Privacy policy
Last updated: 22 September 2026.
This is a translation for information purposes. In case of discrepancy, the Spanish version prevails.
This policy explains what personal data Voyko processes, why, on what legal basis, for how long and with whom it is shared, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
1. Data controller
- Controller: José Antonio Martínez Gómez
- Tax ID (NIF): 77723042Q
- Address: C/ Garajonay, 2, 4.º G, 28701 San Sebastián de los Reyes (Madrid), España
- Privacy email: hola@voyko.app
2. What data we process
Account data (only if you sign up):
- Email and password. The password is never stored in plain text, only an irreversible hash of it.
- Your name, if you give it.
- City of residence and age range, which we ask for when you sign up.
- If you sign up with Google: the email and name Google provides when you log in.
- Account usage data: whether you have verified your email, how many trips you have generated and your plan.
- Active sessions (a random identifier that keeps you logged in).
Travel preferences and itineraries:
- Destination, number of days, interests, pace, budget, means of transport, language and, if you enter it, the area or accommodation where you are staying.
- The itineraries generated and those you save to your account or share through a link.
Technical data:
- To apply the daily limit of trips per visitor, your IP address is turned into an irreversible fingerprint (a keyed hash) before it is stored. We do not store your IP address in clear in the database.
- Server logs (IP address, date and time, page requested and browser), needed for the security and operation of the website.
- Our own aggregated statistics, without cookies: we count how many times each page is opened, which website or campaign visits come from (the referring domain or the
utm_sourceparameter) how many times each affiliate link is clicked, together with the itinerary's city and the destination website, and how many times an itinerary is generated, shared or saved, or an account is created or someone logs in. Only daily counters are stored. We do not store your IP, your browser or any identifier, and we do not write or read anything on your device, so we cannot know who you are or track you. - If you accept analytics cookies, the browsing data collected by Google Analytics (see the cookie policy).
Data you send us through the form or by email: name, email and the content of your message.
We do not ask for special categories of data. Please do not enter personal data about yourself or others in the trip form fields.
3. Use of artificial intelligence
To generate your itinerary, the data you type into the trip form (destination, days, interests, pace, budget, transport, area or accommodation and language) is sent to Google's Gemini API, the artificial intelligence model that creates the plan and checks the places against Google Maps. We do not send Gemini your email, your name or your account data.
The itinerary is generated automatically by AI, but no decision is taken that produces legal effects concerning you or similarly significantly affects you within the meaning of article 22 GDPR: it is a proposal that you decide whether to use.
4. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, logging in (including with Google), verifying your email and recovering your password | Performance of the contract for use of the service (art. 6.1.b GDPR) |
| Generating, saving and sharing itineraries | Performance of the contract, or providing the service you request even without an account (art. 6.1.b GDPR) |
| Sending you service emails (verification, password recovery) | Performance of the contract (art. 6.1.b GDPR) |
| Understanding, in aggregate, the profile of Voyko users (city of residence and age range) to improve the service | Legitimate interest in improving the service (art. 6.1.f GDPR) |
| Limiting trips per visitor, preventing abuse and protecting the security of the website | Legitimate interest in security and in keeping the service free (art. 6.1.f GDPR) |
| Our own aggregated, cookie-free statistics (visits by page and source, actions on the website, clicks on affiliate links) to improve the website and know which links work | Legitimate interest in understanding how the service is used and measuring the affiliate revenue that funds it (art. 6.1.f GDPR). It does not identify anyone |
| Statistical measurement of website use (Google Analytics) | Your consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE), which you can withdraw at any time |
| Answering your enquiries | Your consent when you write to us (art. 6.1.a GDPR) |
| Complying with legal obligations and handling claims | Legal obligation (art. 6.1.c GDPR) |
We do not use your data to send you advertising or to build commercial profiles, and we do not sell it.
5. Retention periods
- Account and saved trips: as long as you keep your account. When you ask for it to be closed, we delete them, except for what we must keep blocked to deal with possible legal liabilities during the applicable limitation periods.
- Sessions: expire after 30 days.
- Password recovery and email verification links: expire after 60 minutes and 24 hours respectively.
- Cached itineraries (to serve identical requests faster): up to 30 days after they are generated. They are not linked to your identity.
- Shared or saved itineraries (those with a
/p/…link): for as long as the link exists. You can ask us to delete a plan of yours. - IP fingerprints for the daily limit: 30 days at most.
- Server logs: automatically overwritten by rotation within a few days.
- Our own statistics: these are aggregated daily counters that do not identify anyone, so they are not personal data. We keep them for as long as they are useful.
- Google Analytics: according to the period configured in Google Analytics (see the cookie policy).
- Contact messages: as long as needed to handle your enquiry and at most 12 months after it is closed.
6. Recipients and processors
We do not disclose your data to third parties unless legally required. To provide the service we use these providers, which process data on our behalf (processors) or as independent controllers where stated:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Axarnet Comunicaciones, S.L. | Hosting of the server and database | All service data | Spain |
| Google (Gemini API and Google Maps) | Generating the itinerary with AI | What you type into the trip form | USA / global |
| Google (Google Identity Services) | Sign in with Google, only if you use it | Email and name of your Google account | USA / global |
| Google (Google Analytics), only if you accept it | Usage statistics | Browsing data, cookie identifiers and IP | EU / USA |
| Resend (Plus Five Five, Inc.) | Sending service emails and contact form notifications | Email, name and message content | USA |
| CARTO (CartoDB, Inc.) | Base maps for the itinerary | IP and technical data from your browser when loading the map | USA / EU |
Other services we use do not receive your personal data: OpenCage (geocoding the places in the itinerary), Firecrawl (reading public activity catalogues) and Frankfurter (exchange rates).
Affiliate links: when you click a link to Civitatis, Booking.com, GetYourGuide, Viator, IATI Seguros, Holafly or other partners, you leave Voyko and the third party processes your data as controller, under its own privacy policy. We do not send them your identity. The link does include the destination (and, for Booking.com, the area or accommodation you entered) to show you results for that search, as well as our affiliate identifier and a campaign label showing where the link is on Voyko and the itinerary's city (for example, voyko-parada-lisboa). That label contains no data about you. More information on the affiliates page.
Shared itineraries: if you share an itinerary, anyone with the link can see it, and it may appear in the public gallery of recent plans. Itineraries do not include your name or email.
7. International transfers
Some providers (Google, Resend and CARTO) may process data outside the European Economic Area, mainly in the United States. Those transfers rely on the adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it and, otherwise, on the standard contractual clauses approved by the European Commission (art. 46 GDPR).
8. Your rights
You can exercise at any time your rights of:
- Access: to know what data about you we process.
- Rectification: to correct inaccurate data.
- Erasure: to ask us to delete your data, including closing your account.
- Objection: to object to processing based on legitimate interest.
- Restriction: to ask us to suspend processing in certain cases.
- Portability: to receive your data in a structured, commonly used format.
You can also withdraw your consent at any time, without affecting processing carried out before. For cookies you can do so from "Cookie settings" in the footer of any page.
How to exercise them: write to hola@voyko.app from your account email, or tell us which one you used, and explain which right you want to exercise. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it. We will reply within one month at most, extendable by two further months in complex cases.
Complaints: if you believe we have not handled your rights properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid, Spain, www.aepd.es, or with the supervisory authority of your country of residence in the EU.
9. Minors
You must be over 18 to create an account. If you are a minor, do not sign up or send us personal data.
10. Security
We apply technical and organisational measures appropriate to the risk: encrypted connections (HTTPS), hashed passwords, IP addresses stored only as an irreversible fingerprint, restricted access to servers and providers with sufficient guarantees.
11. Changes to this policy
We may update this policy when the service or the law changes. The date of the last update is shown at the top. If the change is significant, we will announce it visibly on the website or by email to registered users.