Challenge legal
Privacy Policy
The challenge application stores mission and receipt data in your browser. It has no accounts, analytics, advertising, payment collection, or live travel supplier connection. The hosting provider still receives ordinary request metadata when it serves the site.
1. Scope and operator
This Privacy Policy explains how FinSync LLC, doing business as Raintree Technology (“FinSync,” “we,” “us”), handles information in connection with the public FlightSweeper WebMCP Challenge Edition website.
It applies only to this challenge site. It does not govern private or production FlightSweeper services, third-party browsers or AI clients, GitHub, or other linked services.
2. Information processed
Challenge data stored in your browser
The application creates one versioned local-storage record under flightsweeper.webmcp.challenge.v1. It may contain:
- synthetic airport, date, cabin, connection, refundability, and spending-policy fields;
- fixture offers, selection state, and quote versions;
- activity entries, policy decisions, and rule evidence;
- idempotency keys entered for sandbox execution; and
- synthetic decision and booking receipts.
The application code does not transmit this record to FinSync, Vercel, an airline, a supplier, an analytics service, or an AI provider. A browser or AI client you choose to use may separately process what you type or what appears on the page under its own policies.
Hosting and request information
Vercel hosts the static site. When your browser requests a page or asset, Vercel may process ordinary network and device metadata such as IP address, user agent, requested URL, date and time, response status, and security or diagnostic data. FinSync may be able to access limited deployment or security logs made available by the host.
Information you send us
If you contact us, we receive the information in your message and related delivery metadata. Do not send passwords, payment-card details, passenger documents, or other sensitive information.
Information the challenge does not request
The challenge has no account or checkout and does not request names, email addresses, phone numbers, passenger details, passport data, loyalty numbers, credentials, or payment information. Do not enter personal or payment information into mission fields or idempotency keys.
3. How information is used
Browser-local challenge data is used on your device to operate the demo, enforce synthetic mission policy, prevent duplicate synthetic outcomes, display activity and evidence, and restore state after reload.
Hosting request data and communications may be used to serve and secure the site, diagnose failures, prevent abuse, respond to requests, comply with law, and protect rights and safety. We do not use challenge data for advertising or AI-model training because the application does not receive that data.
Where data-protection law requires a legal basis, we rely on our legitimate interests in operating and securing the public site, compliance with legal obligations, and steps you request when you contact us. We will seek consent where applicable law requires it.
5. Local storage, cookies, and preference signals
The application uses browser local storage—not a cookie—to preserve challenge state. It does not set advertising, analytics, authentication, or preference cookies. Local storage remains on the device and browser profile where it was created unless you or the browser removes it.
Hosting infrastructure may use strictly necessary mechanisms at the network or security layer. The challenge application does not read or use those mechanisms for tracking.
Do Not Track and Global Privacy Control
The challenge application does not track activity over time across third-party websites, sell personal information, or share it for cross-context behavioral advertising. Because that processing does not occur, a Do Not Track or Global Privacy Control signal does not change the application’s behavior. Third-party browsers, AI clients, extensions, and hosting infrastructure may respond to those signals under their own policies.
6. Retention and deletion
- Challenge data: retained in your browser until you confirm Erase challenge data, clear site data, or the browser removes it. Resetting a transaction or starting a new mission intentionally preserves prior receipts.
- Hosting data: retained by Vercel according to its applicable service configuration and policies.
- Communications: retained as reasonably necessary to respond, maintain business records, resolve disputes, and comply with law.
Erasing challenge data removes the application’s complete local-storage record from that browser and starts a fresh synthetic mission. It does not delete separate records held by your browser vendor, AI client, hosting provider, or communications provider.
7. Your choices and privacy rights
You can avoid browser-local storage by not using the interactive demo, and you can delete it with the on-page erasure control or browser settings. You can use the source code locally instead of the public deployment.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or a copy of personal information we control; to object to certain processing; to withdraw consent; and to appeal or complain to a regulator. Email legal@raintree.technology. We may ask for information reasonably necessary to verify that a request concerns you. An authorized agent may submit a request on your behalf; we may request proof of authorization and, where permitted, direct verification from you. We may retain information where permitted or required by law.
California residents may request information about categories of personal information collected, sources, purposes, and disclosures, and may request correction or deletion where applicable. In the preceding 12 months, the hosting layer may have processed identifiers such as IP address and internet or network activity such as request logs. Those categories come from the visitor’s device and hosting infrastructure and are used and disclosed to Vercel to deliver, secure, and diagnose the site. The challenge does not request sensitive personal information. We do not sell personal information or share it for cross-context behavioral advertising, and we will not discriminate against you for exercising applicable rights.
If you are not satisfied with our response, you may reply to request reconsideration and may complain to the privacy or data-protection regulator where you live.
8. Security
The challenge minimizes data by excluding accounts, personal data fields, payments, live suppliers, application servers, and third-party scripts. Deployment controls include HTTPS, a restrictive Content Security Policy, a least-capability Permissions Policy, no-referrer behavior, and content-type protections. Supplier fixture text is treated as untrusted and rendered as text.
No method of storage or transmission is completely secure. Do not use this public sandbox for confidential, personal, or sensitive information.
9. International use
The challenge is operated from the United States. Vercel and any browser or AI client you choose may process request information in the United States or other countries under their own terms and transfer mechanisms.
10. Children
The challenge is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children through the application. If you believe a child sent personal information to us, contact us so we can review the request.
11. Changes to this policy
We may update this policy as the challenge changes. We will post the revised policy, update the date above, and place a conspicuous notice on the challenge homepage for a material change. Material changes apply prospectively.
12. Contact
FinSync LLC d/b/a Raintree Technologyc/o ZenBusiness Inc. (Registered Agent)
2520 Venture Oaks Way, Suite 120
Sacramento, CA 95833
Email: legal@raintree.technology
Business phone: (650) 442-7029