DRAFT TEMPLATE — REQUIRES LEGAL REVIEW before launch.

Privacy Policy

Last updated: TODO: date

This policy explains what Holocene (“Holocene”, “we”, “us”) collects, why, who we share it with, and the choices you have. We’ve tried to keep it short and plain.

Contact: TODO: contact email

Data controller: TODO: legal entity name and address

What we collect

When you join the waitlist

We use this to send you the flight alerts and updates you asked for, to count sign-ups toward unlocking your airport, to run the referral rewards, and to understand which channels people find us through.

Your sign-up only counts once you confirm your email (double opt-in).

When you sign up for the workshop or enter the Leap Grant

When you become a member

Automatically

We do not knowingly collect data from anyone under 18.

The public map

Our home page shows a map with dots for cities where people have joined the waitlist. The map shows city-level totals only. It never shows names, email addresses, or anything that identifies an individual.

TODO: confirm minimum count per city before a dot is shown.

Cookies and browser storage

We keep this minimal.

Who we share data with

We do not sell your personal data. We use these service providers to run Holocene:

Some of these providers are based in the United States or process data there. TODO: confirm international transfer mechanism (for example Standard Contractual Clauses or the Data Privacy Framework).

We may also disclose data if the law requires it, or to protect our rights or the safety of others.

Affiliate disclosure

Some links on Holocene, including flight links in deal alerts and on deal pages, are affiliate links. If you book through one, we may earn a commission at no extra cost to you. This does not change which deals we show you. We pick deals on price.

How long we keep data

Your rights

Wherever you live, you can unsubscribe from any email using the link at the bottom, and you can ask us to delete your data by writing to TODO: contact email.

EEA and UK (GDPR and UK GDPR)

You have the right to:

California (CCPA/CPRA)

You have the right to:

To use any of these rights, email TODO: contact email. We will reply within the time the law requires. We may need to confirm your identity first.

Security

We limit the data we collect, keep API keys and secrets out of our code, and use signed cookies and bot protection. No system is perfectly secure. If we learn of a breach affecting your data, we will tell you as the law requires.

Changes

If we change this policy in a way that matters, we will update the date above and tell subscribers by email.

Contact

TODO: contact email

TODO: legal entity name and postal address