1. Who we are
ZHAI LTD, a United Kingdom company, operates Cpal, previously known as Cridge. ZHAI LTD is the controller responsible for the personal information described here. References to “Cpal”, “we”, “us” and “our” mean ZHAI LTD.
This policy covers our Traveler and Guide services, our iOS app, the website at cridgeai.com, and related support and communications. Some features depend on your role, location and app version; we collect feature-specific information when you use those features.
Contact the Cpal privacy team at admin@cridgeai.com. Acknowledging this policy does not waive your rights or give blanket consent to optional processing. Separate permission requests apply where needed.
2. Information we collect
Information you provide
- Account and onboarding: your phone number, email, name, role, date of birth or age where provided, verification status, sign-in identifiers, onboarding progress and drafts, and records of privacy acknowledgements and permission choices.
- Profile and preferences: profile pictures, other uploaded photos or videos, biography, prompt answers, languages, occupation, education, home or current city, interests, travel style, social preferences and availability. Optional dietary preferences and allergies can reveal health or religious information. You can leave these fields empty or remove them; avoid adding sensitive information that is unnecessary for your trip.
- Trips and guide services: destinations, travel dates, duration, group size, transport preferences, selected meeting points, itinerary and experience content, guide service areas, capabilities, specialties, professional details and submitted materials used to review a guide profile.
- Communications and media: messages, images, videos, voice recordings, attachments, translations, transcripts, reviews or feedback you submit, and related timestamps and delivery/read information. We also receive the information you include in support enquiries, reports, complaints or disputes.
- Bookings and payments: requests, participants, service details, prices, currencies, billing country, payment and refund references, transaction status and dispute evidence. If you use a guide payout feature, this can include your payout destination, such as a WeChat ID, withdrawal requests and payment receipts. Card entry is handled through Stripe; Cpal does not store your full card number or card security code.
Information from using the service
We process searches, saved or liked profiles and experiences, matching preferences, booking actions, conversation activity and connection status. Technical information can include an IP address, app and operating-system version, device model, language, installation or session identifiers, network status, request timestamps, errors and crash diagnostics. Permission-based location and diagnostics are explained below.
Information from other sources
Apple or WeChat can supply an account identifier and the profile information you authorise when signing in, such as a name, avatar or email; Apple may provide a private relay email. Verification, payment and infrastructure providers return delivery, authentication, transaction and security results. Other users can provide information about you in bookings, messages, feedback or reports. Please provide another person’s information only when you are entitled to do so and they understand the sharing.
Fields needed to create an account or complete a particular request are identified in the relevant flow. Without them, we may be unable to verify your account, arrange that service or process a payment. Optional profile fields and optional permissions are not a condition of browsing the website.
3. Why we use your information
Where UK or European data protection law applies, we use the following legal bases. The basis depends on the particular use, rather than treating acceptance of this policy as consent to everything.
- Provide the service you request — contract: create and authenticate your account; save onboarding progress; display your profile; connect travelers and guides; deliver messages; provide requested translation or itinerary assistance; manage bookings, payments, refunds and related service communications.
- Keep Cpal reliable and safe — legitimate interests: prevent misuse and fraud, enforce reasonable request limits, investigate reports, resolve support issues, protect accounts, diagnose failures and improve service reliability. These interests are providing a functioning marketplace and protecting our users and business, balanced against your privacy rights.
- Personalise discovery — legitimate interests: use profile, trip, language, availability and interaction information to order or suggest relevant people and experiences. You can change your preferences and object to processing based on legitimate interests.
- Meet legal responsibilities — legal obligation: maintain required accounting and tax records, handle lawful authority requests and comply with applicable payment, consumer and data protection requirements. Establishing or defending legal claims may also be necessary for our legitimate interests.
- Optional uses — consent where required: permission-based device access, optional SDK processing and any marketing or non-essential tracking that requires consent. Permission can be withdrawn through the relevant settings or by contacting us. Necessary security and booking messages are service communications.
Where information is legally classed as sensitive, such as health information in an allergy field or support request, we also need an applicable condition under that law, such as explicit consent or the establishment, exercise or defence of legal claims. Providing an ordinary profile or acknowledging this policy is not, by itself, explicit consent for every use of sensitive information.
Discovery ranking and AI assistance use automated processing. We do not use them to make solely automated decisions that have legal or similarly significant effects on you. You can contact us to question a result or request human consideration of an account, booking or payment issue.
4. What other people can see
Profiles and listings. Information you put in your visible profile or publish in an experience can be seen by other users, and publicly accessible listings can be seen by visitors. This can include your name, photo, age where displayed, city, languages, biography, prompt answers, preferences, guide details and experience content. An optional field is not necessarily a private field; consider what you include before publishing it.
Communications and bookings. Message recipients receive what you send. Travelers and guides receive the information needed to discuss and fulfil a booking, including selected meeting details and relevant service requests. A meeting point you publish or share may include an exact address or coordinates. Other users can save or copy information they receive; removing it from Cpal cannot retrieve copies they independently made.
Authorised access. Our authorised personnel and service providers may access relevant records to operate the service, investigate a problem or report, manage a payment, or meet legal obligations. Messages are processed on our servers and are not an end-to-end encrypted service.
We may disclose necessary information to professional advisers, payment or dispute partners, courts and public authorities where there is a lawful basis. If our business is reorganised or transferred, relevant information may be shared under appropriate confidentiality and data protection arrangements, with notice when required.
5. Providers that help run Cpal
We share the information needed for the relevant service with the following providers. A provider may use subcontractors. Some, including sign-in, map and payment providers, also handle information as independent controllers under their own terms.
- Hosting, database and media — Cloudflare and Supabase
- Cloudflare handles website and API delivery, security and storage or delivery of images, files and videos. Supabase stores account, profile, conversation, booking and operational records and supports authentication. Cloudflare privacy · Supabase privacy.
- Account verification — Twilio and Resend
- Twilio handles phone verification over SMS or WhatsApp, including your number, verification message and delivery metadata. WhatsApp delivery also involves Meta’s WhatsApp service. Resend handles email verification and transactional email, including the recipient address, message content and delivery metadata. Twilio privacy · WhatsApp privacy · Resend privacy.
- Sign-in and device services — Apple and Tencent WeChat
- These providers handle the sign-in method you choose. Apple also provides iOS permission, map and relevant device services. Apple privacy · WeChat privacy.
- Payments — Stripe
- Stripe processes payment details, transaction information and fraud or dispute information needed for payments you make through Cpal. Stripe privacy.
- Maps and place search — AMap (Gaode) and Apple
- AMap, provided by Amap Software Co., Ltd., supports China maps and meeting-point search or selection. Apple supports native map and location features. See Section 7 for the information involved. AMap privacy policy.
- Translation, transcription and itinerary assistance — OpenAI and DeepSeek
- These providers process the feature inputs described in Section 6. OpenAI business data privacy · DeepSeek privacy.
- App diagnostics — PostHog
- PostHog receives technical diagnostics and limited, masked session replays as described in Section 8, using its EU-hosted service. PostHog privacy.
Following a provider link opens its own website. That website’s privacy practices apply to your visit.
6. Translation and AI features
Message translation sends the relevant message text to a model provider and stores the resulting translation with the conversation. Incoming messages may be translated when the recipient enables automatic translation; this means a message you send may be processed even if you have not enabled translation yourself. Chinese-language translation uses DeepSeek, and other supported translation languages use OpenAI. Meeting-point text may also be sent to DeepSeek to produce translated labels.
When a guide uses Experience Studio voice transcription or itinerary assistance, the submitted recording, transcript, instructions and relevant experience details are sent to OpenAI to provide that feature. Resulting transcripts and itinerary content are stored so the guide can review and use them. AI output can be inaccurate; check names, places and arrangements before relying on it.
Providers have different rules for retaining and using inputs. OpenAI’s published API policy excludes model training by default. DeepSeek’s published policy describes using inputs to improve and train its technology, and processing in China. The applicable service terms and settings govern provider processing. Avoid including unnecessary sensitive or confidential information in content that will be translated or submitted to AI features.
You can turn off automatic translation for your own account and choose not to use optional AI tools. This does not control a recipient’s translation settings or remove information already processed. Contact us about an existing record or an objection to processing.
7. Location and device permissions
Location. With foreground location permission, the app can obtain your position to identify your current city or help with relevant map features. You can enter a city manually instead. A selected or pasted meeting point can contain a place identifier, address, coordinates, link and directions, which we store and share as part of the relevant experience or conversation. A chosen meeting point is separate from continuous access to your device location.
AMap disclosure. AMap’s iOS map and search SDKs support map display and meeting-point selection after the app’s AMap disclosure is accepted. They can process search terms, map positions, place and coordinate information, IP address, device and operating-system details, SDK identifiers and network information needed to provide and secure those services. Location information is involved when you permit or supply it. AMap’s own policy, linked above, describes its processing, including in China. You may decline the optional AMap functionality.
Photos, camera and microphone. Access is used for the media you choose to select, capture, upload or record, such as a profile photo, message attachment or experience recording. Selected files can contain metadata. Media-library access does not mean we upload your entire library.
Notifications. Where notifications are available and authorised, we may store a device push token and preferences to deliver them. Availability varies by app version and service configuration.
You can manage camera, microphone, photo, location and notification permissions in iOS Settings. Denying or withdrawing a permission can limit the related feature. Changing a device permission does not automatically delete information previously submitted; see Section 12.
8. Diagnostics and website storage
The iOS app sends sanitised technical events, structured error information and crash reports to PostHog through our own relay. These use an opaque user identifier rather than a name, email or phone number. They remain personal information where they can be linked to an account. They help us investigate issues such as media failing to load or a screen crashing.
A limited sample of eligible Discovery sessions (currently 5%) can include session replay. Replay is restricted to the unobscured Discovery screen and configured to mask text, inputs and images and exclude raw network bodies and console capture. Authentication, onboarding, messaging, profile editing and payment surfaces are excluded. An explicitly started diagnostic support session can temporarily enable the same restricted replay for up to 15 minutes. This is not a recording of your camera or microphone.
The app also stores session credentials, cached content, preferences and diagnostic state on your device. Our marketing website uses local storage to remember a theme preference. Some website pages load fonts from Google, which receives the technical information needed to fulfil that request, such as your IP address. This Privacy Policy page loads no external fonts or session-replay scripts. Hosting and security providers still process ordinary request information when you visit.
We do not use advertising cookies or the app’s diagnostics to follow you across other companies’ apps or websites for targeted advertising. You can clear website storage in your browser; doing so may reset preferences. To object to app diagnostics or ask about a support recording, contact admin@cridgeai.com. Where local law requires consent for non-essential device storage or tracking, that requirement is separate from acknowledging this policy.
9. International processing
Cpal is operated from the United Kingdom and connects people traveling in China. Information may be accessed or processed in the United Kingdom, the European Economic Area, the United States, China and other countries where our providers or the people you interact with operate. PostHog diagnostics use its EU service; AMap, WeChat and DeepSeek can involve processing in China. Cloud and delivery networks can process requests across multiple locations.
International processing does not mean every country offers the same legal protections. Transfers subject to UK or EEA restrictions require a recognised legal mechanism: for example, an applicable adequacy decision, or contractual safeguards such as the European Commission’s standard contractual clauses with the UK addendum or UK international data transfer agreement where relevant. Limited legal exceptions may apply to transfers necessary to arrange the overseas service you specifically request. China is not covered by a general UK or EEA adequacy decision.
You can contact us for information about the destinations, transfer arrangements and any applicable safeguards for your information, including how to obtain a copy of relevant contractual safeguards. Acknowledging this policy is not general consent to every international transfer. We will seek separate consent or provide additional information where the law requires it, including for applicable sensitive-information or cross-border processing requirements in China.
10. Retention and deletion
We retain personal information for the purpose it serves, rather than applying one period to everything:
- Account, profile and onboarding records: while needed to provide or resume your account and services. When you ask to close your account or remove information, we assess and remove or anonymise information no longer needed, subject to the reasons below.
- Messages, media and service records: for the relevant conversation or service history, handling support and disputes, and protecting participants. We consider whether a booking or complaint is open, whether the record remains relevant to another participant, and applicable claim periods. Information that another user independently retains may remain with that user.
- Accounting and payment records: generally six years after the end of the last company financial year to which the record relates, or longer where tax law, an open investigation or a legal hold requires it. Account deletion does not erase legally required transaction records.
- Detailed fulfilment or payout evidence, where applicable: our finance retention schedule uses 24 months after the later relevant activity or case closure. Active disputes, payment reviews and legal holds can extend that period. Essential accounting records follow the longer accounting schedule.
- Verification and security records: codes have short validity periods; expiry makes a code unusable and does not itself mean every associated delivery or security record has been erased. Related records are retained as needed to prevent repeated abuse, investigate incidents and demonstrate verification.
- Diagnostics and support: for investigating the relevant issue and identifying recurring faults, taking account of incident severity, recurrence, the age of the record and whether identifying detail is still needed. A diagnostic recording window is distinct from how long its resulting diagnostic records remain stored.
Deletion can require coordinated removal from databases, media storage and providers. Restricted backups may retain information until they are replaced through backup rotation. Legal holds and other justified exceptions limit deletion to the information still needed; they do not justify retaining an entire profile indefinitely.
To request account or data deletion, email admin@cridgeai.com. You can make this request even if an in-app deletion control is unavailable. We will explain any information that must be retained and the reason.
11. Security
We use measures including encrypted connections, authenticated API access, restricted database and administrative access, server-side handling of provider credentials, verification controls and private storage for sensitive operational evidence. Access is limited according to the task and service involved. Public profile and listing content is intentionally available to its audience.
No system can guarantee absolute security. Keep verification codes and account credentials private, and contact us promptly if you believe an account or information has been compromised.
12. Your rights and choices
You can edit available profile fields and preferences in the app, manage device permissions in iOS Settings, and choose whether to use optional features. For other requests, email admin@cridgeai.com, including the phone number or email associated with your account and what you would like us to do. Do not send a password, payment card details or a verification code. We may request proportionate information to confirm your identity or an authorised representative’s authority.
Depending on your location, the type of information and our legal basis, your rights can include:
- Knowing whether and how we process your information, and obtaining access or a copy.
- Correcting inaccurate or incomplete information.
- Requesting deletion or restricting certain processing.
- Receiving eligible information in a portable format.
- Withdrawing consent where processing depends on it, without affecting the lawfulness of earlier processing.
- Questioning a significant automated decision and obtaining applicable human review.
Your right to object: you may object to processing based on legitimate interests, including related profiling, for reasons connected with your situation. You may object to direct marketing at any time. We will assess other objections under the applicable law and explain if there are overriding grounds to continue.
We respond within the time required by applicable law, ordinarily within one month for UK/EEA rights requests, subject to permitted identity checks, clarifications and extensions. We will explain a refusal or extension and how to challenge it. You will not be penalised for exercising an applicable privacy right.
If you are in mainland China, applicable rights can also include requesting an explanation of processing rules and restricting or refusing processing, as well as access, copying, correction, deletion and withdrawal of consent. Contact us through the same address to exercise these rights.
You can complain to the UK Information Commissioner’s Office, or the relevant data protection authority where you live or work. You do not need to contact us first, although we welcome the opportunity to address your concern.
13. Children
Cpal accounts and guide services are intended for adults aged 18 and over. We do not knowingly offer accounts to children. If you believe a child has provided information or created an account, contact us so we can investigate and take appropriate action, including deletion where required. Avoid including identifiable children in uploaded content or trip details unless there is a lawful and necessary reason to do so.
14. Updates and contact
We may update this policy when our services, providers or legal requirements change. The date and version at the top identify the current policy. For material changes, we will provide additional notice through the app, website or an appropriate service communication, and seek fresh consent where required.
Cpal privacy team · ZHAI LTD
For privacy questions, access, correction, objections or deletion requests:
admin@cridgeai.com