Vacationist

Privacy Policy

Effective date: 1 June 2026  ·  Last updated: 26 July 2026

1. Who We Are

Vacationist is operated as a personal side project by Gary Lude, based in Switzerland (hereinafter "we", "us", or "the developer").

Contact: meetdeep.de@gmail.com

This privacy policy applies to the Vacationist mobile application ("the App") available on the Google Play Store and to the Vacationist website at vacationist.app ("the Website").

2. Data We Collect

We collect only the data necessary to provide the service.

Account Information

Trip & Planning Data

Travel Documents

Travel document details you enter (full legal name, document number, date of birth, and any notes) are encrypted at rest in our database before being written. Nationality, issuing country, and expiry date are stored unencrypted, since they are needed to power reminders and are not sufficient on their own to identify a document. Access is restricted by row-level security and, on mobile, by a device biometric or passcode prompt. The encryption key is held by us, not derived from your device or biometrics — we could technically access this data, but access is logged and restricted to what is necessary to operate the service. Trip chat messages are encrypted using the same at-rest method.

Device Data

Website Analytics Data

When you visit the Website, Google Analytics 4 automatically collects the following data via cookies and similar technologies:

This data is collected only on the Website, not within the mobile App.

3. How We Use Your Data

We do not use your data for advertising, profiling, or marketing purposes. We do not sell your data.

4. Data Storage & Security

Your data is stored on servers provided by Supabase Inc., hosted in the EU (Paris, France, AWS region eu-west-3). Supabase Inc. is a US-based company; because it could access EU-hosted data from the US, this transfer is carried out on the basis of Standard Contractual Clauses. Supabase's privacy policy is available at supabase.com/privacy.

All data is transmitted over TLS. Travel documents and trip chat messages are encrypted at the database layer before being written; see the Travel Documents section above for what "encrypted" means in practice.

Authentication is handled by Supabase Auth. Google Sign-In tokens are exchanged server-side and are not stored by us.

5. Third-Party Services

6. Analytics & Cookies

What we use

The Website uses Google Analytics 4, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics places first-party cookies (_ga, _ga_*) in your browser to distinguish visitors and measure how the Website is used.

IP anonymisation

Google Analytics 4 truncates IP addresses before any data is written to Google's servers. Your full IP address is never stored or made available to us. The approximate location derived from the truncated address is limited to country and city level.

Consent

Google Analytics is loaded, and the _ga / _ga_* cookies are set, only after you actively accept via the cookie banner shown on your first visit (legal basis: Art. 6(1)(a) GDPR / § 25(1) TTDSG where applicable; Art. 6 DSG for Swiss visitors). If you decline or do not respond, Google Analytics does not load and no analytics cookie is set. You can review or withdraw your choice at any time via Cookie settings in the footer. We do not use Google Analytics to build personal profiles or target individuals.

International data transfer

Google LLC is headquartered in the United States. Data collected by Google Analytics is transferred to and processed on Google's servers in the US. This transfer is carried out on the basis of Google's Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the Swiss FDPIC, and Google's participation in the Swiss-US Data Privacy Framework. You can review Google's data transfer safeguards at business.safety.google/gdprreference.

Data retention

Analytics event data is retained for 2 months in Google Analytics (the minimum configurable period). Aggregated reports may be retained indefinitely but contain no personally identifiable information.

How to opt out

You have the following options to prevent or stop Google Analytics from collecting data about your visit:

Your cookie choice is remembered in your browser's local storage (key v_consent) for up to 12 months, after which you will be asked again. This storage entry itself is strictly necessary to remember your choice and does not require consent.

The native mobile App (iOS/Android) does not use Google Analytics or any third-party analytics SDK. The web version of the App, at web.vacationist.app, uses privacy-focused Vercel Analytics for anonymised performance monitoring — see Section 5. Google Analytics is used on this marketing website only, and only after consent.

7. Data Retention

Your data is retained for as long as your account exists. If you delete your account, all personal data — including trip data, travel documents, and push tokens — is permanently deleted within 30 days.

Guest accounts (created via an invitation link, without an email address) that are never upgraded to a full account may be deleted after a period of inactivity; this is not currently an automated process. Data associated with a guest account is retained only as long as the account exists.

8. Your Rights

Under the Swiss Federal Act on Data Protection (DSG) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the following rights:

To exercise any of these rights, contact us at meetdeep.de@gmail.com. We will respond within 30 days.

9. Children's Privacy

The App is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time. When we do, the "Last updated" date at the top of this page will change. For material changes, we will notify users via in-app notification. Continued use of the App after changes constitutes acceptance of the updated policy.

11. Contact

For questions, data requests, or complaints, contact the developer at:
meetdeep.de@gmail.com

If you are unsatisfied with our response, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch.