Voyko

Privacy policy

Last updated: 22 September 2026.

This is a translation for information purposes. In case of discrepancy, the Spanish version prevails.

This policy explains what personal data Voyko processes, why, on what legal basis, for how long and with whom it is shared, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).

1. Data controller

2. What data we process

Account data (only if you sign up):

Travel preferences and itineraries:

Technical data:

Data you send us through the form or by email: name, email and the content of your message.

We do not ask for special categories of data. Please do not enter personal data about yourself or others in the trip form fields.

3. Use of artificial intelligence

To generate your itinerary, the data you type into the trip form (destination, days, interests, pace, budget, transport, area or accommodation and language) is sent to Google's Gemini API, the artificial intelligence model that creates the plan and checks the places against Google Maps. We do not send Gemini your email, your name or your account data.

The itinerary is generated automatically by AI, but no decision is taken that produces legal effects concerning you or similarly significantly affects you within the meaning of article 22 GDPR: it is a proposal that you decide whether to use.

4. Purposes and legal basis

Purpose Legal basis
Creating and managing your account, logging in (including with Google), verifying your email and recovering your password Performance of the contract for use of the service (art. 6.1.b GDPR)
Generating, saving and sharing itineraries Performance of the contract, or providing the service you request even without an account (art. 6.1.b GDPR)
Sending you service emails (verification, password recovery) Performance of the contract (art. 6.1.b GDPR)
Understanding, in aggregate, the profile of Voyko users (city of residence and age range) to improve the service Legitimate interest in improving the service (art. 6.1.f GDPR)
Limiting trips per visitor, preventing abuse and protecting the security of the website Legitimate interest in security and in keeping the service free (art. 6.1.f GDPR)
Our own aggregated, cookie-free statistics (visits by page and source, actions on the website, clicks on affiliate links) to improve the website and know which links work Legitimate interest in understanding how the service is used and measuring the affiliate revenue that funds it (art. 6.1.f GDPR). It does not identify anyone
Statistical measurement of website use (Google Analytics) Your consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE), which you can withdraw at any time
Answering your enquiries Your consent when you write to us (art. 6.1.a GDPR)
Complying with legal obligations and handling claims Legal obligation (art. 6.1.c GDPR)

We do not use your data to send you advertising or to build commercial profiles, and we do not sell it.

5. Retention periods

6. Recipients and processors

We do not disclose your data to third parties unless legally required. To provide the service we use these providers, which process data on our behalf (processors) or as independent controllers where stated:

Provider Purpose Data Location
Axarnet Comunicaciones, S.L. Hosting of the server and database All service data Spain
Google (Gemini API and Google Maps) Generating the itinerary with AI What you type into the trip form USA / global
Google (Google Identity Services) Sign in with Google, only if you use it Email and name of your Google account USA / global
Google (Google Analytics), only if you accept it Usage statistics Browsing data, cookie identifiers and IP EU / USA
Resend (Plus Five Five, Inc.) Sending service emails and contact form notifications Email, name and message content USA
CARTO (CartoDB, Inc.) Base maps for the itinerary IP and technical data from your browser when loading the map USA / EU

Other services we use do not receive your personal data: OpenCage (geocoding the places in the itinerary), Firecrawl (reading public activity catalogues) and Frankfurter (exchange rates).

Affiliate links: when you click a link to Civitatis, Booking.com, GetYourGuide, Viator, IATI Seguros, Holafly or other partners, you leave Voyko and the third party processes your data as controller, under its own privacy policy. We do not send them your identity. The link does include the destination (and, for Booking.com, the area or accommodation you entered) to show you results for that search, as well as our affiliate identifier and a campaign label showing where the link is on Voyko and the itinerary's city (for example, voyko-parada-lisboa). That label contains no data about you. More information on the affiliates page.

Shared itineraries: if you share an itinerary, anyone with the link can see it, and it may appear in the public gallery of recent plans. Itineraries do not include your name or email.

7. International transfers

Some providers (Google, Resend and CARTO) may process data outside the European Economic Area, mainly in the United States. Those transfers rely on the adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it and, otherwise, on the standard contractual clauses approved by the European Commission (art. 46 GDPR).

8. Your rights

You can exercise at any time your rights of:

You can also withdraw your consent at any time, without affecting processing carried out before. For cookies you can do so from "Cookie settings" in the footer of any page.

How to exercise them: write to hola@voyko.app from your account email, or tell us which one you used, and explain which right you want to exercise. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it. We will reply within one month at most, extendable by two further months in complex cases.

Complaints: if you believe we have not handled your rights properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid, Spain, www.aepd.es, or with the supervisory authority of your country of residence in the EU.

9. Minors

You must be over 18 to create an account. If you are a minor, do not sign up or send us personal data.

10. Security

We apply technical and organisational measures appropriate to the risk: encrypted connections (HTTPS), hashed passwords, IP addresses stored only as an irreversible fingerprint, restricted access to servers and providers with sufficient guarantees.

11. Changes to this policy

We may update this policy when the service or the law changes. The date of the last update is shown at the top. If the change is significant, we will announce it visibly on the website or by email to registered users.