Privacy policy
Last updated 29 September 2026
Who is responsible
The data controller is Nadir Hussain, Italy. Write to [email protected] for anything about your data.
What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Your account (name, email, password hash or Google account id) | To sign you in and keep your trips | Contract (art. 6(1)(b) GDPR) |
| Sign-in sessions: the device's browser name and IP address | To show you and our support team which devices are signed in, and to stop misuse | Legitimate interest (art. 6(1)(f)) |
| Account emails (confirmation, password reset, welcome, security notices) | To confirm your address and keep your account secure | Contract (art. 6(1)(b)) |
| Trips, saved places, notes and reviews you write | To provide the planner | Contract (art. 6(1)(b)) |
| Reviews you publish: rating, text, and your first name with the initial of your last name | Shown publicly on the place, so other travellers can read them | Contract (art. 6(1)(b)) |
| Usage counts (map views, street views, AI requests) per account or anonymous device id | Fair-use limits and cost control | Legitimate interest (art. 6(1)(f)) |
| Questions you ask the guide and trip preferences you give the planner | To generate answers and plans | Contract (art. 6(1)(b)) |
| Waitlist email and city of interest | To tell you when a city opens | Consent (art. 6(1)(a)), withdraw at any time |
| Product analytics events without cookies | To understand which features help travellers | Legitimate interest (art. 6(1)(f)) |
| Location, only when you tap “I'm here” to check in | To confirm a visit; never stored | Consent (art. 6(1)(a)) |
We never sell your data and never use it for advertising.
Who processes it for us
- Google (Maps Platform): 3D maps, Street View and place details shown in the app.
- Our hosting and database provider (Railway): Runs the application and stores your data in the EU.
- OpenAI (United States): Generates plans and guide answers from your request and our place list, and checks the text of reviews before they are published; no name or email is sent.
- Cloudflare: Delivers the website and protects it from abuse; sees your IP address and the pages you request.
- PostHog (EU cloud): Cookieless product analytics; one-time links are removed from page addresses before sending.
- Our email delivery provider (SMTP): Sends account emails to your address.
- Booking partners (GetYourGuide, Viator): Only when you choose to open a booking link.
- Paddle.com (when paid plans open): Our reseller and Merchant of Record: takes payment and issues invoices under its own privacy notice. We receive your plan, order ids and amount, never card details.
Google processes map requests under the Google Privacy Policy. Where a provider is outside the European Economic Area, transfers rely on the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
- Account, trips and usage counts: until you delete your account.
- Sign-in sessions, with device and IP address: 30 days after last use.
- Email confirmation links expire after 24 hours and password reset links after one hour; we keep only a fingerprint of each link, deleted a week after it expires.
- Records of actions our administrators take on an account: kept for security, with the email address masked once the account is deleted.
- Waitlist: until the city opens and we have told you, or until you ask to leave. If you never confirm the email we send, we delete the address after 30 days.
- AI and booking logs: 13 months, and only as anonymous counts once your account is deleted. Usage counts for visitors without an account: 13 months.
- Resolved reports about reviews: 12 months after the decision.
Cookies and browser storage
We use only essential cookies, so no consent banner is needed for them. Analytics run without cookies.
| Name | Purpose and lifetime | Type |
|---|---|---|
| veduta_at | Keeps you signed in (15 minutes) | Essential |
| veduta_rt | Renews your sign-in, sent only to our sign-in service (30 days) | Essential |
| veduta_session | Tells the site to renew your sign-in; holds no personal data (30 days) | Essential |
| veduta_oauth | Protects a Google sign-in while it is in progress (10 minutes) | Essential |
| veduta_anon | Random device id for fair-use counting without an account (1 year) | Essential |
| Browser storage: veduta.local-trip | Places you saved before signing in, on your device only | Essential |
Your rights
You can access, correct, export and delete your data, object to processing based on legitimate interest, and withdraw consent at any time. Download or delete everything yourself on your account page, or write to us. You can also complain to your data protection authority; in Italy that is the Garante per la protezione dei dati personali.
Children
Veduta is for people aged 16 and over. We do not knowingly collect data from children.
Changes
If we change this policy in a way that matters, we will tell signed-in users before the change applies.