Privacy Policy

Effective date: July 18, 2026 · Visby (“we”, “us”)

Visby is a travel-learning companion and hotel partner platform. This policy explains what we collect, why, and how you can exercise your rights. We do not sell personal information and we do not use data for cross-app advertising tracking. Related: Trust Center, Cookies, Subprocessors, DPA.

1. Controller identity

For the consumer Visby app and marketing site, Visby is the data controller. For hotel partner products, the hotel (Customer) is typically the controller of guest/staff data it connects to Visby, and Visby acts as a processor under our Data Processing Addendum. Contact: hello@visbytravel.com (privacy). Until a dedicated DPO is appointed, that inbox handles data-protection inquiries.

2. Information we collect

3. Lawful bases (GDPR / UK GDPR)

Where those laws apply, we rely on:

4. How we use information

5. Sharing

We share data with service providers that help us run Visby (cloud hosting, authentication, maps, push delivery, AI inference where enabled, messaging channels, and purchase validation). Those providers process data under contracts and only for our instructions. Named providers are listed at /subprocessors. We may disclose information if required by law. We do not sell personal data and we do not share it for cross-app tracking.

6. Children’s privacy (COPPA)

Visby supports a parent-gated under-13 experience. We ask for an age band at signup; under-13 accounts require parent/guardian acknowledgment and a Parent PIN for sensitive settings. We do not knowingly use under-13 data for advertising or tracking. Parents may export or delete a child’s account from Settings → Danger Zone.

7. HealthKit & location

HealthKit access is optional and used for wellness tips on Apple Watch — not medical care. Background / “Always” location is optional (Watch area tips) and can be turned off in Visby Settings and iOS Settings. Core app features work with When In Use location or without location.

8. Retention

9. Your rights (GDPR / UK GDPR)

If you are in the EEA, UK, or a similar jurisdiction, you may have rights to:

In the app: Settings → Export my data and Settings → Delete account. Or use our privacy request form / email hello@visbytravel.com.

10. California (CCPA / CPRA)

We do not sell or share personal information for cross-context behavioral advertising. California residents may request know, delete, and correct rights via the privacy request form or email above. We will not discriminate for exercising privacy rights. If we offer a financial incentive in the future, we will describe it clearly at that time.

11. International transfers

We may process data in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses with subprocessors. Details: Subprocessors and DPA.

12. Security

We use industry-standard measures including encrypted transport (HTTPS/TLS), row-level database security, and secure token storage on device. See Security. No method of transmission or storage is 100% secure.

13. Your choices

14. Contact

Email: hello@visbytravel.com
Form: Privacy request
Web: https://www.visbytravel.com

15. Changes

We may update this policy. We will post the new effective date here and, when changes are material, provide additional notice in the app or by email when appropriate.