Privacy Policy
Last updated: September 4, 2025
Privacy Policy
Mandro (“we,” “our,” or “us”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI-powered trip generation service (“Service”).
1. Information We Collect
We may collect the following types of information:
Personal Information
- Name
- Email address
- Google account information (if you choose to sign in with Google)
- Account credentials if you register directly with email
Trip Information
- Destination
- Start date
- Number of days
- Number of travelers
- Interests
- Transport type
- Budget
- Custom prompt (optional)
Analytics Information
We use Google Analytics and Vercel Analytics to collect anonymized data about how users interact with our website, such as page views and traffic sources.
2. How We Use Your Information
We use the collected information for the following purposes:
- To provide and improve our trip generation service
- To maintain and secure our systems
- To analyze usage patterns through analytics tools
- To send service-related communications (such as account updates or important notices)
- To send marketing or promotional emails through providers such as Mailchimp (with your prior consent, and always with an opt-out option)
3. Data Sharing
We do not sell or rent your personal information. We may share your data only in the following cases:
- With service providers that operate our infrastructure (e.g., MongoDB hosting in the EU/US, analytics tools, email delivery providers, Creem.io as payment processor)
- With Creem.io, our payment processing partner and Merchant of Record, for the purpose of handling subscriptions, payments, tax compliance, and refunds. Your purchase will appear on statements as CREEM.IO* STORE.
- If required by law, legal process, or governmental request
4. Payments
Mandro does not process or store payment card or banking details.
All payments are securely processed by Creem.io, which acts as the Merchant of Record and is responsible for handling transactions, chargebacks, and tax compliance.
5. User Rights
If you are located in the European Union, the United States (California), or other regions with applicable privacy laws, you may exercise the following rights regarding your personal data:
- Access: Request a copy of the information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your account and associated data
- Portability: Request a copy of your data in a structured, commonly used format
- Restriction: Request that we limit the processing of your information in certain circumstances
- Objection: Object to the processing of your data for direct marketing purposes
To exercise these rights, contact us at support@mandro.ai. We will respond within the timeframes required by applicable law.
6. Data Storage and Security
- All data is stored in MongoDB databases hosted on secure cloud infrastructure in the EU and US.
- We implement reasonable technical and organizational measures to protect your information against unauthorized access, loss, misuse, or alteration.
- We retain your personal data only as long as necessary to provide our Service, comply with legal obligations, resolve disputes, or enforce agreements. You may request deletion of your data at any time.
7. Children’s Privacy
Our Service is not directed to children under the age of 16, and we do not knowingly collect personal data from them. If we become aware that we have collected information from a child under 16 without parental consent, we will take steps to delete it promptly.
8. Legal Compliance
We handle data responsibly and in accordance with privacy principles under laws such as the GDPR (Europe) and CCPA (California). While Mandro is not yet formally certified under all regional frameworks, we respect the rights of users globally and provide the protections outlined in this Policy.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website. Continued use of our Service after changes are posted constitutes your acceptance of the revised Policy.
10. Contact
If you have any questions or concerns about this Privacy Policy or our practices, you may contact us at: