Last updated: 25 August 2026

Privacy Policy

This Privacy Policy explains how THE REGENERATIVE TOURISM LLC ("Generant", "we", "us", or "our") collects, uses, shares, and protects information in relation to our website and platform at generant.io ("the Platform").

We are incorporated in the State of Wyoming, United States. Where we process personal data of individuals located in the European Union or United Kingdom, we apply the standards of the General Data Protection Regulation (GDPR) and UK GDPR as a matter of good practice and to meet our legal obligations.

1. Data controller

THE REGENERATIVE TOURISM LLC
Wyoming, United States
Email: support@generant.io

2. Data we collect

We collect the following categories of personal data:

  • Account data: name, email address, hashed password, profile photo, role (operator or traveler).
  • Assessment data (operators): operational metrics (energy, water, waste, employment, procurement, community), evidence files, scoring data, and forward commitment records.
  • Usage data: IP address, browser type, pages visited, actions taken on the Platform, session duration.
  • Operator page analytics (with your consent): when you view a public operator profile, we may record the page view, clicks (booking, website, email, phone links), your locale, referrer, and UTM campaign parameters against that operator, plus a coarse country derived from your network location. This is first-party, is never linked to an account or IP address in storage, and only fires if you have accepted analytics cookies.
  • Diagnostic data (error monitoring, staging/production only): when the Platform errors, we may send technical details (stack trace, URL, browser) to our error-monitoring provider (Sentry) to fix bugs. This never runs on developers' local machines. Session replay (a masked recording of on-screen interactions, with all text and media hidden) is part of this tool but only starts recording once you accept analytics cookies, and stops immediately if you withdraw consent.
  • Communication data: emails sent/received, notification preferences, marketing consent.
  • Payment data: subscription and payment processing is handled by Stripe, Inc., our payment processor (see Section 5). We do not store full card numbers.
  • Consent records: timestamps for terms acceptance, privacy acceptance, marketing opt-in, and cookie preferences.

3. Legal basis for processing

Contract: Processing your account data, running assessments, and delivering the platform features you request.

Legal obligation: Compliance with financial, tax, and regulatory obligations under US federal and state law.

Legitimate interests: Platform security, fraud prevention, and error monitoring (basic crash/error diagnostics, minimised — no IP address or personal data attached, staging/production only) — and audit logging.

Consent: Marketing emails (Klaviyo), analytics cookies (Google Analytics, Microsoft Clarity, Sentry Session Replay), first-party operator page analytics (page views and clicks on operator public profiles), and marketing cookies (Meta Pixel, Google Ads). You may withdraw consent at any time via your account settings or the cookie banner.

For users located in the EU/UK, the above bases correspond respectively to Articles 6(1)(b), 6(1)(c), 6(1)(f), and 6(1)(a) of the GDPR.

4. How we use your data

  • Creating and managing your account.
  • Running Mark and DPI scoring assessments.
  • Generating and publishing operator public profiles.
  • Sending transactional emails (verification, password reset, assessment updates).
  • Sending marketing communications where you have opted in.
  • Improving the Platform through analytics.
  • Maintaining an audit trail for scoring and compliance purposes.
  • Fulfilling legal and regulatory obligations.

5. Third-party processors

Payments (Stripe): to process subscriptions and payments, we use Stripe, Inc. as our payment processor (sub-processor). We are the seller of record for your subscription; Stripe processes your payment on our behalf and calculates applicable tax at checkout. We share your email address and an internal account identifier with Stripe to set up your subscription; Stripe separately collects your payment details, billing address, and IP address directly from you during checkout to complete the transaction, calculate tax, and prevent fraud.

We share data with the following sub-processors, each bound by appropriate data processing agreements:

ProcessorPurposeLocation
StripePayment processingUSA
RailwayCloud hostingUSA
Neon / PostgreSQLDatabaseEU
ResendTransactional emailUSA
KlaviyoMarketing email (with consent)USA
GoogleOAuth login, Analytics (with consent)USA
AWS S3File storage (evidence)EU
MapboxMaps (operator onboarding)USA
Meta (Facebook)Marketing pixel (with consent)USA
Microsoft ClaritySession analytics (with consent)USA
SentryError monitoring; Session Replay (with consent). Staging/production only — never runs on developer machines.USA

For EU/UK users: transfers to processors outside the EEA are protected by Standard Contractual Clauses (SCCs) or adequacy decisions.

6. Data retention

  • Account data: Retained for the duration of your account plus 3 years for legal and audit purposes.
  • Assessment and scoring data: Retained indefinitely — immutable audit records required for scoring integrity.
  • Email logs: Retained for 3 years.
  • Usage/analytics data: Retained for 13 months (Google Analytics default).
  • First-party operator page analytics: Retained for 13 months, then deleted.
  • Error monitoring / Session Replay data (Sentry): Retained per Sentry's plan-level retention (typically up to 90 days), then deleted.
  • Consent records: Retained for 5 years from the date of consent.

7. Your rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data where there is no compelling reason for continued processing.
  • Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Restriction: Ask us to restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw any consent you have given at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@generant.io. We will respond within 30 days. EU/UK users also have the right to lodge a complaint with their local data protection authority.

8. Cookies

We use cookies and similar technologies. For full details, see our Cookie Policy. You can manage your preferences at any time via the cookie banner or your account privacy settings.

9. Security

We implement appropriate technical and organisational measures including encryption in transit (TLS), hashed passwords (bcrypt), role-based access controls, and append-only audit logs. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

10. Children

The Platform is not directed at children under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

For any privacy-related questions or requests, contact us at:
support@generant.io
hello@generant.io