Trust & Privacy

This page is maintained by the Traveler team to answer common questions about how the product handles your account, data, and privacy. It describes the controls currently enabled in the app — not an independent certification or audit.

Accounts & authentication

Sign-in is handled by our managed authentication provider. Passwords are never stored in our application database — only the provider holds password material. Google single sign-on is offered alongside email/password.

Each account is tied to a unique email. Admin-only areas require a separate role on the account, granted server-side; the client cannot self-promote.

Your data

Traveler stores the information you provide to use the product: profile details, trips you create, connection requests you send or receive, messages with accepted connections, and events you create or attend.

Access to your rows is enforced at the database with row-level security. By default, other travelers can only see the fields you choose to share when matching on a trip; your email address and account identifiers are not exposed to other users.

Messaging & connections

Messages are only visible to the two participants of an accepted connection. A connection request can only be accepted by the recipient — the requester cannot self-accept.

You can block another user at any time. Reports you submit are visible to the Traveler safety team and are used to take action on accounts that violate the community rules.

Trip invite links

Trip invite links contain a secret token. Only the trip owner can list the invites they created. Joining a trip via an invite link is processed by a server-side function that validates the token without exposing other invites.

Subprocessors

Traveler runs on managed cloud infrastructure for hosting, database, authentication, file storage, and email delivery. These providers process data on our behalf to make the product work and are bound by their own security and privacy commitments.

Data retention & deletion

You can edit or remove your profile, trips, messages, and events from inside the app. If you would like your account fully deleted, contact us using the address below and we will remove your account and associated personal data.

Security contact

To report a security issue or a privacy concern, email support@jointraveler.com. Please include steps to reproduce and any relevant accounts or URLs. We aim to acknowledge reports within a few business days.

This page reflects current product behaviour and is not a legal contract, certification, or audit report. It is updated as the product changes.