Privacy Policy

Effective Date: July 15, 2026

This Privacy Policy explains how Niafari ("we", "us", "our") collects, uses, and protects your personal data when you use our website and mobile application at app.niafari.com (the "Service"). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) (EU) 2016/679.

1. Data Controller

Niafari is the data controller responsible for your personal data processed through the Service. For any privacy-related questions, contact us at support@niafari.com.

2. Data We Collect

Account Data

When you create an account, we collect your email address, first name, last name, sex, and date of birth.

Usage Data

We automatically collect certain information when you use the Service, including your selected language, trip preferences, and device/browser information. Trips created without an account are stored locally in your browser until you log in.

Trip Data

When you plan or save a trip, we store the destination, dates, traveler count, budget, travel style, itinerary, and other trip-related details you provide.

3. How We Use Your Data

  • To provide and maintain the Service, including generating AI-powered travel itineraries.
  • To manage your account and provide authentication.
  • To remember your language and travel preferences.
  • To display community trips and enable social features like sharing and bookmarking.
  • To improve our Service and develop new features.

4. Legal Basis for Processing

Under the GDPR, we process your personal data on the following legal bases:

  • Your consent (Article 6(1)(a)) — for cookies, local storage, and optional features.
  • Performance of a contract (Article 6(1)(b)) — to provide the Service you requested.
  • Legitimate interests (Article 6(1)(f)) — to operate, secure, and improve our Service.

5. Cookies and Local Storage

We use cookies and browser local storage to operate the Service. These include:

Strictly Necessary

Authentication session tokens managed by our platform to keep you signed in, your selected language, cached translations, and locally saved trips for unauthenticated users. These are essential for the Service to function.

Third-Party Cookies and Scripts

The following third-party services are used by the Service and may set cookies or process data: Google Fonts (font loading), OpenStreetMap (map tiles), Unsplash (stock photography), and Base44 (platform infrastructure, authentication, and error monitoring). When you interact with external booking platforms (e.g., Booking.com, Skyscanner, Rentalcars) through links provided in the Service, those third parties may set their own cookies. We do not control these cookies and recommend reviewing their privacy policies.

Cookie Consent

When you first visit the Service, we ask for your consent to use cookies and local storage. Your choice is stored locally in your browser so you are not asked again on subsequent visits. You can withdraw consent at any time by clearing your browser storage.

6. Third-Party Processors

We do not sell your personal data. We share your data only with the following processors, who act on our behalf under Data Processing Agreements (DPA):

PartyRolePurposeLocation
Base44 Inc.ProcessorHosting, database, authentication, and platform infrastructureUnited States (with Standard Contractual Clauses)
Google (Fonts)ProcessorLoading web fontsUnited States (with appropriate safeguards)
UnsplashProcessorProviding stock photography for destinationsUnited States
OpenStreetMapProcessorDisplay of maps and geographic dataGlobal (OpenStreetMap contributors)
TravelpayoutsProcessorAffiliate tracking for outbound booking linksUnited States

Data Processing Agreements

DPAs are in place with all processors. For processors outside the EEA (Base44, Google), appropriate safeguards including Standard Contractual Clauses (SCCs) ensure GDPR-compliant data protection during international transfers.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law. Trip data is retained until you delete your trips or account. Local storage data in your browser persists until you clear it.

8. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — You can request a copy of your personal data.
  • Right to rectification — You can request correction of inaccurate data.
  • Right to erasure ("right to be forgotten") — You can request deletion of your data.
  • Right to restriction — You can request that we limit processing of your data.
  • Right to data portability — You can receive your data in a structured format.
  • Right to object — You can object to processing based on legitimate interests.
  • Right to withdraw consent — You can withdraw consent at any time without affecting prior processing.

To exercise any of these rights, contact us at support@niafari.com. We will respond within one month of your request.

9. International Data Transfers

Your personal data may be processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your data in accordance with the GDPR.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on the Service. Continued use of the Service after changes constitutes acceptance of the revised policy.

12. Contact Us

If you have any questions about this Privacy Policy or your personal data, please contact us at support@niafari.com. You also have the right to lodge a complaint with your local data protection authority.