Legal
Privacy Policy
Her city, your world.
Effective Date: May 2026 · Version 1.0
Co-Sister (“Co-Sister”, “we”, “us”, or “our”) is a women-centered trusted travel matching platform. We operate the Co-Sister website and mobile application (collectively, the “Platform”), including the services SisterBase (space-sharing matching) and SisterGuide (peer experience sharing). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you access or use our Platform.
By creating an account or using any part of the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Platform.
1. Who This Policy Applies To
This Policy applies to all individuals who interact with Co-Sister, including:
- ◆Guest Sisters — members who use the Platform to find accommodations or book SisterGuide sessions
- ◆Host Sisters — members who offer their home or SisterGuide services on the Platform
- ◆Visitors — individuals who browse co-sister.com without creating an account
The Platform is exclusively available to individuals who identify as women and are 18 years of age or older. We do not knowingly collect personal information from individuals under 18.
2. Information We Collect
2.1 Information You Provide Directly
When you register, verify your identity, or use Platform features, you may provide:
- ◆Account basics: display name, email address, password, nationality, languages spoken
- ◆Travel Persona: MBTI type and responses to our 20-question travel compatibility survey (lifestyle, dietary habits, comfort with strangers, etc.)
- ◆Identity verification: government-issued photo ID image and a selfie (processed solely for verification purposes; document numbers are not stored in your public profile)
- ◆Optional enhanced verification: LinkedIn profile or social media handle
- ◆Stay & hosting details: available dates, city, house rules, photos of your space
- ◆SisterGuide profile: experience tags, topic areas you are willing to discuss
- ◆Emergency contact: name and phone number of a trusted person (visible only to you and the Platform's moderation team; shared with your matched Sister only upon mutual agreement or in an emergency)
- ◆User-generated content: travel stories, reviews, ratings, guide uploads, and any content you choose to share on the Platform
- ◆Communications: messages exchanged with other members through the in-Platform chat
2.2 Information Generated Automatically
- ◆Device and browser information: IP address, browser type and version, operating system, device identifiers
- ◆Usage data: pages visited, features used, timestamps, session duration, referring URLs
- ◆Location data: city-level location when you publish a host listing or use the discovery map (we do not collect precise real-time GPS coordinates without explicit permission)
- ◆Log data: server logs, error reports, and diagnostic information
2.3 Information From Third Parties
- ◆Identity verification providers: confirmation of document authenticity (not the document itself)
- ◆Optional social verification: publicly available profile data from LinkedIn or social platforms, solely to display a verified badge
- ◆Payment processors: transaction confirmation and billing metadata (we do not store full card numbers)
3. How We Use Your Information
We use personal information only for the purposes described below and do not sell your data to third parties.
3.1 Providing and Improving the Platform
- ◆Creating and managing your account and Travel ID
- ◆Generating your Travel Persona card and powering the compatibility matching algorithm
- ◆Facilitating SisterBase space-sharing matches and SisterGuide session bookings
- ◆Processing Stay Agreements and managing the Trust Seed lifecycle (Tagged → Locked → Bloomed / Withered)
- ◆Enabling in-Platform chat, Stay stories, City Circles, and the World Map
- ◆Automatically drafting travel story summaries after a completed stay (you control whether these are private, limited, or public)
- ◆Improving matching accuracy, product features, and user experience through aggregated analytics
3.2 Trust & Safety
- ◆Verifying your identity to maintain a women-only, verified-member community
- ◆Administering the Bad Seed mechanism and account status system (Warning / Restricted / Banned) — account status is visible to other members; event details are kept internal
- ◆Investigating disputes via the Dispute Pool; moderation reviewers access relevant chat logs, photos, and contract records only for the duration of a dispute
- ◆Detecting fraud, abuse, and violations of our Community Guidelines
3.3 Communications
- ◆Sending transactional messages (match confirmations, Stay Agreement notifications, evaluation reminders, seed lifecycle alerts)
- ◆Sending service announcements and updates about the Platform
- ◆Sending optional marketing communications (Founding 500 news, Host webinar invitations) — you may unsubscribe at any time
3.4 Legal Compliance
- ◆Complying with applicable laws and regulations in the jurisdictions where we operate (including Taiwan, Japan, Germany, and the European Union)
- ◆Responding to lawful requests from law enforcement or regulatory authorities
- ◆Enforcing our Terms of Service and contractual obligations
4. Information Sharing and Disclosure
We share personal information only as described below:
4.1 Between Matched Members
Certain information is intentionally progressive — the more trust is established, the more is revealed:
- ◆Before a match: only your public Travel Persona (display name, MBTI type, verification status, travel history counts) is visible
- ◆After a match is confirmed and the Stay Agreement is signed: your real name, phone number, emergency contact, and precise address become mutually visible to the matched pair for the duration of the stay
- ◆After a stay closes: the above sensitive fields are no longer mutually accessible; only your public profile data remains visible
4.2 Service Providers
We share data with carefully selected vendors who process it on our behalf under confidentiality agreements, including: cloud hosting providers, identity verification services, video call infrastructure (SisterGuide sessions), map tile services, and email delivery platforms. These providers may not use your data for their own purposes.
4.3 Legal Requirements
We may disclose personal information if required by law, court order, or government authority, or to protect the rights, safety, or property of Co-Sister, our members, or the public. We will notify affected users of such disclosures where legally permissible.
4.4 Business Transfers
If Co-Sister is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Platform before your information is subject to a different privacy policy.
4.5 Aggregated or De-identified Data
We may share aggregated, de-identified, or anonymized data (e.g., the number of cities covered, average matching time) with partners, researchers, or the public. Such data cannot reasonably be used to identify you.
5. Trust Seed System & Financial Data
Trust Seeds are platform-internal credits, not monetary instruments. They cannot be bought, sold, gifted, or withdrawn as cash. Accordingly, Trust Seed balances and lifecycle records are treated as functional usage data rather than financial records. We retain seed transaction logs for the duration of your membership to support dispute resolution and platform integrity.
Payment for membership subscriptions (Monthly or Annual plans) is handled by third-party payment processors (e.g., Stripe). Co-Sister receives only a transaction confirmation token and billing summary. Full card numbers, CVV codes, and bank details are never transmitted to or stored by Co-Sister.
6. Cookies and Tracking Technologies
- ◆Strictly necessary cookies: required for authentication, session management, and security features. These cannot be disabled.
- ◆Analytics cookies: we use privacy-first analytics tools (such as Plausible Analytics) that do not set third-party tracking cookies or fingerprint users. Aggregated usage data helps us improve the Platform.
- ◆Preference cookies: remember your language and display settings.
We do not use advertising cookies, behavioral tracking cookies, or share cookie data with ad networks. You can manage cookie preferences through your browser settings at any time, though disabling strictly necessary cookies will impair Platform functionality.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce agreements.
You may request deletion of your account at any time. We will delete or anonymize your personal data within 30 days, subject to the retention requirements above.
8. Data Security
- ◆Encryption in transit (TLS 1.2 or higher) for all data transmitted between your device and our servers
- ◆Encryption at rest for sensitive fields such as government ID images and emergency contact information
- ◆Access controls: sensitive data fields (identity documents, emergency contacts, dispute logs) are accessible only to authorized moderation personnel on a need-to-know basis
- ◆Regular security assessments and penetration testing
- ◆Incident response procedures with mandatory notification timelines in line with GDPR requirements
Despite these measures, no method of transmission over the internet is 100% secure. In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and applicable regulatory authorities as required by law.
9. International Data Transfers
Co-Sister operates internationally and your information may be processed in countries other than your country of residence, including Taiwan, Singapore, and member states of the European Union. Where personal data is transferred from the European Economic Area (EEA) or the United Kingdom to countries that do not provide an equivalent level of data protection, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
10. Your Rights
10.1 Rights Available to All Members
- ◆Access: request a copy of the personal information we hold about you
- ◆Correction: request that inaccurate or incomplete information be corrected
- ◆Deletion: request deletion of your personal information (subject to legal retention requirements)
- ◆Portability: request a machine-readable export of data you have provided to us
- ◆Objection to processing: object to the use of your data for direct marketing at any time
10.2 Additional Rights Under GDPR (EEA & UK Residents)
- ◆Restriction of processing: request that we limit how we use your data in certain circumstances
- ◆Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- ◆Lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority
10.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@co-sister.com. We will respond within 30 days (or within 72 hours for security-related requests). We may need to verify your identity before processing your request.
11. Children's Privacy
The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected information from someone under 18, we will delete it promptly. If you believe a minor has registered, please contact us at privacy@co-sister.com.
12. SisterGuide Session Privacy
SisterGuide sessions are 1-on-1 peer experience sharing calls. Recording, screenshotting, or sharing any content from a session without explicit mutual consent is strictly prohibited under our Community Guidelines and may constitute a violation of applicable law. The Platform infrastructure does not automatically record sessions. If a participant records a session without consent, this constitutes a serious violation subject to the Bad Seed mechanism, up to and including permanent removal from the Platform.
13. User-Generated Content
When you publish a travel story, guide, review, or any public content on the Platform, that content is visible to other members as per the privacy setting you select (Private / Matched Sisters only / Public). By publishing content, you grant Co-Sister a non-exclusive, worldwide, royalty-free license to display, reproduce, and promote that content on the Platform and in Co-Sister's marketing materials, subject to our commitment to protect your core privacy (precise address, identity documents, and private chat messages are never used in marketing materials).
You may delete your published content at any time. Following deletion, content will be removed from public view within 48 hours, though copies may remain in backup systems for up to 30 days.
14. Third-Party Links and Services
The Platform may contain links to third-party websites or services (for example, flight search tools, language resources, or social media platforms). This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies before sharing any personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by email (to the address on your account) and post a notice on the Platform at least 14 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
We maintain an archive of prior versions. If you wish to review a previous version, please contact us at privacy@co-sister.com.
16. Contact & Data Controller Information
Co-Sister is the data controller for personal information processed through the Platform.
Brave women, shared homes, one world.