Privacy

Privacy policy

Escape Muse is in a launch-readiness state. Local saves use browser storage. Trip briefs and package quote requests are only persisted when the approved Supabase configuration is present, and production form APIs fail closed when required persistence is missing.

Escape Muse launch data map
AreaData collectedStorageControl
Local account and saved placesSaved guides, saved destinations, visited/want-to-go places, local sign-in flag, and newsletter email when saved locally.Browser localStorage on the visitor's device.Clear browser site data. Local account sync is deferred until approved auth and persistence are connected.
Trip BriefEmail, destination or shortlist, dates or season, flexibility, trip length, budget range, travelers, style tags, must-haves, avoidances, notes, and consent.Supabase only when production persistence is configured. Production requests fail closed when persistence is missing.Use contact with the submitted email or reference context for correction, export, or deletion requests.
Package quote requestName, email, optional phone, airport, dates or month, traveler/room counts, hotel tier, room and flight preferences, selected upgrades, notes, acknowledgements, and marketing consent.Supabase only when quote persistence is configured. No booking, deposit, supplier confirmation, or package contract is created from the form.Use contact with the quote reference for corrections. Do not submit passport, payment card, medical, or emergency information.
Payments, analytics, email, monitoringDisabled or configuration-gated until provider, consent, and privacy review are approved.Stripe should handle card details if checkout is later enabled; Escape Muse should not store full payment card data.Production env writes, tracking behavior, monitoring DSNs, and payment activation require explicit approval before launch.
Hotel booking (activation-gated)Guest names and ages, booking email and phone, stay dates, arrival time, hotel and room choice, residency, special request, cancellation acknowledgements, supplier and payment references.RLS-protected Supabase booking tables when configured. Stripe handles card data. RateHawk receives only the fields required for supplier fulfilment; the B2B contact remains the fixed Nova contact.Guest bookings use an opaque private link. Account claiming requires the same verified email. Live checkout remains disabled until legal, provider, database, email, and payment gates are approved.

Data minimization

Trip and quote forms are for planning context only. Do not submit passport numbers, payment card details, medical records, emergency information, or sensitive identity documents. Free-text notes should stay limited to travel preferences and constraints.

Deletion, export, and correction

Until the production admin workflow is connected, requests are handled manually through the contact route. Retention windows and the final paid-launch privacy policy still require legal review before production payments or live quote operations are enabled.

Contact support