Privacy

Privacy Notice

Effective date: 14 September 2026 · Version 5. This Notice explains how Maverick Bits S.R.L. handles personal data when you visit or use Crossing Paths, including partner invitations, billing for Crossing Paths Plus (“Plus”), and the optional Gmail trip-import feature.

Usage data

Analytics

Off

We collect no new product usage from this device.

1. Who is responsible for your data

Maverick Bits S.R.L. is the controller of the personal data described in this Privacy Notice. In this Notice, “Crossing Paths”, “Maverick Bits”, “we”, “us”, and “our” refer to Maverick Bits S.R.L.

Registered office: jud. Bihor, mun. Oradea, str. Slatinei, nr. 21, bl. PB47, ap. 16, Oradea, Romania. Trade Register number: J05/2124/2022. Unique registration and tax code: 46518982. VAT number: RO46518982.

For privacy questions or to exercise your rights, contact us at contact@crossing-paths.app. This address is our direct privacy contact.

2. Scope of this Notice

This Notice explains how we collect, use, disclose, retain, and protect personal data when you visit crossing-paths.app, create or use a Crossing Paths account, submit a contact request, view or share a profile or trip, claim a partner invitation, buy or manage Plus, or connect the optional Gmail trip-import feature.

It does not govern a third-party website, application, or service that you choose to use, even if Crossing Paths links to it. Those third parties process data under their own terms and privacy notices. Where a service provider processes personal data for us, we remain responsible for choosing and instructing that provider as required by applicable law.

3. Personal data we collect

Account and authentication data includes your email address, first and last name, username, internal account identifier, authentication status and timestamps, and the information needed to secure your session. If you sign in with Google, we receive the identifiers and basic account information that Google makes available under the permissions you approve. Password authentication is handled through Supabase Auth; we do not have access to your password in plain text.

Profile and contact data may include your profile image, contact email address, Instagram username, phone number, contact-visibility choice, and the people you have restricted. Some profile fields are optional.

Friend and sharing data includes requests, accepted friendships, removals, restrictions, shared links, and the information needed to decide who may view a trip or contact channel.

Trip and place data includes the places, dates, status, and travel intention you add; your optional base and current stay; place identifiers, map coordinates and time zone associated with a selected place; and the resulting overlap records and notifications. These coordinates describe a place selected from a map service. We do not collect your device’s GPS position or continuously track your physical location.

Billing data may include the country code used to select the offer currency; Stripe customer, Checkout, price, product, subscription, invoice, charge, and payment-event identifiers; the base and local presentment currency, price, tax treatment, billing interval, and Managed Payments status; subscription, renewal, cancellation, payment-recovery, and Plus-access status; billing name, address, and tax information made available through Stripe; and billing-email delivery records. Payment-method details are entered on Stripe or Link-hosted pages and sent directly to Stripe. Crossing Paths does not receive or store your full card number or card security code on its servers.

Partner-invitation data includes the named partner and invitation identifiers, benefit type and duration, eligibility and claim outcome, claim and grant identifiers and timestamps, and first-touch partner attribution for a successful public referral. For private invitations, we retain protected credential-verification and token-history data rather than the raw distributed token. Partners do not provide us with employee or member directories through this feature.

Support data includes the email address, message, and related correspondence you provide when contacting us. Technical data may include IP address, browser and device information, request and security logs, page routes, consent choices, diagnostic details, and product-interaction events.

4. How we obtain data and what is optional

We receive data directly from you, from Google when you use its sign-in service, from Gmail when you expressly connect the import feature, from other users when they interact with you, and automatically from your browser, device, and our service providers when the service is requested or used.

We obtain partner-invitation data when you open or claim an invitation and generate the related eligibility, claim, grant, limit, and attribution records. A named partner may distribute an invitation, but does not provide us with a list confirming who is eligible. Possession of a link does not verify employment or membership.

We receive billing data from you and Stripe when you view a Plus offer, open Checkout, pay, manage or cancel a subscription, request a refund, use Link order tools, or when Stripe sends us a payment or subscription event. To select the offer's base currency, we use the country of your saved base when available and otherwise a limited country code from the request context. Managed Payments may present and charge the corresponding amount in a supported local currency. Payment-method details entered in Stripe Checkout, Link, or the Stripe customer portal go directly to Stripe.

Your name, email address, authentication information, and other fields marked as required are needed to create and secure an account. A username is required to complete your profile and use profile-based features. If you do not provide required information, we cannot create or operate the relevant account or feature. Trip, base, current-stay, profile-contact, phone, and Gmail data is optional, but the corresponding feature cannot work without the information it needs. Billing and payment information is needed only if you choose Plus or ask us to handle a related billing request.

If you provide personal data about another person, you are responsible for having a lawful basis and any permission required to do so. Please do not include unnecessary sensitive personal data in a profile, trip, or contact message.

5. Why we use personal data

We process account, profile, friend, trip, place, sharing, and notification data to create and administer your account; provide the features you request; compare intentionally shared plans; show relevant overlaps; apply visibility and restriction choices; and respond to account actions. The legal basis is performance of our contract with you and taking steps at your request before entering that contract.

We process billing data to select and display the applicable base offer currency; create and secure Stripe Checkout; provide and administer Plus; reconcile recurring payments and access; let Stripe and Link present local currency, handle applicable indirect taxes, and provide transaction support; keep subscription and access status accurate; handle failed payments, cancellations, refunds, disputes, support, and account deletion; prevent duplicate or fraudulent transactions; and maintain records required for accounting, tax, or legal claims. Depending on the purpose, the legal basis is taking steps at your request, performance of our contract, compliance with legal obligations, or our legitimate interests in reconciling payments, preventing fraud, and establishing, exercising, or defending legal claims, except where those interests are overridden by your rights and freedoms.

We process partner-invitation data to display and validate invitations, provide and administer Complimentary Plus, enforce per-account and capacity limits, prevent misuse, maintain claim and grant records, attribute public referrals, and measure program performance. We rely on taking steps at your request and performance of our contract to provide a claimed benefit, and on our legitimate interests in administering and securing the program, preventing abuse, recording public referral attribution, and measuring aggregate performance, except where those interests are overridden by your rights and freedoms. PostHog processing remains based on your analytics consent.

We process optional Gmail data to connect the mailbox you choose, identify supported reservation messages, create or suggest trips, keep imported trips updated, and let you disconnect the integration. The legal basis is performance of the feature you request. Your Google authorization is separate and may be withdrawn at any time.

We process contact requests to respond, keep an appropriate record, and protect the service and our legal position. Depending on the context, the legal basis is taking steps at your request, our legitimate interests in providing support and administering communications, or compliance with a legal obligation.

We use limited technical, security, and diagnostic data to authenticate users, prevent abuse, investigate failures, maintain availability, enforce our Terms, and establish or defend legal claims. We rely on our legitimate interests in operating a reliable and secure service, except where those interests are overridden by your rights and freedoms, and on legal obligations where applicable.

We use PostHog analytics and session replay only if you give the required analytics consent. You may refuse or withdraw that consent without losing access to the core service. Withdrawal does not affect processing that was lawful before withdrawal.

6. Profiles, visibility, and sharing

Your username, name, profile image, and profile link are public and may be viewed by people without a Crossing Paths account. If you select public contact visibility, your contact email address and Instagram username are also public. If you select friends-only visibility, those contact channels are available only to you and accepted friends. A phone number you add is available only to you and accepted friends.

Your trip plans are intended to be available only to you and eligible accepted friends. A private trip link does not override those access rules. We use base and current-stay information to determine relevant overlaps; we do not present it as live device location.

Changing a visibility setting, removing a friend, restricting someone, or deleting information changes future access through Crossing Paths. It cannot remove information that another person lawfully saw, copied, exported, or shared before access changed. Search engines or third-party caches may also take time to update after public information is removed.

7. Gmail trip imports

Gmail import is optional and begins only after you choose to connect a Gmail account and approve Google’s read-only Gmail permission. Google does not offer a narrower booking-only permission. Crossing Paths narrows that access in its own processing to supported Airbnb and Booking.com reservation messages.

The importer first uses message metadata and sender-authentication indicators to identify likely reservation messages. It temporarily reads the content of a likely message to extract reservation provider, destination, dates, and reservation status. The email content is processed in memory and is not kept as a stored copy.

We may store the connected Gmail address, Google account identifier, encrypted refresh credential, granted permissions, synchronization status, hashed message and reservation identifiers, parser outcome, and the trip details derived from a supported reservation. We do not store the email subject, email body, exact accommodation address, booking code, or raw Gmail message identifier.

Gmail data is not used for advertising, sold, used to build marketing profiles, or used to train a general-purpose artificial-intelligence model. Supported reservation details are extracted using fixed, testable rules rather than an AI model. Human access to Google user data is not permitted except where you give specific permission for a support purpose, where access is necessary for security, or where the law requires it.

Our use and transfer of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We disclose Google user data only as needed to provide or secure the visible import feature, comply with law, or in another circumstance expressly permitted by that policy.

You can disconnect Gmail from your settings. We then delete the stored mailbox credential, stop the mailbox watch, and ask Google to revoke access. Trips already imported remain in your Crossing Paths account until you delete them or delete your account.

8. Analytics and fully masked session replay

If you consent, we use PostHog EU Cloud to understand whether features work, measure product interactions, diagnose errors, and improve the service. Analytics may include a Crossing Paths user identifier, name, email address, page route, action and feature names, count ranges, browser and device details, approximate location derived from network information, IP address, and technical error information.

Session replay records interaction patterns such as page structure, navigation, clicks, scrolling, and timing. We configure replay so that displayed text, input values, images, and sensitive network information are masked or excluded in the browser before replay data is transmitted. Masking reduces the content visible in a recording, but it does not make the session anonymous because the recording may still be associated with an account identifier and technical information.

We do not send Gmail message content to PostHog. Product events are designed to use feature names, action types, counts, ranges, and other limited operational properties rather than the contents of your trips or messages. Partner-invitation events may include partner and invitation identifiers, benefit type and duration, viewer or claim result, and sharing method. For a successful public referral, consented account-linked analytics may record that partner and invitation as a first-touch acquisition source. Private invitation tokens are excluded, and a private benefit claim does not set acquisition properties.

Analytics events are retained for 14 days and masked session recordings for 30 days under our current PostHog settings. Identified person properties are kept only while needed for account-linked analytics and are included in our handling of a verified objection or erasure request.

9. Cookies and local device storage

Crossing Paths uses strictly necessary cookies to establish, maintain, refresh, and protect authenticated sessions. A short-lived security cookie also binds an optional Gmail authorization request to the signed-in browser. Disabling necessary cookies may prevent sign-in or other protected features from working.

After you open a valid private partner invitation, a strictly necessary first-party HttpOnly cookie retains the access credential from the link for up to seven days and only on that partner-benefit path. This lets the invitation remain available through sign-in and profile completion. The cookie is not used for analytics or made available to the partner, and it is used independently of analytics consent.

We use limited local device storage for functional purposes such as returning you to the requested page after authentication, remembering that an onboarding hint has been shown, or remembering that you dismissed a Gmail-import suggestion. This information remains on the device until the application or your browser removes it.

PostHog may use cookies or local storage only after you consent to analytics. Those technologies help distinguish sessions, remember the analytics choice, and associate permitted events with a visitor or signed-in account. You can refuse or later withdraw analytics consent through the consent controls provided by the service. Withdrawing consent stops future analytics collection but does not affect strictly necessary storage.

10. Contact requests and service email

When you use the Contact page, we store the email address and message you submit so that we can review and respond to the request. Please do not send passwords, access tokens, identity documents, health information, or other sensitive material unless it is genuinely necessary and we have asked for it.

We use Resend as our transactional-email provider, including for account-confirmation and password-reset messages sent through Supabase Auth, optional trip-overlap alerts, and necessary Plus-access lifecycle messages. Resend processes the recipient and sender address, message subject and content, and delivery and diagnostic metadata needed to transmit and troubleshoot the email. Stripe also sends receipts, invoices, refund notices, and certain subscription messages through Link for Managed Payments transactions. Resend currently stores its account data, email metadata, logs, and API records in the United States, and retains email data for 30 days under its standard service settings.

We do not currently use your account email address to send marketing messages. We may send service communications that are necessary to administer your account, security, legal notices, or a feature you requested. Necessary billing messages, such as subscription activation, cancellation, payment problems or recovery, and the approaching or completed end of Plus, may be sent even when optional trip-email alerts are off.

11. Service providers and other recipients

We use Supabase for our EU-region database, authentication and file storage, together with distributed server-side functions and related infrastructure; Netlify to host and deliver the web application through a global content-delivery network and to run application requests; Stripe and Link to host Checkout and subscription-management pages, act as merchant of record for Managed Payments transactions, process recurring payments, handle applicable indirect taxes, maintain billing records, send transaction messages, provide transaction support, and manage fraud and disputes; Resend to deliver transactional email; and PostHog EU Cloud for consent-based analytics, error capture, and masked session replay.

Stripe acts as an independent controller and, through Link, the merchant of record for Managed Payments transactions. It determines how it processes data for the sale, payment, applicable indirect-tax compliance, invoicing, fraud prevention, disputes, refunds, transaction support, security, financial operations, legal compliance, and service improvement. Stripe may also act as our processor or service provider for limited integration activities performed under our instructions. Stripe explains these activities and applicable rights in its own privacy notice.

We also use Google for optional sign-in, Gmail authorization and processing, push notifications used by the Gmail integration, and interface resources; and Geoapify to search for and validate place names and convert a selected place into map coordinates and time-zone information. These providers receive only the information needed for the relevant request, together with standard technical data such as IP address and request headers where inherent in internet communications.

A partner named in an invitation does not receive access through this feature to claimant identities, accounts, profiles, friends, trips, or claim-level records.

Personal data may also be disclosed to people you deliberately make it visible to; professional advisers and insurers under confidentiality duties; competent courts, regulators, law-enforcement bodies, or other authorities where disclosure is legally required; and a successor in a genuine corporate reorganisation or transfer, subject to applicable law and any additional consent required for Google user data.

We do not sell or rent personal data, disclose it to data brokers, or use it for behavioural advertising.

12. International transfers

Our Supabase database project and PostHog environment are configured in the European Union. Supabase Edge Functions and Netlify use distributed infrastructure that may process requests outside the database region, and Resend stores account data, email metadata, logs, and API records in the United States regardless of the email-sending region. Stripe and its affiliates or subprocessors, as well as Google, Geoapify, and other service-provider group companies or subprocessors, may also process data outside the European Economic Area.

When personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on an applicable safeguard made available under the relevant provider agreement, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. You may contact us for further information about the safeguard applicable to a particular transfer.

13. How long we keep data

Account, profile, friendship, restriction, trip, base, current-stay, overlap, notification, imported-trip, and local billing data is generally kept while your account remains active or until you delete the relevant information. Stripe customer mappings, Checkout attempts, subscription status, and billing-email delivery records are kept as needed to administer Plus, reconcile payments, provide support, and handle disputes. We may keep limited transaction, accounting, tax, refund, fraud-prevention, or legal-claim records longer where necessary to comply with law, resolve a dispute, prevent abuse, or establish, exercise, or defend legal claims.

Account-linked public referral claims, private partner-benefit claims, Complimentary Plus grants, and first-touch partner attributions are generally kept while your account remains active and are removed from active application systems when you delete it. Partner configuration and private-token history may be retained for program administration and security, but do not contain claimant account identifiers.

Contact-page submissions are retained for 12 months from submission and are then scheduled for deletion, unless a particular message must be kept longer for an unresolved request, legal obligation, or legal claim.

For Gmail import, temporary OAuth state expires within 10 minutes, unresolved review candidates expire after 30 days, Google push-message receipt identifiers are retained for 30 days, and protected message-processing receipt metadata is retained for 18 months to prevent duplicate processing and support integrity checks. Mailbox credentials are retained until you disconnect the mailbox or delete your account. Technical import records linked to your account are removed when the account is deleted, subject to the exceptions described in this Notice.

PostHog analytics events are retained for 14 days and masked session recordings for 30 days. Resend email data is retained for 30 days under its standard settings. Hosting, authentication, security, and diagnostic logs are retained for the limited period configured or reasonably required by the relevant provider and for security, reliability, and legal purposes.

Stripe determines how long it keeps personal data for processing it controls by considering applicable legal and regulatory duties, the services involved, fraud and financial-crime prevention, disputes, and legal claims. Stripe may therefore retain some transaction or payment data after a subscription ends or after we ask it to delete the customer record associated with the account. We do not state a fixed Stripe retention period because it varies by data, purpose, and applicable law.

We do not currently maintain a separate customer-controlled automatic database-backup archive. Service providers may nevertheless maintain temporary, access-restricted recovery or resilience copies under their own infrastructure cycles. If deleted data remains in such a copy, it is not returned to ordinary use and is removed or overwritten through the provider’s normal cycle unless law requires retention.

When an exact period cannot be fixed in advance, we consider the purpose of processing, the amount and sensitivity of the data, the risk of harm, applicable limitation periods, legal obligations, and whether the purpose can be achieved with less data or anonymised information.

14. Account deletion and erasure

You can delete your account from the account settings. The deletion workflow disconnects Gmail, expires open Stripe Checkout sessions, cancels an active Plus subscription, asks Stripe to delete the customer record associated with the account, deletes stored avatar objects, removes the authentication account, and starts removal of associated profile, friendship, restriction, trip, place, overlap, notification, local billing, partner-invitation claim, grant, attribution, Gmail-connection, and import data from active application systems. You lose access immediately and the action cannot be undone.

Account deletion does not necessarily delete a contact request that must remain for its stated retention period, information another person previously copied, a transaction, accounting, tax, refund, dispute, or fraud-prevention record that we or Stripe may lawfully need to keep, or temporary data in access-restricted provider logs and recovery systems. Stripe may continue to retain and process personal data for the purposes it controls where permitted or required by law. Analytics events and recordings also remain until their applicable retention period expires unless earlier deletion is required in response to a verified request.

Where account-linked personal data remains with a service provider and erasure is required, we will instruct the provider to delete or anonymise it. Some provider deletion jobs, including deletion of associated analytics events or recordings, may complete asynchronously rather than immediately.

15. Security

We use technical and organisational measures intended to protect personal data, including encrypted transmission, access controls, row-level database rules, separation of private import records, restricted administrative credentials, bounded file storage, and encryption of long-lived Gmail credentials before storage. Access is limited to people and providers that need it for an authorised purpose.

No internet service can guarantee absolute security. You should use a strong, unique password, protect access to your email and devices, and contact us promptly at contact@crossing-paths.app if you suspect unauthorised account access. If a personal-data breach occurs, we will assess it and notify affected people and authorities where applicable law requires us to do so.

16. Your data-protection rights

Subject to the conditions and exceptions in applicable law, you may request access to your personal data; correction of inaccurate or incomplete data; deletion; restriction of processing; and a portable copy of data you provided where processing is automated and based on consent or contract.

You may object to processing based on our legitimate interests. You may withdraw consent at any time where processing is based on consent, including analytics, without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where that right applies.

Send a request to contact@crossing-paths.app. Describe the right you wish to exercise and provide enough information for us to identify the relevant account or data. We may request proportionate proof of identity and may refuse or charge a reasonable fee for a manifestly unfounded or excessive request where the law permits. We ordinarily respond within one month, subject to any lawful extension for a complex or numerous request.

You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) through dataprotection.ro or with the competent supervisory authority in the country where you live, work, or believe an infringement occurred. We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching an authority.

17. Automated processing

Crossing Paths automatically compares place and date ranges to identify possible overlaps between eligible friends. The Gmail importer uses fixed rules to classify supported reservation messages and may ask you to review uncertain or changed information. These processes may be incomplete or incorrect, and you remain able to review, correct, or delete the resulting trip data.

We do not use these processes to make decisions that produce legal or similarly significant effects about you. Gmail message extraction does not use an artificial-intelligence model, and we do not use your personal data or Google user data to train a general-purpose artificial-intelligence model.

18. People under 18

Crossing Paths is intended only for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has created an account or provided personal data, contact us so that we can investigate and take appropriate action.

19. Changes to this Notice

We may update this Notice when the service, our providers, or applicable legal requirements change. We will publish the revised Notice with an updated effective date and version number. If a change materially affects how we use personal data, we will provide additional notice or request consent where applicable law requires it.

20. Contact and complaints

Questions, complaints, and data-protection requests may be sent to Maverick Bits S.R.L. at contact@crossing-paths.app or by post to the registered office stated in section 1. Please do not include passwords, access tokens, or unnecessary sensitive information in your request.