RebateTrail Privacy Policy
Effective Date: April 7, 2026
Last Updated: August 29, 2026
Welcome to RebateTrail (the "Platform"). The Platform is operated by Mantu (Shanghai) Travel Consulting Co., Ltd. (缦途(上海)旅游咨询有限公司, Building 1-3, No. 63 Liantai Road, Baoshan District, Shanghai; the "Company"). We take the security of your personal information seriously. This Privacy Policy (this "Policy") explains how we collect, use, store, share, and protect your personal information, and how you can manage it.
Please read this Policy carefully before using the Platform. If you disagree with any part, stop using the Platform immediately. By using the Platform, you acknowledge that you have understood and agreed to this Policy.
This Policy applies to personal information processed through the Platform's website (rebatetrail.com), WeChat Mini Program, Alipay Mini Program, iOS and Android mobile applications, and related services.
1. How We Collect and Use Your Personal Information
We collect and use your personal information only to the extent necessary for the purposes described below.
1.1 Registration and Login
When you register, we collect:
- Email address (required): for registration, identity verification, and notifications
- Password: stored as an irreversible bcrypt hash — we cannot access your plaintext password
- Display name (optional): shown within the Platform
When you log in via WeChat, with your authorization we obtain:
- WeChat UnionID and OpenID: to identify your WeChat identity and link it to your account
- Nickname and avatar: to display your profile
- Public region and gender: to improve localization
When you log in within the Alipay Mini Program, with your authorization we obtain your Alipay user identifier via the Alipay Open Platform, to identify your Alipay identity and link it to your account.
When you sign in with a Google account, with your authorization we obtain:
- Google account ID and email: to create or link your account
- Display name and avatar: to display your profile
When you use Sign in with Apple, with your authorization we obtain:
- Apple user identifier: to create or link your account
- Email address: if you select "Hide My Email," we receive Apple's private relay address, not your real email
- Name: provided by Apple only at first authorization, used for your display name
When you use a passkey:
- We store only your public key credential and its identifier. The private key and the biometrics used to unlock it remain on your device or in your chosen password manager — we do not and cannot collect them
1.2 Using Platform Services
When you use the cashback service, we collect:
- Booking information: reference number, check-in date, hotel brand, source, etc., for verification and cashback calculation
- Preferences: your preferred currency and language
1.3 Withdrawals and Payments
When you request a withdrawal, we collect:
- Payout account: bank, Alipay, or WeChat Pay account details, used solely by the Agent to distribute cashback
- Alipay binding: with your authorization, we obtain your Alipay user identifier (open_id) and verified name via the Alipay Open Platform, to verify payee identity
- Transaction records: cashback credits, withdrawal requests, and balance changes, for your financial history
1.4 Security and Risk Control
To protect your account and Platform security, we automatically collect:
- Device and network information: IP address, OS and version, device model, app/Mini Program version; on the web, also browser type and version
- Login records: time, method, session data
- Verification code records: one-time codes sent for email verification or password resets
1.5 Notifications
- Preferences: you may choose in-app and/or email notifications
- Content: cashback updates, withdrawal progress, referral rewards, etc.
1.6 Referrals
When you participate in the referral program, we record:
- Referral relationships: links between referrer and referred User
- Referral code: the code you set
- Reward records: trigger conditions and payout status
1.7 Device Permissions (App and Mini Programs)
We request permissions only when the relevant feature is triggered. You may decline; declining affects only that feature:
| Permission | When requested | Purpose |
|---|---|---|
| Photo library | Uploading a booking screenshot for cashback; sending an image in a support conversation | Reading and uploading the image you select |
We do not request contacts, location, microphone, camera, calendar, or SMS access. The App currently has no push notifications; we do not collect device push tokens.
You may revoke permissions at any time in your OS or Mini Program settings.
1.8 Information We Receive from Third Parties
To verify that your booking actually took place and adjudicate cashback, we receive booking and commission records from an overseas hotel commission settlement data source (the system the Agent uses to reconcile with upstream suppliers). These records may include:
- Guest name
- Check-in and check-out dates
- Booking reference, hotel name and location, room rate, commission amount, source channel
Key points about this information:
- Origin: you provided it to the hotel or booking channel when you made the reservation; it was aggregated into the settlement system by upstream suppliers — not originating from this Platform
- One-way inbound flow: we read records from these systems and store them on servers in mainland China to match against your cashback applications. We do not send any of your Platform data abroad in the process — read requests carry only the Agent's settlement payee ID and a date range, no user personal information. This is not a cross-border transfer under Section 3.4
- Minimization: we retain only fields relevant to cashback adjudication, per the retention periods in Section 2
1.9 Automated Recognition of Booking Confirmations (Optional)
When submitting a cashback application, you may upload a screenshot and have the system read booking details from it. This is optional; you may fill the form manually. Before first use, we explain the processing below and proceed only after your confirmation.
- Information processed: your uploaded image and information within it (guest name, confirmation number, dates, hotel name, etc.)
- How: the image is sent over an encrypted connection to a third-party AI service provider, which extracts booking details in structured form
- Provider retention: per its published policy, input and output are processed in memory only, not written to persistent storage, and not used for model training. The provider logs metadata (token usage, timestamps, request IDs) for billing and rate limiting. We also explicitly disable conversation retention on every call
- Our retention: the image exists only in server memory during processing — not written to our database or object storage — and is released once recognition finishes or fails. Extracted details are placed into the form and not saved until you confirm and submit
- Our logs: we record call time, your account ID, image size and format, outcome, number of items found, and token usage (for costing). We record neither the image nor the extracted content
- Upload scope: everything in the image is submitted for recognition. Do not upload unrelated information such as ID numbers, bank card numbers, or passport details
1.10 Online Booking
When you use Online Booking, we collect:
- Payment information: your card details are encrypted on your device before submission; the booking and payment processing service provider we work with decrypts, stores, and uses them to complete the charge. The Platform's servers never access or store plaintext card numbers. If you choose to "remember this card," we store only card type, last four digits, and expiration date for display and expiry reminders
- Frequent traveler information: guest name (pinyin), nickname, email, phone, and hotel-chain loyalty numbers you voluntarily save, used to pre-fill booking forms
- Order information: hotel, room type, dates, rate, order status, and cancellation records, for processing your booking, displaying estimated cashback, and verifying cashback
The booking and payment processing service provider we work with is located outside the PRC. Your payment card data (ciphertext), frequent traveler information, and order information are therefore transferred abroad; the provider also shares check-in details with the hotel and its reservation system as needed. See Sections 3.1 and 3.4.
2. How We Store Your Personal Information
2.1 Location
Your personal information is stored on cloud servers and databases in mainland China (Shanghai), with TLS/SSL encryption in transit.
Static web pages for overseas visitors are served by an overseas CDN; those pages contain no personal information. All business data generated after login is processed and stored in mainland China.
2.2 Retention Periods
We retain your information for the minimum period necessary:
| Type | Period | Notes |
|---|---|---|
| Account information | Account lifetime + 30 days | Grace period after deactivation |
| Transaction and financial records | 3 years from completion | Per PRC Accounting Law; includes Online Booking orders and payments |
| Login sessions | 90 days | Security audit |
| Verification codes | 30 days after expiry | Auto-cleared |
| Notifications | Account lifetime | You may delete read notifications at any time |
| Support conversations | 24 hours on-Platform | Entire conversation (including images) deleted 24 hours after last message |
| Booking screenshots for recognition | Not stored | In-memory only; released after processing (see 1.9) |
| Saved card summary (type / last 4 / expiry) | Until you delete it or deactivate | Full card number held by the service provider under its own policy (see 1.10) |
| Frequent traveler profiles | Until you delete them or deactivate | Maintained by you; add, edit, or delete at any time |
2.3 After Account Deactivation
When your account is deactivated (voluntarily or due to inactivity), we will:
- Delete or anonymize personally identifiable information after a 30-day grace period
- Retain legally required transaction records until the statutory period expires, then delete them
- Anonymized data no longer constitutes personal information and may continue to be used
- Support conversations already forwarded to our Feishu (Lark) workspace are not deleted with deactivation — they remain subject to Feishu's own retention policy
3. How We Share, Transfer, and Disclose Your Personal Information
3.1 Sharing
We do not sell your personal information. We share it with third parties only as follows:
| Third Party | Information Shared | Purpose |
|---|---|---|
| Email service provider | Email address, email content | Sending verification codes and notifications |
| WeChat Open Platform | Authorization code (one-time) | WeChat login |
| Alipay Open Platform | Authorization code (one-time), Alipay user ID (open_id) | Alipay Mini Program login and payout-account binding |
| Apple | Authorization code and identity token (one-time) | Sign in with Apple |
| Authorization code (one-time) | Google Sign-In | |
| Cooperating Agent | Payout account details, withdrawal request | Agent distributes cashback to you |
| CDN provider | IP address and request headers (no account data) | Serving static pages to overseas visitors; attack mitigation |
| Exchange rate provider | Currency pair (no personal information) | Reference exchange rates |
| Feishu (Lark) | Your support messages (text, images) and account identifiers (user ID, display name, email) | Staff respond to your enquiry from Feishu |
| AI recognition provider | Booking screenshot you upload and information it contains | Extract booking details to pre-fill your cashback form |
| Booking and payment processing provider (overseas) | Card data (ciphertext), frequent traveler info, order and check-in info | Process Online Booking orders, payments, and check-in |
| Hotel and its reservation system | Guest name, contact details, dates, loyalty number, etc. | Booking confirmation and check-in registration |
All third-party providers are contractually bound to use your information only as necessary for our services.
Commission settlement data: information flows between the Platform and settlement systems in one direction only — inbound. We read records from them; we do not provide your information to them. See Section 1.8.
Support conversations: content you submit through the support channel is forwarded to our Feishu (Lark) workspace. We delete our copy 24 hours after the conversation ends, but the Feishu copy is governed by Feishu's retention policy and is not removed by our clean-up. Each conversation's first message includes your user ID, display name, and email so staff can locate your account. Do not submit sensitive information unrelated to your enquiry.
3.2 Transfer
If the Company undergoes a merger, acquisition, or asset transfer involving your personal information, we will require the new holder to be bound by this Policy, or else to obtain your consent anew.
3.3 Public Disclosure
We do not publicly disclose your personal information except:
- With your explicit consent
- As required by law, legal proceedings, or government authorities
3.4 Cross-Border Transfer
Our databases and primary servers are in the PRC. The following scenarios may involve transferring information abroad:
- Email delivery: your email address and message content are transmitted to an overseas email provider
- Google Sign-In: the authorization flow runs on Google's servers
- Sign in with Apple: authentication runs on Apple's servers
- Overseas page delivery: static pages served by an overseas CDN process your IP address and request headers
- Exchange rate queries: only currency pair data is transmitted (no personal information)
- Online Booking: our booking and payment processing provider is outside the PRC. Your card data (ciphertext), frequent traveler information, and order information are transferred to that provider, which also shares check-in details (name, contact, dates, loyalty number, etc.) with the hotel and its reservation system
Automated recognition (Section 1.9): the provider's servers are in the PRC — no cross-border transfer is involved.
Settlement data (Section 1.8): records flow inbound from overseas sources into China. This is information we receive, not information we provide abroad, and does not constitute cross-border transfer of your data.
We comply with the PRC Personal Information Protection Law to ensure adequate protection for cross-border transfers, including:
- Limiting transfers to the minimum necessary for service purposes
- Using encryption in transit
- Entering into data processing agreements with overseas recipients
3.5 Third-Party SDKs and Services
We integrate the following SDKs and services. Their information handling is also governed by their own privacy policies:
| SDK / Service | Applies to | Information Processed | Purpose |
|---|---|---|---|
| WeChat Open Platform | Mini Program, web | Login credential (one-time code), UnionID/OpenID, nickname, avatar | WeChat login |
| 微信OpenSDK / WeChat OpenSDK(深圳市腾讯计算机系统有限公司) Privacy guidelines | iOS and Android | Device information (brand, model, OS version), device identifiers, network status, whether WeChat is installed and its version; login credential (one-time code) | WeChat login, opening our Mini Program for withdrawal, sharing to WeChat |
| Alipay Open Platform | Mini Program, web, App | Authorization code (one-time), user ID, verified name | Alipay login, payout binding |
| Sign in with Apple | iOS app, web | Apple user ID, email, name (first authorization only) | Apple sign-in |
| Google Sign-In | Web, App | Google account ID, email, display name, avatar | Google sign-in |
| Expo / React Native core | iOS and Android | Device model, OS version, app version; images you select | App runtime, encrypted credential storage in system keychain/keystore, image upload |
| Object storage | All platforms | Booking screenshots and support images you upload | Storing your uploaded images |
| AI recognition service | Web | Booking screenshot and its content | Automated booking recognition (see 1.9) |
| Booking and payment processing | Web, App | Card data (ciphertext), frequent traveler info, order/check-in info | Online Booking orders, payment, and check-in (see 1.10) |
We do not integrate any advertising, analytics, or user-profiling SDKs.
4. How We Protect Your Personal Information
4.1 Technical Measures
- Encryption in transit: all data uses TLS/SSL
- Password security: irreversible bcrypt hashing
- Session tokens: randomly generated, valid for 7 days
- Database security: mandatory encrypted connections with channel-binding authentication
4.2 Administrative Measures
- Strict access controls on who may access personal information
- Security training for personnel with access
- Data security incident response procedures
4.3 Security Incidents
In the event of a personal information security incident, we will promptly notify you — via push notification, email, or other means — of the circumstances, potential impact, remedial measures taken, and steps you can take to mitigate risk, as required by law.
5. Your Rights
Under the PRC Personal Information Protection Law (PIPL) and related laws, you have the following rights:
5.1 Access and Copying
You may access and copy your personal information by logging in and viewing your account, transactions, and notification preferences.
5.2 Correction
If your information is inaccurate, you may correct it via Platform settings or by contacting us.
5.3 Deletion
You may request deletion of your personal information when:
- The processing purpose has been achieved or is no longer necessary
- We have ceased providing services or the retention period has expired
- You withdraw consent
- We have processed your information in violation of law or agreement
Note: legally required records (e.g. transactions) are deleted after the statutory retention period.
5.4 Account Deactivation
You may deactivate your account; processing follows Section 2.3.
Before deactivating:
- Your balance is cleared — complete withdrawals first
- Pending cashback applications will no longer be processed
- Deactivation is irreversible (except during the grace period)
5.5 Withdrawal of Consent
You may withdraw consent at any time. Withdrawal does not affect the validity of prior processing based on that consent.
5.6 Portability
Subject to legal requirements, you may request transfer of your personal information to another processor you designate.
5.7 How to Exercise Your Rights
- Self-service: account settings after login
- Email: privacy#rebatetrail.com (replace # with @)
We will respond within 15 business days.
6. Cookies, Local Storage, and Tracking
6.1 Web Cookies
The Platform website uses only essential cookies — no third-party tracking or advertising cookies:
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
rt_session | Login session | httpOnly (not accessible to JavaScript) | 7 days |
i18nextLng | Language preference | Standard | 1 year |
6.2 App and Mini Program Local Storage
The App and Mini Programs do not use cookies. We store the following locally on your device:
| Item | Purpose | Location |
|---|---|---|
| Session token | Login state | App: OS keychain/keystore (encrypted); Mini Program: local storage |
| Language and theme | Interface settings | App/Mini Program local storage |
Clear these by logging out, deleting the App, or clearing Mini Program cache.
6.3 What We Do Not Do
The cookies and local storage above are essential for the Platform to function. We do not use third-party tracking or advertising tools, do not collect device advertising identifiers (IDFA, OAID, etc.), and do not engage in personalized advertising.
7. Protection of Minors
The Platform is for adults aged 18 and above. We do not knowingly collect information from minors. If we discover such information was collected without verifiable parental or guardian consent, we will delete it promptly.
8. Revisions to This Policy
We may revise this Policy from time to time. Revisions are published on the Platform with an updated date.
8.1 Changes Requiring Your Consent
We will notify you and obtain your consent again before any of the following take effect. New processing will not begin until you have responded:
- Collecting a new type of personal information, especially sensitive information
- Changing the purpose or method of processing
- Providing your information to a new third party
- Providing your information outside mainland China
8.2 Changes Requiring Notice Only
We will inform you (via announcements, in-app notice, or email) without separately seeking consent for:
- Clarifications or wording corrections to existing processing descriptions, where purpose, method, and information categories are unchanged
- Adding an optional feature that collects information only when you actively trigger it (e.g. a new sign-in method) — using the feature constitutes consent
- Replacing a service provider with an equivalent one, with unchanged information categories and purposes
- Updating non-substantive details (law names, contact information, etc.)
If you disagree with any revision, you may stop using the Platform and deactivate your account.
9. Contact Us
For questions about this Policy or to exercise your rights:
- Company: Mantu (Shanghai) Travel Consulting Co., Ltd. (缦途(上海)旅游咨询有限公司)
- Address: Building 1-3, No. 63 Liantai Road, Baoshan District, Shanghai (上海市宝山区联泰路63号1-3幢)
- Privacy email: privacy#rebatetrail.com (replace # with @)
We will respond within 15 business days. If unsatisfied, you may file a complaint with the personal information protection authority in Baoshan District, Shanghai (上海市宝山区).