Privacy Policy
Last updated: May 4, 2026
1. Introduction
12TravelBuddy ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our service, in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws. 12TravelBuddy is a service provided by VisionPathStudio.
2. Data Controller
12TravelBuddy, operating under VisionPathStudio, is the data controller responsible for your personal data. For questions or to exercise your rights, contact us at privacy@12travelbuddy.com.
3. Information We Collect
We collect the following categories of personal data:
- Account Information: Email address, nickname, and password (hashed)
- Profile Information: Birthday, gender, location (country and town), relationship status, about me description, and profile photo (all optional)
- Travel Posts: Trip details including destination, travel period, preferences, and descriptions
- Age Verification Result (optional): If you choose to verify your age, you submit a selfie photo that is transmitted to didit.me for facial age estimation processing. We do not store the photo. We store only the verification result ("age verified: yes") and a timestamp. See the Age Verification section below for full details.
- Usage Data: Pages visited, features used, timestamps, and device/browser information
- Cookies & Similar Technologies: Session cookies for authentication and preferences
4. Legal Basis for Processing (GDPR)
We process your data based on:
- Contractual Necessity: To provide and operate the Service per our Terms of Service
- Legitimate Interests: To improve the Service, ensure security, and prevent fraud
- Consent: For optional profile information and marketing communications (where applicable)
- Legal Obligation: To comply with applicable laws and regulations
5. How We Use Your Information
- Provide, maintain, and improve the Service
- Enable user profiles and travel companion matching
- Send service-related communications (e.g., password resets, account notifications)
- Monitor and enforce compliance with our Terms of Service
- Detect, prevent, and address security issues and abuse
- Aggregate anonymized data for analytics and service improvement
6. Data Sharing & Third Parties
We do not sell your personal data. We may share data with:
- Service Providers: Cloud hosting, email delivery, and analytics providers who process data on our behalf under strict contractual obligations
- Age Verification (didit.me): If you initiate age verification, your selfie photo is transmitted to didit.me, an independent age estimation service, for facial analysis. didit.me acts as a separate data controller for any data you submit to it. 12TravelBuddy receives only the estimated age result and stores only whether verification succeeded and when. We do not store your photo. See didit.me's privacy policy at didit.me/privacy.
- Other Users: Your profile information and travel posts are visible to other registered users as described in our profile privacy design
- Legal Requirements: When required by law, court order, or to protect our rights and safety
7. Age Verification (didit.me)
Members may optionally verify the age they entered on their profile through didit.me, a facial age estimation service. Verification is voluntary, never required to use the Service, and produces a small "Age verified" badge on your profile.
How it works. When you take or upload a selfie on your profile page, the image is securely forwarded from our servers to didit.me's age estimation API. didit.me analyses the photo using facial recognition technology and returns an estimated age. We then compare that estimate against the age derived from the birthday you have on file. The entire process takes only a few seconds. You are not redirected away from the site.
What we receive and store. didit.me returns an estimated age and a confidence result. We store only two values on your profile:
- A timestamp indicating when your age was verified successfully
- (Implicitly: the badge is on or off based on whether that timestamp exists)
We do not store your selfie photo — it is transmitted to didit.me solely for the purpose of age estimation and is then discarded. We do not store government ID numbers, ID document images, biometric templates, or any other personal data beyond the verification timestamp. didit.me is a separate data controller for any data processed on their platform; please review their privacy notice at didit.me/privacy.
Manual review. If the automatic age estimation result is inconclusive (for example because of lighting or image quality), you may request a manual review. An admin will then verify your age manually and update your profile accordingly. Any request for manual review is handled as a support contact and is subject to our data retention practices.
Your control. You can ignore the verification flow entirely. You can also request removal of your verification status at any time by contacting us at privacy@12travelbuddy.com; we will clear the badge from your profile.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States. For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms, to ensure adequate protection of your data.
9. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. After account deletion, we will delete or anonymize your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes).
10. Your Rights
Depending on your location, you have the following rights:
Under GDPR (EEA/UK residents):
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time without affecting prior processing
- Lodge a Complaint: File a complaint with your local data protection authority
Under CCPA (California residents):
- Know: What personal information is collected and how it is used
- Delete: Request deletion of your personal information
- Non-Discrimination: Exercise your rights without discriminatory treatment
- Opt-Out: Opt out of the sale of personal information (we do not sell your data)
To exercise any of these rights, contact us at privacy@12travelbuddy.com. We will respond within 30 days (or as required by applicable law).
11. Cookies
We use essential cookies for authentication and session management. These are strictly necessary and do not require consent. We do not use tracking or advertising cookies. If we introduce optional cookies in the future, we will provide a cookie consent mechanism in accordance with ePrivacy Directive requirements.
12. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), secure password hashing, and access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we learn we have collected data from a child under 16, we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service at least 30 days before changes take effect. Your continued use after the effective date constitutes acceptance.
15. Contact Us
For privacy-related inquiries or to exercise your data rights, contact us at:
12TravelBuddy Privacy Team
A service of VisionPathStudio
Email: privacy@12travelbuddy.com
For EEA residents, you also have the right to lodge a complaint with your local supervisory authority. A list of EEA data protection authorities can be found at edpb.europa.eu.