Menhir
Features Who it's for Pricing Contact
Register
Features Who it's for Pricing Contact Register

Menhir Privacy Policy

Version 1.0 Effective date: 12 July 2026 Last updated: 12 July 2026


1. Who we are

Menhir is a software platform for independent travel businesses, operated by Tobias Franklin, trading as Menhir ("Menhir", "we", "us", "our").

  • Postal address: 14 Printworks Road, Frome, Somerset, BA11 1GN, United Kingdom
  • Email: [email protected]
  • Websites: www.menhiros.com (marketing site), app.menhiros.com (the platform), portal.menhiros.com (client portal)

This policy explains how we handle personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Our two roles

We handle personal data in two distinct capacities, and your rights differ depending on which applies to you:

As a controller. We decide how and why to process the personal data of:

  • travel businesses ("operators") who hold a Menhir account, and their team members;
  • visitors to our marketing site and people who contact us;
  • people who sign documents through the platform, in respect of the signing metadata we capture for fraud prevention (see section 5).

As a processor. Operators use Menhir to store and manage information about their clients — travellers, lead bookers, and enquirers. For that data, the operator is the controller and we process it only on their instructions, through the features of the platform. Our processing commitments to operators are set out in section 7 and in our Terms of Service.

3. If you are a traveller

If you booked a trip with a travel company that uses Menhir, that company — not Menhir — is the controller of your personal data. Menhir stores and processes it on their behalf so they can manage your booking, itinerary, documents, and payments.

To exercise your data protection rights (access, correction, erasure, and so on), contact your travel company directly. If you contact us instead, we will pass your request to them and assist them in responding.

4. Personal data we process for operators (as processor)

Depending on how an operator uses the platform, this can include:

  • travellers' names, email addresses, phone numbers, and postal addresses;
  • passport numbers and expiry dates;
  • dietary requirements and medical information (special category data — the operator is responsible for having a lawful basis, normally your explicit consent);
  • emergency contact details;
  • booking, itinerary, and payment records;
  • messages, emails, and uploaded documents;
  • digital signatures on waivers and forms, together with the signing metadata described in section 5.

We never use this data for our own purposes, we do not sell it, and we do not use it to train AI models.

5. Personal data we collect as controller

Account and profile data. Name, email address, company details, and role, collected when an operator registers or is invited to a team.

Billing data. Plan, subscription status, and billing usage records. Payments are handled by Stripe — we never see or store full card numbers.

Connected mailbox data. If an operator connects their Gmail account to send email through Menhir, we store the OAuth tokens needed to do so, encrypted with AES-256-GCM. Emails are sent from the operator's own mailbox on their instruction. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Document-signing metadata. When someone signs a document through Menhir (the platform agreement, or a waiver in the client portal), we capture the signer's name, email address, IP address, browser user-agent, a timestamp, and a cryptographic hash of the document signed. This is embedded in the signed PDF as an encrypted evidence record so the signature can be verified later. We rely on our legitimate interest in preventing fraud and maintaining an audit trail.

Usage and log data. Standard server logs, including IP addresses, generated when you use the platform.

Contact and support data. Messages sent through the contact form on our marketing site (delivered to us by email) and any support correspondence.

Marketing site visitors. www.menhiros.com uses no analytics and no tracking. We do not profile visitors.

6. Why we process your data and our lawful bases

Purpose Lawful basis
Providing the platform, accounts, and support Performance of a contract
Billing and subscription management Performance of a contract; legal obligation (tax and accounting)
Fraud prevention and signing audit trail Legitimate interests
Securing and improving the platform Legitimate interests
Sending service emails (receipts, reminders, onboarding) Performance of a contract; legitimate interests
Responding to enquiries Legitimate interests; steps prior to a contract
Complying with law and regulators Legal obligation

We do not send marketing emails to operators without a lawful basis, and every non-transactional email we might send in future will include an opt-out.

7. Our commitments as a processor

Where we process client data on behalf of operators, we:

  • process it only on the operator's documented instructions, given through the platform;
  • ensure everyone with access is bound by confidentiality;
  • apply the security measures in section 10;
  • use only the sub-processors listed in section 8 and give notice of material changes;
  • assist operators in responding to data subject requests and in meeting their security and breach-notification obligations;
  • notify operators without undue delay after becoming aware of a personal data breach affecting their data;
  • delete or return client data at the end of the contract, after the 30-day export window described in our Terms of Service.

8. Sub-processors and service providers

We use a small number of carefully chosen providers:

Provider Purpose Location of processing
Supabase Authentication, database, and document storage EEA (Frankfurt, Germany)
Elest.io Hosting for our CRM data layer and automation engine EU data centres
DigitalOcean Application hosting UK/EU data centres
Stripe Payment processing (subscriptions and, where operators enable it, client payments) UK/EEA and US
Resend Transactional email delivery US
Anthropic AI drafting of quote emails (see section 9) US
Google Email sending — only where an operator connects their Gmail account US

We will update this list when providers change and notify operators of material changes.

Third-party content. Our websites load fonts from Google Fonts and icons from the unpkg CDN; maps in the client portal load tiles from OpenStreetMap, and small flag images load from flagcdn.com. Your browser requests these directly, which exposes your IP address to those services, as with any image on a web page. No identifying data is otherwise shared with them.

9. AI features

Operators on eligible plans can use AI to draft quote emails. When they do, the enquiry details (names, trip details, and prices) are sent to Anthropic's API to generate a draft, which the operator reviews and edits before anything is sent. Anthropic does not use data submitted via its API to train its models. We do not use any customer or client data to train AI models.

10. Security

We protect personal data with, among other measures: encryption in transit (TLS) and at rest; AES-256-GCM encryption for stored mailbox tokens; row-level security and per-account isolation in our database; role-based access controls; and encrypted storage of secrets. No system is perfectly secure, but we take proportionate, industry-standard precautions and review them regularly.

11. How long we keep data

Data Retention
Operator account and client data Life of the account, then a 30-day export window, then deletion
Billing and tax records 6 years, as required by UK tax law
Contact form and support correspondence Up to 24 months after the matter is closed
Signed platform agreements and signing evidence 6 years after the account closes (limitation period for legal claims)
In-app notifications 14 days
Server logs Rotated on short cycles, typically within 30 days

12. International transfers

Our core infrastructure is in the UK and EEA; transfers from the UK to the EEA are covered by the UK's adequacy regulations. Where a provider processes data in the United States (Stripe, Resend, Anthropic, and Google), we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on the International Data Transfer Agreement / Standard Contractual Clauses with the UK Addendum.

13. Your rights

If we are the controller of your data, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data in certain circumstances;
  • restrict or object to processing in certain circumstances;
  • portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent.

Email [email protected] to exercise any of these. We may need to verify your identity, and we will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve your concern first.

If we process your data as a processor (you are a client of a travel company), please direct your request to that company — see section 3.

14. Cookies

See our Cookie Policy for details of the small number of cookies we use. In short: essential sign-in cookies, one preference cookie, and no tracking or advertising cookies anywhere.

15. Children

The Menhir platform is for business use by people aged 18 or over. Operators may record details of minors travelling on their trips (for example, a child on a family booking); that data is controlled by the operator and processed by us only on their instructions.

16. Changes to this policy

We will post any changes on this page and update the date at the top. If a change materially affects how we handle your data, we will notify operators by email before it takes effect.

17. Contact

Tobias Franklin, trading as Menhir 14 Printworks Road, Frome, Somerset, BA11 1GN, United Kingdom [email protected]

Menhir

Built for the journey...

Client Login
Sectors Adventure travel Cultural tours Eco travel Sports travel Wellness retreats
Pricing Privacy Policy Terms Cookies Status

© Menhir. All rights reserved.