SociaTrip Logo
Home
Pricing
Blogs
Legal · Privacy

Privacy Policy

How Sociatrip collects, uses, and protects your personal data in full compliance with GDPR.

Last updated: April 2026 ~8 min read Designed to comply with GDPR

On this page

Related documents

Terms & Conditions
01

Introduction

Sociatrip operates the SociaTrip.com platform and mobile application. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our services.

By creating an account or using Sociatrip, you acknowledge that you have read and understood this policy. The data controller of this service is Fadi Massarwa, an individual developer based in Pavia, Italy, operating SociaTrip as a personal project. Contact: info@sociatrip.com

This policy applies to all users regardless of location, with additional rights for EU/EEA residents under GDPR.
02

Data We Collect

We collect information you provide directly and data generated by your use of the platform:

Account Data

  • Name, email address, password (hashed)
  • Profile photo and bio
  • Date of birth (age verification)
  • Nationality / home country

Location Data

  • GPS coordinates (if permission granted)
  • Check-in locations you create
  • Trip routes and destinations
  • IP-based approximate location
  • Users can control the visibility of their location data, including whether it is public, shared with followers, or kept private.

Content Data

  • Photos, videos you upload
  • Posts, comments, reactions
  • Trip plans and travel logs
  • Chat messages (stored securely and accessible only to intended recipients and for moderation in case of abuse reports)

Technical Data

  • IP address and device identifiers
  • Browser type and OS version
  • App version, crash logs
  • Session timestamps
03

Legal Basis for Processing (GDPR Art. 6)

We only process your personal data when we have a lawful basis to do so under GDPR Article 6:

ContractProcessing necessary to provide the services you signed up for (account, trips, chat).
ConsentLocation sharing, marketing emails, optional analytics. You may withdraw at any time.
Legitimate InterestFraud prevention, platform security, and improving service quality.
Legal ObligationCompliance with applicable laws, tax obligations, and law enforcement requests.
04

How We Use Your Data

Provide, operate, and maintain the Sociatrip platform
Show your location on the traveler map and enable check-ins
Connect you with nearby travelers and trip participants
Process payments and manage premium subscriptions
Detect fraud, spam, and ensure platform safety
Analyze usage patterns to improve our service (anonymized)
Send transactional and, with consent, marketing emails
Comply with legal obligations and respond to lawful requests
05

Payments & Billing

All payments on Sociatrip are processed securely through third-party payment providers such as Stripe.

We do not store or have access to full credit card details. All payment information is handled directly by the payment processor in compliance with PCI-DSS security standards.

Billing data (such as transaction IDs and subscription status) may be stored for accounting, fraud prevention, and applicable tax or legal obligations.

For information on subscription cancellations and refunds, please refer to our Terms & Conditions , which contain the full Refund and Cancellation Policy.

When completing a Premium subscription, you explicitly consent to immediate service activation and acknowledge the waiver of your right of withdrawal pursuant to Art. 59(a) of EU Directive 2011/83/EU. This consent, together with a timestamp, is recorded at the time of purchase and retained for the duration required by applicable law.

06

Location Data

Important: Your location may be visible to other Sociatrip users when you enable location sharing or create public check-ins.

We use your location data to show nearby travelers, enable check-ins, and populate your trip timeline. Precise GPS location is collected only when you grant permission. You can revoke this permission at any time in your device settings or account preferences.

Location data is never sold to advertisers. It may be shared with mapping providers (Google Maps, Mapbox) solely to render maps within the app.

07

Data Sharing & Third Parties

We do not sell your personal data. We may share it with:

RecipientPurposeSafeguard
Stripe (Payment Processor)Payment processing and subscription managementStripe (Payment Processor), PCI-DSS compliant infrastructure
Google MapsMap renderingEU SCCs
MapboxMap tiles & geocodingEU SCCs
Firebase / GCPHosting & push notif.EU Data Processing Addendum
Analytics provider (e.g. Google Analytics or equivalent)Aggregated usage metricsAnonymized data where possible, EU SCCs
Law enforcementLegal obligation onlyLegal obligation (Art. 6.1.c)
08

Data Retention

We keep your data only as long as necessary for the purposes described in this policy:

Account dataUntil account deletion + 30 days
Location & check-in dataUntil you delete the content
Chat messagesUntil deleted by either party
Billing & payment records10 years (EU tax law)
Technical logs90 days (rolling)

After account deletion, anonymized aggregate data may be retained indefinitely for analytics.

09

Data Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

  • All data is transmitted over HTTPS (TLS encryption)
  • Passwords are securely hashed and never stored in plain text
  • Access to personal data is restricted to authorized personnel only
  • Infrastructure is hosted on secure cloud providers with industry-standard protections

While we take strong security measures, no system can be 100% secure.

10

Cookies & Tracking

We use cookies and similar technologies to keep you logged in, remember preferences, and understand how the platform is used. You can manage cookie preferences through your browser settings or our in-app privacy controls.

Essential
Functional
Analytics
Marketing
11

Your Rights (GDPR)

As an EU/EEA resident you have the following rights under GDPR:

Right of Access

Obtain a copy of your personal data we hold (Art. 15).

Right to Rectification

Correct inaccurate or incomplete data (Art. 16).

Right to Erasure

Request deletion of your data ("right to be forgotten") (Art. 17).

Right to Restrict

Limit how we process your data in certain circumstances (Art. 18).

Right to Portability

Receive your data in a machine-readable format (Art. 20).

Right to Object

Object to processing based on legitimate interests (Art. 21).

To exercise any of these rights, email us at info@sociatrip.com. We respond within 30 days as required by GDPR Art. 12.
12

International Data Transfers

Sociatrip may transfer your data outside the EU/EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions.

13

Children's Privacy

Sociatrip is not directed at children under under the minimum age required by applicable law (14 in Italy). We do not knowingly collect data from minors. If you believe a child has provided us data, contact us immediately.
14

Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via an in-app notification at least 14 days before changes take effect. Your continued use of Sociatrip after the effective date constitutes acceptance of the updated policy.

15

Contact & Data Protection

Privacy and data protection requests can be sent to the same address and will be handled with priority.

General supportinfo@sociatrip.com

You also have the right to lodge a complaint with your national data protection authority. In Italy: Garante per la protezione dei dati personali.

This service is operated by an individual developer based in Italy. No company entity is currently registered.

Also read our Terms & Conditions

Rules of use, restrictions, payments, and your obligations on Sociatrip.

Read Terms
Home