Legal
Privacy Policy
What we collect, why, how long we keep it, who we share it with, and how to take it back. Written to be read, not survived.
This policy explains how Zestli, Inc. (“Zestli”, “we”, “us”, “our”) handles personal data when you use the website at zestli.ai, the traveler app at app.zestli.ai, our native mobile apps, and the services we offer through them (together, the “Service”). For the purposes of the EU and UK General Data Protection Regulation (“GDPR” / “UK GDPR”), Zestli, Inc. is the controller of your personal data.
Recommendations and itineraries on Zestli are AI-generated — see AI & automated processing and our Terms of Service. A short, plain-language summary of these commitments also appears in the colophon of our website.
1. Who we are & how to reach us
- Controller: Zestli, Inc., Delaware, United States.
- Privacy contact: privacy@zestli.ai.
- Data Protection Officer: not yet designated — privacy inquiries go to the privacy contact above.
- EU representative (GDPR Art. 27): to be designated before bookings open to EU travelers (GDPR Art. 27 / DSA Art. 13).
- UK representative (UK GDPR Art. 27): to be designated before bookings open to UK travelers (UK GDPR Art. 27).
You can exercise any of the rights described below — including export and deletion — at Manage your data, or by emailing the privacy contact above.
2. Data we collect
We collect only what the Service needs. The categories are:
| Category | What it includes |
|---|---|
| Guest session identifier | A pseudonymous token created when you start planning, before any account, so your work persists in that session. |
| Account & contact | Your email when you request a magic link, join the waitlist, or contact us; and metadata that a second factor (MFA) is enrolled and verified — never the secret itself. |
| Trip & concierge data | Itineraries, Trip-Board items, preferences, saved destinations, and the prompts and messages you give the concierge. |
| Booking & payment metadata | Booking amount, currency, status, operator, and a payment-processor reference. Card details go directly to our payment processor — we never receive or store raw card numbers (see §7). |
| Voice & transcript data | If you speak to the concierge — your speech and its transcript. We do not create voiceprints (see §6). |
| Device, log & usage data | IP address, device/browser type, app version, and interaction logs needed to run, secure, and debug the Service. |
| Optional analytics | Aggregate, privacy-respecting usage measurement — only if you consent. No advertising or cross-site tracking (see Cookie Policy). |
| Approximate / precise location | Only if you turn it on at the device level, to surface what is near you. You control this through your operating system and can switch it off at any time. |
Some preferences you share (for example a dietary need or an accessibility requirement) could reveal special-category data under the GDPR. Where you choose to provide such details, you consent to our using them to tailor your trip; you can withdraw that consent and remove the data at any time.
3. How & why we use it
We use personal data to:
- create and operate your trips, and compose recommendations and itineraries you ask for;
- facilitate bookings with independent operators and process the related payment;
- authenticate you, keep the Service secure, and prevent fraud and abuse;
- respond to your messages and provide support;
- meet legal, tax, and accounting obligations; and
- only with your consent, measure how the product is used and send you updates you ask for.
We do not sell your personal data, and we do not use it for third-party advertising.
4. Legal basis (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Creating your account, running your trips and bookings, processing payment | Performance of a contract (Art. 6(1)(b)) |
| Authentication, security, fraud and abuse prevention, service reliability | Legitimate interests (Art. 6(1)(f)) — you may object (see §10) |
| Optional analytics, optional functional cookies, optional marketing email, any special-category preferences | Consent (Art. 6(1)(a); Art. 9(2)(a) for special-category data) — you may withdraw at any time |
| Tax, accounting, and other legal obligations | Legal obligation (Art. 6(1)(c)) |
5. AI & automated processing
Destinations, itineraries, day stories, and recommendations are composed by AI from real places and live availability. When you use the concierge you are interacting with an AI system, not a human, and AI-composed content is labeled as such. Zestli does not fabricate prices, reviews, or availability, and AI does not author traveler reviews. Verify details before you rely on them; bookings are confirmed by the operator (see the Terms).
We use automated tools to personalize what we suggest to you. These suggestions do not produce legal or similarly significant effects, and you are always free to accept, ignore, or change them. You can ask us to explain or review a personalized output, or object to this personalization, by contacting privacy@zestli.ai.
6. Voice & transcripts
When you use voice features, we record and transcribe your speech to understand and fulfill your requests. We do not create voiceprints and do not use voice recordings to identify you biometrically. You can review, redact, and delete transcripts, and we ask for consent before recording where the law requires it. Voice data is never sold.
7. Processors & sharing
We share personal data only with service providers who process it on our behalf under contract, and only as needed. We share data by category of recipient:
- Payment processing — Stripe. Payments are processed by Stripe, Inc. and its affiliates (“Stripe”). Your card details are collected and processed directly by Stripe and are never stored on Zestli’s systems. We share with Stripe the data needed to take payment and prevent fraud (such as name, email, billing details, IP address, and transaction details). Stripe’s handling of that data is governed by the Stripe Privacy Policy.
- Travel operators. When you book, we pass the booking details an operator needs to provide the service you requested.
- Cloud hosting & content delivery. To host the Service, store data, and deliver imagery securely.
- Transactional email. To send magic links, confirmations, and notices.
- AI / inference providers. To compose recommendations, our providers process your prompts and trip context as our processors. We do not sell this data and do not permit it to be used to train third-party models.
- Analytics. Only if you consent — privacy-respecting and aggregate.
- Legal & safety. Authorities or advisors where we are required to disclose by law, or to establish, exercise, or defend legal claims, or to protect someone’s safety.
We do not name every individual sub-processor here to keep this policy readable; a current list of the categories and the specific processors we use is available on request from privacy@zestli.ai.
8. International transfers
Zestli is based in the United States and uses service providers in the United States and other countries. When we transfer the personal data of EU, UK, or Swiss residents outside their home jurisdiction, we rely on legally recognized transfer mechanisms — including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and the Swiss addendum to those clauses — together with supplementary safeguards where required. Where a recipient is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), we may also rely on that certification. You may request a copy of the relevant safeguards from privacy@zestli.ai.
9. Retention
We keep personal data only as long as we need it for the purposes above:
| Data | Retention |
|---|---|
| Guest-session data | Expires automatically after the session / a short inactivity window |
| Account, trip, preference, transcript data | While your account is active, and a reasonable period afterward, then deleted on request or by schedule |
| Booking & payment records | As long as required for tax, accounting, and dispute resolution (typically several years), even after account deletion |
| Security & abuse-prevention logs | A limited period needed to keep the Service safe |
You can erase your data at Manage your data; what is retained for legal reasons is explained there.
10. Your rights
Subject to your local law, you have the right to access your data, rectify it, erase it, restrict or object to processing, receive it in a portable format (portability), and withdraw consent at any time (without affecting processing already carried out). Exercise these at /data or via privacy@zestli.ai — we verify identity with a magic link, and additionally your second factor (MFA) for export or deletion. We respond within the time the law allows (generally one month under the GDPR; within 45 days under US state laws, extendable as permitted), and we will not discriminate against you for exercising a right.
If you are in the EU, UK, or Switzerland and believe we have mishandled your data, you may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to resolve it first.
11. US state privacy rights
If you are a resident of a US state with a comprehensive privacy law (including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others), you have the rights to know/access, correct, delete, and obtain a portable copy of your personal information, to opt out of the sale of personal information, targeted advertising, and profiling with legal or similarly significant effects, and to appeal a denied request. Exercise them at /data or privacy@zestli.ai; you may use an authorized agent.
We do not sell or share your personal information (including for cross-context behavioral advertising), and we do not use sensitive personal information beyond what is needed to provide the Service you asked for. Because of this, there is nothing to opt out of — but we still honor opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out where applicable. California residents can review these choices through the Cookie settings control and Manage your data (a “Your Privacy Choices” mechanism). The categories of personal information we collect, our purposes, and our retention are described in sections 2–9 above; we do not knowingly process the personal information of consumers under 16 for sale, sharing, or targeted advertising.
12. Other regions
If you are in Canada (including Québec), Brazil (LGPD), Australia, or Switzerland, you have rights to access, correction, deletion, and information about how your data is shared, broadly equivalent to those above, and you may contact your national privacy regulator. Direct any request to privacy@zestli.ai.
13. Children
The Service is intended for users aged 18 and over. We do not direct the Service to children and do not knowingly collect their personal data. If we learn we have collected data from a child, we will delete it — contact privacy@zestli.ai.
14. Security & breach
We protect data with encryption in transit, least-privilege and deny-by-default access controls, PII redaction in logs, and ongoing security review. No system is perfectly secure, but if a breach is likely to affect your rights we will notify you and the relevant authorities without undue delay, as required by law. Report a vulnerability via security.txt or security@zestli.ai.
15. Contact & changes
Questions or requests: privacy@zestli.ai (general: hello@zestli.ai). The controller is Zestli, Inc. (Delaware, United States). We post material changes here with a new effective date and, where appropriate, tell you directly. This policy was last updated on 4 June 2026.