Legal
Privacy
Plain-language statement of what we hold, why, and who can reach it.
What we collect
- Account details: email address, and optionally a display name and phone number.
- Report content: reservation details, what happened, financial impact and the outcome you want.
- Evidence: files you choose to upload.
- Operational records: consent records, notifications and audit events describing actions taken on your case.
What we never collect
- Full payment card numbers, CVV codes or bank credentials. We record only the payment method type.
- Government identity documents, unless you volunteer one for identity confirmation and we explicitly request it.
- Location tracking or advertising identifiers.
How evidence is stored
- Evidence lives in private storage that is not publicly addressable.
- Access requires an authenticated request and is served through short-lived signed links.
- Only you and authorised reviewers can retrieve your files. Access is recorded in the audit trail.
What is never published
- Your name, email, phone number or address.
- Confirmation numbers and payment details.
- Uploaded evidence files.
- Internal reviewer notes.
Publication and consent
- A report is private by default. It becomes publicly visible only if you consent and a reviewer publishes it.
- Consent is versioned and recorded. You can withdraw it, after which the public entry is removed.
Your rights
- Access, correct, export or delete your account data by contacting us through the corrections page.
- Withdraw a report at any time.
- Ask which categories of data are held about you and why.
Third parties
- The platform uses a hosted database, authentication and file-storage provider to operate.
- Transactional email, mapping, analytics and error monitoring are integrated behind service abstractions; where a provider is enabled, only the minimum data required is shared, and analytics events never contain report content.
This statement describes current platform behaviour and is updated whenever the data model or providers change.