Legal

Privacy Policy

How Finding Horizons collects, uses, and protects your data

Last updated July 2026

Working draft

This page is a working draft and should be reviewed by qualified legal counsel before public launch.

1. Who We Are

Finding Horizons is a travel organization and discovery application operated by Finding Ventures Inc. ("we", "us", "our"), its parent company. Our mailing address is: 5513 Avenue de Monkland, Montréal, QC H4A 1C8, Canada.

Privacy inquiries: privacy@findinghorizons.ca

This Privacy Policy applies to information collected through our mobile app, website, and related services. It covers Canadian users (PIPEDA and Québec Law 25 awareness) and US users (state privacy law awareness). We do not knowingly collect data from children under 13.

2. Information We Collect

Account & Identity Data: Email address, display name, and profile photo from Apple Sign-In, Google Sign-In, or email magic link; account creation date; optional profile bio and avatar.

Imported & Pasted Content: URLs you import from TikTok, Instagram, YouTube, Google Maps, Klook, or other platforms; page metadata (title, description, thumbnail) extracted server-side; booking confirmation text and itinerary emails you paste; screenshots, PDFs, and images you upload.

Travel & Planning Data: Saved places (Points) including name, category, location, notes, and rating; Collections; Trips, itineraries, side quests, detours, mini quests, and bookings; budget entries.

Location Data (Optional): Approximate or precise device location, only if you grant permission and only when you trigger a location feature. If you opt into background access ("Always Allow", offered only in context), we additionally receive low-power significant-change updates while the app is closed. In both cases we store a single coarse last-known position (~1 km rounding) plus country-level stay records for visa tracking — never a movement trail. See our Location Data Policy.

Camera & Photos (Optional): Photos you take or select for your profile picture, Hidden Gems, and booking/screenshot scanning. Images are processed to extract place and booking details; we never scan your photo library — only what you pick.

Community Contributions: Hidden Gems you create (place name, category, coordinates, description, tips, and photo) and their community status. Personal gems are private to you; sharing one to the community is an explicit action.

Push Notification Data: A device push token (if you enable notifications) and delivery metadata, used solely to send you the alerts you opted into.

Bring-Your-Own-AI Keys: If you mint a personal AI connector key, we store only a one-way hash of it — the key itself is shown to you once and never retained in plaintext.

Payment & Subscription Data: Subscription status; Stripe customer and subscription IDs. We never store card numbers, CVV, or bank details — Stripe handles payment method data exclusively.

AI & Prompt Context: If you use AI planning features, trip and place data you include may be processed by our AI provider. We do not use your data to train AI models unless you explicitly opt in.

Referral Data: Referral code, whether referred users signed up via your link, and referral reward status.

Device & Usage Data: Browser type, device type, OS, app version; pages visited, features used, session timing; error logs and crash reports. Firebase Analytics is optional, browser-only, and requires configuration.

3. How We Use Your Information

  • To provide and operate the Finding Horizons Service
  • To sync places, trips, and collections across your devices
  • To generate AI itinerary suggestions based on your trip context (when enabled)
  • To display maps, place data, and event listings
  • To process subscription payments via Stripe
  • To send magic link emails for sign-in
  • To send optional trip reminders and import alerts (with your permission)
  • To send optional smart notifications — nearby saved places, community gems, quest stops, live-event and disruption alerts, visa-day countdowns — when you enable notifications and location
  • To build aggregated, anonymized travel intelligence (e.g. which places travellers as a whole visit and love). This never identifies you, and personalized features derived from your own activity are transparent and can be turned off
  • To improve the Service through aggregate usage analysis
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations

We do not sell your personal information. We do not use your data for behavioural advertising on third-party platforms.

4. Service Providers & Data Sharing

  • Supabase (Ireland/US): Database, authentication, and storage. Your data is protected by row-level security.
  • Vercel (US): Web hosting and serverless functions.
  • Stripe (US): Payment processing for subscriptions.
  • Google OAuth / Maps / Places API (US): Sign-in and map/place data. Place queries are routed server-side.
  • PredictHQ (NZ/US) & Ticketmaster (US): Live-event and disruption discovery. Queries are server-side and contain a city or coarse coordinates — never your identity.
  • RapidAPI providers (US): Used server-side to read the public social posts and event listings you ask us to import or search. Only the shared URL or query is sent — never your identity or account data.
  • AI providers (e.g. OpenAI, Anthropic, if configured): Content extraction (captions, screenshots, video narration you share) and trip/place context for suggestions. Minimum necessary data only; not used to train their models per our API agreements.
  • Apple Push Notification service: Delivers your notifications; receives only your device token and the message.
  • NOAA (US): Space-weather data for aurora forecasts. No personal data is sent.
  • Firebase (Google, US): Optional analytics and App Check only. Firebase Auth is not used — Supabase is the sole auth system.

We do not share your personal information with unrelated third parties, advertisers, or data brokers. We may share information if required by law or to protect user safety.

5. Cross-Border Data Transfer

Your data may be stored and processed in countries outside Canada (including the US and Ireland) by our service providers. These transfers occur under appropriate safeguards. By using the Service, you consent to these transfers.

6. Data Retention

We retain your account data for as long as your account is active. You can delete your account yourself at any time — in the app under Profile → Settings → Delete account, or on the web under Settings. Deletion is immediate and irreversible: it removes your profile, saved places, trips and plans, imports, photos, collections, community activity and subscription records. Encrypted backups may retain copies for up to 90 days before they age out, and we keep a record that the deletion happened (a bare account identifier and a timestamp, holding no personal information) so we can demonstrate the request was honoured. We retain nothing else except where the law requires it.

7. Your Rights

You may have the right to access, correct, delete, and port your personal data, and to withdraw consent to optional processing. Deletion is self-serve — see section 6. For anything else, contact privacy@findinghorizons.ca — we will respond within 30 days.

7a. Location

Location is optional and the app works without it. We ask for while-using-the-app location the first time a feature needs it, and we only ask for background ("Always") location later, in context, when you open Free Roam — never during sign-up. Background location uses low-power significant-change updates so we can tell you when you pass near a place you saved; it is not continuous tracking, it is never used for advertising, and it is never sold or shared with advertisers. You can withdraw either permission at any time in iOS or Android Settings, and every other feature keeps working.

8. Canadian Privacy Law (PIPEDA & Québec Law 25)

Finding Ventures Inc. operates from Québec, Canada and is subject to PIPEDA and Québec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25). You have the right to access, correct, delete, de-index, and port your personal information. Contact privacy@findinghorizons.ca.

9. US Privacy Awareness

If you are a US resident, applicable state privacy laws (including CCPA) may grant additional rights. We do not sell personal information as defined by these laws. Exercise your rights by contacting privacy@findinghorizons.ca.

10. Security

We use TLS encryption, Supabase row-level security, server-side API key management, and Stripe for payment data. No system is completely secure — you use the Service at your own risk. See our Security page.

11. Cookies & Local Storage

We use session cookies required for authentication and local storage for theme preferences. We do not use cross-site advertising cookies. See our Cookie Policy.

12. Children

The Service is not directed at children under 13. If you believe a child under 13 has provided us with personal information, contact privacy@findinghorizons.ca and we will delete it promptly.

13. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes via in-app notification or email. Continued use after notification constitutes acceptance.

14. Contact

Privacy: privacy@findinghorizons.ca

Support: support@findinghorizons.ca

5513 Avenue de Monkland, Montréal, QC H4A 1C8, Canada

Finding Ventures Inc. · 5513 Avenue de Monkland, Montréal, QC H4A 1C8, Canada
Legal: legal@findinghorizons.ca · Privacy: privacy@findinghorizons.ca