Legal
Privacy & Cookie Policy
Last updated: August 27, 2026
VidiVeni is built around one idea: travel is for everyone. So is privacy. We've written this policy in plain English so you actually know what's going on — not just what satisfies a checkbox.
The short version
- Travelers who follow a shared guide link don't need an account, and we collect almost nothing from them.
- Registered users (travel businesses, beta participants) share account info so we can run the service.
- We don't sell your data. We don't sell your data. We don't sell your data.
- Pseudonymous product analytics are on by default (legitimate interest) — never your name or email — and you can opt out anytime.
- You can ask us to delete your data at any time.
Who we are
VidiVeni is a trading name of Venema Consulting & Innovatie, registered with the Dutch Chamber of Commerce under KVK 42066462 (VAT ID NL005472154B12). That company is the data controller for everything described here.
Questions about your data, or want to exercise a right? Reach us at privacy@vidiveni.app — a human reads and replies.
What we collect and why
If you're a traveler
You've received a guide link from someone — a travel agency, a hotel, a friend. You don't need an account to open it. When you do, our server keeps the short technical record every web server keeps: the time of the request, the address it asked for (the page, or the API path that carries your guide's link), whether it succeeded, and how long it took. No IP address and no browser type is stored with it. We can't identify you from this and we don't try to.
If you install the guide as a PWA, we log that install event so the person who created the guide knows it was used. Still no name, no email, no location.
Venue reports and guide feedback
From inside a guide, travelers can report a problem with a venue (closed, wrong address, bad photo) or send a rating or comment about the guide. We store the report itself — the kind of problem or the score, plus any free text the traveler chooses to write — the venue and guide it concerns, and a one-way, peppered hash of the random device identifier in the traveler's browser. The hash exists only to corroborate reports (several independent devices reporting the same closure carry more weight than one) and cannot be reversed to identify a device. No account, no name and no precise location is attached.
Venue reports are used to fix wrong or closed venues in the shared catalogue and are processed by VidiVeni only. Ratings and experience reports about a guide issued by a client organization are visible to that organization in its own inbox — never to other clients. Handled reports are archived after 180 days, and the free text and device hash are permanently redacted after at most 730 days.
If you're a registered user
We store your email address, username, country, and organization so you can log in and manage your guides. We also record which guides you've created and your dashboard activity — that's how the service works. Nothing more.
Signing in, signing up, and resetting a password additionally record the IP address the request came from, so we can spot attacks on accounts. Once you're signed in, the general request log described above also carries your account id — never your email address.
Social sign-in (Google, Microsoft)
If you choose to sign in via Google or Microsoft, we request only the minimal OAuth scopes needed: email and basic profile (display name). We do not request access to your calendar, contacts, Drive, or any other data. The email address returned is stored as your account identifier; the display name is stored so your dashboard can greet you by name. We never receive your Google or Microsoft password.
You can unlink a social provider or delete your account entirely from your profile settings at any time — this removes all stored OAuth tokens from our systems.
Product analytics (Pendo and Umami)
To understand how features are adopted and improve the product, we load Pendo by default on the basis of legitimate interest. Pendo receives a pseudonymous UUID (a random identifier — never your email or name), your role (e.g. "user"), and your account tier. It is never used for advertising and is never shared with ad networks. You can opt out anytime via the "Cookie settings" link in the footer — opting out stops Pendo and clears its session for the rest of your visit and on future visits.
Guides opened via a share link are different: they load no third-party analytics at all. Instead, a guide sends only first-party, fully anonymous usage events to vidiveni.app — which features of the guide are used, with no identifier of any kind and nothing that can link an event to a person or device — and the opt-out inside a guide lives under Settings → Analytics, taking effect immediately.
Alongside Pendo we use Umami for basic traffic statistics (page views and referrers). Umami is cookieless and stores nothing on your device, but your IP address reaches Umami Cloud when the page loads. It honours the same analytics opt-out as Pendo.
Pendo acts as a data processor under a Data Processing Agreement with Standard Contractual Clauses (SCCs) in place for international transfers.
Marketing communications
We send transactional emails (account verification, password reset, invite notifications) regardless of marketing preferences — these are necessary to operate the service. Separately, you may opt in to occasional product news at signup or from your profile settings. This checkbox is not pre-ticked, and you can withdraw consent at any time from your profile or by following the unsubscribe link in any marketing email.
What we never collect
- Payment card details — handled by our payment processor, never touching our servers
- Your device location, unless you ask for it — see below
- Browsing history outside of VidiVeni
Location
Weather in a guide is looked up using the city coordinates stored in that guide, never the traveler's position. A guide's map has a "Locate me" control; if you tap it, your browser asks your permission and your position is used only to draw you on that map. It stays on your device — it is never sent to us, never stored, and never shared.
Forms on this site
The contact form collects your name, email address, optional company and your message, so we can reply — that is all it is used for. The waitlist form stores your email address and where you signed up from. Both are protected by Cloudflare Turnstile (a privacy-preserving captcha) and both are rate-limited, which means we log the request's IP address to stop abuse. Guide ratings submitted by travelers store the rating, any comment you write, and the random device identifier — no name and no email address.
How we use your data
To run the service. To log you in, show you your guides, deliver those guides to travelers, and keep the platform secure. That's the whole list.
We may use aggregated, anonymized statistics to understand which features are actually useful. This never involves identifying individual users.
Who we share data with
We don't sell your data to anyone, ever.
- AI providers (Anthropic, Google) — when you generate a guide, destination and trip parameters are sent to produce the content. No personal information goes with that request.
- Hosting infrastructure — our servers and storage providers process data to keep the platform running.
- Pendo — pseudonymous product analytics. We send a random UUID, your role, and tier — never your email or name. Pendo processes this under a Data Processing Agreement with Standard Contractual Clauses, and runs on Pendo's EU infrastructure.
- Umami — cookieless traffic statistics. Receives the page visited and your IP address; stores nothing on your device.
- Cloudflare — fronts the whole service (DNS, CDN, and the tunnel to our servers) and provides the Turnstile captcha on our forms. Cloudflare sees the traffic and the IP address of every request.
- Resend — delivers our transactional email (verification, password reset, invitations, contact-form messages). Receives the recipient address and the message.
- Payment processor — billing data for paid plans when applicable. Your card details never touch our systems.
Services your browser contacts directly
Some things are loaded by your browser rather than by us, which means those providers see your IP address as soon as the page loads. We would rather say so than let you find out:
- Google Fonts — our typeface, loaded from Google's servers on every page
- OpenFreeMap — map tiles, loaded only when a traveler opens a guide's map
- Open-Meteo — weather, requested using the guide's city coordinates
- Image providers (Unsplash, Pexels, Pixabay, Wikimedia Commons) — venue photographs
How long we keep data
- Account data: kept while your account is active; the account itself is deleted the moment you close it, and in any case within 30 days
- Guide data: kept while the guide is live. Revoking a guide — which is also what closing your account does to every guide you made — starts a 90-day clock, after which the guide and the ratings on it are permanently deleted
- Server logs: 90 days, then purged automatically
- Traveler access logs: 90 days
- Traveler feedback and venue reports: archived 180 days after they are handled; the free text and the device hash are permanently redacted after at most 730 days
- Expired guide share links: the link token is removed 180 days after it expires, so an old link cannot be revived
- Waitlist entries: until we invite you or you ask us to remove you, and in any case no longer than 24 months
These windows are enforced by an automated weekly retention sweep, not by hand.
Cookies
What we actually store on your device
Most of what we keep is browser storage, not cookies. The difference matters when you want to get rid of it: clearing this site's data removes everything below in one go.
| Name | Kind | Purpose | Type | Duration |
|---|---|---|---|---|
| oauth_state | Cookie | Protects Google/Microsoft sign-in against CSRF. The only cookie we set ourselves. | Necessary | 5 minutes |
| _pendo_* | Cookie | Pendo product analytics on this website and the dashboard (random visitor ID, no personal data). Guides load no Pendo at all. | Analytics | Session / 1 year |
| cga_consent | Local storage | Remembers your analytics choice | Necessary | Until you clear it |
| umami.disabled | Local storage | Umami's own off switch. Written only if you opt out of analytics. | Necessary | Until you clear it |
| cga-admin-token | Local storage | Keeps you signed in to the dashboard (a JWT sent as an Authorization header — not a cookie) | Necessary | Until you sign out |
| cga-theme / mkt-theme | Local storage | Remembers light or dark mode | Necessary | Until you clear it |
| cga-units | Local storage | Remembers whether you read °C/km or °F/mi | Necessary | Until you clear it |
| cga_device_id | Local storage | A random identifier for this browser, created the first time you rate a guide or report a venue. It leaves your device only with such a submission: a venue report carries a one-way hash of it, while a rating is stored against the identifier itself so you can go back and change the score you gave. It is what stops one device counting as several reporters — and what limits you to one rating per guide. | Necessary | Until you clear it |
| cga-favorites, cga-custom-itinerary, cga-position (one set per guide) | Local storage | A traveler's saved places, itinerary edits and last tab. Never sent to us. | Necessary | Until you clear it |
| cga-guide-lang, cga-guide-dest (one pair per link) | Local storage | The guide's language and city, so an error or loading screen can still speak to you when the guide itself fails to load | Necessary | Until you clear it |
| cga-guide-config, cga-guide-mirror-order, cga-clock-witness | Local storage | The offline copy of your guide, which guides are mirrored, and the last time the server's clock was seen — so an expired link cannot be revived by setting your phone back | Necessary | Until you clear it |
| cga-feedback-threads (one per guide) | Local storage | Handles and timestamps for reports you filed from a guide, so you can follow them up. Never the text you wrote. | Necessary | Until you clear it |
| cga-beacon-queue | Local storage | Anonymous usage events waiting to be sent. They leave as soon as there's a connection, and none are written at all if you opt out. | Analytics | Until sent |
| cga-wizard-prefs, logsCollapsedSections, logsViewMode | Local storage | Dashboard-only: your last guide-wizard choices and how you left the log viewer | Necessary | Until you clear it |
| pwa-install-dismissed, cga-wizard-pending-gen | Session storage | Stops the install prompt reappearing after you dismiss it; lets the dashboard pick a running generation back up after a reload | Necessary | Until you close the tab |
| cga-feedback | IndexedDB | A report filed with no signal waits here — text included — until it can be delivered, then it is deleted | Necessary | Until delivered |
| guide-config, guide-content, library-images, app-assets, guide-manifests, guide-climate, openfreemap-tiles, openfreemap-style, unsplash-images | Cache storage | The offline guide itself: pages, venue text, photos and map tiles, so it works with the radio off. Nothing about you is in them. | Necessary | Until you clear it |
What each type means
- Necessary: required for the service to function — login sessions and remembering your cookie choice. Can't be disabled without breaking things.
- Analytics: help us understand broadly how the platform is used. Pseudonymous — never your name or email — and on by default under legitimate interest. You can opt out anytime through the "Cookie settings" link in the footer, or inside a guide under Settings → Analytics. Either switch covers everything: Pendo and Umami on this site and the dashboard, and the anonymous first-party usage events inside a guide.
Your rights (GDPR)
If you're in the EU or EEA, you have the right to:
- Access — request a copy of the data we hold about you
- Rectification — correct anything that's inaccurate
- Erasure — ask us to delete your data entirely
- Restriction — limit how we process your data
- Portability — receive your data in a structured, readable format
- Objection — object to processing based on our legitimate interest
- Object / opt out — stop analytics processing at any time via the "Cookie settings" link in the footer
Email privacy@vidiveni.app to exercise any of these. We'll respond within 30 days. Registered users can also do most of it without asking us: your profile page exports everything we hold about you as JSON, and deletes your account outright. If you only ever joined the waitlist you have no account to do that from — email us and we'll delete the entry, which is the only record we hold of you.
If you think we've handled your data badly, you're entitled to complain to a supervisory authority. Ours is the Dutch Autoriteit Persoonsgegevens. We'd rather you told us first, but that's your call, not ours.
Legal basis for processing (GDPR)
- Contract: processing necessary to deliver the service to registered users
- Legitimate interest: security monitoring, fraud prevention, service improvement, and pseudonymous product analytics (which you can opt out of at any time)
- Consent: marketing email, where you opt in
Security
We use HTTPS everywhere, bcrypt for passwords, JWT for sessions, and restrict access to production systems. We're a small team and we take this seriously.
AI providers and international transfers
Guide generation may send trip parameters (not personal data) to Anthropic (US) or Google (US). Both are covered by Standard Contractual Clauses as required under GDPR.
Children
VidiVeni is not designed for children under 16. We don't knowingly collect data from them. If you believe a child has provided us with personal data, contact privacy@vidiveni.app and we'll delete it promptly.
Changes to this policy
When we make material changes, registered users will hear about it by email or through a dashboard notification before the change takes effect.
Questions?
privacy@vidiveni.app — we're happy to talk through anything in here.