# Privacy Policy

> **Draft notice:** This is a first draft generated to establish baseline terms and is not a substitute for review by a licensed attorney. Given this product handles payments (via Stripe), household PII, and users across multiple countries (US/Ecuador), have an actual lawyer review both this document and the accompanying Terms of Service before they are presented to real users or before billing goes live.

**Last updated: [Date — TBD]**

This Privacy Policy explains how Mandado ("Mandado," "we," "us," or "our") collects, uses, discloses, and retains information when you use the Mandado application and related services (the "Service"). It should be read together with our [Terms of Service](./terms-of-service.md).

## 1. Who This Policy Covers

Mandado is used by households made up of a **Handler** (typically the adult who sets up the household account and owns the billing) and one or more **Requesters** (typically other family members who send requests through a simple chat interface, and who authenticate using their phone number). This Policy applies to both roles.

**A note on consent within households:** Because Requesters often interact with Mandado only through a simple chat interface and may never separately read this Policy themselves, the Handler is responsible for representing to Mandado that they have the authority or permission of any Requester they add to the household, and Mandado relies on that representation. Handlers should make sure every household member they add understands, at a level appropriate to them, what information Mandado collects and how it is used.

## 2. Information We Collect

### 2.1 Information you provide

| Category | Examples | Who provides it |
|---|---|---|
| Phone number | Used for SMS/OTP authentication | Requesters |
| Email address | Used for account access, billing, and notifications | Handlers |
| Product photos | Photos submitted to look up a product's price/availability | Requesters |
| Search requests | Natural-language travel dates, routes, product descriptions, chat messages | Requesters |
| Household/family data | Names, relationships within the household, which members are Handlers vs. Requesters | Handlers |
| Billing information | Handled directly by Stripe; see Section 4 | Handlers |

### 2.2 Information collected automatically

- **Search history** — the flight and product searches performed, and their results, associated with your household.
- **Device and usage data** — basic technical information (such as device type, app version, and general usage patterns) needed to operate, secure, and improve the Service.
- **Push notification tokens** — if you enable browser push notifications, your browser's push service provides us a token used to deliver notifications to you (see Section 4).

### 2.3 Information we do not collect

Mandado does not collect or store full payment card numbers, bank account numbers, or other sensitive payment credentials — these are handled directly by Stripe (Section 4). Mandado does not book travel or purchase products, so we do not collect the information a merchant or airline would collect to complete a transaction (e.g., passport numbers, loyalty program credentials) unless you separately provide such information to that third party directly.

## 3. How We Use Information

We use the information described above to:

- Authenticate Requesters via SMS/phone OTP and Handlers via email;
- Process search requests — looking up flight prices via travel dates/routes, and identifying and pricing products from photos;
- Notify the Handler when a Requester wants to act on a Search Result;
- Operate, maintain, and improve the Service, including troubleshooting and security;
- Process billing and manage subscriptions;
- Send transactional communications (e.g., account, billing, or trial-status notifications); and
- Comply with legal obligations and enforce our Terms of Service.

We do not use your product photos, search history, or household data to serve you third-party advertising, and we do not sell your personal information.

## 4. Sub-Processors and Third-Party Services

Mandado shares limited information with the following third-party service providers ("sub-processors") solely as necessary to provide the Service. Each operates under its own privacy policy and terms.

| Sub-processor | Purpose | What it receives |
|---|---|---|
| **Anthropic** (Claude) | AI-based product identification from photos | Product photos submitted by Requesters, and associated request context needed to identify and describe the product |
| **Duffel** | Flight price and availability data | Travel dates, routes, and related search parameters submitted by Requesters (no payment or identity documents) |
| **SerpApi** | Amazon product search | Product descriptions/search terms and, where relevant, product-identification results, used to retrieve pricing and availability |
| **Resend** | Transactional email delivery | Handler email address and the content of transactional emails (e.g., billing notices, account notifications) |
| **Stripe** | Billing and payment processing | Billing and payment information provided directly by the Handler; **Mandado never receives or stores full card numbers** — Stripe handles this directly and shares with us only what is necessary (e.g., subscription status, last four digits of a card, transaction confirmations) |
| **Web Push provider** | Browser push notifications | We use the push notification service built into your own web browser (e.g., the browser vendor's push infrastructure) to deliver notifications; no separate third-party push vendor is used beyond the browser's own service, and it receives only the minimum data (a device push token and notification payload) needed to deliver a notification |

We may update this list as our Service evolves. Material changes will be reflected in an updated version of this Policy.

## 5. How We Share Information

Beyond the sub-processors listed in Section 4, we may share information:

- **Within your household** — Search Results and relevant request details are shared between the Requester who submitted a request and the Handler of that household, since that is the core function of the Service;
- **With service providers** who help us operate the Service (e.g., hosting/infrastructure providers), under confidentiality obligations;
- **For legal reasons** — if required to comply with a subpoena, court order, or other legal process, or to protect the rights, property, or safety of Mandado, our users, or the public;
- **In connection with a business transfer** — such as a merger, acquisition, or sale of assets, in which case we will provide notice before your information becomes subject to a different privacy policy; and
- **With your consent** — for any other purpose disclosed to you at the time you provide the information.

**We do not sell your personal information to third parties.**

## 6. Data Retention

- **Product photos** are automatically deleted **30 days** after upload.
- **Search history** (the record of searches performed and results shown) is retained for as long as the household account remains active, and is deleted upon account deletion as described below.
- **Household and account data** (phone numbers, email addresses, household relationships) is retained for as long as the account is active and as needed to comply with legal, tax, or accounting obligations after that.
- **Billing records** held by Stripe are retained according to Stripe's own retention practices and applicable legal requirements (e.g., tax recordkeeping).

### 6.1 What happens when a Handler cancels or deletes the account

When a Handler cancels the subscription, the household retains access through the end of the paid billing period, after which paid features are disabled, but account and search data are not immediately deleted — this preserves the ability to reactivate without data loss. When a Handler requests **deletion** of the household account (via account settings or by contacting [support email — TBD]):

- We will delete the household's search history, stored product photos (if not already auto-deleted), and personal information associated with Requester and Handler profiles within a reasonable period (target: 30 days), except where we are required to retain certain records (e.g., billing records for tax/accounting purposes, or information needed to resolve disputes or comply with law).
- Deleting the household account removes access for all Requesters within it; Requesters cannot unilaterally delete the shared household account, since it is administered by the Handler, but a Requester may ask the Handler to remove them, or contact us directly to request removal of their individual information.

## 7. International Data Transfers

Mandado is designed for households that may span multiple countries — including the United States and Ecuador — and our sub-processors operate infrastructure in the United States and potentially other countries. **By using the Service, you understand and consent that your information may be accessed, stored, and processed in the United States or other countries whose data protection laws may differ from those of your home country.** We take reasonable steps to require our sub-processors to protect your information consistent with this Policy regardless of where it is processed.

## 8. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise any of these rights, contact us at **[support email — TBD]**. We will respond within the timeframe required by applicable law.

- **Requesters** may ask their household's Handler, or contact us directly, to access or delete their individual information.
- **Handlers** can manage most account and billing information directly within the Service, and can request full account deletion as described in Section 6.1.
- You may opt out of browser push notifications at any time through your browser's notification settings.

## 9. Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including encryption in transit and access controls limiting who can view household data. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

## 10. Children's Privacy

The Service is **not directed at children under the age of 13** (or the applicable age of digital consent in your jurisdiction, if higher). Requester accounts are intended for adult members of a household coordinating everyday family tasks. We do not knowingly collect personal information directly from children. If you believe a child's information has been submitted to us without appropriate parental or guardian authorization, contact us at [support email — TBD] and we will take appropriate steps to remove it.

## 11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice — such as an in-app notice or an email to the Handler — before the changes take effect. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes.

## 12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact us at:

**[support email — TBD]**

[Company Name — TBD]
[Company Address — TBD]
