Privacy Policy
Last updated: Version v2.2 · Effective February 15, 2026
This Privacy Policy explains how CNFRMD LLC (“we”, “us”, “our”) collects, uses, shares, and protects information when you use our website, products, and services (collectively, the “Services”). By using the Services, you agree to the terms below and the accompanying Terms of Service.
1. Who we are
CNFRMD LLC operates the collaborative group travel planning platform. The data controller is CNFRMD LLC. You can reach us at hello@itscnfrmd.com.
2. Information we collect
We collect only what we need to run and improve the Services.
- Account information: name, preferred name, email, phone, date of birth, gender, profile picture, provider ID (e.g. Google), and login timestamps.
- Travel profile information: accessibility needs, medical considerations, medication notes (including CPAP and insulin refrigeration needs), allergies, dietary preferences, smoking and drinking preferences, service-animal status and documentation.
- Emergency and identity information: emergency contact details, passport information, and travel documents. You control who can view each of these fields.
- Trip information: trips you create or join, reservations, group logistics, roommate preferences, and Trip Confidence Score signals.
- Travelarity™ assessment answers: individual answers remain private and are never shared with other users. Only aggregated compatibility scores are computed.
- Terms acceptance metadata: date, time, version accepted, user ID, IP address, and device information — recorded for audit purposes.
- Usage information (only with consent): anonymous events such as page views and CTA clicks, plus basic technical metadata (browser, referrer).
- Device & session data: cookies and local storage values described in our Cookie Policy.
We do not sell personal data. We do not collect payment card data (payments, when introduced, will be processed by a PCI-compliant provider such as Stripe).
3. Field-level privacy controls
Privacy is user controlled. Every applicable profile field allows you to choose who can view it:
- Only Me — nobody else sees this field.
- Host Only — visible only to the trip host you have granted permission.
- Group Members — visible to all confirmed members of a trip.
- Do Not Share — the field is stored but is not exposed to any other user, even hosts.
This applies to Emergency Contacts, Medical Information, Accessibility Needs, Dietary Needs, Travel Documents, Passport Information, Preferred Name, Allergies, Smoking Status, Drinking Status, Service Animal Information, and any other sensitive personal information. Permission selections are stored individually so you can change your mind at any time.
4. How we use information
- To provide access to the Services and calculate Trip Confidence and Travelarity™ compatibility.
- To authenticate users via email/password and Google Sign-In.
- To communicate about the product, early access, and updates you request.
- To measure and improve the Services (only with your consent for analytics).
- To comply with legal obligations and prevent abuse.
5. Legal bases (GDPR)
Where GDPR applies, we rely on:
- Consent — for analytics/marketing cookies and optional communications.
- Legitimate interests — to secure the Services, prevent fraud, and run essential product operations.
- Contract — to provide the Service you have requested.
6. Third-party sharing
We share information only with vetted service providers acting on our instructions (hosting, database, authentication, email delivery, AI providers, analytics), under confidentiality obligations. We do not sell or rent personal information.
Third-party providers may collect or process information according to their own Terms of Service and Privacy Policies. CNFRMD is not responsible for the privacy practices, security, availability, or content of third-party services.
7. International transfers
Our infrastructure providers may store data outside your country. When transferring data internationally we rely on legally recognized safeguards, including Standard Contractual Clauses where required.
8. Retention
Account and trip data are retained for the duration of your account plus a reasonable period thereafter to comply with legal obligations. When you request deletion, we mark your data as removed but keep it in a soft-deleted state for 7 days so you can restore it if you change your mind. After 7 days it is permanently purged. Session tokens expire after 7 days. Analytics events are retained up to 24 months in aggregated form.
9. Your rights
You have the following rights regarding your personal data:
- Right to access your personal data;
- Right to correct inaccurate or incomplete data;
- Right to delete your account and personal data;
- Right to request a copy of your data in a portable format;
- Right to opt out of the sale or sharing of your personal information (see below);
- Right to withdraw consent where applicable (e.g., SMS opt-in, cookie categories);
- Right to manage SMS and communication preferences — see SMS Preferences;
- Right to contact CNFRMD regarding privacy requests.
The fastest way to exercise access or deletion is our self-serve page: Access or delete your data. You can also email hello@itscnfrmd.com. We respond within 30 days.
California residents may exercise CCPA/CPRA rights. Residents of the EEA/UK may exercise GDPR rights and lodge a complaint with their local supervisory authority.
9a. Do Not Sell or Share My Personal Information
CNFRMD does not currently sell personal information. However, users may still choose to opt out of any future sale or sharing of personal information where applicable by law (CCPA, CPRA, and similar). Your choice is stored with a timestamp so we can honor it going forward.
10. Security
We use encryption in transit (HTTPS), scoped access controls, and minimum-necessary data collection. No system is 100% secure; if we become aware of a breach that affects you, we will notify you as required by law.
11. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from them.
12. Changes
We may update this Policy. Material changes will trigger a Terms version bump and re-acceptance will be required before continued use of the Services.
13. Contact
Data protection queries: hello@itscnfrmd.com.
