LEGAL

Privacy Policy

Last updated: March 7, 2026

1. Introduction

MilesAhead ("we," "our," or "us") operates the website milesahead.club (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using MilesAhead, you consent to the practices described in this policy.

MilesAhead is operated by Gadewar Ventures LLP. If you have questions about this policy, please contact us at privacy@milesahead.club.

2. Information We Collect

2.1 Information You Provide

  • Account Information: When you sign in using Google OAuth or a magic link, we receive your name and email address from your authentication provider.
  • Profile Information: Display name, country, and currency preference you optionally provide during onboarding.
  • Card Portfolio: The names/types of credit cards you select (e.g., "HDFC Infinia," "Axis Magnus"). We do NOT collect card numbers, CVVs, PINs, bank credentials, or any financial account details.
  • Program Enrollment: The loyalty programs you indicate membership in (e.g., "KrisFlyer," "Marriott Bonvoy").
  • Feedback: Any messages, suggestions, or card requests you voluntarily submit.

2.2 Information We Do NOT Collect

  • Credit/debit card numbers, CVVs, or PINs
  • Bank account numbers or login credentials
  • Transaction history or bank statements
  • Aadhaar, PAN, or other government-issued ID numbers
  • Precise geolocation data

2.3 Automatically Collected Information

  • Usage Data: Pages visited, features used, and interactions within the Service.
  • Device Information: Browser type, operating system, and screen resolution.
  • Cookies: Session cookies necessary for authentication. We do not use advertising or third-party tracking cookies.

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Personalize card optimization results based on your portfolio
  • Send transactional emails (magic link sign-in, account-related notifications)
  • Respond to feedback and support requests
  • Improve and develop new features
  • Detect, prevent, and address technical issues or abuse

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Data Storage & Security

  • Your data is stored on Supabase (hosted on AWS infrastructure) with encryption at rest and in transit (TLS 1.2+).
  • Authentication is handled via Supabase Auth with Google OAuth 2.0 and secure magic link tokens.
  • We use parameterized queries to prevent SQL injection.
  • Access to production databases is restricted to authorized personnel only.
  • While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Third-Party Services

We use the following third-party services:

These services may collect information as described in their respective privacy policies. We do not control and are not responsible for their privacy practices.

6. Data Retention

We retain your account and profile data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes.

7. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request your data in a structured, machine-readable format.
  • Withdraw Consent: Withdraw consent for data processing at any time by deleting your account.

To exercise any of these rights, contact us at privacy@milesahead.club.

8. Children's Privacy

MilesAhead is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.

9. International Data Transfers

Your data may be transferred to and processed in countries other than India (including the United States, where our infrastructure providers operate). By using the Service, you consent to such transfers. We ensure appropriate safeguards are in place in accordance with applicable data protection laws.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Disclaimer

MilesAhead is an independent information and optimization tool. We are not affiliated with, endorsed by, or partnered with any credit card issuer, bank, airline, or hotel loyalty program mentioned on our platform. All card names, program names, and trademarks belong to their respective owners.

The information provided on MilesAhead is for general informational purposes only and does not constitute financial advice. Reward point valuations are estimates based on publicly available data and may vary based on actual redemption choices.

12. Governing Law

This Privacy Policy is governed by the laws of India. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Pune, Maharashtra, India.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • Email: privacy@milesahead.club
  • Entity: Gadewar Ventures LLP
  • Website: milesahead.club