Skip to content

Privacy Policy

Effective July 2, 2026 ·Last updated September 30, 2026

The short version

  • We collect the account details, trips, notes, spots, photos, messages, and travel preferences you give us so we can run Treader for you.
  • We use Google's Vertex AI to power Scout, our planning assistant, and to read bookings you ask us to import. We send it your typed messages, a summary of the trip you're planning, the travel preferences you have set (including the optional ones that describe your needs, such as dietary requirements, allergies, and accessibility needs), and anything you paste, upload, or forward to us for import. It also checks photos you post for other people to see for unsafe content. We never send it your email, your account ID, your precise coordinates, or the documents in your Travel Data vault.
  • Those preference fields are optional, are yours to change or clear at any time in Settings, and are never shown on your public profile.
  • We do not sell your personal information, and we run no advertising or cross-site tracking on the web app. We use product analytics, audience measurement, and error reporting (PostHog, Google Analytics, and Sentry, acting only as our service providers, see §7 and §8) to understand which features are used, how people find us, and to fix crashes, never to advertise to you. Analytics is yours to switch off in Settings › Privacy, and in Quebec, the EEA, the UK, Switzerland and the United States it stays off until you accept it. Google Analytics is configured for measurement only: advertising features and Google Signals are switched off, and it is never given your account identifier. Session replays mask every word on screen and everything you type, and a browser that sends Global Privacy Control is treated as having switched analytics off.
  • Our infrastructure providers (Supabase, Google, Stripe, Vercel) are in the United States, and Google may answer an AI request from a data centre in another country, so your information is processed outside Canada.
  • You can view, correct, export, or permanently delete your data — most of it yourself from Settings, and anything else by emailing support@treader.ca.

This summary is for convenience only; the full policy below governs.

1. Who we are and how to reach us

Treader is a collaborative, AI-assisted travel-planning service available at treader.ca (“Treader,” “we,” “us,” or “our”). Treader is an independent service operated as a sole proprietorship under the business name “Treader,” based in the Province of Alberta, Canada.

For the purposes of Canadian privacy law, the individual who operates Treader is the “organization” accountable for the personal information described in this policy. We operate publicly under the Treader business name; the operator’s legal identity is available on request to you or to a privacy regulator. Our person in charge of the protection of personal information is the Founder of Treader. They are accountable for our compliance with this policy and with Canadian and Quebec privacy law, and they answer questions, access requests, and complaints. Contact them at support@treader.ca with Privacy in the subject line.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights and choices available to you. It forms part of, and should be read together with, our Terms of Service.

2. Scope and the law that applies

This policy applies to personal information we collect through the Treader website and application, our application-programming interfaces, and related communications (together, the “Service”). It applies to visitors, registered users, and people who appear in content that our users create (for example, someone you name in a shared trip note).

Because we operate from Alberta and serve users in Canada and abroad, the following laws are most relevant:

  • Alberta PIPA — Alberta’s Personal Information Protection Act, our primary provincial private-sector statute.
  • PIPEDA — Canada’s federal Personal Information Protection and Electronic Documents Act, which governs personal information that flows across provincial or national borders in the course of commercial activity. Because our service providers are outside Alberta and Canada, PIPEDA applies to those transfers.

We build to the ten fair-information principles common to these laws — accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, limiting retention, accuracy, safeguards, openness, and individual access. Where you are located in the European Union, the United Kingdom, Quebec, California, or another U.S. state with its own privacy law, additional rights may apply to you; see §§10 and 12.

A note on Canadian reform. As of the effective date, PIPEDA remains in force; the proposed federal Consumer Privacy Protection Act (Bill C-27) did not become law. We will update this policy if and when a successor statute takes effect.

3. Personal information we collect

We collect only what we need to provide the Service. Depending on how you use Treader, this includes the following specific categories.

3.1 Information you provide

Account and identity.

  • Your email address and, if you sign up with email, a password. Your password is stored only in salted, hashed form by our authentication provider; we never see or store it in plain text. If you sign in with Google, you have no Treader password.
  • Your name, username, and display name.
  • A consent record: the date you accepted these terms and the version you accepted, and, if you ticked the optional box, the date you agreed to receive product and travel email. We keep these because the law puts the burden of proving consent on us.
  • If you sign up for booking dates and guide emails on one of our guides, with or without an account: that email address, the guide you signed up on, the words you agreed to, and the dates you signed up, confirmed and unsubscribed. We keep the address until you unsubscribe, and the consent record after that as proof.
  • Optional profile details: avatar and banner images, a public bio, a home base location (free text, e.g. “Calgary, AB”), external links, a chosen accent colour, and your account/social preferences (such as whether your profile is private and who may send you trip invites).

Travel preferences.

  • Your stated travel style, pace, budget, companions, interests, and preferred transport, and a free-text “about you” description. You provide these during onboarding and in your profile, and they are used to personalise suggestions (including by Scout — see §6).
  • Your home country (Settings › Units). We first guess it from the country our host derives from your IP address, or from your browser's language, and keep it with your other settings on your device and, when you are signed in, on your account. It sets your default currency and units, decides which government's travel advice the pocket guide links, and which trips count as at home. You can change or clear it at any time.
  • Scout preferences (Settings › Scout & AI). Every field is optional, and you can change or clear any of them at any time: dietary requirements (such as vegetarian, vegan, pescatarian, halal, kosher, or gluten-free), free-text allergies you want avoided, accessibility needs (step-free access, less walking), free-text must-avoids, whether you are travelling with children or with a pet, and how you want Scout to write and to treat the weather. Some of these can reveal sensitive information about you — see §4. They are used only to personalise suggestions, they are sent to our AI provider with your Scout requests (see §6), and they are never shown on your public profile. When you set dietary preferences, Scout may include words like “vegan” or “halal” in the place searches it runs through Google Maps Platform. No account identifier goes with them. To check menus, Scout reads restaurants’ public websites from our servers, and nothing about you is sent to them.

Content you create.

  • Trips and itineraries — trip names, destinations, dates, map centres, and the full itinerary, including each stop’s title, location and coordinates, address, website, description, your free-text notes, rich-text note documents, and checklists.
  • Saved spots — custom map locations you save, including name, category, coordinates, address, your notes, ratings, price, amenities, opening times, and photos.
  • Moments — social posts with a photo, caption, place, coordinates, and time window.
  • Interactions — comments, likes, saves/bookmarks, and reactions on content.
  • Messages — direct messages, trip-group chat, and shared locations you send within Treader. Message content is visible to the participants of that conversation or trip.
  • Trip collaboration — who you invite to a trip and their role (owner, editor, viewer).
  • Reports you send: when you report content, a person or a problem, what you write and any screenshot you attach. A problem report also carries technical details about your browser and device (browser and version, operating system, screen and window size, language, time zone, and the page you were on) so we can reproduce the problem. Reports reach Treader support by email.
  • Bookings you import: text you paste, a screenshot or PDF you upload, or a booking email you forward to your Treader import address, so we can read the booking details out of it (see §6). From a forwarded email we keep its subject, its sender, and the details we read, as a draft you can review and delete; only the rows you choose are added to a trip.

Travel Data Suite (Discovery plan).

  • Travel documents you upload to your private vault — for example flight and stay confirmations, insurance, receipts, and identity documents — together with their file metadata and any structured details you or the app records from them.
  • Travel records (structured booking details) and passenger-rights claims (airline, flight number and date, the disruption, delay length, and a generated claim draft).

Your uploaded travel documents are stored privately and are accessible only through time-limited, signed links. We do not send the documents in your vault to our AI provider. Importing a booking is separate: what you paste, upload, or forward for import is read by our AI provider (see §6).

Billing information.

  • If you buy a paid plan (Pro or Discovery), our payment processor, Stripe, collects your billing name, billing email, and billing address, and your payment-card details. Card details are entered directly into Stripe’s secure fields and never reach Treader’s servers.
  • We store, in our own database, only your plan, subscription status, renewal date, and the Stripe customer and subscription identifiers needed to manage your subscription. We can display your card brand and last four digits and your invoices, but we retrieve those from Stripe on demand — we do not store them.

Referrals.

  • Your referral code, a count of your successful referrals, and a record linking a referred account to the referring account so we can apply the referral reward.

3.2 Information we collect automatically

  • IP address. When your browser makes requests to our servers, we process your IP address to enforce rate limits and prevent abuse of our paid data services. For signed-in requests we key these controls to your account rather than your IP. For requests from visitors who are not signed in, we record the IP address as part of short, per-minute and per-day counters (see §11).
  • Request and device metadata. Our hosting provider (Vercel) processes standard technical information — such as IP address, approximate location, browser type, and the pages or endpoints requested — in server logs for reliability and security.
  • Cookies and local storage. We use a small number of strictly functional cookies and browser-storage items to keep you signed in and remember your preferences, plus first-party analytics storage set by our analytics provider. See §7 for the full list. We do not use advertising or cross-site tracking cookies.
  • Usage counters. We keep an aggregate count of your monthly AI (Scout) usage to enforce plan limits, and aggregate, non-identifying service metrics (for example, how often our map data cache is hit). These metrics are not tied to your identity or IP address.
  • How you found us. If your analytics setting allows it, we record with your new account how you arrived at Treader (the site or campaign link that referred you, the first page you landed on and the day, any shared trip you started from, whether you used a referral link, and whether you signed up with email or with Google) so we can tell which of our outreach works. The same details go to our analytics provider with your sign-up.
  • Map tiles. Our map is drawn using background tiles served directly to your browser by a third-party tile host (OpenFreeMap). As with loading any web resource, that host receives your IP address and the map area you are viewing. This request is not linked to your Treader account.

3.3 Information we receive from third parties

  • Google, if you choose Sign in with Google. Google confirms who you are and sends us your name, your email address, and a link to your Google profile photo. We ask for nothing else: we cannot see your contacts, email, files, or any other Google data, and we never post to your Google account. Our authentication provider also keeps Google’s identifier for your account so it can recognise you next time. We use your name as your Treader name and display name, and to suggest your username; your email to run your account; and your Google photo as your avatar, unless you sign up from Quebec, where we leave the avatar blank so you start with your initials instead. Your avatar appears on your public profile (see §9), so if you would rather not show your Google photo, replace it with a photo of your own in Settings › Account › Profile. What Google sends us is used only for these purposes, is shared only with the service providers in §8 that run your account, and is deleted when you delete your account. You can also remove Treader’s access from your Google Account settings. Treader’s use of information received from Google APIs adheres to the Google API Services User Data Policy.
  • Stripe tells us the status of your subscription and payments (for example, active, past due, or cancelled) so we can grant the right plan features.
  • If you follow a booking link on Treader and complete a purchase, our affiliate partners may send us a confirmation that a referred transaction occurred and its commission amount, so we can credit any promotional reward. They do not send us your name, email, or booking details. See §8.

4. Sensitive information

Some information can be more sensitive, and we handle it with particular care:

  • Identity and travel documents in your Travel Data Suite vault (which may include passports or other identity documents you choose to upload). These are stored privately and encrypted (see §14), are accessible only to you through signed, time-limited links, and are not shared with other users or sent to our AI provider. Storing a document here is your choice, and the vault is a convenience copy rather than an official record — keep your originals, and see Terms of Service, §11 for what that means in practice.
  • Precise location. Trip and stop coordinates, saved-spot locations, a moment’s location, locations you share in chat, and your home base are all location data. Much of this is data you deliberately enter about places, not continuous tracking of your device. Treader does not collect your device’s background or real-time GPS location; a map may use your device location only if you actively ask it to (for example, to centre the map on you), and that is handled by your browser.
  • Payment-card information, handled entirely by Stripe (see §3.1).
  • Health and belief-related preferences. The Scout preferences in §3.1 can reveal sensitive information: an allergy or an accessibility need is health information, and a dietary choice such as halal or kosher can reveal a religious belief. We treat them accordingly: every one of these fields is optional and you choose whether to provide it; they are used only to personalise the suggestions you ask for; they are never shown on your public profile and are never shared with other users; and the only third party they reach is our AI provider, as part of the Scout request you make (see §6). You can change or clear them at any time in Settings, and deleting your account deletes them.

Where the law requires your express consent to collect, use, or disclose sensitive information, we will obtain it. You should avoid placing sensitive information you do not want stored into free-text fields (such as notes or messages), and enter into the allergy and must-avoid fields only what you want Scout to act on.

5. How and why we use your information

We identify our purposes for using personal information at or before the time we collect it. We use it to:

  • Provide the Service — create and secure your account, and store and synchronise your trips, notes, spots, moments, messages, and documents across your devices and collaborators.
  • Power planning features — return places, photos, and routes for the areas and searches you request, and generate AI planning assistance through Scout (see §6).
  • Personalise suggestions using your stated travel preferences.
  • Enable social features — profiles, follows, direct messages, trip collaboration and invitations, and public trips, spots, and moments you choose to publish.
  • Process payments and manage subscriptions, including referrals and any promotional credits.
  • Keep Treader safe and available — authenticate requests, enforce rate limits, prevent abuse and fraud, moderate reported content, automatically check photos you post for other people to see for unsafe content (see §6), and protect our paid data services from being drained. Authorised Treader staff may view your account details and trip metadata (how many trips, how long, how many stops) through an internal console to answer support requests and investigate abuse. They do not read the contents of your trips, notes or messages there.
  • Communicate with you — send account and transactional messages such as your email-verification code and, through Stripe, billing receipts. These are part of the Service and are not marketing.
  • Send product and travel email, only if you ask us to. At sign-up you may tick an optional box to hear about new features, offers, and places worth planning around. The box is never pre-ticked, and we record the date you ticked it as our proof of consent under Canada's anti-spam legislation. You can withdraw at any time in Settings → Privacy → Email, or from the unsubscribe link in any such message. The email form on our guides works the same way: we send one email asking you to confirm, mail you only after you do, and every email carries an unsubscribe link. Withdrawing does not affect the account and transactional messages above.
  • Understand and improve the product — measure which features are used and where people get stuck, using our analytics provider (PostHog) tied to your account identifier, measure how many people arrive and from where using Google Analytics (which receives no account identifier), and diagnose errors and crashes using our error-reporting provider (Sentry). Analytics may include a replay of how the interface was used, in which every word on screen and everything you type is masked, and your travel documents, messages, notes, and Scout conversations are not recorded at all.
  • Comply with law — meet legal, tax, and accounting obligations and respond to lawful requests.

We do not sell your personal information, and we do not use it for third-party advertising. The web application contains no advertising network and no cross-site tracking pixels; analytics and error reporting run solely for our own product and reliability purposes.

Legal bases (EU/UK users). Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide the Service you request); our legitimate interests (to secure the Service, prevent abuse, and operate our business), balanced against your rights; your consent (for any optional processing that requires it, which you may withdraw); and compliance with legal obligations (such as tax records held by Stripe).

6. Artificial intelligence (Scout)

Scout is our optional AI planning assistant. It is powered by Google’s Vertex AI service using Google’s Gemini models. We use the same service to read bookings you ask us to import and to check photos for unsafe content. We want to be precise about what this involves.

What we send to the AI

When you use Scout, import a booking, or post a photo, our servers send the following to Google Vertex AI:

  • The messages you type to Scout, and recent turns of that conversation.
  • A summary of the trip you are planning — its name and destination, the stops on your itinerary (times, titles, and types), and, if you have set one, the trip’s budget total and roughly how much of it is planned.
  • The travel preferences you have set, so the suggestions fit you: your style, pace, budget, companions, and interests; your “about you” description; and the Scout preferences from §3.1 — your dietary requirements, the allergies you asked us to avoid, your accessibility needs, your must-avoids, whether you are travelling with children or a pet, and your tone and weather choices. Every one of these is optional; if you leave a field empty, nothing about it is sent. See §4 for how we treat the sensitive ones.
  • When you set dietary preferences, Scout may include words like “vegan” or “halal” in the place searches it runs through Google Maps Platform. No account identifier goes with them. To check menus, Scout reads restaurants’ public websites from our servers, and nothing about you is sent to them.
  • A short list of candidate places (names, categories, and ratings) so Scout can make relevant suggestions.
  • When you use Scout inside the Notes tool, the text of the notes you are working on.
  • When you import a booking, the text, screenshot, or PDF you paste or upload, or the text and first PDF attachment of a booking email you forward to your Treader import address.
  • Photos you post for other people to see (profile photos and banners, trip covers and trip photos, moments, and spot photos), so an automated check can flag unsafe content such as nudity or graphic violence. A photo it flags may be removed or hidden.

What we do not send to the AI

  • Your email address, password, or account identifier.
  • Your precise coordinates or map location.
  • The travel or identity documents in your vault.
  • Other users’ private messages or content you do not have access to.

Processing, retention, and training

  • Requests go to Vertex AI’s global endpoint, so Google may process them in any of its regions, in the United States or elsewhere.
  • We do not keep logs of your Scout prompts or the AI’s responses. About AI use we keep a monthly count, to enforce plan limits, and usage figures for each Scout request (its size in tokens, how long it took, and what it cost, never its words) with our analytics provider, to control costs. Booking details read from an import are kept only as the draft you review.
  • We use Vertex AI’s enterprise service. Under Google’s Vertex AI terms, prompts and responses are not used to train Google’s foundation models. Google may process this data to provide the service and for limited abuse-monitoring as described in its terms.

No automated decisions about you

Scout produces travel suggestions. It does not make decisions that produce legal or similarly significant effects about you (such as eligibility, pricing, or access decisions). AI output can be inaccurate or incomplete — always verify hours, availability, bookings, and travel details before relying on them.

7. Cookies and local storage

We use strictly functional cookies and browser-storage items, plus first-party analytics storage. We do not use advertising or cross-site tracking cookies.

Your choice about analytics. If you are visiting from Quebec, the European Economic Area, the United Kingdom, Switzerland or the United States, the analytics and audience-measurement items below are set only after you accept them. Nothing non-essential is stored on your device before you answer, and declining is one tap and costs you no functionality. Elsewhere they are on by default, as the law there allows, and you can switch them off at any time. If your browser sends a Global Privacy Control signal, we treat it as a no until you switch analytics on yourself. Either way the control is the same one: Settings › Privacy › Product analytics. Turning it off stops the capture and clears the identifier already stored on that device. The choice is remembered per browser, so it is made again on a new device. We tell where you are visiting from using the approximate region our host derives from your IP address. We do not store it for this; we do keep its country as a first guess at your home country (see §3), which you can change in Settings.

  • Authentication session. When you sign in, our authentication provider stores your session token in your browser (as a first-party cookie and/or local storage) so you stay signed in. It is cleared when you sign out.
  • Preview password cookie (treader_gate). While Treader is in private preview, entering the site password sets a functional cookie that lasts about 30 days so you are not prompted every visit. Its value is a one-way hash of the password, never the password itself or any personal data. It exists only while the preview gate is enabled.
  • Analytics (PostHog, first-party). Stores a random identifier in your browser (cookie and/or local storage) so we can count visits and understand feature usage. Requests go to our own domain and are relayed to PostHog acting as our service provider; no advertising network ever sees them. A click is recorded by which kind of element it was and where, never the words on it, and a page view by its address, never its title. Until you have an account, it also keeps a note on this device of how you first arrived (the referring site or campaign link, the first page you landed on and the day). Signing up, signing in or switching analytics off clears it, and it is not used after 90 days.
  • Audience measurement (Google Analytics, third-party). When enabled, Google Analytics stores a random identifier in your browser so we can count visits and see which pages people arrive on. It is configured for measurement only — advertising features, ad personalisation, and Google Signals are switched off, and we never send it your account identifier, your email, anything you type into Treader, a page’s title, or any part of a link beyond the page address and campaign tags (an invite or settle-up link is sent without its code).
  • Preferences and app state (stored in your browser’s local storage). These remember things like your theme and layout choices, a lightweight snapshot of your profile for faster page loads, panel sizes, unread-message markers, onboarding completion, a captured referral code, your analytics choice, whether to keep you signed in, and client-side counters that throttle repeated sign-in attempts.
  • Payment and security checks. When you open checkout, Stripe sets its own cookies to prevent payment fraud, and the sign-up and sign-in forms run a Cloudflare Turnstile check that tells people from bots. Both are strictly necessary for what you asked to do, run only on those screens, and are never used for advertising.

Please note: the standalone Notes workspace saves its content only in your browser’s local storage, not on our servers. That means it is not backed up, is not synced across devices, and is not removed by deleting your account — clear your browser storage to remove it. (Notes you attach to a trip are stored on our servers and are covered by account deletion.)

8. How we share information (service providers)

We do not sell your personal information. We share it only as described here. Our providers act as our processors / service providers and are permitted to use the information only to provide their service to us.

ProviderPurposeWhat it receives
Supabase (US)Authentication, database, and file storage — our primary infrastructure.Substantially all account data, content, messages, and uploads described in §3.
Google Vertex AI (US and other regions)Powers the Scout assistant, reads bookings you import, and checks posted photos for unsafe content.Only the data listed in §6 (Scout chat text, trip summary, preferences, candidate place names, notes text, bookings you import, and photos you post for other people to see).
Google Maps Platform (US)Places, place details, photos, and routing.The map area you view, your typed search terms (and Scout’s, which may carry a diet word such as “vegan”), place identifiers, and stop coordinates. Not your identity.
OpenStreetMap servicesFree fallback for places and routing (Nominatim, Overpass, OSRM), and map tiles (OpenFreeMap).Map areas, search terms, and coordinates. Tiles are requested directly by your browser, which reveals your IP address to the tile host.
Open-MeteoWeather for destinations.Only an approximate destination coordinate and date. No identity.
Stripe (US)Payment processing and subscription billing.Your email and account identifier, and the billing name, address, and card details you enter into Stripe (see §3.1).
Vercel (US)Application hosting and delivery.Standard request metadata, including IP address, in server logs.
PostHog (US)Product analytics — feature usage, funnels, and masked session replay.Your account identifier and plan tier, pages viewed, interface interactions (which element, never the words on it), and device/browser metadata. In replays every word on screen and everything you type is masked, and your travel documents, messages, notes, and Scout conversations are not recorded at all. Our servers also send it a few events tied to your account whatever your analytics setting: starting a checkout, a subscription starting or ending, deleting your account, opening your referral link, voting in a date poll, and the size and cost of each Scout request (never its words). Never your email or name.
Google Analytics (US)Audience measurement — how many people arrive and which pages they land on.Pages viewed, the site that referred you, approximate location derived from your IP address, and device/browser metadata. Advertising features and Google Signals are off. Not your account identifier, email, name, or anything you type into Treader.
Vercel Analytics (US)Aggregate traffic and page-performance measurement.Pages viewed, referrer, and device/browser metadata, aggregated. No cookie is set and no cross-site identifier is used.
Sentry (US)Error and crash reporting.Technical details of errors (stack trace, page, browser and device metadata, IP address). Request bodies and auth headers are excluded.
Resend (US)Email delivery, and receiving booking emails you forward to us.Your email address and the messages we send you (sign-in codes, receipts, renewal notices, and any email you opted into), and the booking emails you forward to your Treader import address.
Cloudflare Turnstile (US)Telling people from bots on the sign-in and sign-up forms.Your IP address and browser and device signals while the check runs. Not your account details.
Your browser’s push serviceDelivering notifications, only if you turn them on (Google, Apple, Mozilla, or Microsoft, depending on your browser).A device address your browser creates, and each notification in encrypted form the push service cannot read.
Travel data providersFlight status and prices, stay prices, public holidays, road, border, wildfire and avalanche conditions, and park reservations (for example SerpApi, Nager.Date, Recreation.gov, the U.S. National Park Service, and government road and border agencies).Only the places, routes, dates, and flight numbers being looked up. Never your identity.
Affiliate partnersBooking links (Booking.com, GetYourGuide, Outdoorsy, RVshare).When you click a booking link, your browser goes directly to the partner. We append the destination/search term and, if you are signed in, an anonymous Treader account identifier so a resulting purchase can be credited. See below.

About booking links. Booking links are optional. If you follow one while signed in, we include your Treader account identifier so that, if you complete a purchase, our reward system can credit your account. The partner’s own privacy policy governs what it does with your visit and purchase. You can choose not to use these links; an operator can also disable the entire booking-link surface.

Other disclosures.

  • Content you publish is shared as you direct — see §9.
  • Apps you connect. If you connect Treader to an AI assistant such as Claude (made by Anthropic), that assistant can list and read your trips and create new trips you ask it to, for as long as it stays connected. What it does with that data is governed by its maker’s terms. You can disconnect it at any time in the assistant’s settings.
  • Legal and safety. We may disclose information where required by law, to respond to lawful requests, to enforce our Terms, or to protect the rights, safety, or property of Treader, our users, or the public.
  • Business transfers. If Treader is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction; we will require the recipient to honour this policy or notify you of any material change.

9. Public and social features

Treader includes features that let you share content publicly. When you choose to make something public, it can be viewed by anyone — including people without a Treader account and search engines — until you unpublish or delete it. Specifically:

  • Public profile (at treader.ca/u/your-username): your username, display name, and avatar are visible; and, unless your profile is private, your bio, home base, banner, links, accent, and follower/following counts. Your email is never shown publicly, and neither are your travel or Scout preferences (including your dietary, allergy, and accessibility fields). If you create your account from Quebec, your profile starts private and out of search engines by default, and new followers need your approval; you can change either setting in Settings.
  • Public trips (at treader.ca/t/its-link): when you publish a trip, its name, destination, dates, and entire itinerary — including your free-text notes and checklists — become publicly readable. Do not publish a trip that contains information you want to keep private. If you also turn on “Show public trips in search engines” in Settings, search engines may index your published trips and their name, destination, length, and stop count are listed at treader.ca/t.
  • Community spots and public moments: spots and moments you mark as public (name, category, location, notes, photos, ratings) are visible to other users and, for public items, to anyone.

Content shared with a limited audience — direct messages, trip-group chat, friends-only or private spots and moments, and private trips — is visible only to the people you share it with. Remember that anyone who can see your content can copy or re-share it outside Treader.

10. International data transfers

Treader is operated from Alberta, Canada, but our infrastructure and service providers — Supabase, Google, Stripe, and Vercel — store and process personal information in the United States, and Google may process AI requests (see §6) in its data centres in other countries. This means your personal information is transferred outside your province and, if you are outside Canada, outside your country. As a result, it may be accessible to those providers and, in limited circumstances, to foreign courts, law enforcement, or regulatory authorities under the laws of the jurisdictions where it is processed.

We use contractual and technical measures to require our providers to protect your information to a comparable standard and to use it only to provide services to us. By using Treader, you acknowledge this cross-border processing.

EU/UK users: where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) implemented by our providers. You may request more information about these safeguards using the contact details in §16.

11. How long we keep your information

We keep personal information only as long as needed for the purposes described in this policy, to provide the Service, and to meet legal, accounting, or reporting requirements. In practice:

  • Account, profile, content, messages, and uploads — kept while your account is active, and deleted when you delete your account (see §12). Deleting your account is immediate and permanent.
  • Route pictures in trip emails: a picture of your route, drawn from your trip's stops, is stored so it can show in your email, and deleted after about 60 days.
  • Trips you delete — moved to a recoverable state for 30 days so you can restore them, then permanently purged.
  • Billing records — subscription status and identifiers are kept while you have or had a paid plan. Stripe retains payment and invoice records under its own policies and applicable tax law.
  • Security and rate-limit records (including the IP addresses of visitors who are not signed in): kept for about two days, then deleted.
  • Analytics and error reports: session replays are deleted after 30 days. Other analytics events and error reports are kept by PostHog and Sentry for as long as our plan with each keeps them. You can ask us to delete yours (see §12).
  • Cached map/place data — held very briefly to avoid repeat lookups; it contains no account identifiers.
  • Aggregate usage counts — retained to enforce plan limits and understand overall usage; they are not tied to identifiable content.

Content stored only in your browser (such as the standalone Notes workspace and cached preferences) stays on your device until you clear it and is not affected by server-side deletion.

12. Your rights and choices

Everyone.

  • Access and edit most of your information directly in the app — your profile, preferences, trips, spots, moments, messages, and documents.
  • Delete your account at any time from Settings. This permanently and irreversibly deletes your account and the data linked to it.
  • Turn off product and travel email in Settings → Privacy → Email, or from the unsubscribe link in any such message. Account and billing messages continue, because they are part of the Service.
  • Withdraw consent to optional processing, and contact us with any privacy request at support@treader.ca.

Canada (PIPEDA and Alberta PIPA).

You have the right to access the personal information we hold about you, to ask that we correct inaccuracies, and to ask how it has been used and to whom it has been disclosed. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice. We will respond to a verified request within the timeframe required by law (generally 30 days). If you are not satisfied with our response, you may complain to:

Quebec (Law 25).

If you are in Quebec, you additionally have the right to data portability (to receive certain computerized personal information in a structured, commonly used technological format) and to be informed about, and to request review of, decisions based exclusively on automated processing. You may complain to the Commission d’accès à l’information. Tools that could identify, locate, or profile you, such as our product analytics, stay off until you switch them on (see §7). Our person in charge of the protection of personal information is named in §1.

European Union / United Kingdom (GDPR).

If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests), the right not to be subject to solely automated decisions with legal or similarly significant effects, and the right to withdraw consent at any time. We will respond within one month. You may lodge a complaint with your local supervisory authority.

United States, including California (CCPA/CPRA).

If you are a California resident, you have the rights to know/access, delete, and correct your personal information, to opt out of the “sale” or “sharing” of personal information and to limit the use of sensitive personal information, and not to be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes that would trigger the right to limit. We honour opt-out preference signals such as Global Privacy Control. Visitors in the United States are asked before any product analytics, audience measurement or session replay runs, and nothing is recorded until they accept (§7). Residents of other U.S. states with comprehensive privacy laws have comparable rights, which we extend to them. We will respond within 45 days (extendable as the law permits).

To protect your account, we will take reasonable steps to verify your identity before acting on a request — typically by confirming control of your account or account email. You may use an authorised agent where the law allows.

13. Children and minors

Treader is intended for a general audience and is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your jurisdiction, if higher) to create an account, and you must be the age of majority in your province, state, or country to purchase a paid plan. In Quebec, personal information of a minor under 14 will not be collected without parental consent.

We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe a child has provided us personal information, contact us at support@treader.ca and we will delete it.

14. How we protect your information

We use technical and organizational safeguards appropriate to the sensitivity of the information, including:

  • Encryption in transit — the Service is served over HTTPS, and files you upload or download travel over that same encrypted connection.
  • Encryption at rest — the database and the file storage holding your content, including Travel Data Suite documents, are encrypted at rest by our infrastructure providers.
  • Database-level access controls — row-level security rules ensure each account can access only its own data (and content explicitly shared with it); these rules, not the browser, are the enforcement boundary.
  • Authenticated access — every request to our data endpoints is verified against a signed session token.
  • Secret isolation — provider keys are held only on our servers and are never exposed to the browser; the browser communicates only with Treader’s own endpoints.
  • Payment security — card data is handled entirely by Stripe (a PCI-DSS Level 1 provider) and never reaches our servers.
  • Password protection — passwords are stored only as salted hashes by our authentication provider.
  • Abuse controls — server-side rate limiting and spend caps protect the Service and your data.
  • Private storage — sensitive uploads (such as travel documents and private spot photos) are kept in non-public storage reached only through signed, expiring links.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach of security that creates a real risk of significant harm to you, we will notify you and the relevant authorities — including, as applicable, the Office of the Information and Privacy Commissioner of Alberta, the Office of the Privacy Commissioner of Canada, and (for EU/UK users) the relevant supervisory authority — without undue delay and as required by law.

15. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or the law, and each update changes the “Last updated” date above. When a change is material, for example a new kind of information we collect or a new use for it, we tell you before it takes effect, in the app and, if you have an account, by email. If a new use needs your consent, we ask for it first.

16. Contact us and complaints

For any privacy question, to exercise a right, or to make a complaint, contact our person in charge of the protection of personal information (the Founder of Treader) at support@treader.ca. We take privacy complaints seriously and will investigate and respond.

If you are not satisfied with our response, you may also contact the applicable regulator listed in §12 — for Alberta residents, the Office of the Information and Privacy Commissioner of Alberta, and for other Canadians, the Office of the Privacy Commissioner of Canada.

Mail: Treader, 10503 98 Avenue NW, Edmonton AB T5K 0B2, Canada.

This Privacy Policy is provided for transparency and does not constitute legal advice. If you have questions about how it applies to you, please contact us.