TreaxuresPilot contact
Legal

Privacy Policy

Draft — pending legal review. This document has not yet been reviewed by Indian-jurisdiction counsel and is not in effect. Content is subject to change before publication.

Privacy Policy

Status: Draft — not effective

Last reviewed for product accuracy: 2026-07-19 Operator: Treaxures, operated by ESPR Creative Lab Private Limited, Aizawl, Mizoram, India

This draft describes the data used by the focused Aizawl field-guide product. It does not claim compliance with any law and must not be treated as the final notice until counsel approves it and the release manager reconciles it against the exact signed app and hosted services.

1. When Treaxures collects data

You can browse the public Aizawl catalogue without creating an account or granting location access. Treaxures asks for data progressively when a feature needs it.

Account and profile

If you create an account, we process your account identifier, email or phone where used, sign-in provider data, display name, optional profile fields, preferences, consent records, security events, and account-recovery data.

Foreground location and field activity

If you start a location-dependent field feature, we may process foreground GPS coordinates, accuracy, timestamps, route progress, stop confirmations, and device-generated activity needed for that feature. Browsing and preparation remain available when location is denied. Treaxures does not collect continuous background location in the Aizawl launch profile.

Location evidence is not automatically treated as a purchase, contribution, respectful action, or completed journey. Completion and Passport records use the documented server rules and keep uncertainty visible.

Camera, photos, and audio

Camera frames used only for an on-device view are not uploaded unless the user chooses to capture or submit media. Uploaded photos, video, narration, captions, transcripts, credits, consent, rights records, and technical metadata are stored for the submitted purpose.

The launch build may request microphone access for voice search or an authorised audio-recording workflow. It does not use public multiplayer voice chat. The permission is requested at point of use.

Device, notifications, security, and diagnostics

We may process app and OS version, locale, time zone, installation and push tokens, network/error context, consent state, security signals, crash reports, and performance information. Product analytics and optional diagnostics must follow the consent configuration recorded for the release.

Content and communications

Depending on the features you use, we process field-guide drafts, route data, source notes, contributor credits, media, corrections, reports, eligible completed-experience reviews, selected profile stories, support messages, and private Creator Studio submissions.

Payments, offers, products, and bookings

Only an operationally approved commercial capability may collect order, booking, price, tax, fee, seller/provider, fulfilment, receipt, refund, dispute, payout, and reconciliation records. The payment provider processes payment credentials; Treaxures must not store a full card number, UPI PIN, or net-banking credential.

An outbound product handoff records attribution only when the user opts in after the disclosure. A redirect is not recorded as a sale. Conversion or commission information comes from reconciled provider evidence.

Impact Passport and environmental estimates

The Impact Passport is private by default. It keeps transaction-linked records, confirmed actions, observations, journey completion, and qualified estimates as separate evidence types. It does not create a public composite status metric.

A walking-emissions comparison uses the recorded activity data, named baseline, factor version, assumptions, and methodology shown at treaxures.com/methodology/walking-emissions. It is not a measured reduction, offset, credit, or proof of neutral travel.

The public launch does not ask users to connect a blockchain wallet and does not collect data for flight or hotel booking.

2. Why data is used

Subject to the lawful bases and consent language approved by counsel, data is used to:

  • provide authentication, catalogue, field, offline, Passport, support, and user-requested creator or partner workflows;
  • protect accounts, enforce permissions, prevent fraud/abuse, and maintain an audit trail;
  • operate an explicitly enabled payment, booking, offer, product-handoff, refund, or payout flow;
  • review sources, cultural context, routes, safety/access, media rights, commercial disclosures, corrections, and reports;
  • deliver transactional communications and consented optional communications;
  • monitor reliability and improve the service using governed analytics;
  • meet valid legal, tax, accounting, consumer, and regulatory obligations.

Treaxures does not sell personal data or use it for third-party behavioural advertising.

3. Service providers

The final notice must list only providers that receive production data from the exact release. Current candidates are:

ProviderConditional purpose
SupabaseAuthentication, database, storage, realtime, and server functions
Firebase (Google)Push delivery and consent-configured analytics, crash, or performance telemetry
MapboxMaps, navigation, and map-related requests
RazorpayPayment processing when an approved paid flow is enabled
MeilisearchSearch indexing and retrieval where configured
ResendTransactional email where configured

Disabled travel-booking, multiplayer, wallet, and generic marketplace integrations are not public launch processors. Before publication, the operator must verify contracts, data locations, subprocessors, transfers, retention, and links for every active provider.

4. Who can see data

Public clients can read only explicitly released public projections. Workspace members, contributors, partners, reviewers, and staff receive scoped access based on their role and task. Private originals, participant details, payment evidence, reports, and Passport records are not made public by default.

Treaxures may disclose data to a provider for the documented service, to an accountable seller/provider needed to fulfil a user request, or when required by a valid legal process. The final legal notice must define each disclosure and the applicable safeguards.

5. Retention, deletion, and export

A category-level retention schedule exists in the platform, but its production values, statutory periods, deletion/anonymisation rules, backup expiry, legal holds, and owners are a release gate pending counsel and accountant approval. The app must show the approved schedule rather than hardcoded generic periods.

Users can request access, correction, export, consent withdrawal, grievance handling, or deletion through the in-app privacy controls or by contacting privacy@treaxures.com. Some financial, fraud, dispute, rights, or legal-hold records may need to be retained or de-identified; the final notice must state the exact approved rule.

See the Data Deletion page for the current product workflow.

6. Children and guardian controls

The launch age threshold, notice, guardian-consent mechanism, paid-feature restrictions, and deletion/escalation process are not legally approved in this draft. The release must remain blocked until counsel confirms the experience against the law and store requirements that apply on the release date.

7. Security

Treaxures uses encrypted transport, provider-managed encrypted storage, row-level and capability-scoped access policies, short-lived private links, multi-factor protection for staff operations, secret management, audit trails, rate limits, and incident workflows. These controls reduce risk but do not make any system perfectly secure or by themselves establish legal compliance.

Report a suspected privacy or security issue to privacy@treaxures.com or support@treaxures.com. The counsel-approved incident notice will define required notification procedures and timelines.

8. Contact, rights, and grievances

Privacy requests: privacy@treaxures.com

Data-protection contact: dpo@treaxures.com

General support: support@treaxures.com Operator: ESPR Creative Lab Private Limited, Aizawl, Mizoram, India

The final policy must state the rights, grievance path, regulator, jurisdiction, response periods, international-transfer basis, and effective date approved for the actual launch.