Privacy Policy
Effective: September 3, 2026 · Version 1.1
1. Overview
Wikitinerary (“we,” “us,” or “our”) operates the travel planning platform at wikitinerary.com. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and your choices. We may update this policy at any time; continued use of the Service after an update constitutes acceptance of the revised policy.
2. Information We Collect
Information you provide
- Account data: email address and display name when you register
- Payment data: billing information processed by Stripe — we never store raw card numbers
- Trip data: saved itinerary blocks, custom trip plans, and destination preferences you create
- Communications: messages or feedback you send to us
Information collected automatically
- Usage data: pages visited, itineraries viewed, blocks saved, time on site
- Device and browser data: IP address, browser type, operating system, referring URL
- Cookies and local storage: session tokens for authentication, preference settings (e.g., dismissed banners), and analytics identifiers
- Affiliate click data: when you click a booking link, we log the click for commission tracking and reporting
3. How We Use Your Information
- Provide, operate, and improve the Service
- Authenticate your account and manage subscriptions
- Personalize recommendations based on your saved destinations and interests
- Send transactional emails (account confirmation, password reset, subscription receipts)
- Send marketing communications about new destinations, features, and promotions — you may opt out at any time
- Analyze usage trends to improve content quality and platform performance
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Automated Content Moderation
When you post a comment on a travel block, suggest a new destination, or report an issue with a listing, that submission is automatically screened by an AI model before it is published or actioned. We use this to catch spam, harassment, and clearly invalid submissions faster than a human reviewer alone.
- What’s screened: block comments, destination suggestions (including any reason you provide for suggesting them), and block issue reports
- How it works: the submitted text is sent to OpenRouter, which routes the request to Google’s Gemini model, to classify the content. The model returns a decision (e.g., allow, block, or flag for human review) — it does not generate content on your behalf or store a profile of you.
- What’s not sent: your account email, payment information, and saved trip data are never included in these requests — only the text of the specific submission.
- Fallback: if the moderation service is unavailable, submissions are queued for manual human review rather than auto-approved or auto-rejected.
5. How We Share Your Information
We do not sell your personal information. We share data only in these circumstances:
Service providers
- Supabase — database and authentication infrastructure. Data stored in the US and EU.
- Vercel — web hosting and edge delivery. US-based with global CDN.
- Stripe — payment processing. Governed by Stripe’s privacy policy.
- Analytics providers — aggregated, privacy-respecting usage analytics (e.g., Vercel Analytics or equivalent). We do not share individual user profiles with analytics providers.
- OpenRouter / Google Gemini— automated content moderation for comments, destination suggestions, and issue reports. See Section 4 above for what is and isn’t sent.
Affiliate partners
When you click a booking affiliate link, standard HTTP referrer information and our affiliate identifier are transmitted to the booking platform. We do not share your email address or account data with affiliate partners.
We participate in the CJ Affiliatenetwork (operated by Conversant LLC). When you click certain booking links on this site, CJ may set a tracking cookie on the destination advertiser’s site to attribute any resulting purchase and calculate our referral commission. For more information, see the CJ Affiliate Services Privacy Policy.
Legal and safety
We may disclose information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect the safety of any person or prevent fraud.
Business transfers
If Wikitinerary is acquired, merged, or sold, user data may be transferred as part of that transaction. We will notify registered users before their data becomes subject to a materially different privacy policy.
6. Cookies and Tracking
We use the following types of storage:
- Session cookies: required for authentication — cannot be disabled without breaking login
- Preference storage (localStorage): stores UI settings like dismissed banners
- Analytics cookies: used to measure aggregate usage — you may opt out via browser settings or by emailing us
Affiliate tracking cookies:when you click a booking link (hotels, car rentals, tours, travel insurance, etc.), the destination platform and our affiliate network (CJ Affiliate) may set cookies on their domains to track referrals and calculate commissions. These cookies are governed by the respective platform’s privacy policy, not ours.
We do not use cross-site tracking cookies or serve retargeting ads based on your browsing history outside of Wikitinerary.
7. Marketing Communications
By creating an account, you consent to receive occasional marketing emails about new features, destinations, and promotions. You may unsubscribe at any time via the link in any email or by emailing [email protected]. Unsubscribing from marketing does not affect transactional emails.
8. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law (e.g., payment records for accounting purposes, which are retained for 7 years).
9. Your Rights
You may:
- Access the personal data we hold about you
- Correct inaccurate data via your account settings or by contacting us
- Delete your account and associated data — self-serve at Profile → Delete account
- Opt outof marketing emails at any time, and of analytics/tracking cookies via the “Do Not Sell or Share My Info” link in the site footer
- Port your data — download a machine-readable export any time at /api/account/export (also linked from Profile → Privacy & data)
If you are located in the European Economic Area or the UK, you may also have rights under GDPR including the right to object to processing and the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email [email protected].
9a. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following additional rights:
- Right to know what personal information we collect, use, and disclose, and to whom
- Right to delete personal information we’ve collected, subject to certain exceptions
- Right to correct inaccurate personal information
- Right to opt out of the “sale” or “sharing” of personal information
- Right to non-discrimination for exercising any of these rights
We do not sell personal information for money. Under CPRA’s broader definition, the analytics and affiliate-tracking cookies described in Section 6 may count as “sharing.” You can opt out of this at any time — not just on your first visit — using the “Do Not Sell or Share My Info” link in the footer of every page. Declining does not affect your ability to use the Service.
To exercise any California right, use the self-serve tools linked in Section 9 above, or email [email protected]. We will not discriminate against you for exercising these rights.
10. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such data, we will delete it promptly.
11. Security
We use industry-standard security practices including encrypted connections (HTTPS), hashed passwords, and access controls on our database. No system is perfectly secure; we cannot guarantee that data will never be accessed without authorization.
12. Changes to This Policy
We may update this Privacy Policy at any time. When we do, we will post the revised policy on this page with an updated effective date. For material changes, we will notify registered users by email or in-app notice. Prior versions are archived and linked from the current policy for reference.
13. Contact
Privacy questions or requests: [email protected]