Privacy Policy

Version 2026-09-06 · Last updated September 6, 2026

This policy explains what Viro Travel LLC. (“Viro”, “we”, “us”) collects when you use our website and application, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to everyone who uses Viro — and to people who never signed up, but whose details someone added to a trip (§16).

The short version. A summary, not a substitute for the sections below.

1. Who this policy covers

This policy applies to everyone whose personal information reaches Viro, which is a wider group than our users:

Viro Travel LLC. is the controller of that information. Where we handle information on behalf of an organisation that uses Viro as a workspace, we act on that organisation's instructions for the workspace content, and the organisation's own policies apply to it as well.

2. Information you give us

Account and profile. Your name, display name, email address, phone number, job title, profile photo, and the organisation you belong to. You choose a password; it is hashed by our authentication provider and we never see it in a readable form.

Traveller and passenger details. For anyone travelling on a trip: legal given and family name as shown on their passport or government ID, title, date of birth, the gender shown on their travel document, email address, phone number, home city and home airport, airline and transport preferences, dietary and accessibility preferences, and loyalty programme numbers. The name, date of birth and gender are required in order to issue an airline ticket, because the airline matches the ticket against the travel document.

Documents you upload. Files added to a trip, which may include passports, visas, insurance certificates, vouchers and confirmations. They are held in a private store and are served only through signed links that expire after ten minutes.

Trip content. Destinations, dates, itineraries, saved and searched places, discussion posts, poll answers, tasks, photos, costs, budgets and invoices.

Payment information. Card details are entered directly with our payment processor and are never received or stored by us. We store the card brand, the last four digits, the amount, the currency, the status, the processor's reference for the payment, and any refund, cancellation or dispute linked to it.

Support and correspondence. Messages you send us, support tickets, and anything you choose to include in them.

3. Information we collect automatically

Usage and device data. IP address, browser type and version, operating system, device and browser identifiers, pages viewed, features used, time and duration of visits, referring pages, and diagnostic data such as errors and performance measurements.

Approximate location. Derived from your IP address, and from any city or airport you tell us about, so we can show relevant flights and places. We do not collect precise device GPS location. The Service never asks your browser or phone for it.

Cookies, analytics and session recordings. Described in full in §7 and §8.

4. Information we receive from others

From travel suppliers, through our booking provider: confirmation numbers, ticket numbers, booking references, schedule changes, cancellations and refund outcomes.

From our payment processor: whether a payment succeeded or failed and why, the card brand and last four digits, and dispute and chargeback notifications.

From other people: if someone adds you to a trip, or imports a list of travellers, we receive whatever they provided about you. Our Terms require them to have your permission first — see §16.

From your organisation, if you use Viro through an employer's workspace.

5. Sensitive information

Some of what we handle deserves more care than the rest:

We collect these only to arrange travel and to meet supplier and regulatory requirements. We do not use them for advertising, for profiling, or for training AI models, and we do not disclose them for any purpose other than those in §10.

In the EEA and the UK, where a dietary or accessibility preference reveals health or religious belief, we rely on your explicit consent and use it only to arrange the specific travel you asked for. In California, we do not use or disclose sensitive personal information beyond the purposes the law permits without an option to limit it.

Uploading a passport is optional. You can book without it, and you can delete an uploaded document at any time.

6. Why we use your information, and our legal basis

The “legal basis” column applies where the EU or UK GDPR governs the processing (§15).

What we doWhyLegal basis
Create and run your accountSo you can sign in, plan trips, and use the product.Performance of a contract
Book flights, rooms and other travelTo search, price, reserve, ticket and confirm a booking, and to pass the supplier the details it needs in order to provide the travel.Performance of a contract
Take payment, issue refunds, handle disputesTo charge the amount you authorised, refund cancellations, and respond to chargebacks.Performance of a contract; legal obligation
Send transactional messagesConfirmations, cancellations, schedule changes, invitations and account email. Sent to every traveller on a booking, because they need them in order to travel.Performance of a contract; legitimate interests
Coordinate trips between membersTo show a trip’s contents to the people it was shared with, at the access level they hold.Performance of a contract; legitimate interests
Generate AI itinerary and destination suggestionsTo produce the recommendations you asked for.Performance of a contract; legitimate interests
Prevent fraud and abuse, and keep the Service secureTo detect card testing, fraudulent bookings and account takeover, and to carry out sanctions screening.Legitimate interests; legal obligation
Measure and improve the productTo understand how the product is used and to diagnose problems.Consent where required; otherwise legitimate interests
Meet legal, tax and accounting obligationsRecordkeeping, responding to lawful requests, and establishing or defending legal claims.Legal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and you can object — see §14 and §15.

We do not sell your personal information for money, and we do not disclose it to third parties for their own independent marketing.

7. Cookies and similar technologies

Cookies and similar technologies — including browser storage — are how the Service keeps you signed in and how we measure usage. These are the families we set:

Set byWhat forRoughly how long
Viro, through our authentication provider (names beginning sb-)Keeps you signed in and protects the session. Strictly necessary: the Service does not work without these, and they are always on.The life of your session, refreshed while you stay signed in
Viro (browser storage)Remembers preferences and your analytics opt-out. Not shared with anyone.Until you clear your browser storage
Vercel Web AnalyticsMeasures visits and which features are used. Sets no cookie and stores nothing in your browser.Not applicable — no identifier is stored on your device

We do not run third-party advertising networks on the Service, and we do not place advertising cookies.

You can block or delete cookies in your browser, though the Service will not work properly without the strictly necessary ones. §8 explains the analytics controls specifically, and what each of them actually stops.

8. Analytics

We use a single analytics provider, Vercel Web Analytics, to understand which pages are visited and which features are used. We previously used Google Analytics and Amplitude; both have been removed, along with session replay, which we no longer operate in any form.

When analytics load

Nothing loads until you accept. The analytics script is not fetched, and no event is recorded, unless you choose “Accept” on the cookie banner. If you reject, or simply ignore the banner, no analytics code runs at all. Rejecting after having accepted stops collection immediately, without waiting for a reload.

What is recorded

Your controls, and what each one stops

9. AI features

Some features use artificial intelligence to generate itinerary suggestions, compare destinations and make recommendations. To produce them, the trip details relevant to your request — destinations, dates, party size and the preferences you have stated — are sent to our AI provider, Anthropic, which processes them on our instructions and does not use them to train its models.

We do not send payment details or travel-document details to the AI provider. We keep a record of the request and the response against the trip, so that the suggestions persist and so that we can diagnose bad output.

AI output is a suggestion rather than advice, and it can be wrong. We do not use AI to make decisions that produce legal or similarly significant effects for you.

10. Who we share it with

Travel suppliers. To book travel we send passenger details to our booking provider, which passes them to the airline, property or distribution system that actually provides the travel. This is unavoidable: a supplier cannot issue a ticket without them. Once a supplier holds those details it does so as an independent controller under its own privacy policy, and we cannot retract them (§12).

Service providers. We use the companies below to run the Service. Each may use personal data only on our instructions and only for the purpose shown.

ProviderWhat they do for usWhat they receiveWhere
Stripe, Inc.Payment processing, card authorization and capture, refunds, and payment fraud prevention.Card details (entered directly with Stripe), billing details, amounts, payment metadata.United States
Duffel LimitedFlight and accommodation search, booking, and cancellation. Duffel passes booking details onward to the airline, property, or global distribution system that actually provides the travel.Passenger legal name, title, date of birth, gender, email address, phone number, itinerary, loyalty numbers.United Kingdom and European Economic Area
Supabase, Inc.Database, authentication, and file storage for the Viro application.All account, trip, traveler, booking and uploaded document data.United States
Vercel, Inc.Application hosting and content delivery.Request metadata, IP address, device and browser information.United States
Resend (Plus Five Five, Inc.)Delivery of transactional email — booking confirmations, cancellations, invitations and account email.Name, email address and the contents of the message.United States
Anthropic PBCAI generation of itinerary suggestions, destination comparisons and trip recommendations.The trip details included in a prompt — destinations, dates, party size, stated preferences. We do not include payment details or travel-document details in prompts.United States
Google LLC (Maps and Places)Map rendering, place search, and place details shown in the product.Searched and saved places, approximate location, and the device and network data inherent in making the request.United States
Vercel Inc.Application hosting, and website and product measurement — which pages are visited and which features are used.Pages viewed as route patterns rather than URLs, named usage events with at most two short properties each, device and browser data. Cookieless: no identifier is stored on the visitor’s device.United States
Salesforce, Inc. (Slack)Internal operational and product-usage alerting to our own team — for example, notifying us that somebody signed up, started a trip or made a booking, or that a request failed.Limited operational details, which may include a name, an email address, a trip reference, or a booking reference.United States
LiquidSpace, Inc.Meeting room and workspace availability for business trips.Search criteria — city, dates, capacity.United States

Other users and organisations. Trip members see the trip contents shared with them, at the access level they hold — itineraries, discussions, polls, costs and payments, traveller details, booking details and uploaded documents. Organisation administrators can see and manage their organisation's workspace. Invitation links and calendar subscription feeds work without a login: anyone holding one can see what it points at, and you can revoke a calendar feed at any time in Settings → Calendar.

Professional advisers. Our accountants, auditors, insurers and lawyers, where they need the information to advise us and are bound to keep it confidential.

Legal and safety. We may disclose information where we believe in good faith that it is necessary in order to comply with law or a valid request from a public authority, to enforce our terms, to detect or prevent fraud, to establish or defend legal claims, or to protect the rights, property or safety of anyone.

Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of it. We will give notice before your information becomes subject to a different privacy policy.

11. International transfers

We are based in the United States and our infrastructure is primarily there. Booking travel is inherently international: to arrange a trip, details are transferred to our booking provider in the United Kingdom and the European Economic Area, and onward to the airline, property or distribution system involved, wherever in the world it is located.

Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses — together with the UK Addendum or International Data Transfer Agreement where applicable — and on additional safeguards where they are needed. A transfer of passenger data to a supplier so that the booking you asked for can be made is also necessary for the performance of that contract.

You can request a copy of the safeguards we use by emailing privacy@viro.travel.

12. How long we keep it

WhatHow long
Account and profileWhile your account is open, then deleted within 90 days of closure, subject to the exceptions below.
Trip content — itineraries, discussions, polls, photosWhile the trip exists. Deleting a trip removes it. Content you contributed to a shared trip may remain visible to that trip’s other members.
Booking and payment recordsSeven years from the date of the booking, for tax, accounting and audit purposes. This includes the passenger details attached to the booking, because a booking record without them is not a record of anything.
Payment disputes and chargeback evidenceSeven years, or longer while a dispute remains unresolved.
Uploaded documents (passports, visas, insurance)Until you delete them, or until the trip is deleted. You can delete an uploaded document at any time.
Session recordingsUp to 90 days.
Analytics and usage dataUp to 25 months.
Support correspondenceThree years from the last message, so that we still have the history if you come back to us.

Two limits on deletion are worth stating plainly. We cannot delete a record of a booking or a payment within the periods above, and we cannot retract personal data that has already been sent to an airline or a property — that data is theirs to hold and to delete, under their own policy. Everything else we delete on request (§13).

We may keep information for longer where we need it to establish or defend legal claims, or where the law requires it.

13. Your choices and controls

14. US state privacy rights

Depending on where you live — California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and a growing list of other states — you may have the right to:

Categories of personal information

In the last twelve months we have collected and disclosed the following categories, using the California statutory labels.

CategoryCollectedDisclosed for a business purpose to
Identifiers — name, email, phone, IP address, account and device identifiersYesTravel suppliers, payment processor, hosting, database, email and analytics providers
Customer records — billing details, payment metadataYesPayment processor, travel suppliers
Protected classification characteristics — age and date of birth, gender as shown on a travel documentYesTravel suppliers
Commercial information — bookings, purchases, refunds, saved placesYesTravel suppliers, payment processor, analytics providers
Internet or network activity — usage, pages viewed, session recordingsYesAnalytics providers, hosting
Geolocation — approximate only, from IP address or a city you tell usYesAnalytics providers, hosting
Sensitive personal information — travel documents you upload, dietary and accessibility preferences, account credentialsYesDatabase and storage providers; travel suppliers where required in order to arrange travel
Inferences — trip and destination preferencesYesAnalytics providers

We have not sold personal information for money in the last twelve months, and we have not sold or shared the personal information of anyone we know to be under 16.

Sharing for advertising, and how to stop it

We have not shared personal information for cross-context behavioural advertising or targeted advertising. Our previous use of Google Analytics and Amplitude with attribution enabled may have been treated as “sharing” under California and other state laws; both have been removed. The analytics we run now are cookieless, build no cross-site profile and feed no advertising network. To opt out entirely, reject the cookie banner, send a Global Privacy Control signal from your browser (§8), or email privacy@viro.travel and we will apply it on our side.

How to make a request

Email privacy@viro.travel. Tell us what you want and which email address your account or your traveller record uses. We verify your identity against information we already hold before acting on a request, and we may ask for more where the request is a sensitive one. An authorised agent may make a request for you with written proof of authority.

We respond within 45 days, and may extend once by a further 45 days where a request is complex — if we do, we will tell you why within the first period. If we refuse a request, you may appeal by replying to our decision, or by writing to privacy@viro.travel with “Appeal” in the subject line. We respond to an appeal within 45 days with a written explanation, and we will tell you how to complain to your state Attorney General if you are still unsatisfied.

15. EEA, UK and Swiss rights

If the EU or UK GDPR applies to you, Viro Travel LLC. is the controller of your personal data and you have the right to access it, to have it corrected or erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent at any time — withdrawal does not affect processing already carried out on the basis of that consent.

You may object at any time to processing we base on legitimate interests, including profiling, and you may object to direct marketing at any time without giving a reason.

To exercise any of these, email privacy@viro.travel. We respond within one month, extendable by two further months for complex requests.

Complaints. You have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.

Representative. We have not appointed a representative in the EU or the UK under Article 27. Please contact us directly at privacy@viro.travel, or by post at Viro Travel LLC., 115 Old Stonewall Rd, Easton, CT 06612, United States.

Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone (§9).

16. If someone else added you to a trip

You may be in our systems because a friend, a family member, a colleague or a travel organiser added you as a traveller. Our Terms require them to have your permission before doing that, and to show you this policy.

You have the same rights as everyone else, whether or not you have an account. You can ask what we hold about you, have it corrected, or ask us to delete it — subject to the booking retention rules in §12, and noting that we cannot delete a ticket an airline has already issued. Email privacy@viro.travel and we will help.

You will still receive transactional email about travel booked for you — confirmations, changes and cancellations — because you need it in order to travel. It contains no marketing.

17. Security

What we do:

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as the law requires, and without undue delay.

18. Children

The Service is not directed to children, and you must be 18 to hold an account. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, contact privacy@viro.travel and we will delete it.

An adult can book travel for a minor, which means giving us that minor's name, date of birth and travel-document details. We use those details only to arrange the travel.

19. Other sites and suppliers

The Service links to sites we do not operate and displays content from third parties. Once a booking is made, the airline, property or other supplier handles your information under its own privacy policy, as an independent controller. We are not responsible for their practices, and we would encourage you to read their policies before you travel.

20. Changes to this policy

We may update this policy. When a change is material we will update the version and date at the top of this page and notify you by email or by a notice in the Service before it takes effect. Other changes take effect when they are posted. Previous versions are available on request.

21. How to contact us

Viro Travel LLC.
115 Old Stonewall Rd, Easton, CT 06612, United States

Related documents: Terms and Conditions · Booking Terms