Last updated: 12th August 2026

Privacy Policy

This Privacy Policy explains how ViraLoca ("we", "us", "our") handles your personal information when you use viraloca.com or any service we provide (together, the "Service"). ViraLoca Ltd is a company registered in England and Wales with company number 17336293, whose registered office is at 66 Paul Street, London, England, EC2A 4NA. ViraLoca Ltd is the data controller for the personal information described in this policy.

If you have any questions, contact us at privacy@viraloca.com.

What information we collect

We try to collect the minimum needed to run the Service well.

Account information — when you create an account, we store your email address and either an encrypted (hashed) password or an identifier from a social sign-in provider (Google). If you sign in with Google, we receive your email, name, and profile picture from Google.

Usage information — places you save, AI itinerary plans you generate (including the inputs you provide and the plans we return), your taste preferences, group lists you create, and any plans you mark as public.

Payment information — when you buy credit packs, you provide payment details directly to Stripe; we never see or store your card number. We do receive a transaction ID, the amount paid, the currency, the country of issue, and whether the payment succeeded.

Technical information — your IP address (we store only a one-way hashed version), browser type and version, device type, the pages you view on viraloca.com, and any errors your browser reports.

Communications — if you email us, we keep that correspondence to respond and to identify recurring issues.

We do not knowingly collect information from anyone under 18. The Service is intended for adults aged 18 and over. If you believe we have collected information from a child, contact us at support@viraloca.com and we will delete it.

How we collect information

We collect information in three ways:

  • Directly from you when you create an account, sign in, save a place, generate a plan, or contact us.
  • Automatically through cookies and similar technologies — see "Cookies" below.
  • From third parties if you sign in with Google, in which case we receive the information Google shares with our app (email, name, profile picture).

How we use your information

We use the information we collect for a few related purposes, and the lawful basis under the UK GDPR depends on the activity.

We process information on the basis of our contract with you (Article 6(1)(b)) to create and maintain your account, show you your saved places and plans, generate AI itinerary plans from the inputs you provide, take payment when you buy a credit pack, issue receipts, and send transactional emails like password-reset links and purchase confirmations. Without these activities we cannot deliver the Service you signed up for.

We rely on our legitimate interests (Article 6(1)(f)) to diagnose errors, prevent abuse of the Service, and hash and rate-limit IP addresses to deter automated attacks. These activities are necessary to keep the Service running securely and reliably, and we have balanced our interest in doing so against your right to privacy.

We rely on your consent (Article 6(1)(a)) to measure how the Service is used so we can improve it — analytics cookies are off by default and only set if you opt in via the cookie banner. We also rely on your consent, alongside our contract with you, to show you content that matches the taste preferences you have actively set on your profile. You can withdraw consent at any time without affecting any other part of the Service.

Finally, we rely on legal obligation (Article 6(1)(c)) to retain certain records (for example, payment records for HMRC tax purposes) and to respond to lawful requests from regulators or courts.

We do not sell your personal information. We do not use it for automated decision-making with legal or similarly significant effects.

Cookies and similar technologies

We use three categories of cookies and local browser storage. You can manage your preferences from the cookie banner on first visit, or any time via the cookie settings link in the footer of viraloca.com.

Strictly necessary — required to run the Service securely. These cookies remember your sign-in session, your anonymous session for credit accounting, and your cookie preferences themselves. They do not require your consent under UK PECR.

Analytics — anonymous, aggregated metrics about how people use the Service (page views, button clicks, navigation paths). Set only with your explicit consent. You can withdraw consent at any time without affecting the rest of the Service.

Third-party content — when you view a video embedded in a place page from a third-party platform, that platform may set its own cookies under its own privacy policy. We do not control those cookies. Embeds load only after you press play; before that point, no third-party cookies are set.

We do not use advertising cookies. We do not run third-party ad networks on the Service.

Who we share your information with

We do not sell your personal information. We share it only with carefully selected service providers ("data processors") who help us deliver the Service. Each is bound by a data-processing agreement and acts only on our written instructions, never for their own commercial purposes. The categories of recipients we use are:

  • Hosting, database, and authentication — to store your account, your saved places, and your plans, and to verify who you are when you sign in
  • Payment processing — to take payment when you buy a credit pack and to issue receipts
  • Transactional email delivery — to send things like password-reset links and purchase confirmations
  • Error monitoring — to spot and diagnose technical issues across the Service
  • Anonymous analytics — to understand how the Service is used in aggregate (only with your consent)
  • Maps and geocoding — to display venue locations
  • AI services — to generate itinerary plans from the inputs you provide

We may also disclose personal information when we are legally required to (for example, in response to a valid court order) or to protect the rights, property, or safety of ViraLoca, our users, or others.

In the unlikely event of a business sale, restructure, or insolvency, your personal information may be transferred to the new owner subject to the protections in this policy.

Where we store your personal information

Your account data is stored in the UK. Some of our service providers are based in the US or process data outside the UK. Where personal data is transferred outside the UK, the transfer is protected by one of the following:

  • The UK adequacy decision for the receiving country (where one exists)
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses
  • Other appropriate safeguards under Article 46 of the UK GDPR

You can request a copy of the relevant safeguard by emailing privacy@viraloca.com.

How long we keep your information

We keep personal information only as long as we need it for the purposes described above.

  • Account and usage data: while your account is active. If you delete your account, we delete or anonymise associated data within 30 days, except where we are required by law to keep certain records.
  • Payment records: at least 6 years to comply with UK tax record-keeping requirements (HMRC).
  • Error logs: 90 days, then automatically purged.
  • Analytics events (anonymous): up to 12 months.
  • Email correspondence: up to 2 years after the last interaction, then deleted.

Your rights

Under the UK GDPR you have the right to:

  • Access the personal information we hold about you (Article 15)
  • Rectify information you believe is inaccurate (Article 16)
  • Erase your personal information ("right to be forgotten") (Article 17)
  • Restrict how we process your information (Article 18)
  • Port your data to another service in a machine-readable format (Article 20)
  • Object to processing based on our legitimate interests (Article 21)
  • Withdraw consent at any time, where we rely on consent

To exercise any of these rights, email privacy@viraloca.com. We respond within 30 days. We will ask you to verify your identity before acting on your request to ensure we share data only with the right person.

If you believe we have not adhered to this policy or handled your personal information properly, please email us directly at privacy@viraloca.com.

Security

We take security seriously and use industry-standard measures to protect your information, including:

  • TLS encryption for all data transmitted between your browser and our servers
  • Password hashing using bcrypt — we never see or store your plaintext password
  • Row Level Security (RLS) in our database, enforced at the database layer so a logged-in user can only access their own data
  • Hashed IP addresses rather than raw IPs, for anonymous usage tracking
  • Third-party-hosted card forms so payment details never touch our servers
  • Error log scrubbing so URL query parameters that might contain tokens are stripped before any logs are written

No system is 100% secure. If we ever become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and, where required, notify you directly.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will post a notice on viraloca.com and update the "Last updated" date at the top of this policy. We encourage you to review this page periodically.

Contact

For any privacy-related question, request, or concern:

ViraLoca — Privacy Team
Email: privacy@viraloca.com