Privacy Policy
Visby is a travel-learning companion and hotel partner platform. This policy explains what we collect, why, and how you can exercise your rights. We do not sell personal information and we do not use data for cross-app advertising tracking. Related: Trust Center, Cookies, Subprocessors, DPA.
1. Controller identity
For the consumer Visby app and marketing site, Visby is the data controller. For hotel partner products, the hotel (Customer) is typically the controller of guest/staff data it connects to Visby, and Visby acts as a processor under our Data Processing Addendum. Contact: hello@visbytravel.com (privacy). Until a dedicated DPO is appointed, that inbox handles data-protection inquiries.
2. Information we collect
- Account: email address and password (stored by our auth provider), display name / username, age band at signup.
- Profile & progress: Visby companion state, Aura, stamps, bites, lessons, houses, cosmetics, trips, and similar in-app progress.
- User content: photos you take or choose for stamps, food logs, chat attachments, and messages you send in place/room chat.
- Location (optional): when you grant permission, approximate or precise location to power nearby places, stamps, and optional Apple Watch area tips. You can deny or revoke access in system Settings.
- Health (optional, Apple Watch / HealthKit): read-only activity-style data (for example steps, heart rate, active energy) used only for friendly wellness tips. Visby does not write to HealthKit and does not provide medical advice or diagnosis.
- Device & notifications: push notification tokens if you enable notifications; basic device identifiers needed to operate the service.
- Purchases: subscription and Aura pack transactions are processed by Apple / Google. We receive entitlement status and transaction identifiers needed to unlock features — we never receive your full payment card number.
- Analytics: privacy-first product events (for example app screen views, marketing site page views, and feature use) without advertising IDs and without precise lat/lng in event properties. On the website, analytics runs only with your consent where required — see Cookies.
- Under-13: if the age band is under 13, a parent/guardian acknowledgment and Parent PIN (hashed) are required for certain settings, export, and account deletion.
- Hotel partner data: property configuration, staff accounts/roles, guest messaging content, and integration metadata as configured by the hotel.
3. Lawful bases (GDPR / UK GDPR)
Where those laws apply, we rely on:
- Contract: creating and operating your account, syncing progress, providing features you request.
- Legitimate interests: product improvement with privacy-first analytics, security, fraud prevention, and moderating abuse — balanced against your rights.
- Consent: optional permissions (location, HealthKit, notifications), website analytics where required, and certain marketing emails.
- Legal obligation: tax, accounting, or lawful requests.
4. How we use information
- Provide and sync your Visby account across devices
- Power learning, collection, maps, chat, Watch, and hotel concierge features you enable
- Process in-app purchases and restore entitlements
- Moderate user-generated content (reports / blocks) and keep the service safe
- Improve the product with aggregated, privacy-first analytics
- Meet legal obligations and enforce our Terms
5. Sharing
We share data with service providers that help us run Visby (cloud hosting, authentication, maps, push delivery, AI inference where enabled, messaging channels, and purchase validation). Those providers process data under contracts and only for our instructions. Named providers are listed at /subprocessors. We may disclose information if required by law. We do not sell personal data and we do not share it for cross-app tracking.
6. Children’s privacy (COPPA)
Visby supports a parent-gated under-13 experience. We ask for an age band at signup; under-13 accounts require parent/guardian acknowledgment and a Parent PIN for sensitive settings. We do not knowingly use under-13 data for advertising or tracking. Parents may export or delete a child’s account from Settings → Danger Zone.
7. HealthKit & location
HealthKit access is optional and used for wellness tips on Apple Watch — not medical care. Background / “Always” location is optional (Watch area tips) and can be turned off in Visby Settings and iOS Settings. Core app features work with When In Use location or without location.
8. Retention
- Account & profile data: kept while your account is active; deleted when you delete your account, subject to limited legal/fraud retention.
- Product analytics events: typically up to 24 months.
- Security audit logs: typically up to 24 months.
- Purchase / entitlement records: as needed for fraud prevention, refunds, and legal obligations.
9. Your rights (GDPR / UK GDPR)
If you are in the EEA, UK, or a similar jurisdiction, you may have rights to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase data (“right to be forgotten”) where applicable
- Restrict or object to certain processing
- Data portability (machine-readable export)
- Withdraw consent where processing is consent-based
- Lodge a complaint with your local supervisory authority
In the app: Settings → Export my data and Settings → Delete account. Or use our privacy request form / email hello@visbytravel.com.
10. California (CCPA / CPRA)
We do not sell or share personal information for cross-context behavioral advertising. California residents may request know, delete, and correct rights via the privacy request form or email above. We will not discriminate for exercising privacy rights. If we offer a financial incentive in the future, we will describe it clearly at that time.
11. International transfers
We may process data in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses with subprocessors. Details: Subprocessors and DPA.
12. Security
We use industry-standard measures including encrypted transport (HTTPS/TLS), row-level database security, and secure token storage on device. See Security. No method of transmission or storage is 100% secure.
13. Your choices
- Revoke camera, photos, location, microphone, notifications, or Health access in system Settings
- Opt out of product analytics in app Settings (Privacy preferences)
- Reject website analytics via the cookie banner (see Cookies)
- Restore or manage subscriptions in Apple ID / Google Play settings
- Export or delete your account in-app as described above
14. Contact
Email: hello@visbytravel.com
Form: Privacy request
Web: https://www.visbytravel.com
15. Changes
We may update this policy. We will post the new effective date here and, when changes are material, provide additional notice in the app or by email when appropriate.