Privacy Policy
This policy describes what personal information TravelMindsAI ("we", "us") collects when you use our website, API, and related services, why we collect it, how we share it, and the choices you have. We aim to keep this short, plain, and accurate.
1. What we collect
- Account information: name, email, password hash, organisation name (if provided).
- Billing information: billing name, address, country, tax IDs, and the last four digits of the payment method. Full card details are not stored on our servers; they are handled by our payment processor.
- API usage: request timestamps, endpoint paths, response codes, byte counts, and rate-limit counters. We do not log API request bodies or query content beyond what is required to deliver the response and to investigate abuse.
- Site analytics: coarse-grained page views, country, and referrer. We do not run third-party advertising trackers.
- Communications: emails you send to us and any support tickets you open.
2. Why we collect it
- To provide and operate the Services and your account.
- To bill you, calculate taxes, and detect fraud.
- To enforce rate limits, terms, and acceptable-use rules.
- To respond to support requests.
- To send essential service updates and, with your consent, occasional product news.
- To comply with our legal obligations.
3. Payment processing
Our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders, and is independently responsible for processing your payment, calculating and remitting taxes, and handling refunds. When you make a purchase, your payment details are submitted directly to Paddle and are governed by Paddle's Checkout Buyer Terms and Privacy Notice. We receive a transaction record (order ID, billing country, amount) but we do not receive your full card number.
4. Sub-processors and infrastructure
The categories of vendors we rely on:
- Cloud hosting and CDN — for serving the website and API.
- Email delivery — for transactional and support email.
- Payment processing — Paddle, as described above.
- Error monitoring — for diagnosing crashes and performance issues.
We will publish a current list of named sub-processors on request to privacy@travelmindsai.com. We have data-processing agreements in place with vendors that handle personal data on our behalf.
5. Data retention
Account and billing records are retained for as long as your account is active and for the period required by tax, accounting, and anti-fraud laws after closure (typically 7 years). API request metadata is retained for up to 12 months. Support correspondence is retained for up to 3 years after the last interaction.
6. International transfers
We are based in India. Some of our vendors may process data in other jurisdictions, including the European Economic Area, the United Kingdom, and the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.
7. Your rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your account and associated personal data;
- Object to or restrict certain processing;
- Receive a portable copy of your data;
- Withdraw consent for marketing communications at any time.
To exercise these rights, write to privacy@travelmindsai.com. We respond within 30 days. You may also lodge a complaint with your local data-protection authority.
8. Security
We use industry-standard measures to protect personal data: encryption in transit, encryption at rest where the underlying store supports it, role and license-aware database access controls, audit logs, least-privilege credentials, and routine vulnerability scans. No system is perfectly secure; if we discover a breach affecting your data we will notify you without undue delay.
9. Children
The Services are not directed to children under 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
10. Cookies
Our website uses a small number of strictly necessary cookies for session management and security. Optional analytics cookies, if any, are listed in a cookie banner where required. You can control cookies through your browser settings.
11. Changes to this policy
We will update this page when our practices change. The "Last updated" date at the top reflects the current version. Material changes will be notified to active customers by email.
12. Contact
Questions about this policy or how we handle your data: privacy@travelmindsai.com.