Privacy Policy
Effective Date: June 12, 2026
Updated September 23, 2026: our company name changed from AO2 Live Solutions Inc. to Arkhe Technologies Inc. Nothing else in this document changed.
1. Overview
This Privacy Policy explains how Arkhe Technologies Inc. ("we," "us," or "our") collects, uses, and protects information when you use the Thimble Travel mobile application ("App"). Thimble Travel is a trade name operated by Arkhe Technologies Inc. We are committed to being transparent about our data practices. By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide. Account information: your name and email address when you create an account. If you sign up using email and password, we also store your password in hashed form (see Section 8). If you sign in with Apple or Google, we store the identifier that provider gives us for your account (your "Apple user ID" or "Google user ID") and, where that provider shares a verified email address with us, your email address; we do not receive your Apple ID or Google account password. Travel inputs: destinations, dates, traveler counts, and any other information you share in the AI chat. Trip content: itineraries, notes, and favourites you create in the App. User preferences: settings such as adventure level, budget range, and transit preferences. Subscription information: managed by Apple App Store or Google Play: we do not store your payment card details.
2.2 AI Chat Messages. We store the full text of your conversations with our AI features in our own database so we can maintain your trip history and let you continue conversations across sessions. Messages are linked to your account. See Section 4 for how messages are processed and Section 7 for retention.
2.3 Notifications. When the App sends you a push notification, we store the title and body of that notification on our servers so it can be delivered and displayed in your in-app notification history.
2.4 Information Collected Automatically. Device identifier: a unique device ID used to manage usage limits and link guest activity to your account if you later sign up. We collect this for both guest and registered users. Usage data: interactions within the App, screens visited, features used, and session duration. Per-trip AI usage analytics: counts of AI interactions per trip, used to enforce limits and improve the product. Session recordings: we record user sessions (screen interactions and taps) using our analytics provider: recordings do not capture text typed into input fields, passwords, or payment fields. Analytics events: app opens, trip creation, paywall interactions, navigation patterns, and similar product usage events. Push notification token: a unique identifier used to deliver notifications to your device. Crash and error data: technical information to diagnose and fix issues.
2.5 Hotel Booking Information. When you make a hotel booking through the App, you provide information needed to complete that booking, which may include the booking holder's name, email address, and phone number, the guest name(s), stay dates, room and occupancy selections, and any special requests. A contact phone number for the booking holder is required to make a hotel booking. We transmit this information to our booking provider, Nuitée Travel Limited (which operates LiteAPI), and, through them, to the hotel or supplier, so your reservation can be fulfilled; this includes sharing the booking holder's contact details (name, email, and phone number) with the hotel or supplier for operational contact about your stay. We receive and store booking records (such as a booking reference, hotel, dates, amount, and status) so we can show you your bookings and provide support. We do not collect, receive, or store your payment card number, CVV, or full card details: those are entered into the booking provider's hosted payment form and handled by the provider as merchant of record (see Sections 4 and 6).
2.6 Information We Do Not Collect. Precise geolocation; contacts, photos, or other device data; biometric data; and full payment card details for any payment, including hotel bookings (card data is entered directly into our booking provider's hosted payment form and is never transmitted to or stored on our servers).
3. How We Use Your Information and Our Lawful Basis
We use the information we collect for the purposes below. For users in the European Economic Area and the United Kingdom, the lawful basis under Article 6 of the GDPR is identified for each purpose.
3.1 Provide the Service. To create and operate your account, generate itineraries, store your trips and chat history, and let you continue conversations across sessions. Lawful basis: performance of a contract (Art. 6(1)(b)).
3.2 Process AI Requests. To send your AI chat messages to our AI processing provider and return responses to you. Lawful basis: performance of a contract (Art. 6(1)(b)).
3.3 Manage Subscriptions. To verify and sync your subscription status and enforce free-tier usage limits. Lawful basis: performance of a contract (Art. 6(1)(b)).
3.4 Process Hotel Bookings. To process and fulfill hotel bookings you request, including transmitting your guest and booking details to our booking provider (Nuitée Travel Limited / LiteAPI) and the relevant hotel or supplier, providing booking confirmations, and supporting cancellations and customer service for your booking. Lawful basis: performance of a contract (Art. 6(1)(b)).
3.5 Send Transactional Email and Push Notifications. To send account-related email (e.g. password resets, account confirmations) and to deliver push notifications you have enabled. Lawful basis: performance of a contract (Art. 6(1)(b)) for transactional communications; consent (Art. 6(1)(a)) for push notifications, which you can disable in your device settings.
3.6 Improve the App. To analyze product usage (events and session recordings) and per-trip AI usage analytics so we can improve the user experience. Lawful basis: legitimate interests (Art. 6(1)(f)) in operating and improving our Service.
3.7 Security and Abuse Prevention. To detect and prevent fraud, abuse, and security incidents, and to enforce usage limits using your device identifier. Lawful basis: legitimate interests (Art. 6(1)(f)).
3.8 Legal Compliance. To comply with applicable laws and respond to lawful requests, and to retain certain booking and transaction records for tax, accounting, and dispute-resolution purposes. Lawful basis: legal obligation (Art. 6(1)(c)); and, for retention of booking records, legitimate interests (Art. 6(1)(f)) in managing chargebacks and disputes.
4. AI Processing and Chat Storage
When you interact with the AI trip planning features, your messages are sent to our AI processing provider for processing. This includes your destination preferences, travel dates, and any other information you share in the chat. The provider processes this data according to its privacy policy and data usage terms. We do not use your conversations to train AI models, and our AI processing provider does not use data submitted via its API to train its models. We apply measures to limit sensitive data exposure, including message length limits and input validation, before sending data to third-party AI services.
We also store the full text of your conversations in our own database so we can maintain your trip history and let you continue conversations across sessions. Messages are linked to your account. See Section 7 for how long we retain chat messages.
Although your messages are linked to your account so we can show you your trip history and let you continue conversations across sessions, no Thimble Travel employee reads your messages as part of normal operations. Access is restricted to a small number of authorized engineers, and only for: (a) debugging issues you have explicitly reported to support, (b) abuse investigations, or (c) where required by law. We do not use the content of your conversations to train AI models, target advertising, or sell to third parties. You can delete your account at any time, which permanently removes your messages from our database within 30 days.
Hotel bookings. When you book a hotel, your booking details are sent to our booking provider, Nuitée Travel Limited (LiteAPI), who acts as the merchant of record and processes your payment through their own secure, hosted payment form. Your full payment card details are entered directly into that form and are handled by the provider; they are not sent to or stored by us. Nuitée Travel Limited and the hotel process your information to fulfill and support your booking under their own privacy terms.
5. Analytics and Session Recording
We use a third-party analytics provider to collect analytics data and session recordings. The provider captures how users interact with the App (taps, navigation, feature usage) to help us understand what's working and what needs improvement. Session recordings capture your in-app interactions but do not record text you type into input fields, passwords, or payment information. The provider assigns each user a distinct identifier used to associate events with the same user over time.
6. Sharing of Information
We do not sell your personal information. We share information with third-party service providers ("sub-processors") only to the extent necessary to operate the Service, and they are bound by confidentiality and data protection obligations.
6.1 Sub-processors
We work with the categories of sub-processors below. The specific providers may change from time to time as we add, replace, or remove vendors; the providers in each category as of the Effective Date are shown for transparency, and the current list is available on request at hello@ao2live.com.
AI processing: processing of your chat messages and itinerary requests (currently OpenAI).
Analytics and session recording: product analytics and session recordings (currently PostHog).
Image content: destination images displayed in the App (currently Pexels).
Subscription management: in-app purchase and subscription state (currently RevenueCat).
Email and notifications: transactional email and push notification delivery (currently OneSignal).
Sign-in: Sign in with Apple and Sign in with Google identity verification (Apple, Google).
Hosting and database: application hosting, runtime infrastructure, and managed database (currently Replit, Inc.).
Hotel booking and payment: hotel search, booking fulfillment, and payment processing as merchant of record (Nuitée Travel Limited / LiteAPI, located in Dublin, Ireland). This provider receives the guest and booking details needed to complete your reservation and process payment.
6.2 Other Disclosures. Legal compliance: when required by law, regulation, or valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with appropriate notice to you. Safety: to protect the rights, property, or safety of Arkhe Technologies Inc., our users, or others.
7. Data Retention
7.1 Account Data and Trip Itineraries. Retained for as long as your account is active. If you delete your account, your account information and trip itineraries are permanently deleted within 30 days, except where we are required to retain specific records for legal, tax, or dispute-resolution purposes (see Section 7.6).
7.2 AI Chat Messages. While your account is active, messages are retained for as long as you keep the account, so you can continue conversations and reference past trip planning. If you delete a trip, its chat history is deleted with it. When you delete your account, your account is soft-deleted immediately, then permanently purged from our systems within 30 days. After purge, your messages cannot be recovered.
7.3 Stored Notifications. Push notification titles and bodies are retained for up to 90 days, then deleted automatically.
7.4 Guest Session Data. Device ID and usage counts for guest activity are retained for a reasonable period to enforce usage limits and prevent abuse, typically up to 12 months of inactivity.
7.5 Analytics and Session Recordings. Session recordings are retained for up to 30 days and event analytics for up to 12 months under our analytics provider's standard retention settings, after which session recordings are deleted and event data is retained in aggregated form only.
7.6 Hotel Booking Records. We retain records of your hotel bookings (such as booking reference, hotel, dates, amount, and status) for longer than the 30-day account-deletion window where we are required or reasonably need to do so, for example, to meet tax and accounting obligations, to handle refunds, chargebacks, and payment disputes, and to comply with applicable law. These records are retained for the period required by the applicable obligation and then deleted or anonymized. Deleting your account does not delete booking records we are required to keep; see Section 10 for how this interacts with your erasure rights.
8. Data Security
We implement reasonable technical and organizational measures to protect your information from unauthorized access, disclosure, alteration, or destruction. These measures include encrypted data transmission (HTTPS), server-side authentication and authorization controls, and input validation to prevent injection attacks.
Account passwords are never stored in plaintext. We hash all passwords using bcrypt with an industry-standard work factor before storing them, and we hash password-reset codes the same way. Plaintext passwords are never logged, transmitted to third parties, or retained after hashing.
Hotel payments are processed through our booking provider's secure, hosted payment form; your card details are transmitted directly to the provider and are not handled by our servers.
While we work hard to protect your information using the measures above, no online service can promise perfect security. If a security incident ever affects your data, we will notify you in accordance with applicable law.
9. Age Requirement and Children's Privacy
The App is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that a user under 18 has provided personal information, we will delete it promptly and terminate their account.
If you believe a person under 18 has provided us with personal information, please contact us at hello@ao2live.com.
10. Your Rights and Choices
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar data protection laws, you have the following rights regarding your personal information:
Access: request a copy of the personal information we hold about you.
Rectification: request that we correct inaccurate or incomplete information.
Erasure: request deletion of your personal information. You can delete your account at any time from the Profile section of the App.
Portability: request a copy of your information in a structured, commonly-used, machine-readable format.
Objection: object to processing based on our legitimate interests.
Restriction: request that we limit how we process your information in certain circumstances.
Withdraw consent: where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority.
Limits on erasure. When you ask us to delete your information, we will do so except where we are permitted or required to keep certain records, in particular hotel booking and transaction records that we must retain for tax, accounting, fraud-prevention, chargeback, or dispute-resolution purposes (see Section 7.6). In those cases we retain only the minimum information necessary, for the period required, and then delete or anonymize it.
To exercise any of these rights, contact us at hello@ao2live.com. We will respond within the timeframes required by applicable law.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
Right to know: request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties with whom we share it. The categories we collect are described in Section 2 and our sub-processor categories are listed in Section 6.
Right to delete: request deletion of personal information we have collected from you, subject to certain legal exceptions, including the booking-record retention described in Section 7.6.
Right to correct: request that we correct inaccurate personal information.
Right to opt-out of sale or sharing: We do not sell or share your personal information as those terms are defined under California law. There is nothing to opt out of.
Right to non-discrimination: we will not discriminate against you for exercising any of your privacy rights.
Authorized agents: you may designate an authorized agent to make a request on your behalf. We will require written, signed authorization and may verify your identity directly before fulfilling the request.
To submit a California privacy request, contact us at hello@ao2live.com.
12. International Data Transfers
The App is operated by Arkhe Technologies Inc. from Alberta, Canada. Our application hosting and managed database are operated on infrastructure located in the United States. When you make a hotel booking, your booking information is processed by Nuitée Travel Limited (located in Dublin, Ireland, in the European Economic Area) and by the hotel or supplier fulfilling your reservation, which may be located in the European Union, the United States, or other countries. Other sub-processors may process your information in the United States or other jurisdictions where they operate. If you are accessing the App from outside these jurisdictions, your information may be transferred to, stored, and processed in countries that may have data protection laws different from those of your country. By using the App, you consent to this transfer. Where required, we rely on appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or via email before the changes take effect. Continued use of the App after the effective date constitutes acceptance of the updated policy.
14. Contact Us
Arkhe Technologies Inc., hello@ao2live.com
