Trust Center
Visby builds for travelers and hotel partners. This Trust Center summarizes how we protect data, what we process, and where to find enterprise compliance materials.
Compliance status
- Security program: Controls are designed to align with the SOC 2 Trust Services Criteria (Security). A formal SOC 2 report is not yet issued; when available, it will be shared with enterprise customers under NDA.
- GDPR / privacy: We support access, portability, and erasure for consumer accounts, document subprocessors, and offer a Data Processing Addendum for hotel partners. We do not claim “GDPR certified” — GDPR is a legal regime, not a product certification.
- COPPA: Under-13 experiences are parent-gated with a Parent PIN for sensitive settings and account deletion.
Documents
- Security practices
- Privacy Policy
- Cookies & similar technologies
- Subprocessors
- Data Processing Addendum (DPA)
- Terms of Use
- Submit a privacy request
How we protect data
- Encrypted transport (HTTPS/TLS) for the app, site, and APIs
- Row-level security in our Postgres database (Supabase)
- Role-based access for platform admins and hotel property teams
- Account deletion and data export in the consumer app
- Security audit events for high-risk admin and integration actions
Retention (summary)
- Account data: until you delete your account, then removed subject to limited legal/fraud retention
- Product analytics: typically up to 24 months in aggregated or event form
- Security audit logs: typically 24 months
Full detail is in our Privacy Policy.
Contact
Privacy & security: hello@visbytravel.com
Vulnerability reports: see our SECURITY.md when published, or email the address above with subject “Security”.