Privacy Policy

Effective September 3, 2026

1. Who we are and what this covers

Blocks is a platform for managing hotel room blocks, rooming lists, hotel contracts and event travel. It is operated by Fuse Technologies, Inc. DBA Jampack, 7165 Rafael Ridge, Las Vegas, Nevada 89119 (“we”). “You” means whoever is reading this.

This policy covers www.blocks.travel, the Blocks application at app.blocks.travel and its API, guests’ personal pages, department and hotel portal pages, and the inbox.blocks.travel addresses that receive mail.

2. Our two roles

We handle two kinds of personal information.

The first is about our own users and visitors: people who sign up, fill in a form, or browse either site. We decide how that is used.

The second is what a customer organization puts into Blocks about other people: guests and travelers, hotel contacts, department heads. We process that on the customer’s instructions, and the customer decides what to collect, who sees it, and how long to keep it. If you are a guest, hotel contact or department head, start with the organization that invited you. Section 11 explains how to reach us directly.

3. What we collect, from whom, and why

Account holders. Name and email address (from Google or Microsoft if you sign in that way), organization membership and role, sign-in events with IP address, and an activity log of product changes: who, from which IP address and browser, and the record before and after.

Guests and travelers. What a customer enters or collects about the people it books rooms for. This can include name, email address, phone number, employment status, job title, supervisor, department, arrival airport, flights, ground transport and ride codes, roommates, room type and dates, hotel confirmation and room number, special requests, loyalty program and number, and whether the person pays for their own room. From an uploaded boarding pass or flight confirmation we extract passenger names and the booking reference.

Department heads. Name, email address, phone number and department, and any staff roster they import.

Hotel contacts. Name, title, department, email address and phone number of hotel staff a customer works with, entered directly or extracted from uploaded contracts. Section 7 explains how this is shared.

People who email us. Mail sent to an organization’s inbox.blocks.travel address is stored in full, with attachments, as the record of the conversation.

Slack users. If you connect Slack, we read your display name and profile email to match you to your account, and store only the display name.

Site visitors and waitlist signups. What you type into the waitlist form, plus the campaign parameters on the link you arrived from, so we can follow up.

We use this to provide and secure the service, decide who sees what, send the messages in section 4, understand usage in aggregate, and meet legal obligations.

4. Email we send

No email reaches a hotel unless a signed-in user of the customer’s organization sends it.

Guests receive email when a coordinator sends it, when a department head sends it through their portal link, or when the guest asks for it, for example by changing their email address or completing a self-signup form.

Automatic email goes only to the customer’s own team: digests for people who opted in, deadline reminders to the organization owner, a notice to coordinators when a hotel uploads a rooming list through its portal link, and notices when a message has bounced.

Negotiation text is a draft that opens in your own mail application. Nothing is sent from Blocks, and we hold no permission to read or send mail from your mailbox.

You can turn off digests and reminder types from the link in those emails; operational mail has no unsubscribe.

5. Artificial intelligence

Several features use Google’s Gemini models. We send Google:

  • the full text or file of a hotel contract you upload, for term extraction and review;
  • a hotel’s returned rooming report, including guest names and confirmation numbers, when you audit it;
  • a staff roster spreadsheet, including names, emails and phone numbers, when it is imported;
  • a boarding pass or flight confirmation, plus the traveler’s name, when a guest uploads one;
  • a sample of spreadsheet rows, when Blocks works out which column is which;
  • your question, the conversation, and whatever the assistant looks up to answer it, which can include guest names and the text of stored emails.

We use the paid tier of the Gemini API. Google’s terms for that tier state that Google does not use prompts or responses submitted through it to improve its products.

We keep chat conversations so the assistant can continue them, and an automated check reviews a sample for answer quality.

AI output is decision support. Contract review carries this notice where the output appears: “Business decision-support, not legal advice. These flags highlight commercial terms — rates, dates, and penalty exposure — to review with your team or counsel before signing. No attorney-client relationship is formed.”

6. Service providers

  • Cloudflare hosts our application, API and sites, and stores uploaded contracts, original inbound email, backups and exports in R2.
  • Supabase provides the database holding substantially all customer data.
  • Google provides the models in section 5; sign-in if you use it; Places, which receives hotel names, addresses and text you type but never guest details; and Drive and Calendar if you connect them.
  • Resend delivers outbound email and receives the recipient, subject, full message and any attachment.
  • PostHog receives product analytics and error reports. See section 9.
  • Slack receives the assistant’s replies if you connect it, which can include names, hotels and rates.
  • Aggregate Intelligence provides published hotel rates for rate audits and receives hotel identifiers, locations and dates, never personal information.
  • GitHub runs our nightly database backup job, so a database copy passes through it.

7. Hotel data shared across customers

Blocks keeps a hotel directory shared across customers, and your use contributes to it.

Hotel property records, such as name, brand, address and location, are visible to all customers.

Hotel contact records, including a hotel employee’s name, title, email address and phone number, are visible to all customers by default, unless marked so only the contributing organization sees it.

Rate and contract-term data extracted from a customer’s contracts stays private at the individual level. Other customers see it only as a median and quartile range, only where at least five organizations have contributed comparable data, a floor enforced by the database itself.

Guest and traveler information never enters this pool. Neither do contract files, contract text, organization names or event names.

There is no self-serve opt-out from contributing hotel contacts or benchmark rows; if your organization needs different treatment, write to privacy@blocks.travel.

8. Google API Services User Data Policy

Blocks’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sign-in gives us your email address and basic profile only; two optional permissions are requested separately.

Drive access uses the drive.file scope, limited to files Blocks created. With Drive backups on, Blocks writes nightly event backup files containing guest names, contact details and booking details into a Blocks Backups folder in your own Drive. They are yours, and Blocks does not delete or rotate them.

Calendar access uses the calendar.app.created scope, limited to a calendar Blocks created: a separate Blocks Deadlines calendar holding hotel names, event names and deadline text, never guest details.

Blocks requests no Gmail permission and cannot read, send or draft mail in your mailbox.

9. Cookies, local storage and analytics

Cookies. Signing in sets HTTP-only, secure session cookies on api.blocks.travel that last up to seven days. Connecting Google sets a ten-minute anti-tampering cookie limited to the connection page. The app sets small layout preference cookies. Our marketing site sets no cookies of its own.

Local storage. The app keeps your identity, organization list, assistant conversation and preferences in your browser, cleared when you sign out. The marketing site stores only your arrival link’s campaign parameters for the visit.

Analytics. We use PostHog on the app and the marketing site. We send a user identifier and, for signed-in users, your email address and name as profile properties and your organization name as a group property. Before an event leaves your browser we strip emails, names, hotel and organization names, filenames, free text, loyalty numbers, and the secret part of any guest or portal link.

Session replay. In the app, replays are recorded with every text node and form field masked in your browser before transmission, so we receive layout and clicks rather than content. Replay is off on pages reached through a guest or portal link, and we record no replays on the marketing site.

We show no cookie consent banner and do not act on Do Not Track signals. You can block or clear cookies and site data in your browser, which signs you out of the app.

10. Retention and deletion

We keep customer data for as long as the customer’s organization uses Blocks.

Some data has a fixed lifetime: sign-in records 90 days; a document a guest uploads, 30 days if the extraction was never confirmed and 90 days if it was; nightly per-event backup files 30 days; files exported by the assistant seven days; hotel location data fetched from Google 30 days.

Everything else is kept until the account or organization is removed. Our change log is immutable by design and is not deleted.

There is no self-serve delete for an account or organization. Email privacy@blocks.travel and we will do it and tell you what we removed; the change log is retained, and files in your own Google Drive are yours to delete.

Links expire: a personal guest link 60 days after the event ends, a department portal link after 90 days without use, a hotel rooming link after 30 days. Coordinators can revoke a guest or group link at any time.

11. Your choices and rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict or object to our use of your personal information. Email privacy@blocks.travel; we will verify who you are before we act.

If an organization put your details into Blocks, that organization decides what happens to them; contact them first, and if you contact us instead we will pass the request on and help them respond.

Coordinators can export a full copy of an event’s data from its settings screen in Excel or CSV.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

12. Security

Every database query is scoped to one organization by row-level security enforced in the database itself. Traffic is encrypted in transit. Stored Google and Slack tokens are encrypted with AES-256-GCM. Application logs are scrubbed of emails, phone numbers and token-shaped strings, and we do not retain request logs that would hold the secret part of a link. Production access is limited to a few people, and administrator sign-in requires two-factor authentication at the identity provider.

We are working toward a SOC 2 Type I report and are not SOC 2 certified today. No system is perfectly secure.

13. International transfers

We and our service providers are based in the United States, and our database and analytics providers run in their United States regions. If you are elsewhere, your information is transferred there and processed under laws that may differ from yours.

14. Children

Blocks is a business tool, not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child’s information has reached us, write to privacy@blocks.travel and we will remove it.

15. Changes and contact

We may update this policy. For a material change we will update the effective date above and, if you have an account, tell you by email or in the product before it takes effect.

Privacy questions: privacy@blocks.travel. Everything else: support@blocks.travel. Postal mail: Fuse Technologies, Inc. DBA Jampack, 7165 Rafael Ridge, Las Vegas, Nevada 89119.