Legal

Privacy Policy

Last updated: [Date]

This policy explains what information Stedra (“we,” “us”) collects when you use the Stedra travel planning platform, why we collect it, and what choices you have. Stedra is operated by [Company Legal Name], [Company Address].

1. Information we collect

  • Account information. Your email address, and if you sign in with Google, the basic profile information Google provides for that sign-in.
  • Traveler Profile. Preferences you tell us about — pace, budget, interests, things you'd rather avoid — used only to personalize your own trip recommendations.
  • Trips and searches. What you ask Pathfinder Concierge to plan, the itineraries we generate for you, and the destinations you search for — including destinations we don't currently support, if you ask to be notified when we launch there.
  • Favorites and Memory. Places, experiences, and notes you choose to save.
  • Photos you upload. For Local Voices contributions, Trip Memories, or a claimed business listing. Every photo has its embedded location/ device metadata (EXIF) removed automatically before it is stored.
  • Location. Only ever sent to us for a specific “near me”-style search, and only after you explicitly grant permission for that request. We do not track your location in the background.
  • Payment information. Handled entirely by Stripe — we never see or store your card details ourselves.
  • Technical information. A guest identifier cookie (if you use Stedra without an account), and standard server logs.

2. How we use it

We use your information to generate and personalize trip itineraries, find real places and events for you, process payments, moderate user-submitted content for safety, and operate and improve Stedra. We do not sell your personal information, and we do not use third-party advertising trackers.

3. Who we share it with

We work with the following service providers to operate Stedra. Each only receives what it needs to do its job:

  • Supabase — account authentication, database, and file storage.
  • OpenAI — generating your trip itinerary from your request.
  • Google — finding real places, and for “Sign in with Google.”
  • Stripe — payment processing for Premium and AI-plan purchases.
  • Ticketmaster — real event listings.
  • Pexels — stock destination imagery where we don't have a real photo.
  • Resend — sending a trip postcard when you choose to share one by email.

We disclose information beyond this list only if required by law, or to protect the safety of our users.

4. Your choices and rights

You can delete a saved trip, a favorite, or a Local Voices contribution yourself at any time from your account. You can close your account by contacting us at privacy@stedra.no. Depending on where you live, you may have additional rights to access, correct, or export your data — contact us and we'll help.

5. Security

Your data is protected by row-level database security, so your account can only ever read or write its own data. Uploaded photos are stripped of embedded location metadata before storage. All traffic to Stedra is encrypted.

6. Children's privacy

Stedra is not directed at children, and we do not knowingly collect information from anyone under 16.

7. Changes to this policy

If we make a material change to this policy, we'll update the date at the top of this page and, where required, let you know directly.

8. Contact

Questions about this policy or your data: privacy@stedra.no.