travelism

Privacy Policy

Effective Date: August 27, 2026

Last Updated: August 27, 2026

Version: 1.1

Travelism is operated by Nalagamage Nayanajith Dilshan, an individual operator based in Sri Lanka.

This Privacy Policy explains how Travelism collects, uses, stores, shares, protects, and deletes information when you access or use the Travelism mobile application, website, and related services.

By using Travelism, you acknowledge the practices described in this Privacy Policy.

1. Who We Are

Travelism is a travel-focused social platform that allows users to create profiles, share travel experiences, communicate with other users, plan trips, collaborate on travel activities, follow profiles, and use personal or business verification features.

For privacy-related questions, contact:

Privacy: privacy@travelism.app

Support: support@travelism.app

Legal: legal@travelism.app

Postal address:

Nalagamage Nayanajith Dilshan

No. 04, Diyawiddagama

Nawamedagama

Ampara District, 32120

Sri Lanka

2. Minimum Age

Travelism is intended only for users who are at least 18 years old.

We do not knowingly collect personal information from anyone under 18. If we learn that a person under 18 has created an account or provided personal information, we may suspend the account and delete the information where appropriate.

A parent, guardian, or other person who believes that an underage user has provided information to Travelism may contact privacy@travelism.app.

3. Information We Collect

The information we collect depends on the features you use.

3.1 Account and authentication information

When you create or access a Travelism account, we may collect:

  • Email address
  • Password-related authentication records
  • Account identifiers
  • Login and session information
  • Email-verification status
  • Authentication-provider identifiers
  • Account creation and login timestamps
  • Account status and lifecycle information

Travelism does not directly store your plain-text password. Authentication credentials are processed through our authentication service providers.

3.2 Social sign-in information

When you choose to sign in using Google, Facebook, Apple, or another supported authentication provider, we may receive information permitted by that provider and authorized by you, such as:

  • Name
  • Email address
  • Profile image
  • Provider-specific account identifier
  • Authentication tokens or confirmation data

The information received depends on the provider, your provider settings, and the permissions you approve.

3.3 Personal profile information

You may provide information for your Travelism profile, including:

  • First and last name
  • Username
  • Profile photograph
  • Cover photograph
  • Biography
  • Country, city, or general location
  • Travel interests
  • Languages
  • Website or social links
  • Other profile information you choose to display

Some profile information may be visible to other Travelism users or to the public, depending on the feature and your account settings.

3.4 Business profile information

If you create or manage a business profile, we may collect:

  • Business name
  • Business username
  • Business description
  • Logo and cover image
  • Business category
  • Contact information
  • Website and social links
  • Business address or service location
  • Ownership information
  • Business verification information
  • Store or service-related information

Business profile information is generally intended to be publicly visible.

3.5 Personal verification information

When you apply for personal identity verification, we may collect sensitive personal information, including:

  • Full legal name
  • Date of birth
  • Residential country
  • Residential address
  • City, state, province, or postal code
  • Identity-document type
  • Identity-document issuing country
  • Document expiry date
  • Photographs or scans of identity documents
  • Selfie or identity-confirmation images
  • Verification application status
  • Review decisions
  • Rejection or change-request categories
  • Verification audit and processing records
  • File hashes and technical evidence-processing information

Verification documents may contain additional information visible on the document you submit.

Verification evidence is stored separately from ordinary public profile content and is not displayed publicly. Other users may only see an approved verification badge or status where applicable.

3.6 Business verification information

When a business applies for verification, we may collect:

  • Business registration details
  • Ownership or authorization information
  • Business addresses and contact details
  • Registration certificates
  • Licences or supporting records
  • Tax or government registration information
  • Authorized representative information
  • Encrypted verification drafts
  • Submitted documents
  • Review decisions and audit records

Only the verification status or badge intended for public display will be shown publicly.

3.7 Posts, Moments, statuses, and other content

When you create or interact with content, we may collect:

  • Post captions
  • Photographs and videos
  • Moments or temporary status content
  • Hashtags
  • Destinations and location descriptions
  • Tagged profiles
  • Comments and replies
  • Likes and reactions
  • Saved or archived content
  • Sharing activity
  • Content visibility and audience settings
  • Content creation and modification timestamps

Content you publish may be visible to other users or the public, depending on the selected audience and feature.

3.8 Social relationships and activity

We may collect information about how you interact with other profiles, including:

  • Profiles you follow
  • Follow requests
  • Accepted or rejected requests
  • Followers and following lists
  • Profile visits or exploration activity
  • Tagged-profile requests
  • Blocks and unblocks
  • Content reports
  • Likes, comments, reactions, saves, and shares

3.9 Chat and communication information

When you use Travelism messaging features, we may collect:

  • Chat messages
  • Photographs, videos, and files sent in chats
  • Message timestamps
  • Delivery and seen status
  • Typing status
  • Chat participants
  • Archived, muted, blocked, or deleted-chat settings
  • Message reports
  • Limited identity snapshots required to display conversation participants

Messages are intended for the participants in the conversation. Travelism personnel may access reported content where necessary for safety, moderation, support, or legal compliance.

3.10 Trip and collaboration information

When you use trip-planning features, we may collect:

  • Trip title and description
  • Destination and country
  • Start and end dates
  • Cover images
  • Itinerary items
  • Trip activities
  • Notes
  • Packing lists
  • Collaborators and collaborator roles
  • Invitations and invitation responses
  • Trip-chat information
  • Accommodation or travel preferences
  • Public or private trip settings
  • Trip changes, versions, and activity records

Trip information may be shared with collaborators or displayed publicly when you choose a public setting.

3.11 Location information

Travelism may collect locations that you manually enter, select, tag, or include in content, such as:

  • Country
  • City
  • Destination
  • Place name
  • Trip location
  • Business location

Travelism uses continuous or background device-location tracking only when you choose to start Live Location sharing in a chat conversation. This feature is off by default, requires your explicit action to turn on, and can be stopped at any time by you or by leaving the conversation.

If additional device-location features are introduced later, Travelism will request the relevant device permission and provide any required disclosure before collecting that information.

3.12 Camera, photo, video, and file information

When you choose to upload or capture media, Travelism may access:

  • Selected photographs
  • Selected videos
  • Camera-captured images
  • Files selected for upload
  • Image or video metadata
  • Temporary media files created during cropping or compression
  • File type, size, and upload status

Travelism accesses these files only when you select or capture them for a Travelism feature.

You should remove sensitive information from photographs, videos, documents, or file metadata before uploading them when that information is not necessary.

3.13 Push-notification and device information

When notifications are enabled, we may collect:

  • Firebase Cloud Messaging token
  • Device or installation identifier
  • Device platform
  • App version
  • Build number
  • Notification-delivery status
  • Notification interactions
  • Notification preferences

Notification content may include limited information about activity on Travelism, such as a username, interaction type, message alert, or content reference.

Notification previews may be visible on your device lock screen depending on your operating-system settings.

3.14 Support, reports, and safety information

When you contact support or submit a report, we may collect:

  • Email address
  • Profile or user identifier
  • Report category
  • Description of the issue
  • Reported account, post, comment, message, or other content
  • Screenshots and attachments
  • Device and app information
  • Communication history
  • Moderation decisions
  • Administrative notes
  • Action taken
  • Fraud, abuse, or security indicators

3.15 Technical and automatically collected information

Travelism and its service providers may automatically process limited technical information, including:

  • IP address
  • Device platform
  • App version and build number
  • Authentication and session identifiers
  • Request timestamps
  • Server and network logs
  • Error information
  • File paths and upload records
  • Security and abuse-prevention information
  • Service-performance information

Travelism does not currently use third-party advertising or behavioral-advertising SDKs.

4. How We Use Information

We may use information to:

  • Create and maintain accounts
  • Authenticate users
  • Operate personal and business profiles
  • Display posts, Moments, comments, trips, and other content
  • Enable follows, messaging, collaboration, and social interactions
  • Process personal and business verification applications
  • Display verification badges
  • Deliver push notifications
  • Provide customer support
  • Investigate reports and complaints
  • Detect spam, fraud, abuse, impersonation, and security threats
  • Enforce our Terms of Service and Community Guidelines
  • Maintain platform security and availability
  • Improve app reliability and user experience
  • Comply with legal obligations
  • Establish, exercise, or defend legal claims
  • Protect Travelism, its users, and the public

We will not use verification documents for advertising.

5. How Information Is Shared

5.1 With other users and the public

Information that you publish or choose to display may be shared with other users or the public, including:

  • Username
  • Display name
  • Profile and cover images
  • Biography
  • Public business information
  • Posts and media
  • Comments and reactions
  • Public trips
  • Verification badges
  • Following or follower information
  • Other publicly visible activity

You should not publish information that you do not want others to access, copy, share, screenshot, or redistribute.

5.2 With trip and chat participants

Information may be shared with users participating in:

  • Direct chats
  • Group or trip chats
  • Trip collaborations
  • Shared packing lists
  • Itineraries
  • Invitations
  • Other collaborative features

5.3 With service providers

We use service providers that process information on our behalf, including:

Supabase

Used for authentication, database hosting, file storage, server-side functions, and realtime app features.

Google Firebase

Used for push-notification delivery through Firebase Cloud Messaging.

Google

Used when a user chooses Google authentication or other Google-supported features.

Meta Platforms

Used when a user chooses Facebook authentication.

Apple

Used when Sign in with Apple is available and selected.

Resend or configured email-delivery providers

Used to deliver authentication, verification, password-reset, support, and service-related emails.

Service providers may process information in countries other than your country of residence.

We may disclose information when reasonably necessary to:

  • Comply with applicable law, court orders, or lawful government requests
  • Investigate fraud, abuse, threats, or illegal activity
  • Protect the rights, property, and safety of Travelism, users, or others
  • Enforce our Terms of Service and Community Guidelines
  • Respond to emergencies involving a risk of harm

5.5 Business transfers

If Travelism is involved in a merger, acquisition, restructuring, financing, transfer, or sale of all or part of the service, information may be transferred as part of that transaction.

Any successor will be required to handle personal information consistently with applicable privacy obligations.

We may share information for another purpose when you specifically authorize or request it.

6. Public Content and User Responsibility

Travelism includes user-generated content and social features.

Information shared publicly can be:

  • Viewed by others
  • Copied or downloaded
  • Shared outside Travelism
  • Indexed or cached
  • Captured in screenshots
  • Reposted by other users

Travelism cannot control copies independently created or distributed by other people.

Do not upload identity documents, payment information, passwords, private addresses, or other sensitive information to public posts, comments, profile fields, or chats unless the feature specifically requires it.

7. Data Storage and International Processing

Travelism uses cloud-service providers to store and process information.

Your information may be processed in Sri Lanka, the United Arab Emirates, Singapore, the United States, or other countries where Travelism or its service providers operate infrastructure.

Data-protection laws in those countries may differ from those in your country.

Where required, we will use reasonable safeguards for international data processing and transfers.

8. Data Security

We use reasonable technical and organizational safeguards designed to protect information, including:

  • Authentication and access controls
  • Private storage for sensitive verification evidence
  • Encrypted network communications
  • Restricted administrative access
  • Database security rules
  • Audit and processing records
  • File validation and processing checks
  • Account-lifecycle controls
  • Security monitoring and abuse prevention

No electronic transmission or storage system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

Users are responsible for protecting their login credentials and devices.

9. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention depends on the type of information and may include:

  • Account and profile information: retained while your account remains active.
  • Public content: retained until you delete it, it expires, or your account is deleted, subject to limited exceptions.
  • Messages: retained while needed to provide messaging functionality or until deleted in accordance with available controls.
  • Trips and collaborations: retained until deleted by an authorized participant or through account deletion.
  • Notification tokens: retained while the device registration remains active or until the token is removed or becomes invalid.
  • Verification applications and evidence: retained while needed to process verification, prevent fraud, maintain security, respond to disputes, and comply with legal obligations.
  • Reports and moderation records: retained as necessary to investigate abuse, protect users, prevent repeat violations, and establish or defend legal claims.
  • Support and bug-report information: retained while needed to resolve the issue and maintain service records.
  • Technical and security logs: retained for a limited period appropriate to security, diagnostics, and fraud prevention.
  • Backups: deleted information may remain temporarily in protected backups until those backups are overwritten or deleted.

We may retain certain information after account deletion where reasonably necessary for:

  • Legal or regulatory compliance
  • Fraud and abuse prevention
  • Safety and security
  • Dispute resolution
  • Enforcement of agreements
  • Protection of legal rights
  • Financial, audit, or administrative obligations

When information no longer needs to identify you, we may anonymize it instead of deleting it.

10. Account Deactivation and Deletion

You may initiate account deletion through the account settings available in Travelism.

You may also request account deletion using the account-deletion resource at:

https://travelism.app/account-deletion

or by contacting:

support@travelism.app

We may ask you to verify that you own the account before completing a deletion request.

When an account-deletion request is completed, Travelism will delete or anonymize personal information associated with the account unless retention is reasonably required for legal, safety, fraud-prevention, dispute, or regulatory purposes.

Account deletion may include:

  • Disabling access to the account
  • Removing or anonymizing profile information
  • Removing personal and business profiles owned by the account
  • Removing or anonymizing posts and other user-generated content
  • Removing stored media where applicable
  • Removing device-notification registrations
  • Ending active sessions
  • Removing verification evidence when no longer legally or operationally required

Content independently copied, downloaded, screenshotted, or shared by other users may remain outside Travelism’s control.

We may use a short deletion-processing or recovery period to prevent accidental or unauthorized deletion. The app will communicate the applicable deletion date or status where this feature is provided.

Temporary account deactivation is separate from permanent deletion.

11. Your Choices and Rights

Depending on your location, you may have rights to:

  • Access personal information
  • Correct inaccurate information
  • Delete information
  • Delete your account
  • Object to or restrict certain processing
  • Withdraw consent
  • Request a copy of certain information
  • Complain to an appropriate data-protection authority

You may also:

  • Edit profile information in the app
  • Delete eligible posts or content
  • Control some audience settings
  • Block other profiles
  • Manage notification permissions through device settings
  • Revoke Google, Facebook, or Apple access through the relevant provider
  • Contact us with a privacy request

To exercise a privacy right, contact privacy@travelism.app.

We may request reasonable information to confirm your identity and protect your account.

12. Device Permissions

Travelism may request device permissions only when needed for a feature, including:

  • Camera access
  • Photo or media-library access
  • File access
  • Notification permission
  • Vibration or haptic functionality
  • Microphone access
  • Contacts access
  • Precise and background location access
  • Calendar access
  • Bluetooth access
  • Biometric authentication (Face/Touch ID or fingerprint)

You may deny or revoke permissions through your device settings. Some features may not work without the relevant permission.

Microphone access is used only when you record or send a voice message, or join a voice or video call. Contacts access is used only if you choose to search for people you know on Travelism. Precise and background location access is used only when you choose to start Live Location sharing in a chat, or add a location to a post, Moment, or trip. Calendar access is used only if you choose to add a trip date to your device calendar. Bluetooth access is used only to route audio during a voice or video call. Biometric authentication is used only if you enable App Lock; verification happens through your device's own operating system and Travelism does not receive or store your biometric data. Travelism does not currently use advertising-tracking permission for its core functionality.

Travelism may contain links to third-party websites, profiles, booking resources, social platforms, or services.

This Privacy Policy does not govern third-party services. Their privacy practices are controlled by their own policies.

Review the privacy policy of a third-party service before providing information to it.

14. No Sale of Personal Information

Travelism does not currently sell personal information.

Travelism does not currently use personal information for third-party behavioral advertising.

If this practice changes, we will update this Privacy Policy and provide any legally required notice or choice before the change takes effect.

15. Future Commercial Features

The current version of Travelism does not offer active paid subscriptions, payment processing, or paid booking transactions.

If Travelism introduces payments, subscriptions, bookings, commissions, promoted content, or other paid services, this Privacy Policy will be updated to explain:

  • Payment information processed
  • Payment providers used
  • Transaction and booking records
  • Fraud-prevention processing
  • Financial-record retention
  • Relevant user choices and rights

Travelism does not intend to store complete payment-card details directly. Payment details will ordinarily be processed by authorized payment providers.

16. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • Travelism features change
  • New providers or technologies are introduced
  • Data practices change
  • Legal or regulatory requirements change
  • Safety and security practices are updated

The updated policy will show a revised effective date, last-updated date, and version number.

Where required, we will provide additional notice through the app, website, email, or another appropriate method.

Continued use of Travelism after an updated policy becomes effective constitutes acknowledgment of the updated policy, except where separate consent is legally required.

17. Contact Us

For privacy questions, rights requests, complaints, or account-deletion assistance, contact:

Privacy: privacy@travelism.app

Support: support@travelism.app

Legal: legal@travelism.app

Operator:

Nalagamage Nayanajith Dilshan

No. 04, Diyawiddagama

Nawamedagama

Ampara District, 32120

Sri Lanka

Website: https://travelism.app/