Privacy Policy
Effective Date: August 31, 2026 — Last Updated: August 31, 2026
This Privacy Policy explains how MGChufa LLC (“Mesh,” “we,” “us,” or “our”), a Wyoming limited liability company, collects, uses, shares, and protects information about you when you use the Mesh website (gomesh.app), mobile applications, and related services (collectively, the “Service”).
Mesh is a curated, invitation-only platform that helps entrepreneurs find co-founders, connect with other members, attend member-hosted events and retreats, discover vendors, and access private concierge services. Because the Service is built around connecting people with one another, please read this Policy carefully so you understand what is shared with other members versus what we keep private.
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Service.
1. Who We Are and How to Contact Us
The data controller responsible for your information is:
MGChufa LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Privacy inquiries: privacy@gomesh.app
General and support inquiries: support@gomesh.app
2. Information We Collect
2.1 Information You Provide to Us
- Account and registration data: name, email address, phone number, password, and (where required) date of birth to confirm you are at least 18. Creating an account requires a valid, unused invite code.
- Profile information: your professional background, industry, skills, company or venture details, the type of co-founder or connection you are seeking, location/city, photos, links (e.g., LinkedIn, company website), and any other content you choose to add.
- Identity verification data: information and documents you submit to obtain a verification badge, processed through Stripe Identity (see Section 4).
- Host verification call data: if you apply to host a retreat, adventure, or event, notes from — and, where applicable, a recording of — the verification phone call between you and Mesh, used to confirm your identity and that the listing is genuine (see Section 4).
- Invite data: the invite code you signed up with, invite codes you receive as a member and their redemption status, and the identities of members you invite or who invited you, used to administer the invite program described in Section 4.
- Retreat data:if you host or attend a member-hosted retreat, we collect retreat reservations and payments, your role (host or attendee), the Airbnb reservation-confirmation email you forward to us (which may include the host's and other participants' information and Airbnb booking details), confirmations and attestations you submit at each stage (booking confirmed, added as a guest, arrival), the Host's warranty that the retreat is real (see Section 4), and payout information for hosts. Retreat funds are processed and held by Stripe, not Mesh.
- Concierge and vendor booking data: if you request a private concierge booking (such as a luxury car rental, yacht, or private chef), the details of your request (dates, preferences, party size, contact information) and any information needed to complete the booking with the third-party vendor providing the service.
- Content and communications: messages you send to other members, posts, event listings you create or RSVP to, vendor inquiries, and information you provide when you contact support, submit a refund request, or report another user.
- Survey and waitlist data: information you submit when joining a waitlist, completing a survey, or participating in early-access programs.
2.2 Information We Collect Automatically
- Usage data: features you use, matches and connections you make, events you view or attend, search activity, invite activity, and interaction patterns.
- Device and technical data: IP address, device type, operating system, browser type, app version, identifiers, and crash/diagnostic data. (We also use IP-based location to enforce the geographic restrictions in Section 1.)
- Location data: approximate location from your IP address, and — only with your permission — more precise location from your device, used mainly for local-first matching and nearby events. You can disable precise location in your device settings.
- Cookies and similar technologies: see Section 7.
2.3 Information From Third Parties
- Social or single sign-on logins (e.g., Google, Apple, LinkedIn): basic profile details that platform shares with us.
- Stripe Identity: identity verification results.
- Stripe (payments): confirmation of transactions and limited billing metadata.
- Concierge vendors: confirmation of bookings you request through the private concierge service.
- Analytics partners: aggregated or device-level data about how you reach and use the Service.
3. How We Use Your Information
We use your information to: create and manage your account and profile; verify and administer invite codes and invite rewards; power co-founder matching, member discovery, and local-first recommendations; enable member-hosted events and vendor matching; operate member-hosted retreats, including verifying booking and arrival stages, instructing Stripe on rule-based fund releases, processing host payouts, and defending payment disputes and chargebacks; verify members and prospective hosts (including through verification phone calls) and issue badges; arrange and facilitate private concierge bookings with third-party vendors on your behalf; detect and prevent invite abuse, host fraud, and other fraud; process payments and refund requests; enable member-to-member messaging; keep the Service safe; provide support; send service-related and (where permitted) marketing communications you can opt out of; analyze and improve the Service; enforce our Terms; and comply with legal, tax, and regulatory obligations.
4. Identity Verification, Host Verification, Badges, and the Invite Program
Identity verification. We use Stripe Identity to verify member identities and issue verification badges. When you verify, your identity documents and related data are collected and processed by Stripe under its own privacy practices (https://stripe.com/privacy). A verification badge confirms only that a specific, limited check was completed. It is not a guarantee of any member's identity, character, trustworthiness, qualifications, or intentions, and it is not an endorsement. You remain responsible for your own diligence before entering any business, financial, or personal relationship with another member.
Host verification calls.During Mesh's early growth phase, before a member may host a retreat, adventure, or event, Mesh may conduct a phone call with that member to verify their identity and confirm the listing is genuine, in addition to Stripe Identity checks. These calls may be recorded, and we will tell you before the call begins if it is being recorded. We keep notes and any recording as described in Section 9. Completing this call does not guarantee approval to host; Mesh may decline at its discretion.
Invite program. Mesh is invitation-only: you need a valid, unused invite code from an existing member (or from Mesh) to create an account. As a member, you may earn additional invite codes to give to people you know: by default when you join, by completing your profile, by adding a verified business email, by hosting an adventure or event, and by hosting a retreat. Invite codes are single-use, do not expire, and may only be used by the person they were issued to — they cannot be transferred, sold, purchased, or otherwise monetized. We process the invite code you used to join, the codes you hold or redeem, and the identities of members connected through invites to administer the program, calculate reward eligibility, and prevent abuse. If a member you invited is removed from the Service for cause, we may take that into account when evaluating your own account, and we retain full discretion over who may join or remain on Mesh.
5. Legal Bases (Where Data-Protection Law Requires)
Where a comprehensive data-protection law applies to your use of the Service, we rely on these bases: contract (to provide the Service and the invite program); consent (for precise location, host verification call recording, and certain marketing, withdrawable at any time); legitimate interests (to operate, secure, and improve the Service and prevent fraud); and legal obligation (including tax and anti-fraud requirements).
6. How We Share Information
- With other members: your profile, photos, and chosen content are visible to other members per your settings; messages, posts, event listings, and vendor inquiries are seen by the members you interact with. Anything you share with another member is outside our control once shared.
- Event hosts: your name and RSVP details when you attend their event.
- Retreat hosts and co-attendees:if you host or join a retreat, your identity and relevant reservation details are shared with the retreat's host and, as needed, with other attendees (for example, to add you as a named guest on the lodging reservation). Hosts receive attendee information needed to organize the retreat.
- Concierge vendors: when you request a private concierge booking (car rental, yacht, or private chef), we share the information needed to complete that booking — such as your name, contact details, dates, and preferences — with the third-party vendor providing the service. The vendor, not Mesh, is the merchant of record for that booking and is responsible for delivering it.
- Stripe: for identity verification, payments, and retreat fund custody and payouts.
- Service providers: vendors who host, support, analyze, secure, or operate the Service on our behalf, under confidentiality and data-protection obligations.
- Legal and safety: to comply with law, respond to lawful requests, enforce our Terms, or protect Mesh, our members, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets.
We do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising (targeted advertising based on your activity across different sites and services). We do not use non-essential advertising cookies or similar technologies, and we do not pass identifiers, device data, or usage activity to advertising networks or ad-tech partners.
7. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service, remember preferences, keep you signed in, track invite attribution, and analyze usage on an aggregate, internal basis. We do not use non-essential cookies for third-party advertising, and we do not share cookie or usage data with advertising networks or ad-tech partners. You can manage cookies through your browser or device settings; blocking some cookies may affect how the Service works.
8. Your Privacy Rights
Depending on where you live (including under California's CCPA/CPRA and other US state privacy laws), you may have the right to access, correct, delete, or port your information; to opt out of marketing communications; and to withdraw consent. Mesh does not sell or share personal information for cross-context behavioral advertising, so there is no “sale”/“sharing” opt-out to exercise (see Section 6). To exercise a right, contact privacy@gomesh.app. We will verify and respond within the time the law requires, and you will not be discriminated against for exercising your rights.
9. Data Retention
We keep your information only as long as needed for the purposes described in this Policy, then delete or anonymize it. Specifically:
- Account and profile data, messages, and other content: kept while your account is active and deleted or anonymized within 90 days after you close your account, except where we must retain it longer for a reason below.
- Identity verification data (Stripe Identity): retained while your account is active and deleted within 90 days after account closure, unless we need it longer to investigate fraud, abuse, or a legal claim.
- Host verification call notes and recordings: retained for as long as you remain an active or prospective host, and for up to 2 years after your most recent hosting-verification call, unless we need it longer to investigate fraud, abuse, or a legal claim.
- Invite code and reward data: retained while your account is active and for 90 days after account closure, unless needed longer to investigate abuse of the program.
- Payment, transaction, and tax records: retained for 2,555 days (7 years) to meet accounting, tax, and audit obligations that apply in most jurisdictions; some jurisdictions may require a longer period, in which case we follow the longer requirement.
- Safety, fraud, and legal-hold records: retained for as long as needed to resolve the matter, comply with law, or establish, exercise, or defend legal claims, and then deleted.
- Backups: residual copies in routine backups are overwritten on our normal backup cycle, generally within 90 days.
Where information is retained beyond an active account, we limit access to it and use it only for the purpose that requires the retention.
10. Security
We use technical and organizational measures designed to protect your information. No system is perfectly secure, so we cannot guarantee absolute security. Use a strong password and keep your credentials confidential.
11. International Data Transfers
Mesh is operated from the United States, and your information is processed in the United States and by our service providers (such as Stripe), which may be located in other countries. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States and other countries that may have different data-protection laws than your own. Where required for transfers from the EEA, the UK, or other regions with cross-border transfer rules, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum).
12. Children
The Service is intended only for individuals 18 years of age or older. We do not knowingly collect information from anyone under 18 and will delete it if we learn we have.
13. Changes to This Policy
We may update this Policy. If we make material changes, we will notify you through the Service or by other reasonable means and update the “Last Updated” date. Continued use after changes take effect means you accept the updated Policy.
14. Contact Us
Privacy questions: privacy@gomesh.app. General questions: support@gomesh.app. Mailing address: MGChufa LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, USA.