Contents
- Who We Are
- What Information We Collect
- Sensitive Personal Information
- How We Use Your Information
- Legal Basis for Processing (GDPR)
- How We Share Your Information
- Third-Party Service Providers
- International Data Transfers
- Data Retention
- Security
- Children's Privacy
- Your Privacy Rights
- Cookies & Tracking
- Changes to This Policy
- Contact & Data Controller
1. Who We Are
Cordobase Software Solutions ("Cordobase," "we," "us," or "our"), based in Windsor, Ontario, Canada, is the data controller responsible for the personal information collected through the Serai travel companion application and its associated website (collectively, the "Service").
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to it. It applies to all users of the Service, regardless of where you are located.
2. What Information We Collect
Information You Provide Directly
| Category | Examples | Required? |
|---|---|---|
| Account information | Name, email address, password | Yes |
| Trip data | Trip name, destination, dates, waypoints, notes | When using trip features |
| Expense data | Expense amounts, categories, split details | Optional |
| Chat messages | Text messages sent within trip group chats | Optional |
| Traveler profile | Dietary restrictions, allergies, emergency contacts | Optional |
| Sensitive information | Medical notes, blood type, passport details, visa info, travel insurance | Entirely optional — see Section 3 |
| Guest traveler data | Name, relationship, DOB, dietary/medical info for non-account travelers | Optional — added by trip editors |
Information Collected Automatically
| Category | Examples |
|---|---|
| Location data | GPS coordinates, accuracy radius (only when GPS sharing is enabled by you) |
| Device information | Device type, operating system, browser type |
| Usage data | Pages visited, features used, timestamps of activity |
| Log data | IP address, request logs (standard server logs) |
3. Sensitive Personal Information
Serai allows you to optionally store categories of information that are considered sensitive under applicable privacy laws, including:
- Health and medical information (conditions, medications, medical notes, blood type)
- Biometric-adjacent data (allergies, dietary restrictions related to medical conditions)
- Government-issued document details (passport numbers, expiry dates, visa information)
- Financial information (travel insurance policy details)
- Information about minors (when creating guest traveler profiles for children)
We do not require sensitive information to use the app. You choose what to enter. By entering sensitive information, you explicitly consent to our processing of that data for the sole purpose of providing the Service to you.
We apply additional technical safeguards to this data, including database-level row security and encryption at rest and in transit. However, no system is perfectly secure — see Section 10 (Security).
4. How We Use Your Information
We use the information we collect to:
- Provide the Service — create and manage your account, display your trips, enable collaboration with trip members
- Enable real-time features — group chat, live GPS location sharing (only when you enable it)
- Improve the Service — understand how features are used to make them better
- Ensure security — detect fraud, abuse, and unauthorized access
- Communicate with you — respond to support requests, send service-related notifications
- Comply with legal obligations — respond to lawful requests from authorities
We do not:
- Sell your personal information to any third party
- Use your personal information for targeted advertising
- Share your information with advertisers
- Use your sensitive health or travel document data for any purpose other than delivering the Service to you
5. Legal Basis for Processing (GDPR)
GDPR If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal information on the following legal bases:
- Contract performance — processing necessary to provide the Service you signed up for (e.g., storing your trip data, enabling group chat)
- Legitimate interests — operating and improving the Service, preventing fraud and abuse, ensuring security
- Consent — for optional sensitive data (medical notes, passport info), real-time location sharing, and any marketing communications (if applicable)
- Legal obligation — complying with applicable laws and responding to lawful government requests
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Withdrawing consent for sensitive data may limit certain app features.
6. How We Share Your Information
With Other Trip Members
By design, certain information you enter is shared with the members of your trip. This includes:
- Your name and profile details visible to trip members
- Trip waypoints, notes, and itinerary items
- Chat messages sent in the trip group chat
- GPS location (only when you enable sharing)
- Expenses you log and their split details
- Guest traveler profiles (visible to all trip members)
Your sensitive personal information (medical notes, passport details, blood type) entered in your personal traveler profile is visible to all members of the trip you have entered it for. Enter only what you are comfortable sharing with your trip companions.
With Service Providers
We share data with third-party service providers who help us operate the Service, under strict data processing agreements. These providers may only use your data as directed by us — see Section 7.
Legal Requirements
We may disclose your information if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect the safety of any person, prevent fraud, or protect our legal rights.
Business Transfers
If Cordobase Software Solutions is acquired, merges with another company, or sells substantially all of its assets, your personal information may be transferred as part of that transaction. We will notify you in advance if your data will be subject to a materially different privacy policy.
7. Third-Party Service Providers
| Provider | Purpose | Data Shared | Their Policy |
|---|---|---|---|
| Supabase | Database, authentication, real-time messaging | All user data you enter into the app | supabase.com/privacy |
| Mapping providers | Displaying maps and waypoints | Approximate location when viewing maps | Varies by provider |
| Weather providers | Weather at trip destinations | Destination city name or coordinates | Varies by provider |
We are not responsible for the privacy practices of third-party providers. We encourage you to review their privacy policies.
8. International Data Transfers
Cordobase Software Solutions is based in Canada. Our infrastructure provider, Supabase, may store and process your data on servers located in the United States or other countries outside your country of residence.
GDPR If you are located in the EEA or UK, your data may be transferred to countries that the European Commission has not recognized as providing an adequate level of data protection. In such cases, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or the data processing terms provided by our infrastructure providers, which incorporate these mechanisms.
PIPEDA Canada's Personal Information Protection and Electronic Documents Act permits cross-border transfers of personal information. We take reasonable contractual steps to ensure that any third-party recipient of your data provides a comparable level of protection.
By using the Service, you acknowledge that your information may be transferred to and processed in countries other than your own.
9. Data Retention
We retain your personal information for as long as your account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data — retained while your account is active; deleted within 90 days of account deletion upon your request
- Trip data and messages — retained as long as the trip exists and any member of it has an active account; deleted with the trip upon request
- Location data — not permanently stored; only the last known position is retained per session
- Log and usage data — retained for up to 12 months for security and operational purposes
- Backup data — may be retained in encrypted backups for up to 90 days after deletion for disaster recovery purposes
To request deletion of your data, contact us at privacy@serai.app.
10. Security
We implement industry-standard technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest
- Row-Level Security (RLS) — database-level access controls that prevent one user from accessing another user's data
- Secure, hashed password storage via our authentication provider
- Regular security reviews of our codebase and database policies
No system is perfectly secure. Despite our best efforts, we cannot guarantee that unauthorized third parties will never be able to defeat our security measures. You use the Service at your own risk. If you become aware of any security vulnerability or breach, please contact us immediately at security@serai.app.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and applicable regulatory authorities as required by law.
11. Children's Privacy
Serai is not directed to children under the age of 13. We do not knowingly collect personal information directly from children under 13. If we become aware that we have inadvertently collected such information, we will delete it promptly.
Serai does allow trip editors to create Guest Traveler profiles for children (under 18) as part of family trip planning. This information is entered by a parent or guardian who takes full responsibility for the child's data. By adding a child's information, you represent that you are that child's parent or legal guardian, or have the express consent of their parent or legal guardian.
If you believe a child's data has been entered without appropriate consent, please contact us at privacy@serai.app and we will take appropriate action.
12. Your Privacy Rights
Depending on where you are located, you may have the following rights regarding your personal information:
Access
Request a copy of the personal information we hold about you.
Correction
Ask us to correct inaccurate or incomplete data.
Deletion
Request that we delete your personal information, subject to legal obligations.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Ask us to limit how we process your data in certain circumstances.
Objection
Object to processing based on legitimate interests or for direct marketing.
Withdraw Consent
Withdraw consent for processing at any time (e.g., location sharing, sensitive data).
Complaint
Lodge a complaint with your local data protection authority.
GDPR EU/UK Residents
You have all the rights listed above under the General Data Protection Regulation. You may lodge a complaint with your national data protection authority if you believe we have not handled your data lawfully. For EU matters, our primary supervisory authority is the Office of the Privacy Commissioner of Canada (OPC), though you may also contact the relevant EU Member State authority.
CCPA California Residents
Under the California Consumer Privacy Act, you have the right to know what personal information we collect and how we use it, request deletion of your personal information, opt out of the sale of your personal information (we do not sell your data), and not be discriminated against for exercising your rights. To submit a request, contact privacy@serai.app.
PIPEDA Canadian Residents
Under Canada's Personal Information Protection and Electronic Documents Act, you have the right to access your personal information and challenge its accuracy, and to withdraw consent to our collection and use of your data (subject to legal and contractual restrictions). Contact our privacy officer at privacy@serai.app.
We will respond to all verifiable privacy requests within 30 days, or within the timeframe required by applicable law.
13. Cookies & Tracking
The Serai web application and landing page may use the following types of cookies and similar technologies:
- Essential cookies — required for the app to function (e.g., session authentication tokens). These cannot be disabled without breaking the Service.
- Analytics cookies — used to understand how the Service is used, in anonymized or aggregated form. We do not use third-party advertising cookies.
We do not use cookies for targeted advertising. We do not share cookie data with advertising networks.
You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, applicable law, or our practices. We will update the effective date at the top of this page when we do.
For material changes — especially those that expand how we use your sensitive data — we will make reasonable efforts to notify you via email or in-app notice before the changes take effect. If you do not agree with the updated policy, you should delete your account and stop using the Service.
15. Contact & Data Controller
The data controller for your personal information is:
Cordobase Software Solutions
Windsor, Ontario, Canada
Privacy Officer / Data Protection Contact:
Email: privacy@serai.app
Security concerns:
Email: security@serai.app
General inquiries:
Email: hello@serai.app
If you have a complaint about our handling of your personal information that we have not resolved to your satisfaction, you may contact the relevant privacy authority:
- Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca
- EU / EEA: Your national data protection authority — edpb.europa.eu
- UK: Information Commissioner's Office — ico.org.uk
- California: California Privacy Protection Agency — cppa.ca.gov