Remsee Privacy Policy

Version: v1.0
Effective date: 29 June 2026
Company: Numtrend Co., Ltd.

1. Purpose

This Privacy Policy explains how Numtrend Co., Ltd. collects, uses, discloses, stores, and protects Personal Data when you use Remsee.

2. Scope

  1. This policy applies to the Service, including AI Features, social feed, User Content, wallet, subscriptions, boost posts, affiliate booking referrals, marketplace features, customer support, websites, and mobile applications.
  2. Travel Partners, app stores, payment providers, and external websites may process Personal Data under their own privacy policies.

3. Roles

  1. For consumer Service use, Numtrend Co., Ltd. generally acts as a controller or equivalent business/operator.
  2. For enterprise, partner, or processor arrangements, roles may be governed by the Data Processing Agreement or a signed agreement.
  3. Where we process Personal Data for a third party, that party may be the controller and we may act as processor or service provider.

4. Personal Data We Collect

  1. Account data: name, username, email, phone number if provided, authentication identifiers, profile photo, language, country, and account settings.
  2. Travel preference data: destinations, dates, budgets, travel style, interests, accessibility preferences, saved places, saved trips, itinerary details, and planning prompts.
  3. User Content: posts, comments, reviews, images, videos, captions, creator materials, marketplace listings, reports, and profile content.
  4. AI interaction data: prompts, inputs, generated itineraries, recommendations, feedback, safety signals, and AI Feature usage logs.
  5. Wallet and transaction data: RSM balances, grants, rewards, token transactions, subscription tier, boosts, marketplace purchases, refunds, and ledger metadata.
  6. Booking referral data: affiliate click identifiers, referral URLs, partner identifiers, destination search parameters, booking metadata received from Travel Partners, and commission attribution data.
  7. Payment data: purchase status, subscription status, app store transaction identifiers, payment processor identifiers, invoices, receipts, and limited payment metadata. We do not intentionally store full card numbers.
  8. Device and usage data: IP address, device identifiers, operating system, app version, browser, crash logs, diagnostics, session data, analytics events, security logs, push notification tokens, and notification preferences.
  9. Location data: approximate location from IP address and precise location only if you grant device permission.
  10. Communications: support messages, surveys, feedback, legal requests, and preference center choices.
  11. Compliance data: age confirmation, consent records, fraud signals, moderation records, report records, copyright notices, sanctions screening results if applicable, and audit logs.

5. Sources of Personal Data

  1. You provide data directly.
  2. Data is generated through your use of the Service.
  3. We receive data from authentication providers, app stores, payment providers, analytics providers, cloud providers, AI providers, Travel Partners, affiliate networks, fraud prevention providers, notification providers, mapping providers, bot protection providers, error monitoring providers, and support tools.
  4. Other Users may provide data about you through tags, comments, reports, messages, or User Content.

6. How We Use Personal Data

  1. Provide, maintain, secure, and improve the Service.
  2. Create and manage Accounts.
  3. Generate AI trip plans, recommendations, budget suggestions, packing lists, and personalized travel experiences.
  4. Operate social feed, User Content, moderation, reporting, creator tools, and community features.
  5. Operate wallet, RSM grants, rewards, subscriptions, boosts, marketplace transactions, refunds, and purchase records.
  6. Facilitate Affiliate Booking referrals and partner attribution.
  7. Process payments and subscription status through third-party providers.
  8. Provide customer support and legal notices.
  9. Detect, prevent, investigate, and respond to fraud, abuse, security incidents, policy violations, and unlawful activity.
  10. Measure performance, debug errors, conduct analytics, and improve product quality.
  11. Send service messages, transactional notices, marketing communications where permitted, and preference-based recommendations.
  12. Comply with Applicable Law, enforce terms, and protect rights.

7. Legal Bases for GDPR and UK GDPR

Where GDPR, UK GDPR, or similar laws apply, we rely on:

  1. Contract: to provide the Service, manage Accounts, process subscriptions, operate wallet features, and deliver requested features.
  2. Consent: for optional marketing, certain cookies, precise location, and other consent-based processing.
  3. Legitimate interests: for security, fraud prevention, product improvement, analytics, service communications, moderation, and business operations, balanced against your rights.
  4. Legal obligation: for tax, accounting, consumer protection, law enforcement, sanctions, and regulatory compliance.
  5. Vital interests or public interest where relevant to urgent safety or legal situations.

8. PDPA Notice

Where Thailand's Personal Data Protection Act or similar PDPA laws apply:

  1. We process Personal Data for the purposes described in this policy.
  2. We use legal bases recognized by applicable PDPA laws, including contract, consent, legitimate interests, legal obligation, and other permitted bases.
  3. You may have rights to access, correct, delete, restrict, object, withdraw consent, request portability, and complain to a supervisory authority.
  4. Withdrawal of consent does not affect prior lawful processing and may limit certain features.

9. CCPA and US State Privacy Notice

Where the California Consumer Privacy Act, as amended by the CPRA, or similar US state privacy laws apply:

  1. We may collect the categories listed in Section 4.
  2. We use these categories for the business and commercial purposes listed in Section 6.
  3. We may disclose categories of Personal Data to service providers, processors, contractors, Travel Partners, payment providers, analytics providers, AI providers, and legal recipients.
  4. We do not sell Personal Data in the traditional sense. If any analytics, affiliate attribution, advertising, or similar activity is treated as "sale", "sharing", or targeted advertising under applicable US state privacy laws, we will provide required notices and opt-out choices.
  5. You may have rights to know, access, delete, correct, opt out of sale/sharing or targeted advertising, limit use of sensitive Personal Data, and non-discrimination.

10. Cookies and Tracking

  1. We use cookies, SDKs, pixels, local storage, and similar technologies as described in the Cookie Policy.
  2. You can manage certain preferences through browser settings, device settings, consent banners, or in-app controls where available.

11. AI Processing

  1. AI Feature inputs and outputs may be processed by Remsee and approved AI providers to generate, personalize, evaluate, secure, and improve AI Features.
  2. Do not submit sensitive Personal Data, passport numbers, government IDs, payment card numbers, health information, or confidential third-party data into AI prompts unless a feature expressly requests it and appropriate safeguards are stated.
  3. AI Output should not be treated as professional, legal, medical, immigration, financial, safety, or travel-agent advice.

12. Sharing Personal Data

We may share Personal Data with:

  1. Service providers and processors.
  2. AI and cloud infrastructure providers.
  3. Analytics, diagnostics, and security providers.
  4. Authentication providers.
  5. Payment processors, app stores, and subscription management providers.
  6. Travel Partners and affiliate networks when you click or use booking referral features.
  7. Marketplace sellers or buyers as necessary for transactions, support, delivery, compliance, or disputes.
  8. Other Users when you post User Content or interact socially.
  9. Professional advisers, auditors, insurers, and corporate transaction parties.
  10. Regulators, courts, law enforcement, and other recipients where legally required or necessary to protect rights.

12A. Third-Party Services We Use

Remsee may use third-party service providers to operate, secure, measure, and improve the Service. These providers process data under their own terms and privacy notices where applicable. Current or planned providers may include:

  1. Supabase for authentication, database, storage, and backend infrastructure.
  2. Firebase for analytics, cloud messaging, and related app services.
  3. PostHog for product analytics.
  4. Sentry for error monitoring, crash reporting, and diagnostics.
  5. RevenueCat, Apple App Store, and Google Play for subscriptions, in-app purchases, entitlement status, receipts, and purchase validation.
  6. Google Maps and device location services for maps, nearby places, and travel-location features.
  7. Cloudflare Turnstile for bot protection and abuse prevention.
  8. AI and cloud infrastructure providers for AI Features, hosting, security, and service operation.
  9. Travel Partners and affiliate networks for booking referral attribution when you use partner booking links.

We do not intentionally provide full payment card numbers to Remsee systems. Payment details are processed by app stores or payment providers.

13. International Transfers

  1. We may process and transfer Personal Data across borders.
  2. Where required, we use appropriate safeguards such as standard contractual clauses, data processing agreements, transfer impact assessments, consent, adequacy decisions, or other lawful mechanisms.

14. Retention

  1. We retain Personal Data for as long as needed for the purposes described in this policy, including Service operation, security, legal compliance, dispute resolution, and enforcement.
  2. Account data is generally retained while your Account is active.
  3. When you request Account deletion in the app, your Account is deactivated and scheduled for permanent deletion after a 30-day grace period (during which it can be restored via support). After the grace period, your Account and associated personal data — including trips, posts, and other User Content — are permanently erased, except for records we are required or permitted to retain under Applicable Law.
  4. Wallet, transaction, tax, payment, fraud, audit, and legal records may be retained for longer periods as required by law or legitimate business needs.
  5. Deleted User Content may remain in backups, logs, moderation records, legal holds, or partner systems for limited periods.

15. Your Rights and Choices

Depending on your location, you may request:

  1. Access to Personal Data.
  2. Correction of inaccurate Personal Data.
  3. Deletion of Personal Data.
  4. Restriction or objection to processing.
  5. Portability.
  6. Withdrawal of consent.
  7. Opt out of marketing.
  8. Opt out of sale, sharing, or targeted advertising where applicable.
  9. Limitation of sensitive Personal Data use where applicable.
  10. Appeal of certain privacy decisions where required by law.

Submit requests to privacy@numtrend.com. We may verify your identity before responding.

15A. Account Deletion

You may request deletion of your Remsee Account in the app, where available, or by contacting privacy@numtrend.com or remseesupport@numtrend.com. Account deletion requests are handled as described in Section 14. If you submit a request by email, include the email address or account identifier associated with your Remsee Account so we can verify and process the request.

16. Children's Privacy

  1. Remsee is not intended for children under 13.
  2. We do not knowingly collect Personal Data from children below the required age without appropriate consent.
  3. If you believe a child has provided Personal Data improperly, contact privacy@numtrend.com.

17. Security

  1. We use technical, organizational, and administrative safeguards designed to protect Personal Data.
  2. No system is completely secure. See the Security Policy for more information.

18. Automated Decision-Making

  1. We may use automated systems for recommendations, personalization, ranking, moderation, fraud detection, security, and AI Features.
  2. Where legally required, you may request human review or object to certain automated decisions.

19. Data Protection Contacts

Privacy: privacy@numtrend.com
DPO or representative: dpo@numtrend.com

20. Changes

We may update this Privacy Policy. We will provide notice where required by Applicable Law.

21. Governing Law

This Privacy Policy is subject to the laws of the Kingdom of Thailand, with the courts of Bangkok having jurisdiction, unless mandatory privacy or consumer protection law provides otherwise.

22. Change History

| Version | Date | Owner | Summary | | --- | --- | --- | --- | | v1.0 | 29 June 2026 | NUMTREND Co., Ltd. | Initial Privacy Policy draft covering GDPR, PDPA, CCPA, AI, wallet, affiliate, and marketplace processing. | | v1.0 | 29 June 2026 | NUMTREND Co., Ltd. | Reviewed and approved by NUMTREND — ready for use. | | v1.0 | 3 July 2026 | NUMTREND Co., Ltd. | Added Section 12A (Third-Party Services We Use) and Section 15A (Account Deletion); expanded device/usage data and data sources; clarified US state privacy "sale/sharing" wording. |