Privacy Policy

Last updated: March 1, 2026

1. Data We Collect

We collect the following categories of personal data when you use our Smart Trip Planner:

  • Traveler Profile Data: Country of origin, party type, age range, travel preferences, budget range, and interest scores. This data is stored session-only for free users and persisted for Premium users.
  • Email Address: Collected only when you opt in to receive your itinerary summary PDF or create an account.
  • Payment Information: Processed exclusively by Stripe. We never store credit card details on our servers (PCI DSS compliance delegated to Stripe).
  • Cookie Data: Essential cookies for site functionality, and optional analytics/marketing cookies with your explicit consent.

2. How We Use Your Data

  • Generate personalized Normandy travel itineraries
  • Process payments for Premium services
  • Send transactional emails (itinerary delivery, booking confirmations)
  • Send nurture email sequences (only with explicit consent)
  • Improve our service through anonymized analytics

3. GDPR Rights

Under GDPR, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Withdrawal of Consent: Withdraw consent for marketing communications at any time

4. Cookie Policy

We use cookies to provide essential functionality and, with your consent, to analyze site usage and personalize content. You can manage your cookie preferences at any time through our cookie consent banner.

  • Essential Cookies: Required for site functionality (session management, security)
  • Analytics Cookies: Help us understand how visitors use our site (Google Analytics, PostHog)
  • Marketing Cookies: Used for targeted advertising and retargeting

5. Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store, process, or transmit credit card information on our servers. All payment data is encrypted and handled directly by Stripe's secure infrastructure.

6. Data Retention

  • Free users (session-only): Profile data is deleted when the browser session ends
  • Registered users: Data retained until account deletion is requested
  • Email captures: Retained until unsubscribe or deletion request
  • Payment records: Retained as required by applicable tax and financial regulations

7. Contact

For any privacy-related questions or to exercise your rights, contact us at privacy@visitnormandy.com.