jurisdiction) must be completed and the document reviewed by qualified legal counsel before publication, particularly for compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act ("CCPA").


Table of Contents

  1. Introduction
  2. Definitions
  3. Information We Collect
  4. Automatically Collected Information
  5. Cookies and Similar Technologies
  6. Analytics and Crash Reporting
  7. Location Information
  8. Images and Uploaded Content
  9. Chats and Messages
  10. How We Use Your Information
  11. Legal Basis for Processing
  12. How We Share Your Information
  13. Third-Party Service Providers
  14. International Data Transfers
  15. Data Security
  16. Data Retention
  17. Your Privacy Rights
  18. Account Deletion
  19. Data Deletion Requests
  20. Children's Privacy
  21. Changes to This Policy
  22. Contact Information

1. Introduction

PlanFolks ("PlanFolks," "we," "us," or "our") operates a travel companion platform available through our mobile application and website at https://planfolks.com (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.

This Policy applies to all users of PlanFolks globally and is designed to align with the Google Play Developer Program Policies, Apple App Store Review Guidelines, the DPDP Act, GDPR, and CCPA, where applicable. By using the Service, you agree to the collection and use of information in accordance with this Policy.

If you do not agree with this Policy, please do not access or use the Service.

2. Definitions

Term Meaning
Personal Data Any information relating to an identified or identifiable natural person.
Processing Any operation performed on Personal Data, including collection, storage, use, and deletion.
Data Subject / User An individual who uses the Service and whose Personal Data is processed.
Data Fiduciary (DPDP Act) PlanFolks, as the entity determining the purpose and means of processing Personal Data.
Data Controller (GDPR) PlanFolks, as the entity determining the purposes and means of processing Personal Data of EU residents.
Service Provider / Processor A third party that processes Personal Data on our behalf.

3. Information We Collect

3.1 Information You Provide Directly

When you register for and use PlanFolks, we collect:

  • Account Information: Name, email address, and authentication credentials (via Email OTP, Google Sign-In, or Apple Sign-In).
  • Profile Information: Profile photo, bio, age, gender, country, city, and travel interests.
  • User-Generated Content: Travel plans, posts on the travel feed, photos and images you upload, and messages sent through chat.
  • Communications: Information you provide when contacting support, submitting a report, or responding to surveys.

3.2 Data Collection Summary

Category Examples Purpose
Identity Data Name, email, profile photo Account creation, identity display
Demographic Data Age, gender, country, city Matching, personalization, safety
Preference Data Travel interests Recommendations, discovery
Content Data Uploaded images, travel plans, feed posts Core app functionality
Communication Data Chat messages Enabling traveler communication
Technical Data Device information, IP address Security, diagnostics
Usage Data Analytics, crash logs Product improvement, stability

4. Automatically Collected Information

When you use the Service, we automatically collect:

  • Device Information: Device model, operating system and version, unique device identifiers, and mobile network information.
  • IP Address: Used for security, fraud prevention, and approximate geolocation.
  • Usage Data: Screens viewed, features used, session duration, and interaction patterns.
  • Log Data: Timestamps, error reports, and diagnostic logs generated by the app.

5. Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies to operate and improve the Service. See our Cookie Policy for full details on the categories of cookies used, their purposes, and how to manage your preferences. Our mobile application uses functionally equivalent technologies (such as device identifiers and local storage) for the same purposes described in the Cookie Policy.

6. Analytics and Crash Reporting

We use Firebase Analytics and Firebase Crashlytics (provided by Google) to:

  • Understand how users interact with the Service.
  • Identify and fix bugs, crashes, and performance issues.
  • Improve features and user experience.

These tools may collect device identifiers, usage patterns, and diagnostic/crash data. This data is processed by Google in accordance with the Firebase Privacy and Security policy.

7. Location Information

PlanFolks does not currently collect precise real-time location data. Location-related features (such as showing nearby travelers or destinations) are planned for future releases ("Possible Future Data"). If and when location collection is introduced, we will:

  • Request explicit device-level permission before accessing location data.
  • Update this Policy to describe the purpose, scope, and retention of location data.
  • Provide an in-app control to disable location sharing at any time.

8. Images and Uploaded Content

Profile photos and images you upload to travel plans, the travel feed, or chats are stored using our cloud storage infrastructure (Cloudflare) and may be processed for content moderation purposes (see our Content Policy). You retain ownership of your content, subject to the license granted under our Terms and Conditions and Intellectual Property Policy.

Do not upload images containing sensitive personal data of other individuals (e.g., government ID documents, financial information) unless required for a verification feature explicitly requesting such information.

9. Chats and Messages

Messages exchanged between users through the in-app chat feature are stored to enable message history and delivery. Chat content may be:

  • Automatically scanned using moderation tooling to detect abusive content, scams, or safety violations.
  • Reviewed manually in response to a user report or legal obligation.
  • Retained after a conversation ends, subject to the retention periods described in Section 16.

We do not sell the contents of your private messages to third parties.

10. How We Use Your Information

We use collected information to:

  1. Create and manage your account.
  2. Provide core features: travel plans, the travel feed, chat, search, and discovery.
  3. Personalize your experience and suggest relevant travelers, plans, or content.
  4. Send transactional notifications (e.g., messages received, plan updates) and, where permitted, promotional communications.
  5. Detect, investigate, and prevent fraud, abuse, harassment, and violations of our Community Guidelines.
  6. Maintain the security, integrity, and reliability of the Service.
  7. Comply with legal obligations and respond to lawful requests (see our Law Enforcement Guidelines).
  8. Analyze usage trends to improve features and fix technical issues.
  9. In the future, process payments and manage premium subscriptions, should you opt in to such features.

11. Legal Basis for Processing

Where the GDPR applies, we rely on the following legal bases:

Legal Basis Example Use
Contractual necessity Creating your account, enabling core features
Legitimate interests Fraud prevention, product analytics, safety enforcement
Consent Marketing communications, optional location sharing (future)
Legal obligation Responding to lawful government or law enforcement requests

Where the DPDP Act applies, we process Personal Data based on your consent, provided at the time of registration and for specific processing activities, or as otherwise permitted under applicable law (e.g., for legitimate uses specified in the DPDP Act).

12. How We Share Your Information

We do not sell your Personal Data. We may share information with:

  • Other Users: Your profile information, public posts, and travel plans are visible to other users as part of core platform functionality.
  • Service Providers: Third parties that help us operate the Service (see Section 13).
  • Legal and Safety Purposes: When required by law, legal process, or to protect the rights, property, or safety of PlanFolks, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • With Your Consent: For any other purpose disclosed to you at the time of collection with your consent.

13. Third-Party Service Providers

We work with the following categories of third-party providers to operate PlanFolks:

Provider Purpose
Firebase (Google) — Analytics, Crashlytics, Cloud Messaging Analytics, crash reporting, push notifications
Railway Application hosting and infrastructure
PostgreSQL (self-managed / hosted) Primary database storage
Redis Caching and session management
Resend Transactional email delivery
Cloudflare Content delivery, image storage, security (DDoS protection)
Google Sign-In Authentication
Apple Sign-In Authentication
Stripe (future) Payment processing for premium subscriptions
Razorpay (future) Payment processing for premium subscriptions (India)

Each provider processes data under its own privacy policy and, where applicable, a data processing agreement with PlanFolks that limits their use of your data to providing services to us.

14. International Data Transfers

PlanFolks may store and process your data on servers located outside your country of residence, including in jurisdictions that may have different data protection laws. Where we transfer Personal Data internationally (e.g., from the EU or India to other jurisdictions), we rely on appropriate safeguards, including standard contractual clauses, provider certifications, or other legally recognized transfer mechanisms.

15. Data Security

We implement technical and organizational measures designed to protect your Personal Data, including:

  • Encryption of data in transit (TLS/HTTPS).
  • Secure credential storage and hashed authentication tokens.
  • Access controls limiting employee access to Personal Data on a need-to-know basis.
  • Regular monitoring for unauthorized access and security vulnerabilities.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any identified vulnerabilities and, where legally required, notifying affected users of data breaches.

16. Data Retention

We retain Personal Data for as long as necessary to fulfil the purposes described in this Policy, including:

Data Type Retention Period
Account and profile data Until account deletion, plus a limited grace period (see Account Deletion Policy)
Chat messages Until account deletion or as required for safety/legal investigations
Analytics and crash logs Up to 14 months, in line with standard Firebase Analytics retention
Reports and moderation records Up to [3] years, to support repeat-offender enforcement and legal defense
Legal and financial records (future — payments) As required by applicable tax and financial regulations

17. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access the Personal Data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your Personal Data (see Sections 18–19).
  • Restrict or object to certain processing activities.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Opt out of the sale/sharing of Personal Data (CCPA) — note that PlanFolks does not sell Personal Data.
  • Lodge a complaint with your local data protection authority (e.g., the Data Protection Board of India under the DPDP Act, or your EU supervisory authority).

To exercise these rights, contact us at privacy@planfolks.com. We will respond within the timeframe required by applicable law.

18. Account Deletion

You may delete your account at any time from within the app (Settings → Account → Delete Account) or by emailing privacy@planfolks.com. Full details of the deletion process, timeline, and what happens to your data are set out in our Account Deletion Policy.

19. Data Deletion Requests

Even without deleting your entire account, you may request deletion of specific categories of Personal Data, subject to legal and operational exceptions. See our Data Deletion Policy for the full process and timelines.

20. Children's Privacy

PlanFolks is intended for users who are 18 years of age or older. We do not knowingly collect Personal Data from individuals under 18. If we become aware that we have collected Personal Data from a child under 18, we will take steps to delete such data promptly. If you believe a child has provided us with Personal Data, contact privacy@planfolks.com immediately. See also our Child Safety Standards.

21. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes via the app or by email, and will update the "Last Updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

22. Contact Information

For questions about this Privacy Policy or our data practices, contact:


This Privacy Policy should be read alongside our Terms and Conditions, Cookie Policy, Account Deletion Policy, and Data Deletion Policy.