Privacy Policy
Effective: May 24, 2026
1. Introduction
This Privacy Policy explains how Viagem ("Viagem," "we," "us," or "our") collects, uses, shares, and protects information about you when you use our website, mobile-responsive web app, or any related services (collectively, the "Service"). Viagem is a product of NLH Enterprises LLC, a Utah limited liability company doing business as "Viagem," based in Utah, USA.
By using the Service, you agree to the collection and use of information consistent with this policy. If you do not agree, please do not use the Service.
2. Information we collect
2.1 Information you provide
- Family profile: family name, home airport, traveler names, ages, adult/child role, and stated travel preferences.
- Trip planning inputs: travel windows, max budget, and the priority weights you tune on your profile.
- Loyalty programs: program names and member numbers you choose to store so we can surface them at booking. We do not access your point balances or transaction history at the loyalty program.
- Account credentials: email address and password (stored hashed and salted) once accounts are live.
- Billing information: processed by Stripe; we receive billing status and the last four digits of your payment method, but never your full card number or banking credentials.
- Communications: messages you send us through support email, feedback forms, or in-app surfaces.
2.2 Information collected automatically
- Usage data: which pages you view, trips you grade, search filters you set, and click events on booking handoff buttons. Used to improve grading, recommendations, and the product.
- Device and connection data: IP address, browser type and version, operating system, device type, referring URLs, and approximate location (city or region) derived from IP.
- Local storage: a JSON blob stored in your browser's local storage that remembers your family profile, wishlist, and preferences between visits on the same device. Cleared when you clear your browser's site data for Viagem.
2.3 Information from third parties
- Authentication providers (if you sign in via Google, Apple, or similar): name, email, and a unique provider ID from the chosen provider.
- Affiliate networks: we may receive notifications when a booking attributed to a Viagem click clears, including the booking value and commission earned — never your name, payment information, or full booking details.
- Analytics providers: aggregate and de-identified usage signals.
3. How we use information
- Operate the Service — grade trips against your family's priorities, generate AI-assisted itineraries, surface stored loyalty numbers at booking handoff.
- Improve grading algorithms, recommendations, and the overall user experience.
- Communicate with you about your account, the Service, updates, or support requests.
- If we offer paid features in the future, process payments and manage subscriptions (via a payment processor such as Stripe).
- Detect, investigate, and prevent fraudulent or unauthorized activity.
- Comply with legal obligations and enforce our Terms of Service.
- With your separate consent, send marketing communications you can unsubscribe from at any time.
Where required by law, we rely on one of the following legal bases: performance of a contract with you, your consent, our legitimate interests (e.g., improving the Service and preventing fraud), or compliance with a legal obligation.
4. How we share information
We do not sell your personal information. We share it only in the following circumstances:
- Service providers: companies that process data on our behalf under written agreements that bind them to use the data only for the services they provide us. Current and planned providers include Vercel (hosting), Supabase (database and authentication), Stripe (payment processing), Anthropic (AI itinerary generation via Claude API), and Travelpayouts (flight and hotel price data).
- Affiliate networks: when you click a booking link, we pass a click identifier and your destination URL to the affiliate network so commissions can be attributed. We do not share your family profile, traveler information, or stored loyalty numbers with affiliate networks.
- Airline and hotel brands: when you click "Book direct," we hand you off to the brand's own website. From that point on, you are interacting with that brand under their privacy practices. We may pre-fill your stored loyalty number into the brand's URL where the brand supports it.
- Legal requirements: when required by valid legal process, to protect rights and safety, or to enforce our Terms.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case we will require the successor to honor this policy or notify you and give you the choice to delete your data.
- With your consent: any sharing not described above will be done only with your explicit consent.
5. Cookies and tracking technologies
Viagem uses a small number of cookies and similar technologies. We group them into four categories:
- Strictly necessary: required for the Service to function, such as a session cookie for sign-in. These cannot be disabled.
- Functional: remember preferences such as your selected travel window or budget slider position so you don't have to re-enter them. Today, these are stored in your browser's local storage rather than as cookies.
- Analytics: help us understand how the Service is used in aggregate. We do not use analytics for cross-site tracking or advertising.
- Advertising: Viagem does not currently set advertising cookies and does not run third-party ads on the Service.
Most browsers let you manage or block cookies. Blocking strictly-necessary cookies may break sign-in and other Service features. Blocking functional cookies or clearing local storage will reset your stored preferences.
6. Third-party services and links
The Service contains links to airline, hotel, and other third-party websites (especially via "Book direct" handoffs). We are not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies before providing any information.
7. Data retention
We keep account and family-profile data for as long as your account is active. When you delete your account, we delete or anonymize that data within 30 days, except where we are required to retain it longer (e.g., billing records for tax purposes, typically up to seven years). Aggregate, de-identified usage data may be retained indefinitely to improve the Service.
8. Data security
We use industry-standard administrative, technical, and physical safeguards to protect your information: TLS encryption in transit, encryption at rest for sensitive fields, hashed-and-salted passwords, least-privilege access controls, and routine audits of our service providers. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by applicable law.
9. Your privacy rights and choices
You have the following rights, subject to applicable law:
- Access: request a copy of the personal information we hold about you.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion: ask us to delete your information, subject to limited exceptions.
- Portability: receive your data in a structured, commonly used, machine-readable format.
- Opt-out of marketing: unsubscribe from any marketing email using the link in the message; service-related communications will continue.
- Withdraw consent: where processing is based on your consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email us at the address in Section 14. We will respond within 30 days (or as required by applicable law). We will not discriminate against you for exercising any of these rights.
9.1 California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the CPRA, including the right to know the categories of personal information we collect, the right to delete personal information, the right to correct inaccurate information, and the right to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising, so there is no "Do Not Sell or Share My Personal Information" link to enable. To exercise any California-specific right, email us at the address in Section 14 with "California Privacy Request" in the subject line.
9.2 European residents (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation, including the rights listed above and the right to lodge a complaint with your local data protection authority. We act as the data controller for personal information collected through the Service. Where we transfer data outside the EEA, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
10. Children's privacy
Viagem is designed for parents and other adult guardians planning family travel. We do not knowingly collect personal information directly from children under 13. Parents and guardians may enter children's first names and ages as part of the family profile so we can grade kid-fit for activities; this information is treated as part of the adult parent's family profile, not as direct collection from the child. If you believe a child under 13 has provided personal information directly to us, please contact us and we will delete the information promptly.
11. International data transfers
Viagem is operated from the United States. If you use the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your country. We take steps to ensure that international transfers comply with applicable law.
12. Do Not Track
Some browsers transmit a "Do Not Track" (DNT) signal. There is no industry consensus on how to respond to DNT signals, and we do not currently respond to them.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date at the top of the page. If the change is material, we will notify you in-app or by email before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
14. Contact us
Questions, concerns, or requests to exercise any of your privacy rights: support@viagem.com. We will respond within 30 days.