Privacy Policy
Last updated: August 2026
Who we are
sotto.travel is a registered trade name based in the Netherlands, and the controller of the personal data described in this policy.
Chamber of Commerce (KvK): 96507020
VAT (BTW): NL005213643B66
Address: Schiekade 189, 3013 BR Rotterdam, the Netherlands
Email: [email protected]
Information we collect
When you order an itinerary, we collect your email address and the answers you give in the travel questionnaire (destination, dates, travel style, group size, and similar details). If ordering is temporarily paused, you can leave your email address instead so we can let you know when spots open up; in that case we collect that address and the questionnaire answers you already entered. If you ask for three free picks, we collect your email address, the city, roughly when you are travelling, the kinds of places you like, anything you choose to tell us in the note field, and your consent to be emailed. In all these cases we also record, where available, which link, ad or website brought you to the site (see Cookies & local storage below). We do not collect payment details directly: these are handled securely by Stripe.
How we use your information
Your information is used solely to create and deliver your itinerary, and to communicate with you about your order. Building your itinerary means sharing your relevant questionnaire answers with the local host curating your plan for that city. We will not sell, rent, or share your personal information with third parties, except as described below.
The legal bases for this under the GDPR are: performance of a contract (creating and delivering your itinerary, and processing your payment), consent (the optional marketing cookies described below, and the marketing emails you opt into when you ask for free picks, both of which you can withdraw at any time; every email we send carries a one-click unsubscribe link), and legitimate interest (the anonymous, cookieless measurement of how the site and questionnaire are used, and keeping simple records of which campaigns work).
Third-party services
We use a small number of trusted third-party services to operate sotto.travel:
- Stripe: secure payment processing
- Resend: email delivery
- Supabase: secure data storage
- Anthropic (Claude): AI-assisted itinerary drafting
- Google (Gemini): AI-assisted itinerary drafting
- Cloudflare: website hosting and privacy-friendly, cookieless analytics
- Google Maps: location maps in some articles, loaded only if you click to show them, never on page load
- Meta: ad measurement via the Meta pixel, set only with your consent
- Google Ads: ad measurement via the Google Ads tag, set only with your consent
Each of these services has its own privacy policy and processes data only as needed to provide their service.
Our database is hosted in the EU (Ireland). Some of the providers above process data outside the EU, for example in the United States. Where that happens, the transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses.
Data retention
We retain your order information (email, questionnaire answers, and delivered itinerary) for up to 12 months, after which it is deleted. The same 12-month limit applies to details left for the waitlist. If you asked for free picks, the trip details you gave (dates, the kinds of places you like, your note) are erased after 12 months, while your email address is kept until you unsubscribe, because that is what your consent is for; once you unsubscribe we keep only enough to make sure we do not email you again, and erase that after a further 12 months. You can request deletion at any time by contacting us.
Cookies & local storage
We use optional marketing and analytics cookies, currently 2: the Meta (Facebook) pixel and the Google Ads tag, which help us see which of our ads bring visitors to the site. They are set only if you choose "Accept" in the cookie banner. If you decline, or simply ignore the banner, no tracking cookies are set. You can change your choice at any time via "Cookie settings" in the site footer, or .
One piece of this is not a cookie. If you accepted marketing cookies and then place an order, we also confirm that purchase to Meta from our own server, because measurement made in the browser is often blocked and would otherwise undercount. The confirmation contains the order amount and your email address in scrambled (hashed) form, which lets Meta match the order to an ad without receiving the address itself. Nothing is sent if you declined the banner or never answered it.
Beyond that, your device stores two small things, neither of which tracks you or is visible to any third party. First, your quiz progress: when you take the questionnaire, your answers are kept temporarily in your browser (sessionStorage) so the form remembers where you are; this is cleared automatically when you close the tab. Second, a short note of which link, ad or website brought you here (for example "came via a sticker in a Rotterdam café"). That note stays in your browser and travels to us in full only if you place an order, join the waitlist or ask for free picks, so we know which of our campaigns actually work. It is stored with your order and deleted with it under the retention policy above.
Separately, when you arrive through one of our tagged links, ads or short links, we count the visit itself: an anonymous ping records the campaign name, the country the visit came from, and the page you landed on. It contains nothing that identifies you, no IP address and no device details, and it works the same whether or not you order anything. These aggregate counts are kept for up to 13 months, in the same spirit as the Cloudflare analytics below.
In the same anonymous way, we measure how the questionnaire is used: which steps visitors reach and where they stop, so we can make it better. These measurements carry a random temporary code instead of any identity, are not connected to your answers, your email or your order, record no IP address or device details, and are kept for up to 13 months. For delivered itineraries we also record simple usage signals, such as the plan being opened or saved as a PDF, so we know our plans are genuinely useful on the road. Those signals are linked to the order they belong to, not to you as a visitor, and are deleted together with the order under the retention policy above.
For analytics we use Cloudflare Web Analytics, which is cookieless: it measures page views and referrers in aggregate, sets no cookies, stores nothing on your device, and does not track individuals or follow you across other websites.
Data security
We take reasonable precautions to protect your personal information from unauthorised access or disclosure. All data is transmitted over HTTPS.
Your rights
You have the right to access, correct, or delete your personal data at any time, to receive a copy of it in a portable format, and to object to processing based on legitimate interest. To make a request, contact us at [email protected]. If you believe we have handled your data improperly, you can also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Third-party links
Our website and itineraries may contain links to external websites (restaurants, venues, etc.). We are not responsible for the privacy practices or content of those sites.
Changes to this policy
We may update this privacy policy from time to time. The current version will always be posted on this page.
Contact
Questions about your data or this policy? Contact us at [email protected].