Privacy Policy

Last updated: April 11, 2026 · Effective date: April 11, 2026

This Privacy Policy describes how CoseNostre, LLC ("we", "us", "our"), operating the Andüma! platform at anduma.io, collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable privacy laws.

1. Who We Are

Data Controller:
CoseNostre, LLC
18513 San Quentin Dr.
Michigan 48076, United States
Email: [email protected]

2. Data We Collect

CategoryDataPurposeLegal Basis
AccountName, email addressAuthentication, account managementContract performance
ProfilePreferred language, home province, saved favourites, trip plansPersonalisationContract performance / Legitimate interest
LocationApproximate geolocation (browser-based, on request)"Near you" featuresConsent
UsagePages visited, features used, session dataAnalytics, service improvementLegitimate interest
PaymentPayment method details (processed by Stripe — we do not store card data)Subscription processingContract performance
TechnicalIP address, browser type, device typeSecurity, fraud preventionLegitimate interest

3. How We Use Your Data

We use your personal data to provide, operate and improve Andüma!; personalise your experience; process payments; send transactional emails; analyse usage; and comply with legal obligations. We do not sell your data or use it for advertising profiling.

4. Third-Party Services

ServicePurposePrivacy Policy
SupabaseDatabase and authenticationsupabase.com/privacy
StripePayment processingstripe.com/privacy
Google (OAuth)Optional sign-inpolicies.google.com/privacy
Google AnalyticsUsage analytics (anonymised)policies.google.com/privacy
NetlifyWeb hostingnetlify.com/privacy

5. Data Retention

We retain your data while your account is active. Upon account deletion, data is permanently removed within 30 days, unless legally required to retain it longer.

6. Your Rights (GDPR)

EU/EEA users have the right to: access, rectify, erase, port, object to, or restrict processing of their data, and to withdraw consent at any time. Contact [email protected] to exercise these rights. We respond within 30 days. You may also lodge a complaint with your local data protection authority.

7. Cookies

Andüma! uses minimal cookies and localStorage for session management and preferences. We do not use advertising tracking cookies. Google Analytics is configured with IP anonymisation.

8. Data Security

We use HTTPS encryption, secure database infrastructure, and access controls. Payment data is handled exclusively by Stripe and never stored on our servers.

9. International Transfers

Data may be processed outside the EEA, including in the United States. We ensure appropriate safeguards including Standard Contractual Clauses where required.

10. Children

Andüma! is not directed at children under 16. If you believe a child has provided data, contact