Archived copy. This is version 2026-10-02 of the Creo Proposals Privacy Policy, as published on October 2, 2026. The current version is at creoproposals.com/privacy.
Back to home

Privacy Policy

Version 2026-10-02 · Last updated October 2, 2026

This Privacy Notice for Creo Proposals ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share your personal information when you use our services, including when you visit https://creoproposals.com or use the Creo Proposals platform.

Questions or concerns? Contact us at support@creoproposals.com.

Summary of Key Points

  • Personal information we process: What you give us when you sign up and use the Services — your account and agency details, your clients' details, and your trips — and the records our systems make while you use them, such as sign-in records. Section 1 lists all of it.
  • Sensitive information: We ask for one kind, and only as an option: when you build an itinerary, you can tick "Limited mobility" or "Dietary needs" so that the trip allows for it (Section 1). Our Terms prohibit uploading documents that contain other sensitive information, such as card or passport numbers, dates of birth, or medical details. If a document you upload contains some anyway, we hold what is read from it only as part of that trip and never use it for any separate purpose.
  • Supplier documents: The PDFs you upload are sent to our AI provider to be read. We keep what is read from them with the trip; we do not store the files.
  • Information about your clients: When you share a trip, the people who open it either arrive through a link we emailed them or type an email address, and may give a name, leave a comment, say which option they prefer, or accept. We record those things and when the trip was opened, and tell you about them. That is information about someone else, given to us by them, and it is described in Section 1.
  • Third-party data: We do not buy information about you, and we do not receive it from data brokers or advertisers.
  • How we process your information: To provide, improve, and administer our Services, communicate with you, and comply with law.
  • Data safety: We use organizational and technical safeguards, but no transmission over the internet is 100% secure.

1. What Information Do We Collect?

Personal information you give us

We collect the personal information you give us when you sign up, set up your account, use the Services, or contact us:

  • Your account. Your name and email address. If you sign in with Google, the name, email address and profile picture on your Google account.
  • Your agency profile. Your agency's name, your name and title, the email address and phone number you give clients, your website, logo and brand colors, your terms and conditions, and the wording of your client emails. Also your time zone, which we read from your browser when you first sign in and which you can change in Settings. We use it to write the times in our emails in your time, and to send our getting-started emails in your morning.
  • Your clients. The names, email addresses, phone numbers and mailing addresses you enter for them, your notes about them, and the groups you put them in.
  • Your trips. Each itinerary or proposal you build: who is traveling, where and when, prices and terms, the photos you add, the emails you send through Creo, and what you entered or uploaded to build it (described below).
  • Billing. Your credit balance and history, your auto-reload settings, and the identifiers Stripe gives us (see Payment Data below).
  • Messages to us. If you use the contact form, your name, email address and message, with the page you sent it from and the browser you used, are emailed to our support inbox.
  • Teams plan. If you ask to hear about the Teams plan, the email address you give.

Information our systems record

  • Sign-in records. For each sign-in, a session record with the IP address and browser (user agent) it came from, when it started, and when it expires.
  • Sign-in codes. When you ask for a sign-in code, the code and the email address it was sent to. A code works for five minutes and is deleted when it is used; one that is not used is deleted within two (2) days of expiring, and any we still hold for your address are deleted with your account.
  • Records of agreement. Each time you agree to these documents: which version, when, and the IP address and browser it came from (see Section 8).
  • Auto-reload. When you turned auto-reload on, which version of its wording you were shown when you did, and when it was turned off.
  • Data requests. When you download your data, ask for your account to be deleted, or cancel that request: what was asked, when, and whether it was done (see Section 8).
  • Referrals. Your referral code and, if you joined through another advisor's invitation link, who invited you, so that they can be credited when you first buy credits. They see how many people joined and bought through their link, not who.
  • Getting-started emails. Which of them we have scheduled or sent you, and whether you have turned them off.
  • Tours. Which pages of the app you have opened, so that each page's tour is shown only once.

Information about the people you share a trip with

You share a trip through a link. A link in an email we send for you opens the trip straight away, for thirty (30) days, because it carries a code tied to the address we sent it to. Anyone else who opens the link — from a forwarded email, or a link you copied and sent yourself — is first asked for an email address, and then for a name. We do not check that the address belongs to the person who types it. Until an address is given, the link shows only the trip's cover photo, its name as your client sees it, and your name, title, agency name, logo and colors. Once the trip has been accepted, it shows someone without an address only when it was accepted, the first name of the person who accepted it, and the contact details in your profile. A link that has been turned off or has expired shows only that, with the same contact details.

What we keep about the people who open it, and what we do with it:

  • Opens. Each time the trip is opened we record when, the kind of device (phone, tablet or computer), and a code computed from the visitor's email address with a secret key — enough to count each person once, but the address cannot be read back from it. Opens made with your own email address are not recorded. The first time a trip is opened, we email you the name, if one has been given, and the email address of the person who opened it.
  • Names. When someone we emailed the link to gives a name, we keep it with their address on the trip so that they are not asked again. Anyone else's name is not stored on its own: it appears only where they use it — with their comments, in an acceptance, and in the email that tells you the trip was opened.
  • Comments. The comment and any replies, the name shown with it, the email address the person opened the trip with, and whether that address is one we emailed the link to. We email you each comment. When you reply, we email your reply to the person who commented, but only at an address we emailed the link to or one you have on file for a traveler on that trip.
  • Option picks. If a trip offers a choice between options, the people we emailed the link to can say which they prefer. We store their choice; a name to show you — the one on your record for them, otherwise a name they gave, otherwise their email address; and a code computed from their email address with a secret key, which counts each person once. A stored pick is deleted as soon as you settle the choice it was about.
  • Acceptance. When someone accepts a proposal we record the name they type, when they accepted, the email address they opened it with, and whether that address is one we emailed the link to or one typed at the link. We email you those details. We email a confirmation to the person who accepted if we emailed them the link or theirs is a traveler's address you have on file; otherwise we send it to the first traveler on the trip with an email address on your record.
  • Emails you send through Creo. For each email you send a client from Creo, we keep the recipient, the subject, the heading and message you wrote, and whether our email provider accepted it (with its reason if it did not), so that you can read it back later.

How long we keep it. All of this — including the note of a commenter's name in the trip's version history — lasts as long as the trip does, and is deleted with the trip or with your account. A stored pick goes sooner, as described above.

Payment Data. Card details are entered on a page hosted by Stripe, our payment processor, and are never transmitted to or stored on our servers. This applies both when you buy credits and when you save a card. What we store is an identifier Stripe gives us for your customer record, and one for the card on file: the card you most recently saved, or bought credits with, which Stripe keeps for future payments such as auto-reload. The card's brand, last four digits and expiry are read back from Stripe when we display them or name the card in an email, and are not kept by us. You may find Stripe's privacy notice at https://stripe.com/privacy.

Social Media Login Data. We may provide you with the option to register using your existing Google account. If you choose to register in this way, we will collect certain profile information from Google: your name, email address and profile picture.

Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How We Handle Uploaded Documents, What You Enter, and Generated Files

  • Documents you upload to build a proposal. These are sent to our AI provider to be read, and are not stored. What is read from them — bookings, dates, prices, the number of travelers, and the travelers' names where the document shows them — is kept with the trip.
  • Supplier invoices you add to a trip. These are sent to our AI provider to be read, and the file itself is not stored, so it cannot be downloaded from Creo later. What we keep is what was read from it — the supplier, invoice number, dates, amounts, the number of travelers, and each line as printed — and the file's name. We do not ask for the passengers' names and do not store them, although a line copied as printed contains whatever the supplier wrote on it. What was read from an invoice stays with the trip until you remove that invoice, or delete the trip or your account.
  • What you enter to build an itinerary. The places, nights, dates and travelers; your choices of pace, budget, style and interests; anything you ask it to work around; your notes; and your answers to any questions it asks before building. All of it is kept with the trip, and parts of it are sent again with later AI edits so that the changes fit the trip.
  • "Limited mobility" and "Dietary needs." The itinerary form lets you tick either one so that the trip allows for it. It is a tick on the trip, not a description of anyone, but it may say something about a traveler's health, a disability, or religious practice. We store it with the trip and send it to Anthropic, our AI provider, so that the itinerary avoids stairs, steep ground and long walks, or favors places that handle dietary needs well. We use it for nothing else. Tick these, and write notes, only where the trip needs them.
  • What the AI read, and what you entered. Both are kept with the trip, not discarded, and are deleted when you delete the trip or your account.
  • Generated PDF Files. Final proposal PDFs are rendered on demand and streamed directly to you or your client. They are not stored on our servers.

What We Store in Cloud Storage

Files are stored in Cloudflare R2, our cloud storage provider, in two places:

  • Publicly readable storage. Agency logos; location photos chosen from Pexels; photos you upload to a trip; and the picture a trip link shows when it is pasted into a message, made from the trip's cover photo, your logo and your agency name. These have to appear in your clients' browsers and in emails, so anyone who has a file's address can open it (see Section 9).
  • Private storage. Proposal snapshots: saved versions of a trip, made automatically when you share it, save changes, apply an AI or invoice change, restore an earlier version, or a client comments. We keep the most recent fifty (50) for each trip, for version history and restore.

No supplier document is stored in either.

2. How Do We Process Your Information?

We process your personal information for the following purposes:

  • To create your account and sign you in
  • To build itineraries and proposals with AI from the documents and details you give us, and to make the changes you ask for
  • To share your trips with the people you choose, send the emails you ask us to send, and tell you when someone opens, comments on, picks an option in, or accepts a trip
  • To respond to user inquiries and offer support
  • To send administrative information about our products and services
  • To send getting-started emails about using Creo, starting when you first agree to these documents. You can turn them off with the link in any of them. An email whose purpose is to sell you something, such as a reminder about credit packs, is sent only with our postal address and an unsubscribe link in it.
  • To fulfill and manage your orders, including payments, credit usage and auto-reload
  • To keep a record of your agreement to these documents and of the requests you make about your data
  • To prevent harm and protect the security of our Services

3. Legal Bases for Processing

If you are located in the EEA, UK, or Switzerland: The Services are intended for users in the United States and Canada (see Section 23 of our Terms of Use). If you nonetheless use them from the European Economic Area, the United Kingdom, or Switzerland, the legal bases we rely on are Consent, Performance of a Contract, and Legal Obligations.

If you are located in Canada: We may process your information if you have given us specific permission (express consent) or where your permission can be inferred (implied consent). You can withdraw your consent at any time.

4. When and With Whom Do We Share Your Information?

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf:

CategoryProvider
AI Service ProvidersAnthropic
Third-Party Account ConnectionGoogle account
File Storage (logos, photos, snapshots)Cloudflare R2
Invoice and BillingStripe
User AuthenticationGoogle OAuth 2.0
Email DeliveryResend
Photo SearchPexels
Infrastructure and HostingRailway
Edge Delivery and CDNCloudflare Workers
Error MonitoringSentry

Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, or acquisition of all or a portion of our business.

5. Cookies and Tracking Technologies

We use cookies only to keep you signed in and for essential site functions. We do not use advertising cookies or analytics cookies, we do not run any third-party visitor-tracking or visitor-identification technology on any page, and we do not sell or share your information with advertisers.

Your browser also keeps a few things for us in its own storage: the code that lets someone reading a shared trip keep reading it in that tab, the invitation code from another advisor's link for up to thirty (30) days, and display preferences such as whether a page's tour has been shown. None of it is used to follow you across sites.

Our pages do not load fonts, scripts or other files from any other company's servers: everything comes from Creo itself or from our own storage at Cloudflare. No payment provider's code runs on any page of ours — to buy credits or save a card, you are taken to a page hosted by Stripe and returned afterwards.

6. Artificial Intelligence-Based Products

We build and edit trips with AI through our third-party service provider, Anthropic. Your input and personal information will be shared with and processed by Anthropic to enable your use of our AI products.

Our AI products are designed for:

  • Reading the supplier documents and invoices you upload
  • Building itineraries and proposals, and writing their narrative content
  • Making the changes you ask for to a trip

What we send is what the task needs: the documents you upload; what you enter to build a trip, including the travelers' names for a proposal and any "Limited mobility" or "Dietary needs" ticks and notes for an itinerary; and, when you ask for a change, the trip's content and the brief it was built from. It is transmitted to Anthropic via encrypted HTTPS and processed in real time. Anthropic does not use API inputs to train its models by default.

Anthropic's privacy policy: https://www.anthropic.com/privacy

7. Social Logins

Our Services offer you the ability to register and log in using your Google account. Where you choose to do this, we will receive certain profile information from Google: your name, email address and profile picture. We will use the information we receive only for the purposes described in this Privacy Notice.

8. How Long Do We Keep Your Information?

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law.

No purpose in this notice will require us to keep your personal information in our active systems for longer than three (3) months past the deletion of your account, except for the two records described below. You can delete your account yourself at any time from Settings. Your account remains usable for thirty (30) days so the request can be cancelled if it was made in error; after that your data is removed from our active systems. You can also download a copy of your data from the same place. It contains your account and the sign-in methods linked to it; where and when you signed in (never the sign-in tokens or credentials); your profile; your clients, with their notes and groups; every trip, with its travelers, its share links (their dates, not the links themselves), its opens, the emails sent for it, the people who gave a name when opening it, comments and replies, acceptance, option picks, what was read from its invoices, and a list of its saved versions; your credit history; the getting-started emails sent to you; what you agreed to and when; the requests you have made about your data; any Teams plan or waitlist sign-up under your address; and whether another advisor invited you, with how many people you invited. It leaves out the contents of a trip's earlier saved versions, which you can read in the app or ask us for, and the codes computed from email addresses described in Section 1 and below, which identify no one without our secret keys.

Backups. Our database is backed up automatically on a daily, weekly and monthly rotation, and we may also take a backup by hand before maintenance. Data removed from active systems may persist in encrypted backups for up to one hundred and twenty (120) days, after which it is deleted in the normal course of that rotation. Backups are not used to restore deleted accounts.

Records of agreement, and of your data requests. Two exceptions to the periods above. When you accept these documents we record which version you accepted, when, and the IP address and browser user agent the acceptance came from. When you download your data, ask for your account to be deleted, or cancel that request, we record what was asked, when, and whether it was done — with counts and dates, never names or addresses. We keep both records after your account is deleted and beyond the three-month period described above — without your account identifier, and linked only to an irreversible code derived from your email address — because without them we could not establish what was agreed, or show that a request was answered, if a dispute arose. We use them for that purpose and no other.

When you delete your account, your credit history is deleted with it, and the card saved with Stripe is detached from your Stripe customer record. Records of payments you actually made are held by Stripe, our payment processor, under their own retention policy — we do not keep a separate copy. An address you gave us to hear about the Teams plan is deleted with your account when it is your account's address; the form is open to anyone, so we cannot match any other address to you, and we delete one on request to support@creoproposals.com. We do not store supplier documents at all; what was read from them is deleted with the trip, or with your account.

9. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect your personal information, including:

  • All data transmitted between your browser and Creo is encrypted via TLS (HTTPS)
  • Our servers reach our storage, email, payment and AI providers over encrypted connections, and our PDF renderer is reachable only on our hosting provider's private network
  • Our database can be reached only with credentials held by our application and by us
  • Authentication secrets and API keys are stored as environment variables, never in source code
  • Uploaded documents are handled in memory on our application servers and are not written to their disk
  • Supplier documents you upload are not stored
  • Proposal snapshots are kept in private storage that is not publicly addressable, is never shared by link, and is read only through our authenticated application
  • Card details are entered on Stripe's own hosted page and never reach our servers; no payment provider's code runs on any page of ours, and our Content-Security-Policy is configured to refuse it
  • Our database is backed up automatically by our infrastructure provider (Railway) on a daily, weekly and monthly rotation, with the retention described in Section 8
  • Logos, photos, and the pictures trip links show when pasted into a message are kept in publicly readable storage, because they must appear in your clients' browsers and in emails. Their addresses include long identifiers that are hard to guess, and appear only in the pages and emails where the files are shown, but these files are not access-controlled: anyone who has the address of one can open it

Despite our safeguards, no electronic transmission over the Internet can be guaranteed to be 100% secure. You should only access the Services within a secure environment.

10. Information From Minors

We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 years of age. If you become aware of any data we may have collected from children under age 18, please contact us at support@creoproposals.com.

11. Your Privacy Rights

In some regions (such as Canada), you have certain rights under applicable data protection laws, including the right to:

  • Request access and obtain a copy of your personal information
  • Request rectification or erasure
  • Restrict the processing of your personal information
  • Data portability
  • Not be subject to automated decision-making

Account Information. You may review or change the information in your account by logging in to your account settings. When you delete your account from Settings, we delete it and its information from our active systems once the thirty-day period described in Section 8 has passed.

12. Do-Not-Track Features

Most web browsers include a Do-Not-Track ("DNT") feature or setting. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.

13. United States Residents — Specific Privacy Rights

If you are a resident of California, Colorado, Connecticut, or other applicable states, you may have specific rights regarding your personal information.

CategoryCollected
A. Identifiers (name, email, postal address, phone, IP address)YES
B. Personal information per California Customer Records statuteYES
C. Protected classification characteristicsYES
D. Commercial information (transaction history)YES
E. Biometric informationNO
F. Internet or other similar network activityYES
G. Geolocation dataNO
H. Audio, electronic, sensory informationNO
I. Professional or employment-related informationYES
J. Education informationNO
K. Inferences drawn from collected personal informationNO
L. Sensitive personal informationYES

Category F is sign-in records, and the record of when a shared trip was opened and on what kind of device (Section 1). Category I is your agency's name and your title, as you enter them in your profile.

Categories C and L are "YES" because of what you may record about a traveler's needs. We never ask about anyone's race, religion, sexual orientation or similar characteristics, and our Terms prohibit uploading documents that contain sensitive information. But when you build an itinerary, you can tick "Limited mobility" or "Dietary needs" so that the trip allows for it. Either may say something about a traveler's health, a disability, or religious practice. We store the tick with the trip and send it to Anthropic to plan the trip, and use it for nothing else. A supplier document you upload, or a note you write, could also contain sensitive information; where it does, we hold what is read from it as part of that trip and do not use or disclose it for any purpose beyond building and storing your trip.

We have not sold or shared any personal information to third parties for a business or commercial purpose.

Your rights include:

  • Right to know whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request the deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to non-discrimination for exercising your rights

How to Exercise Your Rights: Contact us at support@creoproposals.com.

14. Updates to This Notice

We may update this Privacy Notice from time to time. Each version is published here with its date at the top, and earlier versions stay available. If a change is material — for example, a new kind of information collected, or a promise narrowed — you will be asked to agree to the new version, with a short summary of what changed, the next time you use Creo, and you cannot continue until you do. A correction that changes nothing you agreed to is published with a new date, and you are not asked again.

15. How Can You Contact Us?

If you have questions or comments about this notice, you may email us at:

Creo Proposals
support@creoproposals.com

16. Review, Update, or Delete Your Data

Based on the applicable laws of your country or state of residence, you may have the right to request access to, correct, or delete your personal information. To request to review, update, or delete your personal information, please email us at support@creoproposals.com. We will respond within forty-five (45) days, or sooner where the law that applies to your request requires it. You do not have to wait for us for the two most common requests: Settings lets you download a copy of your data (described in Section 8), and delete your account, yourself and at once.