Legal
Privacy & Cookie Policy
Last updated: September 16, 2026
VidiVeni is built around one idea: travel is for everyone. So is privacy. We've written this policy in plain English so you actually know what's going on — not just what satisfies a checkbox.
The short version
- Travelers who follow a shared guide link don't need an account, and we collect almost nothing from them.
- Registered users (travel businesses, beta participants) share account info so we can run the service.
- We don't sell your data. We don't sell your data. We don't sell your data.
- Pseudonymous product analytics are on by default (legitimate interest) — never your name or email — and you can opt out anytime.
- You can ask us to delete your data at any time.
Who we are
VidiVeni is a trading name of Venema Consulting & Innovatie, registered with the Dutch Chamber of Commerce under KVK 42066462 (VAT ID NL005472154B12). That company is the data controller for everything described here.
Questions about your data, or want to exercise a right? Reach us at [email protected] — a human reads and replies.
What we collect and why
If you're a traveler
You've received a guide link from someone — a travel agency, a hotel, a friend. You don't need an account to open it. When you do, our server keeps the short technical record every web server keeps: the time of the request, the address it asked for (the page, or the API path that carries your guide's link), whether it succeeded, and how long it took. No IP address and no browser type is stored with it. We can't identify you from this and we don't try to.
If you use a guide, it sends the usage events described under Product analytics below — which features are used, recorded against the guide rather than against you or your device. No name, no email, no location, and you can switch them off inside the guide.
If someone made a guide for you, they may have given us a first name or a group label for the people travelling, with the destination and dates. That name did not come from you, so here is what happens to it: we use it only to personalise that guide — its greeting, its title and the places suggested for each day — and to write that text it is sent, with the destination and dates, to the AI provider that generates the guide (Anthropic or Google, US, under Standard Contractual Clauses). Anyone holding the guide's link can see it, as can the guide's creator and their organization; it never appears on the preview image or title shown when the link is shared in a chat. It is kept as long as the guide exists and deleted with it. The guide itself tells you all this, in its own language. To see it or have it removed, email [email protected] with the guide's link — no account needed. We remove a name rather than replace it; whoever made the guide can then issue a new one.
Venue reports and guide feedback
From inside a guide, travelers can send us three things: a report that a venue is wrong or has closed (closed, wrong address, bad photo), a rating or comment about the guide, and a report about how the guide itself is working for them, with an optional score. We store the report itself — the kind of problem or the score, plus any free text the traveler chooses to write — the venue and guide it concerns, and a one-way, peppered hash of the random device identifier in the traveler's browser. The hash exists only to corroborate reports (several independent devices reporting the same closure carry more weight than one), to stop one device flooding the queue, and cannot be reversed to identify a device. A rating is the one exception: so a traveler can come back and change the score they gave, it is stored against the device identifier itself rather than its hash. No account, no name and no precise location is attached to any of them.
Venue reports are used to fix wrong or closed venues in the shared catalogue, and only VidiVeni acts on them — the catalogue is one dataset every client's guides read from. If an organization issued the guide, it can see that a venue report was raised on it and what kind of problem it names, so it knows its own guide is going stale; it never sees the traveler's text or our internal notes. Ratings and reports about a guide are visible in full to whoever issued it — the client organization, or the person who made it — and never to other clients.
Handled reports are archived 180 days after they are closed, and their free text and device hash are permanently redacted after at most 730 days. Ratings have no such lifecycle — nobody closes a four-star — so they run on age alone: the comment and the device link are removed 730 days after the traveler last changed one, and the rating is archived in the same step. The star itself stays; an average built from rows we then delete would be a number with no provenance.
If you're a registered user
We store your email address, username, country, and organization so you can log in and manage your guides. We also record which guides you've created and your dashboard activity — that's how the service works. Nothing more.
Signing in, signing up, and resetting a password additionally record the IP address the request came from, so we can spot attacks on accounts. Once you're signed in, the general request log described above also carries your account id — never your email address.
If you report a problem from inside the dashboard, we store what you wrote, the page you were on and your account id, so we can answer you — and the answer comes back on your profile. If you belong to an organization, its owners and managers can read the reports filed from inside it. Everything you have written on a report, and everything you have written while handling someone else's, comes out in your data export. Closing your account erases the text of the reports you filed and unlinks them from you; notes you left while handling other people's reports stay, because they are that ticket's history, but your name comes off them.
Social sign-in (Google, Microsoft)
Signing in with Google or Microsoft is built but not switched on — the buttons are hidden and the routes decline. If we enable it, we will request only the minimal OAuth scopes: email and basic profile (display name). We would not request your calendar, contacts, Drive, or any other data. The email address returned would be stored as your account identifier and the display name so your dashboard can greet you; we would never receive your Google or Microsoft password. Deleting your account removes any stored sign-in link with it.
Product analytics (Pendo and Umami)
To understand how features are adopted and improve the product, we load Pendo by default on the basis of legitimate interest. Pendo receives a pseudonymous UUID (a random identifier — never your email, your name or your avatar), your role and account tier, your country, timezone and language, whether your email is verified and whether you opted in to marketing, where you signed up from, your sign-up and activity dates and how many guides you have made. If you belong to an organization it also receives that organization's name, its short name, industry, plan status, its country, its brand colours, its logo and favicon URLs, whether white-label is switched on, its custom domain, when it was created, and how many members and guides it has. It is never used for advertising and is never shared with ad networks. You can opt out anytime via the "Cookie settings" link in the footer — opting out stops Pendo and clears its session for the rest of your visit and on future visits.
Guides opened via a share link are different: they load no third-party analytics at all. Instead, a guide sends only first-party usage events to vidiveni.app — which features of the guide are used, carrying no identifier for you or your phone, no name, no email and no location. Each event is recorded against the guide, not against you: the guide is what we are measuring, and a guide made for named travelers is not an anonymous thing, which is why this says "against the guide" rather than "anonymous". The opt-out inside a guide lives under Settings → Analytics and takes effect immediately.
Alongside Pendo we use Umami for basic traffic statistics (page views and referrers). Umami is cookieless and stores nothing on your device, but your IP address reaches Umami Cloud when the page loads. It honours the same analytics opt-out as Pendo.
Pendo acts as a data processor under a Data Processing Agreement with Standard Contractual Clauses (SCCs) in place for international transfers.
Marketing communications
We send transactional emails (account verification, password reset, invite notifications) regardless of marketing preferences — these are necessary to operate the service. Separately, you may opt in to occasional product news at signup or from your profile settings. This checkbox is not pre-ticked, and you can withdraw consent at any time from your profile or by following the unsubscribe link in any marketing email.
A daily summary of the feedback queue is built but not switched on — the separate sender it needs does not exist yet, so no summary has ever been sent. If we enable it, accounts that handle feedback — platform staff, and an organization's owners and managers — would receive one mail a day: how many new reports, of what kind, and how many are still open. It would carry no traveler's words, no venue and no guide name, and one link to the dashboard. It would be on by default because it is about your own work, and you would be able to switch it off under Email preferences on your profile. We would keep a record of each summary sent — which account, which window, the counts — for 90 days, and then delete it.
What we never collect
- Payment card details — nothing is paid for through this website
- Your device location, unless you ask for it — see below
- Browsing history outside of VidiVeni
Location
Weather in a guide is looked up using the city coordinates stored in that guide, never the traveler's position. A guide's map has a "Locate me" control; if you tap it, your browser asks your permission and your position is used only to draw you on that map. It stays on your device — it is never sent to us, never stored, and never shared.
Forms on this site
The contact form collects your name, email address, optional company and your message, so we can reply — that is all it is used for. The demo request form stores your name, email, company, business type, town or area, expected volume and message next to a waitlist row, so we can follow up — it is deleted with the entry. Both are protected by Cloudflare Turnstile (a privacy-preserving captcha) and rate-limited, which means we log the request's IP address to stop abuse. The captcha script is fetched only when you start filling a form, so a visitor who never touches one sends Cloudflare nothing on our account. Guide ratings submitted by travelers store the rating, any comment you write, and the random device identifier — no name and no email address.
How we use your data
To run the service. To log you in, show you your guides, deliver those guides to travelers, and keep the platform secure. That's the whole list.
We may use aggregated, anonymized statistics to understand which features are actually useful. This never involves identifying individual users.
Who we share data with
We don't sell your data to anyone, ever.
- AI providers (Anthropic, Google) — when you generate a guide, the destination, trip dates and trip preferences are sent to produce the content — and so is the first name or group label you entered for the travelers, because the guide's greeting and title are written around it. No account data goes with it: not your email, not your username.
- Hosting infrastructure — our servers and storage providers process data to keep the platform running.
- Pendo — pseudonymous product analytics. We send a random UUID and the account and organization details listed under "Product analytics" above — never your email, your name or your avatar. Pendo processes this under a Data Processing Agreement with Standard Contractual Clauses, and runs on Pendo's EU infrastructure.
- Umami — cookieless traffic statistics. Receives the page visited and your IP address; stores nothing on your device.
- Cloudflare — fronts the whole service (DNS, CDN, and the tunnel to our servers) and provides the Turnstile captcha on our forms. Cloudflare sees the traffic and the IP address of every request.
- Resend — delivers our transactional email (verification, password reset, invitations, contact-form messages, and the feedback summary described above, if we switch it on). Receives the recipient address and the message.
Services your browser contacts directly
Some things are loaded by your browser rather than by us, which means those providers see your IP address as soon as the page loads. We would rather say so than let you find out:
- OpenFreeMap — map tiles, loaded only when a traveler opens a guide's map
- Open-Meteo — weather, requested using the guide's city coordinates
- Image providers (Unsplash, Pexels, Pixabay, Wikimedia Commons) — venue photographs
- Partner booking sites (GetYourGuide, Airalo) — opened only when a traveler taps a link marked "Partner link" inside a guide. The link carries our partner id so the partner can pay us a commission if they book; it carries nothing about the traveler
How long we keep data
- Account data: kept while your account is active; the account itself is deleted the moment you close it, and in any case within 30 days
- Guide data: kept while the guide is live. Revoking a guide — which is also what closing your account does to every guide you made — ends every traveler's access to it at once. Deleting a guide removes it and the ratings on it permanently. Our policy is to delete revoked guides once they have been revoked for 90 days; the sweep that would do that on a clock is written but not yet switched on, so until it is, ask us and we will delete one
- Server logs: 90 days, then purged automatically — this is the record described under "If you're a traveler" and covers every request, a traveler's included
- Guide usage events: the statistics described under "Product analytics", recorded against the guide. They are not yet on an automatic clock: the sweep reports what a window would remove so we can choose one against real numbers rather than guess, and this line will name it once it runs
- Traveler ratings, feedback and venue reports: a report is archived 180 days after it is handled, and its free text and device hash are permanently redacted after at most 730 days. A rating has no such lifecycle — nobody closes a four-star — so it runs on age alone: its comment and the device link are permanently removed 730 days after the traveler last changed it, and the rating is archived at that same moment
- Expired guide share links: the link token is removed 180 days after it expires, so an old link cannot be revived. The guide itself is kept
- Feedback summary emails: if we switch the summary on, the record that one was sent — which account, which window, the counts — is deleted after 90 days
- Waitlist entries: until we invite you or you ask us to remove you, and in any case no longer than 24 months
An automated weekly retention sweep enforces these windows, not a person — with the two exceptions named in the list above, which the sweep currently reports on rather than acts on, and which we do by hand on request in the meantime.
Cookies
What we actually store on your device
Most of what we keep is browser storage, not cookies. The difference matters when you want to get rid of it: clearing this site's data removes everything below in one go.
| Name | Kind | Purpose | Type | Duration |
|---|---|---|---|---|
| oauth_state | Cookie | Protects Google/Microsoft sign-in against CSRF. The only cookie we set ourselves. | Necessary | 5 minutes |
| _pendo_* | Cookie | Pendo product analytics on this website and the dashboard (random visitor ID, no personal data). Guides load no Pendo at all. | Analytics | Session / 1 year |
| cga_consent | Local storage | Remembers your analytics choice | Necessary | Until you clear it |
| umami.disabled | Local storage | Umami's own off switch. Written only if you opt out of analytics. | Necessary | Until you clear it |
| cga-admin-token | Local storage | Keeps you signed in to the dashboard (a JWT sent as an Authorization header — not a cookie) | Necessary | Until you sign out |
| cga-theme / mkt-theme | Local storage | Remembers light or dark mode | Necessary | Until you clear it |
| cga-units | Local storage | Remembers whether you read °C/km or °F/mi | Necessary | Until you clear it |
| cga_device_id | Local storage | A random identifier for this browser, created the first time you rate a guide or report a venue. It leaves your device only with such a submission: a venue report carries a one-way hash of it, while a rating is stored against the identifier itself so you can go back and change the score you gave. It is what stops one device counting as several reporters — and what limits you to one rating per guide. | Necessary | Until you clear it |
| cga-favorites, cga-custom-itinerary, cga-position (one set per guide) | Local storage | A traveler's saved places, itinerary edits and last tab. Never sent to us. | Necessary | Until you clear it |
| cga-guide-lang, cga-guide-dest (one pair per link) | Local storage | The guide's language and city, so an error or loading screen can still speak to you when the guide itself fails to load | Necessary | Until you clear it |
| cga-guide-config, cga-guide-mirror-order, cga-clock-witness | Local storage | The offline copy of your guide, which guides are mirrored, and the last time the server's clock was seen — so an expired link cannot be revived by setting your phone back | Necessary | Until you clear it |
| cga_rated_… (one per guide) | Local storage | The score this browser gave a guide, so the guide can show it back to you and let you change it once | Necessary | Until you clear it |
| cga-offline-pack:… (one per guide) | Local storage | A list of what an offline download saved — which photos and map tiles — so the guide can tell you what is already on your phone. Filenames only, nothing about you. | Necessary | Until you clear it |
| cga-feedback-threads (one per guide) | Local storage | Handles, timestamps and the last status we reported back for the reports you filed from a guide and for the rating you gave it, so you can follow them up. Never the text you wrote, and never our reply. | Necessary | Until you clear it |
| cga-experience-prompt (one per guide) | Local storage | Remembers that you answered or declined the one-time “How is the app working for you?” question, so a guide only ever asks once. | Necessary | Until you clear it |
| cga-beacon-queue | Local storage | Usage events waiting to be sent, carrying no identifier for you or your phone. They leave as soon as there's a connection, and none are written at all if you opt out. | Analytics | Until sent |
| cga-wizard-prefs, logsCollapsedSections, logsViewMode | Local storage | Dashboard-only: your last guide-wizard choices and how you left the log viewer | Necessary | Until you clear it |
| pwa-install-dismissed | Session storage | Stops the install prompt reappearing after you dismiss it | Necessary | Until you close the tab |
| cga-scroll:… (one per guide) | Session storage | How far down a guide's tab you had scrolled, so a reload puts you back where you were | Necessary | Until you close the tab |
| cga-wizard-pending-gen | Local storage | Dashboard-only: the guide you are building — including the trip details you entered, the travelers' names among them — so a reload or a second tab can pick it back up | Necessary | Until the guide is ready; ignored after 20 minutes and removed on your next dashboard visit |
| cga-feedback | IndexedDB | A report filed with no signal waits here — text included — until it can be delivered, then it is deleted | Necessary | Until delivered |
| guide-config, guide-content, library-images, app-assets, guide-manifests, guide-climate, openfreemap-tiles, openfreemap-style, unsplash-images | Cache storage | The offline guide itself: pages, venue text, photos and map tiles, so it works with the radio off. Nothing about you is in them. | Necessary | Until you clear it; the browser also expires every cache the service worker manages on its own clock, between a day and a year |
What each type means
- Necessary: required for the service to function — login sessions and remembering your cookie choice. Can't be disabled without breaking things.
- Analytics: help us understand broadly how the platform is used. Pseudonymous — never your name or email — and on by default under legitimate interest. You can opt out anytime through the "Cookie settings" link in the footer, or inside a guide under Settings → Analytics. Either switch covers everything: Pendo and Umami on this site and the dashboard, and the first-party usage events inside a guide.
Your rights (GDPR)
If you're in the EU or EEA, you have the right to:
- Access — request a copy of the data we hold about you
- Rectification — correct anything that's inaccurate
- Erasure — ask us to delete your data entirely
- Restriction — limit how we process your data
- Portability — receive your data in a structured, readable format
- Objection — object to processing based on our legitimate interest
- Object / opt out — stop analytics processing at any time via the "Cookie settings" link in the footer
Email [email protected] to exercise any of these. We'll respond within 30 days. Registered users can also do most of it without asking us: your profile page exports everything we hold about you as JSON, and deletes your account outright. If you only ever joined the waitlist you have no account to do that from — email us and we'll delete the entry, which is the only record we hold of you.
If you think we've handled your data badly, you're entitled to complain to a supervisory authority. Ours is the Dutch Autoriteit Persoonsgegevens. We'd rather you told us first, but that's your call, not ours.
Legal basis for processing (GDPR)
- Contract: processing necessary to deliver the service to registered users
- Legitimate interest: security monitoring, fraud prevention, service improvement, and pseudonymous product analytics (which you can opt out of at any time)
- Consent: marketing email, where you opt in
Security
We use HTTPS everywhere, bcrypt for passwords, JWT for sessions, and restrict access to production systems. We're a small team and we take this seriously.
AI providers and international transfers
Guide generation sends trip parameters — including the travelers' first name or group label, where the guide's creator gave one — to Anthropic (US) or Google (US). Both are covered by Standard Contractual Clauses as required under GDPR.
Children
VidiVeni is not designed for children under 16. We don't knowingly collect data from them. If you believe a child has provided us with personal data, contact [email protected] and we'll delete it promptly.
Changes to this policy
When we make material changes, registered users will hear about it by email or through a dashboard notification before the change takes effect.
Questions?
[email protected] — we're happy to talk through anything in here.