Next
🏨 Hotel, attraction or tour guide? You have your own portalTourism providers sign inOpen a provider account
TripShare
💬

Privacy policy

Version 2026-09 · Demo template — have counsel review before launch.

This policy explains what personal data TripShare Rewards (sharetrip.site) collects, why, and your rights. Data controller: Meir Gilady, Israel (contact via the contact page). It is written to comply with the Israeli Protection of Privacy Law (including Amendment 13, 2025) and, for visitors from the EU/UK, the GDPR. Version 2026-09.

What we collect

Account: email, display name, handle, language, password (stored as a one-way hash). Content: trips, places, scores, tips and photos you publish. Proof of travel: vouchers, receipts and tickets (visible to moderators only). Hotel contacts you give us (email, website) so we can invite the hotel. Contact-form messages. Technical: request logs with a request id, browser type and a salted, rotating hash of your IP address.

Attribution data

When you click a booking link we store an opaque token, the trip and place, a referrer category, your consent state and the IP hash, deleted after 30 days. Raw IP addresses are never stored. This is needed to attribute a booking to the traveler who recommended it.

Why we process data (legal bases)

To run the service and your account (contract); to attribute and pay commissions (contract, legal obligation for financial records); to invite hotels that travelers recommended (legitimate interest of the traveler and the platform); security, fraud prevention and moderation (legitimate interest); analytics only with your consent.

Sharing

Hotels and partners receive the recommendation, the traveler's display name and the trip link — never your email or documents. Service providers that host and send for us: Hostinger (servers and email, EU/US), Google (maps, voice recognition when you use the microphone), Anthropic (the chat assistant processes the text you type; it is not used to train models). We do not sell personal data.

Retention

Account data for as long as the account exists and 30 days after deletion; ledger, invoices and audit records for the period required by law (7 years in Israel); IP hashes 30 days; unconverted click tokens 180 days; contact messages 12 months.

Your rights

Access, correction, export and deletion from the dashboard or by contacting us; objection to processing based on legitimate interest; withdrawal of consent at any time; the right to complain to the Israeli Privacy Protection Authority or your local supervisory authority. We answer within 30 days.

Security

HTTPS everywhere, hashed passwords, role-based access, audit log, immutable financial ledger, documents visible only to moderators, backups encrypted at rest.

Cookies

Essential cookies keep you signed in and remember your language and consent. Analytics runs only after you allow it. See the cookie policy.

Children

The service is for adults (18+). We do not knowingly collect data of minors; contact us and we will delete it.