Mandado — Privacy Policy
Effective date: August 22, 2026 Last updated: August 22, 2026
This Privacy Policy explains how Omni Devs LLC, a Florida limited liability company doing business as "Mandado" ("Mandado," "we," "us," or "our"), collects, uses, discloses, and retains information when you use the Mandado application, website, and related services (the "Service"). Omni Devs LLC is the controller (and, under Ecuadorian law, the responsable del tratamiento) of the personal information described here.
Read this Policy together with our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
Contact: support@omnidevs.cloud
Summary (not a substitute for the full Policy)
- We collect what we need to run the Service: your email, your household's members and their details, the requests you send, and the photos and links you share.
- Your photos, requests, and shared links are sent to third-party providers — including Anthropic, Duffel, and SerpApi — so we can answer them.
- We use PostHog to measure how the app is used and to capture crash reports.
- We do not sell your personal information and we do not use it for targeted advertising.
- We never see your full card number. Stripe handles payments.
- Your information is processed in the United States.
- You can request access to, correction of, or deletion of your information at support@omnidevs.cloud.
1. Who This Policy Covers
Mandado is used by households made up of one or more Handlers (adults who administer the household and its billing) and one or more Requesters (household members who send requests through a chat interface). This Policy applies to both roles, and to anyone who visits our website.
A note on consent within households. Requesters often interact with Mandado only through a simple chat interface and may never separately read this Policy. A Handler who adds someone to a household represents to us that they have that person's permission to add them, to submit information about them, and to have Mandado contact them — and we rely entirely on that representation (Terms, Section 3.3). Handlers should make sure every person they add understands what Mandado collects and how it is used. If you were added to a household and did not agree to it, contact us at support@omnidevs.cloud and we will help.
2. Information We Collect
2.1 Information you or your Handler provides
| Category | Examples | Typically provided by |
|---|---|---|
| Account identifiers | Email address (used to sign in and to receive one-time passcodes), display name | Handlers and Requesters |
| Household data | Household name, member names, member roles (Handler or Requester), preferred language, notification preferences | Handlers |
| Contact details for members | Email address and, where a Handler chooses to provide one, a phone number for a household member | Handlers |
| Requests and messages | The text of chat messages, natural-language travel dates and routes, product descriptions, questions, and any other content you type | Requesters and Handlers |
| Product photographs | Photos submitted to identify and price a product, and any information visible in them | Requesters and Handlers |
| Links you share | URLs you send, and the content we retrieve from those pages (title, description, images, and a text excerpt) | Requesters and Handlers |
| Travel records you enter | Airline, flight number, confirmation code, origin and destination, travel dates, passenger name, price paid, and your notes — for bookings you made elsewhere and chose to record in the Service | Handlers |
| Search configuration | Preferred airports, airlines, fare tiers, price-watch criteria, and similar settings | Handlers |
| Billing information | Provided directly to Stripe. We receive only limited billing metadata — see Section 2.4 | Handlers |
| Support correspondence | The content of emails you send us and our replies | Anyone who contacts us |
2.2 Information collected automatically
- Authentication data. One-time passcodes we generate and their expiry and use status, and a session token stored in a cookie on your device.
- Request and result history. A record of the requests your household has made, the results shown, notifications sent, and price watches configured, associated with your household.
- Product and usage analytics. Through PostHog (Section 4), we collect page views, page-leave events, interactions with the interface, the pages and URLs you visit within the Service, referring pages, approximate location inferred from IP address, browser and device type, operating system, screen size, language, and timestamps.
- Error and crash reports. Through PostHog, we automatically capture unhandled errors and unhandled promise rejections, including error messages, stack traces, the page URL where the error occurred, and browser and device details. An error report can incidentally include information that was present on the page at the moment of the error.
- Server and security logs. Our hosting provider and our own code record IP addresses, request paths, timestamps, response codes, user-agent strings, and error output. We use these to operate and secure the Service, and to enforce rate limits that protect against abuse.
- Push notification tokens. If you enable browser push notifications, your browser's push service issues an endpoint and keys that we store in order to deliver notifications to your device.
2.3 Cookies and similar technologies
We use a small number of cookies and browser storage items. We do not use advertising cookies, and we do not permit third parties to use cookies on the Service for cross-site behavioral advertising.
| What | Type | Purpose |
|---|---|---|
| Session authentication cookie | Strictly necessary | Keeps you signed in. Without it the Service cannot function. |
| Theme preference (browser local storage) | Functional | Remembers whether you chose light or dark mode. |
| PostHog analytics cookies and storage | Analytics | Distinguishes sessions and returning devices so we can measure usage and diagnose errors. See Section 4 and Section 9.5 to opt out. |
You can block or delete cookies through your browser settings, but blocking the session cookie will prevent you from signing in.
2.4 Information we do not collect
- We never receive or store full payment card numbers, CVC codes, or bank account numbers. These go directly to Stripe. From Stripe we receive only limited metadata such as a customer identifier, subscription status, plan, and renewal dates.
- Because Mandado does not book travel or purchase products, we do not collect passport numbers, government identification numbers, loyalty-program credentials, or the payment and identity details an airline or merchant would need — unless you volunteer such information in a message or photograph, which you should not do (Terms, Section 8).
- We do not intentionally collect biometric identifiers, precise geolocation, health information, or other sensitive categories of personal information. Please do not submit them. If sensitive information appears incidentally in a photograph you upload, it will be processed as part of that photograph; contact us to have it deleted.
3. How and Why We Use Information
| Purpose | Examples | Legal basis (where GDPR or similar law applies) |
|---|---|---|
| Provide the Service | Authenticating you by email one-time passcode; running flight, product, and general requests; identifying products from photos; retrieving pages you link to; notifying Handlers; delivering push notifications; storing your travel records and sending reminders | Performance of a contract |
| Billing | Creating and managing subscriptions, processing payments through Stripe, tracking trial status, sending renewal and billing notices | Performance of a contract; compliance with legal obligation (tax and accounting) |
| Communicate with you | One-time passcodes, request and result notifications, service and security announcements, changes to this Policy or the Terms, responses to support requests | Performance of a contract; legitimate interests |
| Operate, secure, and improve | Monitoring availability, diagnosing errors and crashes, enforcing rate limits, detecting and preventing fraud, abuse, and unauthorized access, understanding which features are used | Legitimate interests in running a secure, working service |
| Comply with law and protect rights | Responding to lawful requests, keeping tax and transaction records, establishing, exercising, or defending legal claims, including responding to payment disputes and chargebacks | Compliance with legal obligation; legitimate interests |
| Optional marketing | Occasional product announcements you can unsubscribe from | Consent, or legitimate interests where permitted |
We do not use your product photographs, requests, search history, or household data to serve you third-party advertising, and we do not sell your personal information. See Section 6.
3.1 Automated processing and artificial intelligence
The Service uses artificial intelligence to interpret your requests, identify products from photographs, and generate responses. This processing produces information for you to consider; it does not make any decision that produces a legal or similarly significant effect on you. No human review is applied to individual AI outputs before you see them, and AI output may be inaccurate — see Terms, Section 6. If you have concerns about automated processing of your information, contact us at support@omnidevs.cloud.
We do not permit our AI providers to use your content to train their general-purpose models. We rely on our providers' business and API terms, which by default exclude API inputs and outputs from model training. We cannot guarantee a third party's compliance with its own terms.
4. Service Providers and Sub-Processors
We share limited information with the following providers solely to operate the Service. Each is bound by its own terms and privacy policy and, where required, by a data processing agreement. None of them is authorized to use your information for its own independent purposes.
| Provider | Role | What it receives |
|---|---|---|
| Supabase, Inc. | Database, file storage, and infrastructure | All household data stored by the Service, including account identifiers, household members, messages, requests, results, travel records, and product photographs |
| Vercel, Inc. | Application hosting, content delivery, scheduled jobs | Requests to the Service and associated server logs, including IP addresses, request paths, user agents, and timestamps |
| Anthropic, PBC (Claude) | AI product identification from photographs; AI interpretation of requests and generation of responses | Product photographs, the text of the request, retrieved page content, and household search configuration needed to answer the request |
| Duffel Limited | Flight price and availability data | Travel dates, routes, airports, airline and fare preferences, and passenger counts. No payment details or identity documents |
| SerpApi, LLC | Product search results | Product descriptions and search terms derived from your request or from a photograph |
| PostHog, Inc. | Product analytics and error/exception monitoring | Page views and page-leave events, interface interactions, page URLs, IP address, browser and device information, and automatically captured error reports including stack traces |
| Resend, Inc. | Transactional email delivery | Recipient email address and the content of the email, including one-time passcodes and notification content |
| Stripe, Inc. | Subscription billing and payment processing | Billing and payment details you provide directly to Stripe, plus a household identifier and email address. We never receive your full card number; Stripe returns only limited metadata such as subscription status and card brand and last four digits |
| Browser push services (for example Google, Mozilla, Microsoft, or Apple, depending on your browser) | Delivery of browser push notifications | A push endpoint issued by your browser and the notification payload — only if you enable push notifications |
We may add, replace, or remove providers as the Service evolves, and will update this Policy accordingly. Material changes are handled under Section 14 (Changes to This Policy).
5. How We Share Information
Beyond the providers in Section 4, we share information:
- Within your household. Requests, results, messages, travel records, and related details are visible to the Handlers of your household and, as applicable, to the Requester who submitted them. This is the core function of the Service: a Handler can see what members of their household have asked for. Do not submit anything through the Service that you do not want your household's Handlers to see.
- With professional advisors — accountants, auditors, insurers, and lawyers — under duties of confidentiality.
- For legal reasons. To comply with applicable law, a subpoena, court order, or other lawful request; to enforce our Terms; to collect amounts owed; to respond to and contest a payment dispute or chargeback (which may involve providing your account, acceptance, and usage records to your bank, card issuer, or payment provider); or to protect the rights, property, or safety of Omni Devs LLC, our users, or the public.
- In a business transaction. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, in which case we will require the recipient to honor this Policy or will give you notice before your information becomes subject to a different one.
- With your consent, for any other purpose disclosed to you at the time.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have not done so in the preceding twelve months.
6. Notice for U.S. State Privacy Laws
In the twelve months preceding the date of this Policy, we collected the categories of personal information described in Section 2 — identifiers, customer records, commercial information, internet and network activity, approximate geolocation inferred from IP address, and visual information (photographs) — from the sources described there, for the purposes described in Section 3, and disclosed them for business purposes only to the categories of recipients described in Sections 4 and 5.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. We do not knowingly collect or sell the personal information of consumers under 16 years of age.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights described in Section 9, including the right to appeal a denial of a request (Section 9.4). You will not be discriminated against for exercising any privacy right.
7. Data Retention
We keep personal information only as long as we need it for the purposes in this Policy, or as long as the law requires.
| Data | Retention |
|---|---|
| Product photographs | Retained while your household account is active and needed for the request. We are implementing automatic deletion 30 days after upload; until that automatic process is live, photographs are deleted on request and on household deletion. You may request deletion of any photograph at any time at support@omnidevs.cloud |
| Requests, messages, results, and travel records | While the household account is active; deleted on household deletion as described in Section 8 |
| Household and member data (names, emails, phone numbers, preferences) | While the household account is active, plus any period required to comply with legal, tax, or accounting obligations or to resolve a dispute |
| One-time passcodes | Short-lived; they expire and are marked used shortly after issuance and are purged on a routine basis |
| Push subscriptions | Until you disable notifications, your browser invalidates the subscription, or the household is deleted |
| Analytics and error data (PostHog) | Retained according to our PostHog project configuration, generally no longer than 24 months |
| Server and security logs | Typically 30–90 days, longer where needed to investigate an incident |
| Billing and transaction records | Retained by us and by Stripe as required for tax, accounting, audit, and chargeback-defense purposes, generally seven (7) years |
| Backups | Deleted data may persist in encrypted routine backups for a limited period before those backups expire on their normal cycle |
8. Cancellation, Deletion, and What Happens to Your Data
If a Handler cancels the subscription, the household keeps access through the end of the paid period, after which paid features are disabled. Account and household data are not immediately deleted, so the household can reactivate without losing anything.
If a Handler requests deletion of the household account — by emailing support@omnidevs.cloud from the Handler's account email — we will delete the household's messages, requests, results, travel records, stored product photographs, push subscriptions, and the personal information in Handler and Requester profiles within 30 days, except where we must retain specific records to comply with legal, tax, or accounting obligations, to resolve a dispute, to defend a payment dispute or legal claim, or to enforce our agreements. Deleted data may persist briefly in backups (Section 7).
Deleting a household removes access for every member. A Requester cannot unilaterally delete a shared household account, because the household is administered by its Handlers. A Requester may, however, contact us directly at support@omnidevs.cloud to request deletion of their own personal information, and we will honor that request in accordance with applicable law, notifying the Handler that the member's information has been removed. We will not require a Requester to go through their Handler to exercise a legal right.
9. Your Rights and Choices
9.1 Rights available in many jurisdictions
Depending on where you live, you may have the right to:
- access the personal information we hold about you, and to know how we use and disclose it;
- correct inaccurate information;
- delete your information;
- obtain a portable copy of information you provided to us;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent where we rely on it, without affecting processing already carried out;
- opt out of the sale or sharing of personal information and of targeted advertising — we do none of these; and
- not be discriminated against for exercising any of these rights.
9.2 How to exercise your rights
Email support@omnidevs.cloud with the request and the email address associated with your account. We will verify your identity — usually by confirming control of that email address — before acting, and will respond within the period applicable law requires (generally 30 to 45 days, extendable where permitted). An authorized agent may submit a request on your behalf with proof of authorization.
9.3 What you can do yourself
- Handlers can view and update most household and member information, and manage the subscription, in the Service; billing details can be updated through the Stripe customer portal.
- Anyone can turn off browser push notifications in their browser or device settings, or in the Service.
- Anyone can unsubscribe from marketing email using the link in those messages. Transactional messages cannot be turned off while an account is active.
9.4 Right to appeal
If we decline your request, we will tell you why. You may appeal by replying to our response with the subject line "Privacy Appeal." We will review the appeal and inform you of the outcome, with reasons, within the period required by applicable law. If we deny the appeal, you may contact your state attorney general or other competent supervisory authority.
9.5 Analytics opt-out
You may opt out of PostHog analytics by enabling your browser's "Do Not Track" or "Global Privacy Control" signal, by using a tracking-blocking extension, or by emailing support@omnidevs.cloud and asking us to disable analytics for your account. We honor the Global Privacy Control (GPC) signal as a valid opt-out request where applicable law requires it. Because we do not sell or share personal information for advertising, opting out affects only usage measurement and error reporting.
9.6 European Economic Area and United Kingdom
If you are in the EEA or the UK, our legal bases are identified in Section 3, and you have the rights in Section 9.1 under the GDPR or UK GDPR. You also have the right to lodge a complaint with your local data protection authority. Where we rely on legitimate interests, you may object at any time.
9.7 Ecuador
If you are in Ecuador, the Ley Orgánica de Protección de Datos Personales (LOPDP) applies to your personal data. You have the rights of information, access, rectification and updating, erasure, opposition, annulment, portability, suspension of processing, not to be subject to decisions based solely on automated processing, and to receive notice of a security breach. To exercise any of these rights, contact support@omnidevs.cloud; we will respond within the period the LOPDP requires. You may also file a complaint with the Superintendencia de Protección de Datos Personales. Si prefiere comunicarse en español, escríbanos a support@omnidevs.cloud y le responderemos en español.
10. International Data Transfers
We operate from the United States, and your information is stored and processed in the United States by us and by the providers listed in Section 4, some of whom may process data in other countries.
If you are located in Ecuador, the EEA, the UK, or elsewhere outside the United States, your personal information will be transferred to and processed in the United States, whose data protection laws may differ from — and may provide less protection than — those of your own country, and where public authorities may in some circumstances be able to access data under local law.
Where required, we rely on appropriate safeguards for these transfers, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) in our agreements with providers, together with the contractual and technical measures described in this Policy. For transfers from Ecuador, we rely on the mechanisms permitted under the LOPDP, including your consent and the contractual safeguards necessary to perform our contract with you. You may request more information about these safeguards at support@omnidevs.cloud.
11. Data Security and Breach Notification
We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including encryption in transit, encryption at rest for stored files and database contents at the infrastructure level, access controls that scope household data to that household, short-lived one-time passcodes, signed session tokens, rate limiting on sensitive endpoints, and encryption of any stored third-party credentials.
No method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for safeguarding your own email account, device, and one-time passcodes (Terms, Section 3.4).
Breach notification. If we become aware of a security breach affecting your personal information, we will notify you and the relevant authorities as and when required by applicable law, including the LOPDP, the GDPR or UK GDPR, and U.S. state breach-notification statutes.
12. Children's Privacy
The Service is not directed to children under 13 (or the higher age of digital consent in your jurisdiction), and we do not knowingly collect personal information directly from them. Requester accounts are intended for adult household members.
If a Handler adds a minor to a household, that Handler represents that they are the minor's parent or legal guardian, or are authorized by one, and consents on the minor's behalf to the processing described in this Policy (Terms, Section 9).
If you believe we hold a child's personal information without appropriate authorization, contact support@omnidevs.cloud and we will delete it promptly.
13. Third-Party Links and Content
The Service displays links, images, and summaries from third-party websites, and may retrieve pages you send us. Those sites are not operated by us and are governed by their own privacy policies. We are not responsible for their content or practices. Review their policies before providing them with any information.
14. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we will give at least fourteen (14) days' notice — by email to each Handler, by in-app notice, or both — before it takes effect, and we will update the "Last updated" date above. Where a change requires your consent under applicable law, we will obtain it. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Language
This Policy is provided in English, which is the authoritative and controlling version. Any translation, including into Spanish, is offered for convenience only, and in the event of conflict the English version prevails except where mandatory local law provides otherwise. Esta Política se proporciona en inglés, que es la versión vinculante; cualquier traducción al español se ofrece únicamente por conveniencia.
16. Contact Us
Questions, concerns, or requests about this Policy or your personal information:
Omni Devs LLC d/b/a Mandado A Florida limited liability company Email: support@omnidevs.cloud
Mailing address: [insert registered address of Omni Devs LLC]