Overlap

Overlap

Privacy Policy

Last updated August 17, 2026

The short version: Overlap collects the information it needs to match your trip against other travelers' trips and operate the features you choose to use. We never collect a child's name or birthdate, only a coarse age range, and we don't sell your data. Before a connection, other travelers see only the profile and overlap information allowed by your visibility settings; private details remain gated.

Who this policy covers

This policy explains how Overlap ("Overlap," "we," "us") handles personal information for anyone who creates an account or uses overlaptrip.com (the "Service"). By using the Service, you agree to the collection and use of information as described here. If you don't agree, please don't use the Service.

Overlap is a small, independently run product. If anything here is unclear, email us at hello@overlaptrip.com — a real person reads it.

Information we collect

Account information

  • Email address and a hashed password (we never store your password in plain text and can't see it ourselves).
  • Whether your email has been verified.
  • If you choose to contact another traveler and phone verification is enabled: the mobile number you submit is sent to Google Identity Platform so Google can send and verify an SMS code. Overlap does not keep the full raw phone number in its normal user record after verification; we keep the verification time, a one-way keyed fingerprint used to prevent one number from verifying multiple active accounts, the last four digits, and the provider's user identifier.

Travel party profile

  • Display name for your travel party (e.g., "The Millers"), party type (couple, family, friends, etc.).
  • Home city, state/region, and country.
  • Optional profile photo, bio, languages, and travel-style tags.
  • For each adult traveler in your party: an optional first name, an age range, and their relationship to the party.

Children in your travel party

If you travel with kids, we ask only for a broad age-range label (for example, "3–5" or "10–12"). We do not collect and do not have a field for a child's name, birthdate, photo, or exact age anywhere in the product. This is deliberate: age-range matching is enough to tell another family "kids in a similar age range," and we'd rather not hold data we don't need.

Trip and itinerary information

  • Destinations (city, region, country) and the arrival/departure dates for each stop on a trip.
  • A general accommodation area if you choose to add one (e.g., a neighborhood) — we do not ask for and do not store your exact hotel, room number, or address.
  • Who you'd like to meet: party types, adult/child age-range filters, home-country filter, and activity preferences you set for a trip.

OPAL conversations

If you choose to use OPAL (Overlap Personal Assistant & Logistics), the itinerary text you type into the OPAL box is sent to Google Cloud's Vertex AI service so OPAL can turn it into a proposed trip draft or ask a clarifying question. OPAL is optional. We do not intentionally send your account email, password, messages with other travelers, or child-specific personal information to OPAL. We also ask you not to paste passport details, booking confirmations, exact hotel addresses, or other sensitive information into the box.

OPAL conversation text is not stored in our product analytics. We record only coarse operational facts such as the number of turns, character count, whether OPAL needed clarification, the number of proposed stops, and the model used. A proposed OPAL itinerary does not become a saved trip until you choose to apply it, review the normal trip form, and submit that form.

Connections and messages

When you and another party both express interest, we create a connection and store the messages you exchange through it. Messages are visible to the two parties in that connection and to Overlap staff only as needed for safety investigations (see "Trust & safety" below).

Notifications

We store your notification preferences (which types of alerts you want) and, if you opt in to browser push notifications, the push subscription your browser gives us (an endpoint URL and encryption keys — not readable content). You can revoke this at any time from your browser or in Settings.

Usage and device information

We log lightweight product-analytics events (e.g., "trip created," "connection accepted") to understand how the Service is used, and short-lived rate-limiting records (IP address, email, phone-number fingerprint, or an internal account identifier tied to a timestamp) on sensitive or resource-intensive endpoints to block brute-force, spam, SMS pumping, and abuse. Rate-limit records exist only to enforce request limits and age out automatically.

Google Places lookups

Overlap may send destination or recommendation search terms to Google Places to standardize trip locations, find named places that fit a trip or accepted connection, and retrieve place photos and attribution. We use that data for destination matching and optional travel/meetup suggestions; we do not send your private messages to Google Places. See "Third parties" below.

How we use your information

  • To operate the core product: matching your trips against other travelers' trips using the deterministic rules described in your account and preferences.
  • To provide optional features you request, such as using OPAL to turn your itinerary language into a reviewable trip draft.
  • To let you and a connected party communicate.
  • To verify control of a mobile number before social interactions when the phone trust check is enabled, and to deter spam, duplicate accounts, and SMS abuse.
  • To send account, connection, and match-related emails and (if enabled) push notifications.
  • To secure the Service: rate limiting, fraud/abuse prevention, and investigating reports.
  • To understand aggregate usage and improve the product.

We do not use your data to train third-party AI models, and we do not run behavioral advertising.

What other travelers can see

Overlap is built so strangers see the minimum needed to decide if they want to connect:

  • Before you connect: your party's display name, party type, trip destinations and overlap dates, plus the additional profile details your visibility setting permits. A connections-only profile appears as a deliberately limited match preview until you accept a connection; a nobody profile is not discoverable.
  • If your account has completed phone verification, other travelers may see a 'Phone verified' indicator beside your travel-party name. They never see your phone number or its last four digits.
  • Children are represented only by coarse age-range information used for family matching — never a name or exact age — and those age bands are withheld from a connections-only preview.
  • Your exact accommodation, if you added a general area, is only ever a neighborhood-level label, never an address.
  • Messages are only visible to the two parties in a connection, never shown publicly or to other users.

Third parties we work with

We use a small set of infrastructure providers to run Overlap. Each one processes data only as needed to provide its service to us, under its own privacy terms:

  • Vercel — application hosting and serverless infrastructure.
  • Neon — our Postgres database provider, where account and trip data is stored.
  • Resend — sends transactional email (verification, password reset, connection and match notifications) on our behalf.
  • Vercel Blob — stores uploaded profile photos.
  • Google Identity Platform / Firebase Authentication — when phone verification is enabled and you choose to enter the social layer, processes the mobile number and anti-abuse challenge needed to send and verify an SMS code. Other travelers never receive the number from Overlap.
  • Google Places API — standardizes destination searches and supplies named-place/photo data for optional trip recommendations and meetup ideas. The relevant destination or recommendation search terms are sent to Google for these lookups.
  • Google Cloud Vertex AI — processes the itinerary text you deliberately submit to OPAL so it can propose structured trip details or ask a clarifying question. OPAL is optional and is not used to send messages or take actions on your behalf.

We do not sell your personal information to anyone, for any reason.

Data retention

We keep your account and trip data while your account is active. If you delete your account from Settings, we immediately disable the account, remove its profile from discovery, delete its uploaded profile photo and device notifications, clear its stored phone-verification proof, remove profile details such as names, home location, age ranges and interests, strip optional trip descriptions/accommodation details, and detach product analytics from your account. We retain anonymized message/connection history and limited trip context when another traveler needs that history to remain understandable. Safety reports, moderation records, and records we are legally required to keep may also be retained as needed. Short-lived rate-limit records age out automatically.

How we protect your information

  • Passwords are hashed (never stored in plain text) and never visible to Overlap staff.
  • Sessions use a signed, HttpOnly cookie — it isn't readable by page scripts and isn't sent to third parties.
  • When enabled, phone verification is required before sending or accepting a connection or sending a message; the social trust gate is enforced on the server, not only in the interface.
  • Uploaded photos are validated against their actual file contents, not just the filename, before being accepted.
  • Authentication and resource-intensive endpoints are rate-limited to slow down credential-stuffing, brute-force attempts, spam, and SMS abuse.

No system is perfectly secure, and we're a small team — if you believe you've found a vulnerability, please email hello@overlaptrip.com before disclosing it publicly, and we'll respond promptly.

Your choices and rights

  • Access and correct your profile and trip information at any time from your account.
  • Control who can see your party via the profile visibility setting.
  • Choose whether to use optional features such as OPAL; manual trip entry remains available.
  • Explore trips and overlaps without providing a phone number; phone verification is requested only when you attempt to enter the social layer, when that trust check is enabled.
  • Turn off email or push notification categories individually in Settings.
  • Request a copy of your data or deletion of your account by emailing hello@overlaptrip.com — we'll confirm identity and act within 30 days.
  • Block, unblock, or report another user through Overlap's trust controls.

If you are located in a jurisdiction that grants additional rights (for example, the EU/UK GDPR or a U.S. state privacy law), those rights apply to you in addition to the above; contact us to exercise them.

Children's accounts

Overlap accounts are for adults (see the age requirement in our Terms of Service). Children are represented in the product only as a coarse age range attached to a parent's travel-party profile — never as their own account, and never with a name, photo, or birthdate. Overlap is not directed at children and does not knowingly collect personal information directly from a child.

Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page and, for significant changes, notify you by email.

Contact

Questions about this policy or your data: hello@overlaptrip.com.

This policy is a good-faith, plain-language description of how Overlap actually works today. It is not a substitute for advice from a licensed attorney, and it will be reviewed by one before any large-scale marketing push.