Effective Date: January 1, 2026 | Last Updated: January 1, 2026
1️⃣ Introduction
Welcome to BuddyUp. This Privacy Policy explains how BuddyUp ("we," "our," or "us") collects, uses, discloses, and protects your personal information when you use our ride-sharing and travel companion mobile application and related services (the "Service").
Our Commitment: We are committed to protecting your privacy and being transparent about how we collect and use your data. This policy applies to all BuddyUp users and covers all aspects of our Service.
By using BuddyUp, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
Scope of Policy
This Privacy Policy applies to:
- The BuddyUp mobile application (iOS and Android)
- All features and services provided through the app
- Information collected before, during, and after rides
- Communications between users
3️⃣ How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Provision
- Create and maintain your account
- Match you with compatible travel companions based on preferences
- Enable trip creation, browsing, and joining
- Facilitate communication between users
- Process ride-sharing arrangements and cost splits
- Provide navigation and route optimization
- Calculate and display trip costs
3.2 Safety and Security
- Verify user identities and prevent fraud
- Enable emergency contact features
- Monitor for suspicious activity and violations
- Respond to safety reports and incidents
- Enforce our Terms & Conditions and Community Guidelines
- Conduct background checks (where legally permitted and with consent)
- Maintain trip history for safety and accountability
3.3 Payments and Transactions
- Process payments and cost splits
- Send transaction confirmations and receipts
- Detect and prevent payment fraud
- Resolve payment disputes
- Maintain financial records
3.4 Communications
- Send notifications about trips, matches, and messages
- Provide customer support
- Send service updates and announcements
- Deliver marketing communications (with your consent)
- Request feedback and reviews
3.5 Personalization
- Customize trip recommendations based on your preferences
- Suggest compatible travel companions
- Tailor content and features to your interests
- Remember your preferences and settings
3.6 Analytics and Improvement
- Analyze usage patterns to improve features
- Conduct research and development
- Test new features and optimizations
- Generate aggregated, anonymized statistics
- Understand user demographics and behavior
3.7 Legal Compliance
- Comply with legal obligations and regulations
- Respond to law enforcement requests
- Protect our rights and property
- Enforce our agreements
- Resolve disputes
4️⃣ Information Sharing and Disclosure
We Do NOT Sell Your Personal Information: BuddyUp does not sell your personal information to third parties for their marketing purposes. We only share data in the limited circumstances described below.
4.1 With Other Users
When you use BuddyUp to connect with other travelers, certain information is shared:
Visible to Potential Travel Companions
- Profile information (name, photo, bio, travel preferences)
- Reviews and ratings from previous trips
- Trip listings you've created
- Verification status
- Mutual connections (if any)
Visible to Confirmed Trip Members
- Contact information (as you choose to share)
- Real-time location (if enabled for the trip)
- Trip-related messages and communications
- Payment contributions and split details
- Emergency contact information (in case of emergency)
4.2 Service Providers
We share data with trusted third-party service providers who assist in operating our Service:
- Cloud Hosting: Data storage and server infrastructure
- Payment Processors: Secure payment processing and transaction handling
- Identity Verification: Profile verification and background check services
- Mapping Services: Navigation, routing, and location services
- Analytics Providers: App performance and usage analytics
- Communication Services: Push notifications and messaging infrastructure
- Customer Support: Help desk and support ticket systems
These providers are contractually obligated to protect your data and use it only for specified purposes.
4.3 Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes, court orders, or government requests
- Enforce our Terms & Conditions and other agreements
- Protect the rights, property, or safety of BuddyUp, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Respond to emergency situations involving danger to persons
4.4 Business Transfers
If BuddyUp is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will notify you of any such change and the choices you may have.
4.5 With Your Consent
We may share your information with third parties when you explicitly consent, such as:
- Connecting third-party travel booking services
- Sharing trip details on social media
- Participating in promotions or partnerships
- Opting into data sharing for research purposes
4.6 Aggregated and Anonymized Data
We may share aggregated, anonymized data that cannot identify you personally:
- Usage statistics and trends
- Popular routes and destinations
- General demographics
- Research and insights
5️⃣ Data Security
5.1 Security Measures
We implement industry-standard security measures to protect your data:
Technical Safeguards
- Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Secure Authentication: Password hashing with bcrypt, multi-factor authentication support
- Access Controls: Role-based access controls and principle of least privilege
- Network Security: Firewalls, intrusion detection systems, and DDoS protection
- Regular Updates: Timely security patches and software updates
Organizational Safeguards
- Employee Training: Regular security awareness and privacy training
- Background Checks: Screening of personnel with data access
- Confidentiality Agreements: All staff bound by confidentiality obligations
- Incident Response: Documented procedures for security incidents
Monitoring and Auditing
- Continuous security monitoring and logging
- Regular security audits and penetration testing
- Vulnerability assessments and remediation
- Compliance reviews and certifications
5.2 Payment Security
- We do not store complete payment card details
- All payment processing handled by PCI-DSS compliant providers
- Tokenized payment methods for enhanced security
- Secure payment gateways with fraud detection
5.3 Location Data Security
- Location data encrypted during transmission and storage
- Access to real-time location limited to trip participants (with your consent)
- Location history stored securely with retention limits
- Options to delete location history at any time
Data Breach Notification: In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities as required by law within 72 hours of discovery.
5.4 Your Responsibility
Help us keep your account secure by:
- Using a strong, unique password
- Enabling two-factor authentication
- Not sharing your account credentials
- Logging out after use on shared devices
- Reporting suspicious activity immediately
6️⃣ Your Rights and Choices
You have the following rights regarding your personal information:
6.1 Access and Portability
- View Your Data: Access your personal information through app settings
- Data Export: Request a copy of your data in a portable format
- Download Trip History: Export your trip records and reviews
6.2 Correction and Update
- Update profile information in app settings
- Correct inaccurate or incomplete data
- Request correction of data you cannot edit yourself
6.3 Deletion
- Account Deletion: Delete your account and associated data
- Selective Deletion: Remove specific trips, messages, or photos
- Right to Be Forgotten: Request complete data erasure (subject to legal obligations)
Note: Some data may be retained for legal, safety, or legitimate business purposes even after account deletion.
6.4 Marketing Communications
- Opt-out of promotional emails via unsubscribe links
- Manage push notification preferences in app settings
- Control SMS marketing messages
- You will still receive essential service communications
6.5 Privacy Settings
Control your privacy through app settings:
- Profile Visibility: Choose who can see your profile
- Location Sharing: Control when and how location is shared
- Trip Privacy: Set trips as public, friends-only, or private
- Contact Information: Choose what contact details to share
- Search Visibility: Control whether you appear in search results
6.6 Blocking and Reporting
- Block users from contacting or viewing you
- Report inappropriate behavior or content
- Manage your blocked users list
6.7 Exercising Your Rights
To exercise any of these rights:
- Use in-app settings for most functions
- Contact us at privacy@buddyup.com for requests
- Provide necessary verification for security purposes
- We respond within 30 days of verified requests
7️⃣ Location Data
Location is Essential: Location data is fundamental to BuddyUp's ride-sharing features. You have full control over when and how your location is shared.
7.1 How We Use Location
- Trip Matching: Match you with users traveling similar routes
- Navigation: Provide turn-by-turn directions and route optimization
- Safety: Enable emergency contact location sharing
- Trip Tracking: Record trip routes for reviews and accountability
- Cost Calculation: Calculate fair cost splits based on distance
7.2 Location Sharing Options
You control location sharing with three levels:
Always Allow (Recommended)
- Full access to all ride-sharing features
- Real-time trip matching and navigation
- Emergency location sharing
While Using App
- Location accessed only when app is open
- Core features available
- Limited background tracking
Never / Deny
- Some features will be unavailable
- Cannot create or join trips requiring location
- Can still browse and message users
7.3 Managing Location Settings
Control location sharing:
- Device Settings: Enable/disable in iOS Settings or Android Permissions
- App Settings: Control feature-specific location use
- Trip-Level Control: Choose location sharing per trip
- Emergency Contacts: Separately control emergency location access
7.4 Location Data Retention
- Real-time location during active trips
- Trip routes retained for 2 years
- Location history can be deleted anytime
- Anonymized location data may be retained for analytics
7.5 Impact of Disabling Location
Without location access, you cannot:
- Create or join location-based trips
- Use real-time navigation features
- Share location with emergency contacts
- Receive location-based trip recommendations
8️⃣ Data Retention
8.1 Retention Periods
We retain different types of data for varying periods:
Account Data
- Active Accounts: Retained while account is active
- Inactive Accounts: May be deleted after 3 years of inactivity (with notice)
- Deleted Accounts: Personal data deleted within 30 days
Trip Data
- Active Trips: Retained while trip is active and for 90 days after completion
- Completed Trips: Trip history retained for 2 years
- Reviews: Retained indefinitely (anonymized if account deleted)
Financial Records
- Transaction Data: Retained for 7 years for accounting and tax purposes
- Payment Methods: Tokenized data retained until you remove it
- Dispute Records: Retained for 3 years after resolution
Communications
- Messages: Retained while both parties have accounts
- Support Communications: Retained for 3 years
- Reports: Retained for safety and legal purposes
Analytics and Logs
- Usage Analytics: Aggregated data retained indefinitely
- Individual Data: Retained for 2 years
- Server Logs: Retained for 90 days
8.2 Deletion Process
When you delete your account:
- Personal information permanently deleted within 30 days
- Profile removed from search and matching
- Shared trip data may remain visible to other participants
- Reviews may remain but will be anonymized
- Some data retained in backups for up to 90 days
- Financial records retained for legal requirements
8.3 Legal Holds
We may retain data longer if required by:
- Legal obligations and regulations
- Pending legal proceedings
- Safety investigations
- Dispute resolution
9️⃣ Children's Privacy
Age Requirement: BuddyUp is intended for users aged 18 and older. We do not knowingly collect personal information from individuals under 18.
9.1 Age Restrictions
- Minimum age to use BuddyUp: 18 years old
- Age verification required during registration
- Additional verification may be requested for safety
9.2 No Collection from Minors
We do not knowingly:
- Collect personal information from individuals under 18
- Allow registration by minors
- Market to underage individuals
- Create profiles for children
9.3 Parental Rights
If you believe a minor has created an account:
- Contact us immediately at privacy@buddyup.com
- Provide proof of guardianship
- We will delete the account and associated data promptly
- Report to appropriate authorities if necessary
9.4 COPPA Compliance
We comply with the Children's Online Privacy Protection Act (COPPA) and do not collect information from children under 13 under any circumstances.
🔟 International Data Transfers
10.1 Global Operations
BuddyUp operates globally, and your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for international data transfers.
10.2 Data Transfer Mechanisms
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions for transfers to approved countries
- Binding Corporate Rules for internal transfers
- Consent for specific transfers where appropriate
10.3 GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Legal Basis: Processing based on consent, contract, or legitimate interests
- Right to Object: Object to processing based on legitimate interests
- Right to Restrict: Request restriction of processing
- Right to Lodge Complaint: Contact supervisory authorities
- Data Protection Officer: Contact our DPO at dpo@buddyup.com
10.4 CCPA Compliance (California Users)
California residents have specific rights under the California Consumer Privacy Act:
- Right to Know: Categories and specific pieces of information collected
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: We do not sell personal information
- Non-Discrimination: Equal service regardless of privacy choices
- Shine the Light: Information about data sharing for marketing
10.5 Other Regional Rights
We respect privacy rights under all applicable regional laws. Contact us to learn about your specific rights based on your location.
1️⃣1️⃣ Cookies and Tracking Technologies
11.1 Types of Technologies Used
Essential Cookies
- Session management and authentication
- Security and fraud prevention
- Load balancing and performance
- Cannot be disabled as they're necessary for service functionality
Analytics Cookies
- App usage patterns and feature engagement
- Performance monitoring and crash reporting
- A/B testing and optimization
- Can be disabled in settings
Preference Cookies
- Remember your settings and choices
- Language and region preferences
- Display preferences
- Can be managed in settings
Advertising Cookies (with consent)
- Personalized advertisements
- Measure ad effectiveness
- Limit ad frequency
- Opt-out available
11.2 Purpose of Tracking
- Provide and improve our services
- Understand user behavior and preferences
- Detect and prevent fraud
- Analyze app performance
- Deliver relevant content and features
11.3 Managing Cookie Preferences
- App Settings: Manage tracking in privacy settings
- Device Settings: Control app tracking permissions in iOS/Android
- Ad Tracking: Use "Limit Ad Tracking" (iOS) or opt-out (Android)
- Browser: Control cookies in browser settings for web version
11.4 Third-Party Analytics
We use third-party analytics services:
- Google Analytics (opt-out available)
- Firebase Analytics
- Mixpanel
- AppsFlyer
These services have their own privacy policies governing data collection.
1️⃣2️⃣ Third-Party Services
12.1 Service Provider Integrations
BuddyUp integrates with third-party services. We encourage you to review their privacy policies:
Payment Processing
Mapping and Navigation
Identity Verification
- Third-party verification service providers
- Background check services (where applicable)
Cloud Services
12.2 Social Media Integration
If you connect social media accounts:
- We access information according to your social media privacy settings
- Review and manage connected apps in social media settings
- Disconnect at any time through app or social media settings
12.3 Booking Platform Integration
If you connect travel booking platforms:
- Trip details may be imported with your permission
- Bookings made through third parties subject to their policies
- We are not responsible for third-party booking services
12.4 External Links
BuddyUp may contain links to external websites:
- We are not responsible for external site privacy practices
- Review privacy policies before providing information
- Links do not imply endorsement
12.5 No Control Over Third Parties
We are not responsible for:
- Privacy practices of third-party services
- Content or security of external sites
- Actions of other users
- Third-party data breaches
1️⃣3️⃣ Changes to Privacy Policy
13.1 Right to Modify
We may update this Privacy Policy to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
- User feedback and best practices
- Technology updates
13.2 Notification of Changes
We will notify you of material changes through:
- Email: Notification to your registered email address
- In-App: Prominent notice when you open the app
- Website: Updated notice on our website
- Date Update: "Last Updated" date at top of policy
13.3 Material Changes
For significant changes affecting your rights or data use:
- 30-day advance notice before changes take effect
- Opportunity to review new policy
- Option to delete account if you disagree
- May require explicit consent for certain changes
13.4 Acceptance of Changes
- Continued use after changes constitutes acceptance
- Review policy periodically for updates
- If you don't agree, stop using the Service
13.5 Version History
Previous versions of this policy are available upon request at privacy@buddyup.com
Thank you for trusting BuddyUp with your information. We are committed to protecting your privacy and providing you with transparency and control over your data. Safe travels!