Version 2026-10-02 · Last updated October 2, 2026
This Privacy Notice for Creo Proposals ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share your personal information when you use our services, including when you visit https://creoproposals.com or use the Creo Proposals platform.
Questions or concerns? Contact us at support@creoproposals.com.
We collect the personal information you give us when you sign up, set up your account, use the Services, or contact us:
You share a trip through a link. A link in an email we send for you opens the trip straight away, for thirty (30) days, because it carries a code tied to the address we sent it to. Anyone else who opens the link — from a forwarded email, or a link you copied and sent yourself — is first asked for an email address, and then for a name. We do not check that the address belongs to the person who types it. Until an address is given, the link shows only the trip's cover photo, its name as your client sees it, and your name, title, agency name, logo and colors. Once the trip has been accepted, it shows someone without an address only when it was accepted, the first name of the person who accepted it, and the contact details in your profile. A link that has been turned off or has expired shows only that, with the same contact details.
What we keep about the people who open it, and what we do with it:
How long we keep it. All of this — including the note of a commenter's name in the trip's version history — lasts as long as the trip does, and is deleted with the trip or with your account. A stored pick goes sooner, as described above.
Payment Data. Card details are entered on a page hosted by Stripe, our payment processor, and are never transmitted to or stored on our servers. This applies both when you buy credits and when you save a card. What we store is an identifier Stripe gives us for your customer record, and one for the card on file: the card you most recently saved, or bought credits with, which Stripe keeps for future payments such as auto-reload. The card's brand, last four digits and expiry are read back from Stripe when we display them or name the card in an email, and are not kept by us. You may find Stripe's privacy notice at https://stripe.com/privacy.
Social Media Login Data. We may provide you with the option to register using your existing Google account. If you choose to register in this way, we will collect certain profile information from Google: your name, email address and profile picture.
Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Files are stored in Cloudflare R2, our cloud storage provider, in two places:
No supplier document is stored in either.
We process your personal information for the following purposes:
If you are located in the EEA, UK, or Switzerland: The Services are intended for users in the United States and Canada (see Section 23 of our Terms of Use). If you nonetheless use them from the European Economic Area, the United Kingdom, or Switzerland, the legal bases we rely on are Consent, Performance of a Contract, and Legal Obligations.
If you are located in Canada: We may process your information if you have given us specific permission (express consent) or where your permission can be inferred (implied consent). You can withdraw your consent at any time.
We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf:
| Category | Provider |
|---|---|
| AI Service Providers | Anthropic |
| Third-Party Account Connection | Google account |
| File Storage (logos, photos, snapshots) | Cloudflare R2 |
| Invoice and Billing | Stripe |
| User Authentication | Google OAuth 2.0 |
| Email Delivery | Resend |
| Photo Search | Pexels |
| Infrastructure and Hosting | Railway |
| Edge Delivery and CDN | Cloudflare Workers |
| Error Monitoring | Sentry |
Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, or acquisition of all or a portion of our business.
We use cookies only to keep you signed in and for essential site functions. We do not use advertising cookies or analytics cookies, we do not run any third-party visitor-tracking or visitor-identification technology on any page, and we do not sell or share your information with advertisers.
Your browser also keeps a few things for us in its own storage: the code that lets someone reading a shared trip keep reading it in that tab, the invitation code from another advisor's link for up to thirty (30) days, and display preferences such as whether a page's tour has been shown. None of it is used to follow you across sites.
Our pages do not load fonts, scripts or other files from any other company's servers: everything comes from Creo itself or from our own storage at Cloudflare. No payment provider's code runs on any page of ours — to buy credits or save a card, you are taken to a page hosted by Stripe and returned afterwards.
We build and edit trips with AI through our third-party service provider, Anthropic. Your input and personal information will be shared with and processed by Anthropic to enable your use of our AI products.
Our AI products are designed for:
What we send is what the task needs: the documents you upload; what you enter to build a trip, including the travelers' names for a proposal and any "Limited mobility" or "Dietary needs" ticks and notes for an itinerary; and, when you ask for a change, the trip's content and the brief it was built from. It is transmitted to Anthropic via encrypted HTTPS and processed in real time. Anthropic does not use API inputs to train its models by default.
Anthropic's privacy policy: https://www.anthropic.com/privacy
Our Services offer you the ability to register and log in using your Google account. Where you choose to do this, we will receive certain profile information from Google: your name, email address and profile picture. We will use the information we receive only for the purposes described in this Privacy Notice.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law.
No purpose in this notice will require us to keep your personal information in our active systems for longer than three (3) months past the deletion of your account, except for the two records described below. You can delete your account yourself at any time from Settings. Your account remains usable for thirty (30) days so the request can be cancelled if it was made in error; after that your data is removed from our active systems. You can also download a copy of your data from the same place. It contains your account and the sign-in methods linked to it; where and when you signed in (never the sign-in tokens or credentials); your profile; your clients, with their notes and groups; every trip, with its travelers, its share links (their dates, not the links themselves), its opens, the emails sent for it, the people who gave a name when opening it, comments and replies, acceptance, option picks, what was read from its invoices, and a list of its saved versions; your credit history; the getting-started emails sent to you; what you agreed to and when; the requests you have made about your data; any Teams plan or waitlist sign-up under your address; and whether another advisor invited you, with how many people you invited. It leaves out the contents of a trip's earlier saved versions, which you can read in the app or ask us for, and the codes computed from email addresses described in Section 1 and below, which identify no one without our secret keys.
Backups. Our database is backed up automatically on a daily, weekly and monthly rotation, and we may also take a backup by hand before maintenance. Data removed from active systems may persist in encrypted backups for up to one hundred and twenty (120) days, after which it is deleted in the normal course of that rotation. Backups are not used to restore deleted accounts.
Records of agreement, and of your data requests. Two exceptions to the periods above. When you accept these documents we record which version you accepted, when, and the IP address and browser user agent the acceptance came from. When you download your data, ask for your account to be deleted, or cancel that request, we record what was asked, when, and whether it was done — with counts and dates, never names or addresses. We keep both records after your account is deleted and beyond the three-month period described above — without your account identifier, and linked only to an irreversible code derived from your email address — because without them we could not establish what was agreed, or show that a request was answered, if a dispute arose. We use them for that purpose and no other.
When you delete your account, your credit history is deleted with it, and the card saved with Stripe is detached from your Stripe customer record. Records of payments you actually made are held by Stripe, our payment processor, under their own retention policy — we do not keep a separate copy. An address you gave us to hear about the Teams plan is deleted with your account when it is your account's address; the form is open to anyone, so we cannot match any other address to you, and we delete one on request to support@creoproposals.com. We do not store supplier documents at all; what was read from them is deleted with the trip, or with your account.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect your personal information, including:
Despite our safeguards, no electronic transmission over the Internet can be guaranteed to be 100% secure. You should only access the Services within a secure environment.
We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 years of age. If you become aware of any data we may have collected from children under age 18, please contact us at support@creoproposals.com.
In some regions (such as Canada), you have certain rights under applicable data protection laws, including the right to:
Account Information. You may review or change the information in your account by logging in to your account settings. When you delete your account from Settings, we delete it and its information from our active systems once the thirty-day period described in Section 8 has passed.
Most web browsers include a Do-Not-Track ("DNT") feature or setting. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.
If you are a resident of California, Colorado, Connecticut, or other applicable states, you may have specific rights regarding your personal information.
| Category | Collected |
|---|---|
| A. Identifiers (name, email, postal address, phone, IP address) | YES |
| B. Personal information per California Customer Records statute | YES |
| C. Protected classification characteristics | YES |
| D. Commercial information (transaction history) | YES |
| E. Biometric information | NO |
| F. Internet or other similar network activity | YES |
| G. Geolocation data | NO |
| H. Audio, electronic, sensory information | NO |
| I. Professional or employment-related information | YES |
| J. Education information | NO |
| K. Inferences drawn from collected personal information | NO |
| L. Sensitive personal information | YES |
Category F is sign-in records, and the record of when a shared trip was opened and on what kind of device (Section 1). Category I is your agency's name and your title, as you enter them in your profile.
Categories C and L are "YES" because of what you may record about a traveler's needs. We never ask about anyone's race, religion, sexual orientation or similar characteristics, and our Terms prohibit uploading documents that contain sensitive information. But when you build an itinerary, you can tick "Limited mobility" or "Dietary needs" so that the trip allows for it. Either may say something about a traveler's health, a disability, or religious practice. We store the tick with the trip and send it to Anthropic to plan the trip, and use it for nothing else. A supplier document you upload, or a note you write, could also contain sensitive information; where it does, we hold what is read from it as part of that trip and do not use or disclose it for any purpose beyond building and storing your trip.
We have not sold or shared any personal information to third parties for a business or commercial purpose.
Your rights include:
How to Exercise Your Rights: Contact us at support@creoproposals.com.
We may update this Privacy Notice from time to time. Each version is published here with its date at the top, and earlier versions stay available. If a change is material — for example, a new kind of information collected, or a promise narrowed — you will be asked to agree to the new version, with a short summary of what changed, the next time you use Creo, and you cannot continue until you do. A correction that changes nothing you agreed to is published with a new date, and you are not asked again.
If you have questions or comments about this notice, you may email us at:
Creo Proposals
support@creoproposals.com
Based on the applicable laws of your country or state of residence, you may have the right to request access to, correct, or delete your personal information. To request to review, update, or delete your personal information, please email us at support@creoproposals.com. We will respond within forty-five (45) days, or sooner where the law that applies to your request requires it. You do not have to wait for us for the two most common requests: Settings lets you download a copy of your data (described in Section 8), and delete your account, yourself and at once.