Trickle privacy

Privacy Policy

This policy explains how Trickle handles information when you use our mobile app, website, and people-powered delivery services. We collect what we need to help a parcel follow the journey, keep users safe, and support payments and disputes.

Last updated: 5 August 2026

1. Overview

Trickle connects people who need to send parcels with travelers already going along a route. Trickle is a coordination platform; the sender and traveler remain responsible for the accuracy of their information, the parcel, and the agreed handoff.

By using Trickle, you acknowledge this policy. Where the law requires consent, we will request it separately and you can change your choice where the relevant feature allows.

2. Information we collect

Account information: phone number, OTP verification records, name, email address, date of birth, gender where provided, profile photo, referral information, and identity-verification details.

Delivery information: parcel descriptions, pickup and drop locations, route coordinates, travel dates, delivery deadlines, parcel images or attachments, agreed prices, handoff confirmations, ratings, reports, and support history.

Messages and content: chat messages, attachments, shared location pins, reports, and other content you submit through the service.

Payment and payout information: payment status, transaction identifiers, refund information, payout status, and bank-account details needed for traveler payouts. Payment credentials are handled by our payment provider where possible.

Device and technical information: device model, operating system, app version, country, device identifiers, IP address, log data, crash information, and push-notification token.

Location and address information: location or route information that you enter or choose, and device location when you grant permission for address suggestions or nearby traveler matching.

Support information: messages, attachments, contact details, and information needed to investigate a question, payment issue, safety report, or dispute.

3. How we use information

  • Create and secure accounts using phone verification and session controls.
  • Suggest routes, match parcel requests with travel plans, and coordinate handoffs.
  • Process delivery payments, refunds, traveler payouts, and payment support.
  • Send transactional notifications about OTPs, requests, matches, payments, handoffs, and support.
  • Verify identity, prevent fraud, investigate abuse, and protect users and parcels.
  • Operate chat, file storage, customer support, ratings, reports, and dispute handling.
  • Diagnose crashes, maintain reliability, measure service performance, and improve the product.
  • Meet legal, accounting, tax, regulatory, and law-enforcement obligations.

We do not use deleted-account information for marketing, personalization, or product recommendations during the retention window.

4. How we share information

We share information only as needed to provide the service, protect users, or meet legal obligations. Depending on the feature, recipients may include:

  • Other Trickle users involved in the same parcel, travel plan, match, or conversation. We show only information needed for coordination and safety.
  • Service providers for hosting, databases, file storage, email, SMS, push notifications, maps and address search, analytics or crash reporting, and customer support.
  • Razorpay or another approved payment provider for physical delivery payments, refunds, and traveler payouts.
  • Professional advisers, insurers, authorities, or law enforcement when necessary for a dispute, safety incident, fraud investigation, legal claim, or legal obligation.
  • A successor entity if Trickle is involved in a merger, acquisition, financing, or asset transfer, subject to appropriate confidentiality protections.

We do not sell personal information. We do not share personal information for third-party advertising tracking unless we first update this policy and obtain any consent required by law.

6. What we store and who can access it

Trickle stores account and operational records in its backend systems, including profile information, authentication and device-session records, parcel and travel records, messages and attachments, support and safety records, payment status, provider transaction identifiers, and audit events. Raw card credentials are not intended to be stored by Trickle and are handled by the approved payment provider.

Access is role-based and limited to the user, the other participants who need information for the relevant delivery or travel interaction, authorized Trickle support and safety personnel, approved service providers acting on our instructions, and authorities or advisers where legally permitted or required. Staff access should be logged, limited to business need, and removed when no longer required.

We do not sell personal information. We do not provide personal information to third parties for advertising tracking. Providers may process information only to deliver the contracted service and under their own applicable terms and privacy notices.

7. Security and encryption

Production network traffic is intended to use HTTPS/TLS. Authentication tokens and device-bound sessions are protected with server-side access controls, and active sessions can be revoked. Stored information should be protected with provider encryption at rest, least-privilege access, secret management, backups with controlled access, vulnerability management, and audit logging appropriate to the risk.

Security is a shared responsibility. Keep your device updated, use a screen lock, do not share OTPs or passwords, and report suspicious activity promptly. No online service or transmission method can be guaranteed completely secure.

8. Retention and deletion

When you request account deletion, we immediately deactivate the account, revoke active sessions and notification tokens, anonymize direct profile identifiers, and purge user-owned profile files where possible.

Operational records for payments, disputes, fraud and safety, tax and payouts, parcel requests and matches, travel plans, and chat are targeted for deletion or irreversible anonymization within 30 days after account deletion. The retention schedule is described in this section.

Records under an active legal hold, dispute, fraud or safety investigation, or a longer legal or regulatory requirement may be retained for longer. We restrict those records to the relevant purpose and remove them when the hold or requirement ends.

9. Your choices, withdrawal, and rights

  • Access or update information through Account Settings where the feature is available.
  • Request account deletion from Account Settings or Support.
  • Manage notification permission in the app and your device settings.
  • Deny camera, photo, or location permissions and use an available manual fallback.
  • Withdraw permission for optional device features through the app or device settings. Withdrawal does not affect processing already completed lawfully, and a feature may stop working afterward.
  • Withdraw optional marketing or notification preferences where those controls are available. Transactional messages may still be sent when necessary for account security, delivery, payments, or support.
  • Contact us to ask about access, correction, deletion, restriction, objection, or a copy of your information, subject to applicable law.
  • Report a user, parcel, message, safety concern, or privacy issue through Support.

We may need to verify your identity before fulfilling a request. Some information may be retained or withheld where required to prevent fraud, protect another person, resolve a dispute, or comply with law.

10. Data breaches and security incidents

We maintain an incident process for suspected unauthorized access, disclosure, loss, alteration, or destruction of personal information. The process includes containment, access preservation, technical investigation, risk assessment, remediation, and documentation. We will notify affected users, regulators, or other parties when required by applicable law and within the required timeframe, and will provide practical steps where appropriate.

Report a suspected breach, account takeover, exposed personal information, or unsafe data disclosure to support@trickle.org.in. Do not include passwords, OTPs, full payment credentials, or identity-document numbers in email.

11. Security and international processing

We use access controls, authentication, encryption in transit, session revocation, provider safeguards, and operational monitoring appropriate to the information we process. No internet service can guarantee absolute security, so please protect your device and never share an OTP.

Trickle and its providers may process information in countries other than where you live. We use contractual, technical, or other safeguards required by applicable law for those transfers.

12. Children

Trickle is intended for adults and is not directed to children. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information so we can investigate and remove it where appropriate.

13. Changes to this policy

We may update this policy when our services, providers, or legal obligations change. We will update the date above and provide additional notice for material changes where required.

14. Contact us

For privacy questions, rights requests, or account-deletion support, email support@trickle.org.in. Please include enough information for us to identify your account without sending an OTP or password.