RebateTrail Privacy Policy
Effective Date: April 7, 2026
Last Updated: August 8, 2026
Welcome to RebateTrail (hereinafter referred to as “the Platform” or “we”). The Platform is operated by Mantu (Shanghai) Travel Consulting Co., Ltd. (缦途(上海)旅游咨询有限公司, registered address: Building 1-3, No. 63 Liantai Road, Baoshan District, Shanghai; hereinafter referred to as “the Company”). We fully understand the importance of your personal information and will do our utmost to protect the security of your personal information. This Privacy Policy (hereinafter referred to as “this Policy”) is intended to explain how we collect, use, store, share, and protect your personal information, as well as how you can manage your personal information.
Please carefully read and fully understand this Policy before using the Platform’s services. If you do not agree with any part of this Policy, you should immediately stop using the Platform’s services. By using the Platform’s services, you acknowledge that you have fully understood and agreed to this Policy.
This Policy applies to the processing of personal information you provide through the Platform’s website (rebatetrail.com), the WeChat Mini Program, the Alipay Mini Program, the iOS and Android mobile applications, and related services.
Summary of This Update
This update introduces one optional feature that you switch on yourself — automated recognition of booking confirmations — and explains the processing it involves. Because the feature passes images you upload to a new third-party service provider, it falls under Section 8.1 of this Policy; we therefore explain it and obtain your confirmation the first time you enable it after each visit to the cashback request page. If you never enable it, this update introduces no new processing of your information. The main changes are:
- A new section on the information processed by the automated booking-confirmation recognition feature, how it is processed and how long it is kept (see 1.9)
- A third-party artificial intelligence service provider added to the sharing list and to the third-party service list (see 3.1 and 3.5)
- A note in the retention table that images used for recognition are not stored (see 2.2)
- Confirmation that the feature does not involve providing personal information outside China (see 3.4)
1. How We Collect and Use Your Personal Information
We collect and use your personal information only to the extent necessary to fulfill the purposes described in this Policy. The following outlines the specific scenarios and purposes for which we collect personal information:
1.1 Registration and Login
When you register an account on the Platform, we collect the following information:
- Email address (required): used for account registration, identity verification, and receiving notifications
- Login password: stored in an irreversible encrypted form (bcrypt hash); we cannot access your plaintext password
- Display name (optional): used for display within the Platform
When you choose to log in via WeChat, with your authorization, we obtain the following information from WeChat:
- WeChat UnionID and OpenID: used to identify your WeChat identity and associate it with your Platform account
- WeChat nickname and avatar: used to display your account information
- Publicly available WeChat region and gender information: used to provide better localized services
When you log in within the Alipay Mini Program, with your authorization we obtain your Alipay user identifier through the Alipay Open Platform, used to identify your Alipay identity and associate it with your Platform account.
When you choose to sign in with a Google account, with your authorization, we obtain the following information from Google:
- Google account unique identifier and email address: used to create or associate your Platform account
- Google account display name and avatar: used to display your account information
When you choose Sign in with Apple, with your authorization, we obtain the following information from Apple:
- Apple user identifier: used to create or associate your Platform account
- Email address: if you select “Hide My Email” during authorization, what we receive is the private relay address generated by Apple, not your real email address
- Name: provided by Apple only once, at your first authorization, and used to set your display name
When you register or sign in using a passkey:
- We store only your public key credential and its identifier. The private key used to generate signatures, and the fingerprint, face, or other biometric information used to unlock it, remain on your device or in the password manager you have chosen; we do not collect them and are technically unable to obtain them
1.2 Using Platform Services
When you use the cashback services, we collect the following information:
- Booking information: including booking reference number, check-in date, hotel brand, source platform, etc., used to verify your booking and calculate cashback
- Cashback preferences: including your preferred currency and language settings
1.3 Withdrawal and Payment
When you apply for a withdrawal, we need to collect the following information:
- Payment account information: including bank account, Alipay account, or WeChat Pay account and other payment information, used solely by the Agent to distribute cashback to you
- Alipay binding information: when you bind an Alipay payout account, with your authorization we obtain, through the Alipay Open Platform, your Alipay user identifier (open_id) and account real-name information, used to verify the identity of the payee and distribute cashback to you
- Transaction records: including cashback credits, withdrawal applications, balance changes, etc., used to maintain your financial records
1.4 Security and Risk Control
To safeguard the security of your account and the operation of the Platform, we automatically collect the following information:
- Device and network information: including IP address, operating system and version, device model, and application or Mini Program version; when accessed via the web, also browser type and version
- Login records: including login time, login method, session information, etc.
- Verification code records: records of one-time verification codes sent during email verification or password reset
1.5 Notifications and Communications
- Notification preferences: you may choose to receive in-app notifications and/or email notifications
- Notification content: including cashback status changes, withdrawal progress, referral rewards, and other Platform messages
1.6 Referrals and Rewards
When you participate in the referral program:
- Referral relationships: records of the association between referrers and referred users
- Referral code: the referral code you set
- Reward records: the triggering conditions and distribution status of referral rewards
1.7 Device Permissions in the Mobile Applications and Mini Programs
When you use the mobile applications or Mini Programs, we request the following permission only at the moment the corresponding feature is triggered. You may decline; declining affects only that feature and does not affect your use of other services:
| Permission | When requested | Purpose |
|---|---|---|
| Photo library | When you need to upload a booking screenshot for a cashback claim; when you send an image in a support conversation | To read the image you actively select and upload it to the Platform |
We do not request access to contacts, location, microphone, camera, calendar, or SMS. The mobile applications currently do not include push notifications, and we do not collect device push tokens.
You may withdraw the above authorization at any time in your operating system or Mini Program settings.
1.8 Information About You That We Receive From Third Parties
To verify that the booking you submitted actually took place and to adjudicate cashback accordingly, we receive booking and commission records from an overseas hotel commission settlement data source (the third-party system the agent uses to reconcile with upstream suppliers). Such records may contain the following information about you:
- Guest name
- Check-in and check-out dates
- Booking reference, hotel name and location, room rate, commission amount, and source channel
With respect to such information, we specifically note the following:
- Origin of the information: it was provided by you to the hotel or booking channel when you made the reservation, and was aggregated into the settlement system by upstream suppliers. Its creation and original storage do not originate from this Platform
- The flow is inbound only: we read such records from those systems and store them on servers within mainland China, in order to match them against the cashback claims you submit. We do not transfer any personal information generated on this Platform abroad as a result — a read request carries only the agent’s own settlement payee identifier and a query date range, and contains no user personal information. This scenario therefore does not constitute the provision of personal information abroad described in Section 3.4
- Minimization: we retain only the fields relevant to cashback adjudication, managed according to the retention periods in Section 2
1.9 Automated Recognition of Booking Confirmations (Optional Feature)
When submitting a cashback request, you may upload a screenshot of a booking confirmation email or an order list and have the system read the booking details from it and pre-fill the form. The feature is optional and you may switch to filling the form in by hand at any time. Before it is enabled, the processing described in this section is set out to you separately, and processing begins only once you have confirmed.
- Information processed: the image you upload and the information it contains, which may include the guest name, booking confirmation number, check-in and check-out dates and hotel name
- How it is processed: the image is transmitted over an encrypted connection to a third-party artificial intelligence service provider, which reads the text in it and returns the booking details in structured form
- Processing and retention by that provider: according to its published policy, input and output are processed in memory for the duration of the request only, are not written to persistent storage after the response is returned, and are not used for model training; the provider logs metadata such as token usage, timestamps and request identifiers for billing and rate limiting. We additionally disable conversation retention explicitly on every call
- Retention by us: the image exists only in server memory for the duration of the recognition. It is written neither to our database nor to object storage and is released once recognition finishes or fails. The details returned are placed into the form and are not saved until you confirm and submit
- Our call records: we record the time of the call, your account identifier, the size and format of the image, the outcome of the recognition, the number of bookings found, and the token usage of the call (for cost accounting). We record neither the image itself nor the details recognised from it
- Scope of the upload: everything contained in the image is submitted for recognition. Do not upload information unrelated to the booking, such as identity document numbers, bank card numbers or passport details
2. How We Store Your Personal Information
2.1 Storage Location
Your personal information is stored on cloud servers and cloud databases located within the People's Republic of China (Shanghai). We use encrypted transmission (TLS/SSL) to ensure the security of data during transit.
Static web pages served to visitors outside mainland China are delivered by an overseas content delivery network (CDN); those pages contain no personal information. All business data generated after you log in continues to be processed by servers within mainland China and stored in databases located there.
2.2 Retention Period
We retain your personal information for the minimum period necessary to fulfill the purposes described in this Policy:
| Information Type | Retention Period | Description |
|---|---|---|
| Basic account information | Duration of account plus 30 days after deactivation | Grace period after deactivation to allow you to withdraw your deactivation request |
| Transaction and financial records | 3 years from the date of transaction completion | In accordance with the Accounting Law of the People’s Republic of China and other legal requirements |
| Login session information | 90 days | For security audit purposes |
| Verification code records | 30 days after expiration | Automatically cleared |
| Notification messages | Duration of account | You may delete read notifications at any time |
| Customer support conversations | 24 hours on this Platform | The entire conversation, including any uploaded images, is deleted 24 hours after its last message |
| Booking screenshots used for automated recognition | Not stored | Held in memory for the duration of the recognition and released once it finishes or fails (see 1.9) |
2.3 Processing After Account Deactivation
When your account is deactivated (including voluntary deactivation and closure due to prolonged inactivity), we will:
- Delete or anonymize your personally identifiable information after a 30-day grace period
- Transaction records required to be retained by law will be deleted after the statutory retention period expires
- Anonymized data no longer constitutes personal information and may continue to be used by us
- Support conversation content already forwarded to our Feishu (Lark) workspace is not deleted as part of deactivation; it remains subject to Feishu's own data retention policy
3. How We Share, Transfer, and Publicly Disclose Your Personal Information
3.1 Sharing
We do not sell your personal information to third parties. We share your personal information with third parties only in the following circumstances:
| Third-Party Type | Information Shared | Purpose of Sharing |
|---|---|---|
| Email service provider | Email address, email content | Sending verification codes and notification emails |
| WeChat Open Platform | Authorization code (one-time use) | Enabling WeChat login functionality |
| Alipay Open Platform | Authorization code (one-time use), Alipay user identifier (open_id) | Alipay Mini Program login gating and Alipay payout-account binding |
| Apple | Authorization code and identity token (one-time use) | Enabling Sign in with Apple |
| Authorization code (one-time use) | Enabling Google Sign-In | |
| Cooperating agent | Payment account information, withdrawal application information | Agent distributes cashback to you |
| Content delivery network (CDN) provider | IP address and request headers of the access request (no account information) | Delivering static pages to visitors outside mainland China and mitigating network attacks |
| Exchange rate service provider | Currency pair information (no personal information) | Obtaining reference exchange rates |
| Feishu (Lark) | Content you submit in a support conversation (text, images), together with the account identifiers used to locate your account (user ID, display name, email address) | Enabling our staff to answer your enquiry from within Feishu |
| Third-party artificial intelligence service provider | The booking screenshot you upload and the information it contains | Reading the booking details from the image to pre-fill your cashback request |
All third-party service providers are bound by contractual obligations and may only use your personal information to the extent necessary to provide services to us.
Note on the hotel commission settlement data source: information flows between the Platform and those systems in one direction only — inbound. We read booking and commission records from them and do not provide your personal information to them. That scenario is not “sharing” as used in this section; see Section 1.8.
Note on customer support conversations: content you submit through the support entry point is forwarded to our internal workspace on Feishu (Lark) so that our staff can respond. We delete the copy stored on this Platform 24 hours after the conversation ends, but the copy held by Feishu is governed by Feishu's own data retention policy and is not removed by our clean-up. So that our staff can locate your account and answer accurately, the first message of each support conversation carries your user ID, display name and email address. Please do not submit sensitive personal information that is not relevant to your enquiry.
3.2 Transfer
In the event that the Company undergoes a merger, acquisition, asset transfer, or similar transaction involving the transfer of your personal information, we will require the new holder to continue to be bound by this Policy; otherwise, we will require them to obtain your authorization and consent anew.
3.3 Public Disclosure
We will not publicly disclose your personal information, except in the following circumstances:
- With your explicit consent
- When required by laws, regulations, legal proceedings, litigation, or competent government authorities
3.4 Cross-Border Transfer
The Platform’s databases and primary servers are located within the People’s Republic of China. In the course of providing services to you, the following scenarios may involve the transfer of certain information outside of China:
- Email delivery services: When sending you verification codes and notification emails, your email address and email content will be transmitted to overseas email service providers
- Google Sign-In: When you choose this method, the authorization flow completes on Google’s services, and the authorization code and your Google account information pass through overseas servers
- Sign in with Apple: When you choose this method in the iOS application or on the web, authentication completes on Apple’s services
- Page delivery for overseas access: When you access the Platform’s website from outside mainland China, static pages are served by an overseas CDN, which processes your IP address and request headers
- Exchange rate query services: When querying reference exchange rates, only currency pair information is transmitted, which does not involve personal information
On automated recognition: the recognition described in Section 1.9 is performed by a provider whose servers are located within the People's Republic of China. It does not involve providing personal information outside China.
To be distinguished from the above: the receipt of booking and commission records from an overseas settlement data source, described in Section 1.8, flows from outside into mainland China and constitutes our obtaining information from a third party. It does not constitute the provision of personal information abroad, and does not send any personal information generated on this Platform outside of China.
We will comply with the relevant provisions of the Personal Information Protection Law of the People’s Republic of China to ensure adequate protection of your personal information during cross-border transfers, including but not limited to:
- Limiting cross-border transfers of personal information to the minimum scope necessary to achieve the service purpose
- Adopting necessary security measures such as encrypted transmission
- Entering into data processing agreements with overseas recipients to stipulate their data protection obligations
3.5 Third-Party SDKs and Services We Integrate
We integrate the following third-party SDKs and services across the website, Mini Programs, and mobile applications. Their handling of information is also governed by their respective privacy policies:
| SDK / Service | Applies to | Information that may be processed | Purpose |
|---|---|---|---|
| WeChat Open Platform | WeChat Mini Program, web, mobile applications | WeChat login credential (one-time code), UnionID / OpenID, nickname and avatar | WeChat login |
| Alipay Open Platform | Alipay Mini Program, web, mobile applications | Authorization code (one-time), Alipay user identifier, verified account name | Alipay login gating, payout-account binding |
| Sign in with Apple | iOS application, web | Apple user identifier, email address, name provided at first authorization | Apple account sign-in |
| Google Sign-In | Web, mobile applications | Google account identifier, email address, display name and avatar | Google account sign-in |
| Expo / React Native core modules | iOS and Android applications | Device model, system version, application version; images you actively select | Running the application, storing login credentials encrypted in the system keychain / keystore, and selecting and uploading images |
| Object storage service | All platforms | Booking screenshots and support images you upload | Storing the images you actively upload |
| Artificial intelligence recognition service | Web | The booking screenshot you upload and the information it contains | Automated recognition of booking confirmations (see 1.9) |
We do not integrate any advertising, analytics, or user-profiling SDKs.
4. How We Protect Your Personal Information
We adopt the following technical and administrative measures to protect the security of your personal information:
4.1 Technical Measures
- Encryption in transit: all data transmissions use TLS/SSL encryption
- Password security: user passwords are stored using the bcrypt algorithm in an irreversible encrypted form
- Access tokens: login credentials use randomly generated session tokens with a validity period of 7 days
- Database security: database connections are mandatorily encrypted with channel binding authentication enabled
4.2 Administrative Measures
- Strictly limiting the scope of personnel authorized to access personal information
- Providing security training to employees who may come into contact with personal information
- Establishing data security incident emergency response procedures
4.3 Security Incident Response
In the unfortunate event of a personal information security incident, we will, in accordance with the requirements of laws and regulations, promptly inform you of the basic circumstances of the security incident, its potential impact, the remedial measures we have taken or will take, and recommendations for you to independently prevent and mitigate risks. We will promptly notify you through push notifications, email, and other means.
5. Your Rights
In accordance with the Personal Information Protection Law of the People’s Republic of China (PIPL) and related laws and regulations, you enjoy the following rights with respect to your personal information:
5.1 Access and Copying
You have the right to access and copy your personal information. You may view your account information, transaction records, and notification preferences by logging into your Platform account.
5.2 Correction and Supplementation
When you discover that the personal information we process about you is inaccurate, you have the right to request that we correct or supplement it. You may directly modify certain information through the Platform settings or contact us for assistance.
5.3 Deletion
You may request the deletion of your personal information in the following circumstances:
- The processing purpose has been achieved, cannot be achieved, or the information is no longer necessary for achieving the processing purpose
- We have ceased to provide services, or the retention period has expired
- You withdraw your consent
- We process personal information in violation of laws, regulations, or our agreements with you
Please note: information that is required by laws and regulations to be retained (such as transaction records) will be deleted after the statutory retention period expires.
5.4 Account Deactivation
You have the right to deactivate your Platform account. After deactivation, we will process your personal information in accordance with Section 2.3 of this Policy.
Before deactivation, please note:
- Your account balance will be cleared upon deactivation; please complete any withdrawals in advance
- Pending cashback applications will no longer be processed
- Deactivation is irreversible (except during the grace period)
5.5 Withdrawal of Consent
You have the right to withdraw your previously given consent. Withdrawal of consent does not affect the validity of the processing of personal information carried out based on your consent prior to such withdrawal.
5.6 Personal Information Portability
Subject to the conditions prescribed by laws and regulations, you have the right to request the transfer of your personal information to another personal information processor designated by you.
5.7 How to Exercise Your Rights
You may exercise the above rights through the following means:
- In-Platform actions: manage settings after logging into your account
- Email: send your request to privacy#rebatetrail.com (please replace # with @)
We will respond to your request within 15 business days of receipt.
VI. Cookies, Local Storage, and Tracking Technologies
6.1 Cookies on the Web
The Platform’s website only uses the following essential cookies and does not use any third-party tracking or advertising cookies:
| Cookie Name | Purpose | Type | Duration |
|---|---|---|---|
rt_session | Maintaining your login session | httpOnly (not accessible by JavaScript) | 7 days |
i18nextLng | Remembering your language preference | Standard cookie | 1 year |
6.2 Local Storage in the Mini Programs and Mobile Applications
The Mini Programs and mobile applications do not use cookies. Instead, we keep the following in your device’s local storage:
| Stored item | Purpose | Where it is kept |
|---|---|---|
| Login session token | Maintaining your login state | Mobile applications: the operating system keychain / keystore (encrypted); Mini Programs: Mini Program local storage |
| Language and theme preference | Remembering your interface settings | Application / Mini Program local storage |
You can clear the above by logging out, deleting the application, or clearing the Mini Program cache.
6.3 What We Do Not Do
The above cookies and local storage are essential for the normal operation of the Platform and are not used to collect your browsing behavior or create user profiles. We do not use third-party tracking tools or advertising tracking technologies, do not collect device advertising identifiers (such as IDFA or OAID), and do not engage in personalized advertising.
7. Protection of Minors
The Platform provides services exclusively to adults aged 18 and above. We do not knowingly collect personal information from minors under the age of 18. If we discover that we have collected personal information from a minor without verifiable parental or guardian consent, we will promptly delete the relevant information.
8. Revisions to This Policy
We may revise this Policy from time to time. The revised Policy will be published on the Platform with an updated date noted.
Revisions fall into two categories, which we handle differently:
8.1 Changes Requiring Your Consent Again
In any of the following circumstances, we will notify you through Platform announcements, email, or pop-up notifications before the change takes effect, and obtain your consent again. The new processing will not begin until you have made your choice:
- We begin collecting a new type of personal information, in particular sensitive personal information
- We change the purpose or the means of processing personal information
- We provide your personal information to a new third party
- We provide your personal information outside of mainland China
8.2 Changes Requiring Advance Notice Only
In any of the following circumstances, we will inform you through Platform announcements, in-app notifications, or email, without separately seeking consent:
- Clarification, elaboration, or corrected wording regarding existing processing activities, where the purpose, means, and categories of personal information remain unchanged
- The addition of an optional feature that collects information only when you actively trigger it (for example, a new third-party sign-in method) — your choice to use that feature constitutes your consent to that particular collection
- Replacement of a third-party service provider with an equivalent one, where the categories of information processed and the purpose remain unchanged
- Updates to non-substantive details such as the names of laws and regulations or the Company’s contact information
If you do not agree with the revised Privacy Policy, you may choose to stop using the Platform’s services and deactivate your account.
9. Contact Us
If you have any questions, comments, or suggestions regarding this Policy, or wish to exercise your personal information rights, please contact us through the following means:
- Company name: Mantu (Shanghai) Travel Consulting Co., Ltd. (缦途(上海)旅游咨询有限公司)
- Registered address: Building 1-3, No. 63 Liantai Road, Baoshan District, Shanghai (上海市宝山区联泰路63号1-3幢)
- Privacy contact email: privacy#rebatetrail.com (please replace # with @)
We will respond to your request within 15 business days. If you are not satisfied with our response, you may also file a complaint with the personal information protection authority in Baoshan District, Shanghai (上海市宝山区).