Privacy Policy
How Trustpanion collects, uses and protects your personal data across its three markets.
1. Who is responsible for your data
1.1. The data controller is JurisChain Limited, a company registered in England and Wales (Companies House No. 15561727), trading as "Trustpanion". Registered office: Flat 15, Empire House, 6 Thurloe Place, London, SW7 2RU, United Kingdom. 1.2. Privacy contact: team@trustpanion.com.
2. Who and what this Policy covers
2.1. This Policy covers the Trustpanion websites and apps in our three markets — United Kingdom (/uk), Chile (/cl) and United States (/us) — for Clients, Companions and visitors. 2.2. The laws that apply to you depend on your market: • UK: UK GDPR and the Data Protection Act 2018, as amended (including by the Data (Use and Access) Act 2025), plus PECR for cookies. • Chile: Ley 19.628 on the protection of private life — and, from 1 December 2026, Ley 21.719, which substantially reforms Chilean data-protection law and creates the Agencia de Protección de Datos Personales. This Policy is written to anticipate that standard. • US (California): the California Consumer Privacy Act as amended by the CPRA ("CCPA"), including its notice-at-collection requirements (Section 13).
3. What we collect
We collect only what each feature needs: • Account data — name, email, phone number, password (hashed), date of birth, market/country, language. • Verification data (the trust ladder): • Level 1 (live selfie): runs entirely on your device. The selfie and any biometric data derived from it are processed locally and are never uploaded to, received by, or stored on our servers. We record only the outcome (verified yes/no) and its date. • Level 2 (identity document): our verification provider Persona checks your official ID. We receive and store the outcome and verified data points (e.g. legal name, age/date of birth), not the raw document images. Persona processes the document under its own certified processes as our processor. • Level 3 (background check, optional; mandatory for older-adult companionship): we store the reference/certificate number and the outcome only — never the certificate. This may constitute criminal-offence data, which we handle with additional safeguards. • Profile and Booking data — profile text and photos, offers, availability, prices, Booking requests and confirmations, session start/end codes and timestamps, reviews. • Messages — in-app messages, which are moderated (automated screening, with human review of flagged content) for safety and enforcement of the platonic rule. • Safety data — share-your-plan details you choose to send to a trusted contact; reports and their content; block-list entries (kept as hashed email/phone identifiers, not raw values); enforcement history. • Technical data — device/browser type, IP address, approximate country (to route you to /uk, /cl or /us), log and diagnostic events, essential cookies (see the Cookie Policy). • Support data — your messages to team@trustpanion.com and our replies. We do not collect: your verification selfie or biometric templates (they stay on your device), raw ID documents, background-check certificates, precise geolocation, or advertising identifiers.
4. Why we use your data, and on what legal basis
We use your data for these purposes, on these legal bases (UK GDPR bases shown; the Chile/US equivalent applies): • Create and run your account; provide Bookings, messaging, reviews — data: account, profile, Booking, messages — basis: contract (Art. 6(1)(b)). • Identity and age verification — data: verification — basis: contract; legal obligation where applicable; legitimate interests (platform integrity). • Background checks for older-adult companionship — data: Level 3 outcome + reference — basis: legitimate interests (protecting vulnerable adults); Art. 10 condition. • Safety: moderation, block lists, reports, session codes, share-your-plan — data: messages, safety, Booking — basis: legitimate interests (user safety, fraud/abuse prevention); legal obligation where applicable. • Transactional email (confirmations, safety notices) via Resend — data: account, Booking — basis: contract; legitimate interests. • Service operation, debugging, security — data: technical — basis: legitimate interests (running a secure service). • Legal compliance, responding to authorities, defending claims — data: as required — basis: legal obligation; legitimate interests. • Future: in-app payments and commissions (Stripe/Payku) — data: to be described before launch — basis: contract. We do not use your data for third-party advertising, we do not sell it, and our only analytics is a privacy-preserving, cookieless tool that collects no personal data (Cookie Policy).
5. Special-category and sensitive data
5.1. Biometrics: by design, facial verification happens on your device only. Trustpanion never receives or stores biometric data. If we ever change this, we will update this Policy and ask for the consents the law requires first. 5.2. Criminal-offence data (Level 3): minimised to reference + outcome, restricted access, never published. See Section 3 marker. 5.3. CPRA sensitive personal information: the verified data points from Level 2 may qualify. We use sensitive personal information only for the purposes permitted by the CCPA (providing the service, security, verification) and do not use it to infer characteristics; on that basis a "Limit the Use of My Sensitive Personal Information" link is not required.
6. Who we share data with
6.1. Processors (subprocessors) that run the service: • Supabase — database, authentication, storage. Cloud hosting (EU/US regions); transfers safeguarded by the UK Addendum/SCCs under our data-processing agreement. • Persona — identity verification (Level 2). United States; transfers safeguarded by the UK IDTA/Addendum and SCCs. • Resend — transactional email. United States; transfers safeguarded by the UK IDTA/Addendum and SCCs. • Stripe (future, UK) / Payku (future, Chile) — payment processing when launched. Will be added to this table before activation. Each provider is bound by a data-processing agreement with us. 6.2. Other Users — the necessary minimum: your profile is visible to Users as you configure it; a confirmed Booking shares the plan details between its two participants; your trusted contact receives what you choose to share via share-your-plan. 6.3. Institutional Programmes — where you participate in an older-adult programme, we share with the institution only what the programme agreement requires (e.g. confirmation that visits occurred, safeguarding reports). 6.4. Authorities and legal — where the law requires, to respond to valid legal process, or where necessary to protect someone's life or safety (documented case-by-case). 6.5. Business transfer — if the Trustpanion business is transferred to a successor entity, your data transfers with it under this Policy's protections; we will give notice. 6.6. We do not sell personal data, and we do not "share" it for cross-context behavioural advertising (CCPA meaning). We have not done so in the preceding 12 months.
7. International transfers
Our controller is UK-based and providers may process data in other countries (notably the US). Where personal data leaves the UK, Chile or the US, we use lawful transfer mechanisms — for the UK, the IDTA or the UK Addendum to the EU SCCs, or an adequacy determination; for Chile, the conditions of 19.628 and, from December 2026, Ley 21.719's transfer regime.
8. How long we keep data
We keep data only as long as needed: • Account and profile — while the account is active; deleted on account deletion except as below. • Verification outcomes (Levels 1–3) — while the account is active; deleted with the account. • Bookings, session codes, reviews — while the account is active; reviews of you may remain in anonymised form. • Messages — while the account is active; flagged-content records kept as below. • Safety records: reports, enforcement history, hashed block-list entries — retained after account deletion for platform safety (keeping removed people out), for up to 5 years. • Legal/accounting records — as required by law. • Support correspondence — 24 months. When you delete your account, your profile, Bookings and messages are removed from live systems; residual backup copies are purged on backup rotation.
9. Security
Row-level security and least-privilege access controls; encryption in transit; hashed credentials and hashed block-list identifiers; on-device processing for the most sensitive step (your selfie); no anonymous profiles; staff access on a need-to-know basis; logging of administrative access. If a breach creates risk to you, we will notify you and the relevant regulator as the law requires (including the 72-hour rule under UK GDPR).
10. Your rights
10.1. Everyone: contact team@trustpanion.com to exercise rights. We verify it's you (proportionately — usually via your account email), respond within the legal deadline (one month in the UK, extendable as allowed; 45 days in California, extendable; Chilean statutory terms), and never charge unless the law permits it for excessive requests. You will not be discriminated against for exercising rights. 10.2. United Kingdom (UK GDPR): access; rectification; erasure; restriction; portability; objection (including to legitimate-interests processing); withdrawal of consent. We also operate the complaints procedure introduced by the Data (Use and Access) Act 2025 — complain to us first if you wish (acknowledged within 30 days) — and you can always complain to the ICO (ico.org.uk). 10.3. Chile (Ley 19.628; Ley 21.719 from 1 Dec 2026): access, rectification, cancellation/deletion, and opposition ("derechos ARCO"); from the entry into force of Ley 21.719, additionally portability and the right to complain to the Agencia de Protección de Datos Personales, alongside judicial remedies (habeas data). 10.4. California (CCPA/CPRA): right to know/access; delete; correct; portability; opt out of sale or sharing (we do not sell or share); limit use of sensitive personal information (see 5.3); non-discrimination. You may use an authorised agent. We honour Global Privacy Control signals where required — given we do not sell or share data, GPC does not change our processing. Requests: team@trustpanion.com. 10.5. If we refuse a request we will say why and how to challenge that decision.
11. Children
Trustpanion is strictly 18+. We do not knowingly process children's data; verification is designed to prevent under-18 accounts, and any found are removed (with data deleted per Section 8).
12. Automated decision-making
• The Level 1 face-match runs on your device; we receive only the result. If it fails, you can retry or contact support — a human reviews disputed outcomes. • Persona's identity checks are largely automated; failed or disputed checks can be escalated to human review via support. • We make no fully automated decisions producing legal or similarly significant effects without human review.
13. California notice at collection (summary)
(summary) Whether we collect each CCPA category, and whether we sell or share it: • Identifiers (name, email, phone, IP) — collected: yes; sold/shared: no. • Sensitive PI (verified legal name/DOB from ID; account log-in) — collected: yes (see 5.3); sold/shared: no. • Commercial information (Bookings) — collected: yes; sold/shared: no. • Internet/network activity (logs, essential cookies) — collected: yes; sold/shared: no. • Approximate (coarse) geolocation — country only — collected: yes; sold/shared: no. • Audio/visual (profile photos) — collected: yes; sold/shared: no. • Biometric information — collected: no (on-device only, never received); sold/shared: no. • Inferences for profiling/ads — collected: no; sold/shared: no. Purposes and retention: Sections 4 and 8. Full CCPA rights: Section 10.4.
14. Cookies
Only essential cookies at this stage (sign-in/session, security, country/language routing). No advertising cookies. For traffic measurement we use a cookieless, privacy-preserving analytics tool that collects no personal data. Details, and what happens if this ever changes (consent first), are in the Cookie Policy.
15. Changes to this Policy
We will update this Policy as the product evolves (for example, when in-app payments launch) and will give reasonable advance notice of material changes in-app or by email, with the "effective date" line kept current at the top.
16. Contact and complaints
JurisChain Limited, trading as Trustpanion — Flat 15, Empire House, 6 Thurloe Place, London, SW7 2RU, United Kingdom · team@trustpanion.com Regulators: ICO (UK, ico.org.uk) · Agencia de Protección de Datos Personales (Chile, from Dec 2026; courts under Ley 19.628 meanwhile) · California Privacy Protection Agency / California Attorney General (US).