Version 2026-09-06 · Last updated September 6, 2026
This policy explains what Viro Travel LLC. (“Viro”, “we”, “us”) collects when you use our website and application, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to everyone who uses Viro — and to people who never signed up, but whose details someone added to a trip (§16).
The short version. A summary, not a substitute for the sections below.
This policy applies to everyone whose personal information reaches Viro, which is a wider group than our users:
Viro Travel LLC. is the controller of that information. Where we handle information on behalf of an organisation that uses Viro as a workspace, we act on that organisation's instructions for the workspace content, and the organisation's own policies apply to it as well.
Account and profile. Your name, display name, email address, phone number, job title, profile photo, and the organisation you belong to. You choose a password; it is hashed by our authentication provider and we never see it in a readable form.
Traveller and passenger details. For anyone travelling on a trip: legal given and family name as shown on their passport or government ID, title, date of birth, the gender shown on their travel document, email address, phone number, home city and home airport, airline and transport preferences, dietary and accessibility preferences, and loyalty programme numbers. The name, date of birth and gender are required in order to issue an airline ticket, because the airline matches the ticket against the travel document.
Documents you upload. Files added to a trip, which may include passports, visas, insurance certificates, vouchers and confirmations. They are held in a private store and are served only through signed links that expire after ten minutes.
Trip content. Destinations, dates, itineraries, saved and searched places, discussion posts, poll answers, tasks, photos, costs, budgets and invoices.
Payment information. Card details are entered directly with our payment processor and are never received or stored by us. We store the card brand, the last four digits, the amount, the currency, the status, the processor's reference for the payment, and any refund, cancellation or dispute linked to it.
Support and correspondence. Messages you send us, support tickets, and anything you choose to include in them.
Usage and device data. IP address, browser type and version, operating system, device and browser identifiers, pages viewed, features used, time and duration of visits, referring pages, and diagnostic data such as errors and performance measurements.
Approximate location. Derived from your IP address, and from any city or airport you tell us about, so we can show relevant flights and places. We do not collect precise device GPS location. The Service never asks your browser or phone for it.
Cookies, analytics and session recordings. Described in full in §7 and §8.
From travel suppliers, through our booking provider: confirmation numbers, ticket numbers, booking references, schedule changes, cancellations and refund outcomes.
From our payment processor: whether a payment succeeded or failed and why, the card brand and last four digits, and dispute and chargeback notifications.
From other people: if someone adds you to a trip, or imports a list of travellers, we receive whatever they provided about you. Our Terms require them to have your permission first — see §16.
From your organisation, if you use Viro through an employer's workspace.
Some of what we handle deserves more care than the rest:
We collect these only to arrange travel and to meet supplier and regulatory requirements. We do not use them for advertising, for profiling, or for training AI models, and we do not disclose them for any purpose other than those in §10.
In the EEA and the UK, where a dietary or accessibility preference reveals health or religious belief, we rely on your explicit consent and use it only to arrange the specific travel you asked for. In California, we do not use or disclose sensitive personal information beyond the purposes the law permits without an option to limit it.
Uploading a passport is optional. You can book without it, and you can delete an uploaded document at any time.
The “legal basis” column applies where the EU or UK GDPR governs the processing (§15).
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | So you can sign in, plan trips, and use the product. | Performance of a contract |
| Book flights, rooms and other travel | To search, price, reserve, ticket and confirm a booking, and to pass the supplier the details it needs in order to provide the travel. | Performance of a contract |
| Take payment, issue refunds, handle disputes | To charge the amount you authorised, refund cancellations, and respond to chargebacks. | Performance of a contract; legal obligation |
| Send transactional messages | Confirmations, cancellations, schedule changes, invitations and account email. Sent to every traveller on a booking, because they need them in order to travel. | Performance of a contract; legitimate interests |
| Coordinate trips between members | To show a trip’s contents to the people it was shared with, at the access level they hold. | Performance of a contract; legitimate interests |
| Generate AI itinerary and destination suggestions | To produce the recommendations you asked for. | Performance of a contract; legitimate interests |
| Prevent fraud and abuse, and keep the Service secure | To detect card testing, fraudulent bookings and account takeover, and to carry out sanctions screening. | Legitimate interests; legal obligation |
| Measure and improve the product | To understand how the product is used and to diagnose problems. | Consent where required; otherwise legitimate interests |
| Meet legal, tax and accounting obligations | Recordkeeping, responding to lawful requests, and establishing or defending legal claims. | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and you can object — see §14 and §15.
We do not sell your personal information for money, and we do not disclose it to third parties for their own independent marketing.
We use a single analytics provider, Vercel Web Analytics, to understand which pages are visited and which features are used. We previously used Google Analytics and Amplitude; both have been removed, along with session replay, which we no longer operate in any form.
Nothing loads until you accept. The analytics script is not fetched, and no event is recorded, unless you choose “Accept” on the cookie banner. If you reject, or simply ignore the banner, no analytics code runs at all. Rejecting after having accepted stops collection immediately, without waiting for a reload.
/trips/[tripId]/schedule — never the address you were actually on. Trip and itinerary identifiers do not leave your browser as analytics data.Some features use artificial intelligence to generate itinerary suggestions, compare destinations and make recommendations. To produce them, the trip details relevant to your request — destinations, dates, party size and the preferences you have stated — are sent to our AI provider, Anthropic, which processes them on our instructions and does not use them to train its models.
We do not send payment details or travel-document details to the AI provider. We keep a record of the request and the response against the trip, so that the suggestions persist and so that we can diagnose bad output.
AI output is a suggestion rather than advice, and it can be wrong. We do not use AI to make decisions that produce legal or similarly significant effects for you.
We are based in the United States and our infrastructure is primarily there. Booking travel is inherently international: to arrange a trip, details are transferred to our booking provider in the United Kingdom and the European Economic Area, and onward to the airline, property or distribution system involved, wherever in the world it is located.
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses — together with the UK Addendum or International Data Transfer Agreement where applicable — and on additional safeguards where they are needed. A transfer of passenger data to a supplier so that the booking you asked for can be made is also necessary for the performance of that contract.
You can request a copy of the safeguards we use by emailing privacy@viro.travel.
| What | How long |
|---|---|
| Account and profile | While your account is open, then deleted within 90 days of closure, subject to the exceptions below. |
| Trip content — itineraries, discussions, polls, photos | While the trip exists. Deleting a trip removes it. Content you contributed to a shared trip may remain visible to that trip’s other members. |
| Booking and payment records | Seven years from the date of the booking, for tax, accounting and audit purposes. This includes the passenger details attached to the booking, because a booking record without them is not a record of anything. |
| Payment disputes and chargeback evidence | Seven years, or longer while a dispute remains unresolved. |
| Uploaded documents (passports, visas, insurance) | Until you delete them, or until the trip is deleted. You can delete an uploaded document at any time. |
| Session recordings | Up to 90 days. |
| Analytics and usage data | Up to 25 months. |
| Support correspondence | Three years from the last message, so that we still have the history if you come back to us. |
Two limits on deletion are worth stating plainly. We cannot delete a record of a booking or a payment within the periods above, and we cannot retract personal data that has already been sent to an airline or a property — that data is theirs to hold and to delete, under their own policy. Everything else we delete on request (§13).
We may keep information for longer where we need it to establish or defend legal claims, or where the law requires it.
Depending on where you live — California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and a growing list of other states — you may have the right to:
In the last twelve months we have collected and disclosed the following categories, using the California statutory labels.
| Category | Collected | Disclosed for a business purpose to |
|---|---|---|
| Identifiers — name, email, phone, IP address, account and device identifiers | Yes | Travel suppliers, payment processor, hosting, database, email and analytics providers |
| Customer records — billing details, payment metadata | Yes | Payment processor, travel suppliers |
| Protected classification characteristics — age and date of birth, gender as shown on a travel document | Yes | Travel suppliers |
| Commercial information — bookings, purchases, refunds, saved places | Yes | Travel suppliers, payment processor, analytics providers |
| Internet or network activity — usage, pages viewed, session recordings | Yes | Analytics providers, hosting |
| Geolocation — approximate only, from IP address or a city you tell us | Yes | Analytics providers, hosting |
| Sensitive personal information — travel documents you upload, dietary and accessibility preferences, account credentials | Yes | Database and storage providers; travel suppliers where required in order to arrange travel |
| Inferences — trip and destination preferences | Yes | Analytics providers |
We have not sold personal information for money in the last twelve months, and we have not sold or shared the personal information of anyone we know to be under 16.
We have not shared personal information for cross-context behavioural advertising or targeted advertising. Our previous use of Google Analytics and Amplitude with attribution enabled may have been treated as “sharing” under California and other state laws; both have been removed. The analytics we run now are cookieless, build no cross-site profile and feed no advertising network. To opt out entirely, reject the cookie banner, send a Global Privacy Control signal from your browser (§8), or email privacy@viro.travel and we will apply it on our side.
Email privacy@viro.travel. Tell us what you want and which email address your account or your traveller record uses. We verify your identity against information we already hold before acting on a request, and we may ask for more where the request is a sensitive one. An authorised agent may make a request for you with written proof of authority.
We respond within 45 days, and may extend once by a further 45 days where a request is complex — if we do, we will tell you why within the first period. If we refuse a request, you may appeal by replying to our decision, or by writing to privacy@viro.travel with “Appeal” in the subject line. We respond to an appeal within 45 days with a written explanation, and we will tell you how to complain to your state Attorney General if you are still unsatisfied.
If the EU or UK GDPR applies to you, Viro Travel LLC. is the controller of your personal data and you have the right to access it, to have it corrected or erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent at any time — withdrawal does not affect processing already carried out on the basis of that consent.
You may object at any time to processing we base on legitimate interests, including profiling, and you may object to direct marketing at any time without giving a reason.
To exercise any of these, email privacy@viro.travel. We respond within one month, extendable by two further months for complex requests.
Complaints. You have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.
Representative. We have not appointed a representative in the EU or the UK under Article 27. Please contact us directly at privacy@viro.travel, or by post at Viro Travel LLC., 115 Old Stonewall Rd, Easton, CT 06612, United States.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone (§9).
You may be in our systems because a friend, a family member, a colleague or a travel organiser added you as a traveller. Our Terms require them to have your permission before doing that, and to show you this policy.
You have the same rights as everyone else, whether or not you have an account. You can ask what we hold about you, have it corrected, or ask us to delete it — subject to the booking retention rules in §12, and noting that we cannot delete a ticket an airline has already issued. Email privacy@viro.travel and we will help.
You will still receive transactional email about travel booked for you — confirmations, changes and cancellations — because you need it in order to travel. It contains no marketing.
What we do:
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as the law requires, and without undue delay.
The Service is not directed to children, and you must be 18 to hold an account. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, contact privacy@viro.travel and we will delete it.
An adult can book travel for a minor, which means giving us that minor's name, date of birth and travel-document details. We use those details only to arrange the travel.
The Service links to sites we do not operate and displays content from third parties. Once a booking is made, the airline, property or other supplier handles your information under its own privacy policy, as an independent controller. We are not responsible for their practices, and we would encourage you to read their policies before you travel.
We may update this policy. When a change is material we will update the version and date at the top of this page and notify you by email or by a notice in the Service before it takes effect. Other changes take effect when they are posted. Previous versions are available on request.
Viro Travel LLC.
115 Old Stonewall Rd, Easton, CT 06612, United States
Related documents: Terms and Conditions · Booking Terms