Privacy Policy
Last Updated: December 2025
At Potniq, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service.
1. Who We Are
Potniq Ltd ("Potniq", "we", "us", or "our") is the data controller responsible for your personal data. We are a company registered in England and Wales (Company Number: 16877633).
Contact: [email protected]
If you have any questions about this privacy policy or our data practices, please contact us.
2. Information We Collect
Account Information
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, authentication, service communications | Contract — necessary to provide the Service |
| Full name | Identify you and personalise your experience | Contract — necessary to provide the Service |
| Password (hashed) | Account security | Contract — necessary to provide the Service |
| Job title, Company (optional) | Understand our users and improve the Service | Consent — you choose to provide this |
Itinerary Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Location information (addresses, airports, place names) | Calculate routes and transit times | Contract — necessary to provide the Service |
| Travel dates and times | Plan your itinerary and calculate departure times | Contract — necessary to provide the Service |
| Flight details (times, flight numbers) | Plan your itinerary and calculate departure times | Contract — necessary to provide the Service |
| Accommodation details | Plan transit between locations | Contract — necessary to provide the Service |
| Meeting/activity times and locations | Calculate when you need to leave | Contract — necessary to provide the Service |
Technical & Analytics Data
| Data | Purpose | Legal Basis |
|---|---|---|
| IP address (at registration) | Fraud prevention, security, understanding user geography | Legitimate interest — security and service improvement |
| Device information (browser type, operating system) | Ensure the Service works correctly on your device | Legitimate interest — service operation |
| Usage patterns (features used, frequency of access) | Identify bugs, optimise performance, develop new features | Legitimate interest — service improvement |
| Performance metrics (page load times, errors) | Monitor and improve service reliability | Legitimate interest — service operation |
3. How We Use Your Data
We use the information we collect to:
- •Calculate transit timing: Process your itinerary data to provide accurate travel time calculations
- •Improve the product: Analyse usage patterns to identify bugs, optimise performance, and develop new features
- •Communicate with you: Send service updates, respond to support requests, and notify you of important changes
- •Ensure security: Detect and prevent fraudulent activity, unauthorised access, and security threats
- •Comply with legal obligations: Meet regulatory requirements and respond to lawful requests
We Will Never Sell Your Data
Potniq will never sell, rent, or trade your personal data to third parties for marketing or advertising purposes. Your travel plans, locations, and personal information are yours. We only share data with the service providers listed in Section 5, solely to operate the Service.
4. Data Storage and Security
Where Your Data Is Stored
Your data is stored using secure cloud infrastructure provided by Supabase, with database servers located in the United States (US-East region). All data is encrypted in transit (TLS/SSL) and at rest.
Security Measures
- •Encryption in transit: All data transmitted between your browser and our servers uses HTTPS/TLS encryption
- •Encryption at rest: Data stored in our database is encrypted using AES-256
- •Password security: Passwords are hashed using bcrypt with salt — we never store plain text passwords
- •Access controls: Access to personal data is limited to authorised personnel who need it for their work
- •Row-Level Security: Database policies ensure you can only access your own data
While we take security seriously, no system is completely secure. If you believe your account has been compromised, please contact us immediately.
5. Third-Party Services (Data Processors)
We use carefully selected third-party service providers to help us operate the Service. These providers process your data only on our instructions and are contractually bound to protect it.
DigitalOcean
- What they do: Host our website and API servers
- Data processed: All data transmitted to and from the Service passes through DigitalOcean's infrastructure
- Location: United States (US-East)
- Safeguards: DigitalOcean participates in the EU-US Data Privacy Framework. Data Processing Agreement in place.
- Privacy policy: digitalocean.com/legal/privacy-policy
Supabase
- What they do: Provide our database infrastructure and user authentication
- Data processed: Account information, itinerary data, authentication tokens
- Company location: Singapore
- Data location: United States (AWS US-East)
- Safeguards: Supabase complies with GDPR. Singapore has an EU adequacy decision. US data transfers covered by Standard Contractual Clauses. Data encrypted at rest and in transit.
- Privacy policy: supabase.com/privacy
Resend
- What they do: Send transactional emails (account verification, password resets, service notifications)
- Data processed: Email address, name, email content
- Location: United States
- Safeguards: Resend complies with GDPR.
- Privacy policy: resend.com/legal/privacy-policy
ipapi.co
- What they do: IP geolocation lookup at registration (to detect your country and timezone)
- Data processed: IP address only — no other user data is sent
- Privacy policy: ipapi.co/privacy
Google Maps Platform
- What they do: Provide location search (autocomplete), route calculations, and transit time estimates
- Data processed: Location searches and addresses for route calculations. These are typically public locations (airports, hotels, venues). API calls are made server-side, so Google receives our server's IP address, not yours.
- Location: Google's global infrastructure
- Note: Google's standard API Terms of Service include data processing provisions. No personal data (names, emails) is shared with Google.
- Privacy policy: policies.google.com/privacy
Paddle (Payments)
- What they do: Paddle is our Merchant of Record — they handle all payment processing, billing, invoicing, and tax compliance
- Relationship: When you subscribe, your payment relationship is directly with Paddle, not Potniq. Paddle is an independent data controller for payment data, not our processor.
- Data Paddle collects directly: Payment card details, billing address, transaction history — stored by Paddle, not accessible to us
- Data we share with Paddle: Email address (to link your subscription to your account and send receipts)
- Privacy policy: paddle.com/legal/privacy
6. International Data Transfers
Your personal data is transferred to, and processed in, countries outside the United Kingdom:
United States (data storage and processing):
- •DigitalOcean — website and API hosting
- •Supabase — database storage (AWS US-East)
- •Resend — email delivery
Singapore (company operations):
- •Supabase is headquartered in Singapore
Safeguards: The US providers listed above participate in the EU-US Data Privacy Framework. Singapore has an adequacy decision from the EU (January 2024), which the UK recognises. Where additional safeguards are required, Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office are in place.
7. Data Retention
We retain your data only as long as necessary to provide our services:
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account, plus 30 days for backup deletion |
| Itinerary data | Until you delete the itinerary or your account |
| Authentication logs | 90 days (for security purposes) |
| Analytics data | Anonymised after 90 days; aggregated data retained for 24 months |
| Payment records | Stored by Paddle (our payment provider), not by Potniq — see Paddle's privacy policy |
| Deleted account data | Permanently removed within 30 days of deletion request |
8. Your Rights
Under UK GDPR, you have the following rights:
Right of Access
You can request a copy of the personal data we hold about you. We will respond within one month.
Right to Rectification
If your personal data is inaccurate or incomplete, you can ask us to correct it. You can update most information directly in your account settings.
Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data at any time by emailing [email protected] with the subject line "Deletion Request". We will delete your account and all associated data within 30 days, unless we have a legal obligation to retain it.
Note: Deleting your account will permanently remove all your itinerary data. This cannot be undone.
Right to Restrict Processing
You can ask us to temporarily stop processing your data in certain circumstances, for example while we verify its accuracy.
Right to Data Portability
You can request your data in a structured, machine-readable format (such as JSON or CSV) to transfer to another service.
Right to Object
You can object to processing based on legitimate interests. If you object, we will stop processing unless we have compelling grounds to continue.
Rights Related to Automated Decision-Making
We do not make any decisions based solely on automated processing that significantly affect you.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond within one month. We may ask you to verify your identity before processing your request.
9. Cookies and Tracking
We use only essential cookies necessary for the Service to function:
- •Authentication cookies: To keep you logged in securely
- •Session cookies: To remember your preferences during a session
We do not use advertising cookies or cross-site tracking cookies. Our analytics are configured to work in a privacy-preserving manner without tracking cookies where possible.
You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of Potniq.
10. Children's Privacy
Potniq is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we discover that we have inadvertently collected data from a child under 16, we will delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- •Updating the "Last Updated" date at the top of this policy
- •Sending an email notification to your registered email address
- •Displaying a prominent notice in the application
Your continued use of Potniq after changes become effective constitutes acceptance of the updated policy.
12. Additional Information for EU Users
If you are located in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) also applies to our processing of your personal data. The rights and protections described in this policy meet or exceed EU GDPR requirements.
You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at: edpb.europa.eu/about-edpb/about-edpb/members_en
13. Additional Information for California Users
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may provide you with additional rights.
Your California Privacy Rights:
- •Right to Know: You can request what personal information we collect, use, and disclose (covered by our Right of Access above)
- •Right to Delete: You can request deletion of your personal information (covered by our Right to Erasure above)
- •Right to Correct: You can request correction of inaccurate information (covered by our Right to Rectification above)
- •Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioural advertising. There is nothing to opt out of.
- •Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Categories of Personal Information We Collect:
- •Identifiers (name, email address, IP address)
- •Commercial information (subscription status, payment history)
- •Internet activity (usage data, device information)
- •Geolocation data (addresses and locations you enter in itineraries)
We do not sell your personal information. We have not sold personal information in the preceding 12 months and have no intention of doing so.
To exercise your California privacy rights, contact us at [email protected].
14. Complaints
If you have concerns about how we handle your personal data, please contact us first at [email protected]. We will try to resolve your concern and respond within 7 business days.
UK Users: You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- •Website: ico.org.uk/make-a-complaint
- •Telephone: 0303 123 1113
EU Users: You have the right to lodge a complaint with your local data protection authority. See Section 12 above.
California Users: You may also contact the California Attorney General's office at oag.ca.gov/privacy
15. Contact Us
For any questions about this privacy policy or our data practices, email us at [email protected].
Privacy Contact
Potniq Ltd
Company Number: 16877633
Email: [email protected]
We will respond to all privacy-related inquiries within 7 business days.