Treaxures
Legal

Privacy Policy

Last updated

Draft — pending legal review. This document has not yet been reviewed by Indian-jurisdiction counsel and is not in effect. Content is subject to change before publication.

Status: Draft — not effective

Last updated: 2026-08-25 Operator: Treaxures, operated by ESPR Creative Lab Private Limited, Aizawl, Mizoram, India

This draft describes the data used by the Treaxures product. It does not claim compliance with any law and must not be treated as the final notice until counsel approves it and the release manager reconciles it against the exact signed app and hosted services.

1. Who is responsible for your data

Treaxures is operated by ESPR Creative Lab Private Limited, a company incorporated in India with its place of business in Aizawl, Mizoram, India. For data-protection purposes it is the data fiduciary (the controller) for the personal data described in this notice. It is governed by Indian law, including the Digital Personal Data Protection Act, 2023.

PurposeContact
Privacy requests, consent withdrawal, deletion, exportprivacy@treaxures.com
Data-protection and grievance contactdpo@treaxures.com
General supportsupport@treaxures.com
Legal noticeslegal@treaxures.com

Before publication the operator must add its registered-office address and corporate identity number here, and counsel must confirm the named grievance officer, the statutory response periods, the supervisory authority, the governing law and forum, and the basis for any transfer of data outside India.

Treaxures is not the controller for everything you do inside it. Where a paid guide is fulfilled by the creator who made it, that creator is responsible for the data it holds under its own notice. §4 and §5 say which is which, and the final notice must state the relationship for each.

Treaxures is an open platform. A guide reaches the public catalogue once it has passed the same local-context, field, safety, accessibility, source, rights, and contributor review as any other, wherever it comes from — so the catalogue may be small or empty in a place that has not been reviewed yet. This notice is not limited to one city or region.

2. When Treaxures collects data

You can browse the public catalogue without creating an account or granting location access. Treaxures asks for data progressively when a feature needs it. Most of the capabilities below are optional and collect nothing until you open them.

Account and profile

If you create an account, we process your account identifier, email or phone where used, sign-in provider data, display name, optional profile fields, preferences, consent records, security events, and account-recovery data.

Foreground location and field activity

If you start a location-dependent field feature, we may process foreground GPS coordinates, accuracy, timestamps, route progress, stop confirmations, and device-generated activity needed for that feature. Browsing and preparation remain available when location is denied. The launch build does not collect continuous background location.

Location evidence is not automatically treated as a purchase, contribution, respectful action, or completed journey. Completion and Passport records use the documented server rules and keep uncertainty visible.

Safety features record additional location data only when you invoke them: an SOS alert, a live location share you start, and the emergency contacts you choose to store.

Camera frames used only for an on-device view — including augmented-reality alignment — are not uploaded unless you choose to capture or submit media. Uploaded photos, video, narration, captions, transcripts, credits, consent, rights records, and technical metadata are stored for the submitted purpose.

The field capture tool, which is invitation-only, stores an offline capture session on your device and uploads its media, notes, coordinates, and rights record to the workspace that invited you.

Microphone and speech recognition are requested at point of use, for voice search only. Audio is used to turn what you say into a search query and is not retained as a recording by Treaxures. The app carries no live voice chat.

Direct messages

One-to-one text messages are stored so the person you are writing to can read them. They are not end-to-end encrypted: staff can access them where a report, a legal process, or a safety investigation requires it. We also process the block, mute, and report records you create, and the moderation decisions taken on them. Messages are text only — the app has no attachment, photo, voice-note, or group messaging capability.

Device, notifications, security, and diagnostics

We may process app and OS version, locale, time zone, installation and push tokens, network/error context, consent state, security signals, crash reports, and performance information.

Optional diagnostics are off unless you turn them on. On first launch the app asks you to choose, and every category — product analytics, crash reporting, personalisation, marketing, and optional partner features — starts switched off. Declining is a real switch, not a recorded preference: analytics, crash reporting, and performance collection are each disabled in the underlying SDK at the moment you decline, and the app's own event pipeline drops events before they are built. A Do Not Track setting additionally suppresses analytics and performance collection regardless of the individual choices.

Before publication the app must also offer a way to review and change that choice after the first prompt, and this section must be updated to name it.

Content and communications

Depending on the features you use, we process field-guide drafts, route data, source notes, contributor credits, media, corrections, reports, eligible completed-experience reviews, selected profile stories, support messages, and private Creator Studio submissions.

If you are invited to a private preview, we record the invitation, your acceptance, the access grant that scopes it, and the feedback you submit against that release. A preview grant is issued by the server and is revocable.

Paying for a guide

If you buy a paid guide, we process the order, price, tax, fee, fulfilment, receipt, refund, dispute, payout, and reconciliation records for it. Payment is carried by Razorpay, which processes your payment credentials directly: Treaxures does not store a full card number, UPI PIN, or net-banking credential.

A guide is a real-world guided experience, which is why it is paid for outside the app stores' in-app-purchase system.

This is the only thing the app sells. There is no subscription, no Treaxures Pro, no in-quest hint purchase, no marketplace, no digital collectible, and no way to buy in-app currency. Coins and gems, where shown, are earned only and cannot be bought.

Impact Passport and environmental estimates

The Impact Passport is private by default. It keeps transaction-linked records, confirmed actions, observations, journey completion, and qualified estimates as separate evidence types. It does not create a public composite status metric.

A walking-emissions comparison uses the recorded activity data, named baseline, factor version, assumptions, and methodology shown at treaxures.com/methodology/walking-emissions. It is not a measured reduction, offset, credit, or proof of neutral travel.

Identity and creator verification

If you apply for contributor or creator status, we process the documents and references you submit for that check, the reviewer's decision, its scope, and its date. Verification names exactly what was checked and when; it is not an endorsement. Submitted document files are deleted from storage when the account is deleted (see the Data Deletion page); the record that a check happened is retained under §6.

Staff and administrative access

Treaxures staff can reach production data through an internal admin console. It is capability-scoped, requires multi-factor authentication, and writes an audit entry for every privileged read and action. Those audit entries are retained under §6.

3. Why data is used

Subject to the lawful bases and consent language approved by counsel, data is used to:

  • provide authentication, catalogue, field, offline, direct messaging, Passport, support, and invitation-scoped contributor workflows;
  • protect accounts, enforce permissions, prevent fraud/abuse, moderate reported content and conduct, and maintain an audit trail;
  • take payment for a paid guide and handle its receipt, refund, dispute, and creator payout;
  • review sources, cultural context, routes, safety/access, media rights, corrections, and reports;
  • deliver transactional communications and consented optional communications;
  • monitor reliability and improve the service using governed analytics;
  • meet valid legal, tax, accounting, consumer, and regulatory obligations.

Treaxures does not sell personal data or use it for third-party behavioural advertising.

4. Service providers

The final notice must list only providers that receive production data from the exact release, with each one's data location, subprocessors, transfer basis, and retention confirmed. Current candidates are:

ProviderConditional purpose
SupabaseAuthentication, database, storage, realtime, and server functions
Firebase (Google)Push delivery and consent-configured analytics, crash, or performance telemetry
MapboxMaps, navigation, and map-related requests
RazorpayPayment processing for paid guides
MeilisearchSearch indexing and retrieval where configured
ResendTransactional email where configured
Apple (on-device speech recognition)Converts voice-search audio to text on iOS

The build integrates no other processor. In particular it uses no in-app purchase / store-billing relay, no travel-reservation provider, no IPFS or blockchain publisher, and no real-time voice provider — the capabilities that would need them are not in the app.

A creator whose guide you buy is not a Treaxures processor. They receive the data needed to fulfil what you asked for and act as a controller of it under their own notice.

5. Who can see data

Public clients can read only explicitly released public projections. Workspace members, contributors, partners, reviewers, and staff receive scoped access based on their role and task. Private originals, participant details, payment evidence, reports, and Passport records are not made public by default.

Some things you do are visible to other people by design, and it is worth being specific: a direct message is readable by the person you sent it to; a public profile, post, or eligible review is readable by anyone; and a paid guide's purchase is visible to the creator who is paid for it.

Nothing you do in this build is published to a public blockchain or to a public content-addressed network, and nothing you say is broadcast live to other users.

Treaxures may disclose data to a provider for the documented service, to a creator needed to fulfil a user request, or when required by a valid legal process. The final legal notice must define each disclosure and the applicable safeguards.

6. Retention, deletion, and export

A category-level retention schedule exists in the platform, but its production values, statutory periods, deletion/anonymisation rules, backup expiry, legal holds, and owners are a release gate pending counsel and accountant approval. The app must show the approved schedule rather than hardcoded generic periods.

You can export or delete your account yourself from Profile → Settings ("Download My Data" and "Delete Account"). Deletion runs on a 30-day grace period and you can cancel it during that window. For access, correction, consent withdrawal, or a grievance, write to privacy@treaxures.com. Some financial, fraud, dispute, rights, or legal-hold records may need to be retained or de-identified; the final notice must state the exact approved rule.

Because the build publishes nothing to a public blockchain, holds no travel reservation, and sells no in-app digital goods, there is no category of your data that Treaxures is structurally unable to erase. Anything retained is retained by choice under an approved rule — financial, fraud, dispute, rights, or legal-hold records — not because it is beyond reach. The final notice must state that rule.

The Data Deletion page describes exactly what is deleted, what is detached from your account, what is retained, and when.

7. Children and guardian controls

The launch age threshold, notice, guardian-consent mechanism, paid-feature restrictions, and deletion/escalation process are not legally approved in this draft. The release must remain blocked until counsel confirms the experience against the law and store requirements that apply on the release date.

The threshold applies to more than sign-up. Counsel must specifically approve the position for paying for a guide, direct messaging with people who are not known contacts, and the identity documents a contributor submits. The capabilities that carried the sharpest age questions — in-app purchases and subscriptions, marketplace selling and payouts, collectible minting, live voice, and travel booking — are not in this build, and the position for them is due only if one is ever enabled.

8. Security

Treaxures uses encrypted transport, provider-managed encrypted storage, row-level and capability-scoped access policies, short-lived private links, multi-factor protection for staff operations, secret management, audit trails, rate limits, and incident workflows. These controls reduce risk but do not make any system perfectly secure or by themselves establish legal compliance.

Report a suspected privacy or security issue to privacy@treaxures.com or support@treaxures.com. The counsel-approved incident notice will define required notification procedures and timelines.

9. Contact, rights, and grievances

Privacy requests: privacy@treaxures.com

Data-protection contact: dpo@treaxures.com

General support: support@treaxures.com Legal notices: legal@treaxures.com

Operator: ESPR Creative Lab Private Limited, Aizawl, Mizoram, India. Governed by Indian law; see §1 for the outstanding controller disclosures.

The final policy must state the rights, grievance path, regulator, jurisdiction, response periods, international-transfer basis, and effective date approved for the actual launch.

10. Open items before this notice can take effect

Named so nobody has to reconstruct them from the draft:

  • counsel approval of lawful bases, notices, rights workflow, and effective date;
  • the registered-office address and corporate identity number (§1);
  • the named grievance officer and statutory response periods (§1, §9);
  • the approved retention schedule, backup expiry, and legal-hold rules (§6);
  • the children/guardian position for each capability listed in §7;
  • confirmation of every provider in §4 against the exact signed release, including data location, subprocessors, and transfer basis;
  • a way to review and change the diagnostics choice after the first prompt (§2).

Deliberately not listed, because the capability is not in this build: the multiplayer-voice provider and its recording position; the travel-emissions and carbon-offset methodology. If either is ever enabled it returns to this list and to §2 and §4 before the build that carries it ships.