Zestli

Legal

Privacy Policy

Effective 4 June 2026 · Zestli, Inc.

What we collect, why, how long we keep it, who we share it with, and how to take it back. Written to be read, not survived.

This policy explains how Zestli, Inc. (“Zestli”, “we”, “us”, “our”) handles personal data when you use the website at zestli.ai, the traveler app at app.zestli.ai, our native mobile apps, and the services we offer through them (together, the “Service”). For the purposes of the EU and UK General Data Protection Regulation (“GDPR” / “UK GDPR”), Zestli, Inc. is the controller of your personal data.

Recommendations and itineraries on Zestli are AI-generated — see AI & automated processing and our Terms of Service. A short, plain-language summary of these commitments also appears in the colophon of our website.

1. Who we are & how to reach us

You can exercise any of the rights described below — including export and deletion — at Manage your data, or by emailing the privacy contact above.

2. Data we collect

We collect only what the Service needs. The categories are:

CategoryWhat it includes
Guest session identifierA pseudonymous token created when you start planning, before any account, so your work persists in that session.
Account & contactYour email when you request a magic link, join the waitlist, or contact us; and metadata that a second factor (MFA) is enrolled and verified — never the secret itself.
Trip & concierge dataItineraries, Trip-Board items, preferences, saved destinations, and the prompts and messages you give the concierge.
Booking & payment metadataBooking amount, currency, status, operator, and a payment-processor reference. Card details go directly to our payment processor — we never receive or store raw card numbers (see §7).
Voice & transcript dataIf you speak to the concierge — your speech and its transcript. We do not create voiceprints (see §6).
Device, log & usage dataIP address, device/browser type, app version, and interaction logs needed to run, secure, and debug the Service.
Optional analyticsAggregate, privacy-respecting usage measurement — only if you consent. No advertising or cross-site tracking (see Cookie Policy).
Approximate / precise locationOnly if you turn it on at the device level, to surface what is near you. You control this through your operating system and can switch it off at any time.

Some preferences you share (for example a dietary need or an accessibility requirement) could reveal special-category data under the GDPR. Where you choose to provide such details, you consent to our using them to tailor your trip; you can withdraw that consent and remove the data at any time.

3. How & why we use it

We use personal data to:

We do not sell your personal data, and we do not use it for third-party advertising.

PurposeLegal basis
Creating your account, running your trips and bookings, processing paymentPerformance of a contract (Art. 6(1)(b))
Authentication, security, fraud and abuse prevention, service reliabilityLegitimate interests (Art. 6(1)(f)) — you may object (see §10)
Optional analytics, optional functional cookies, optional marketing email, any special-category preferencesConsent (Art. 6(1)(a); Art. 9(2)(a) for special-category data) — you may withdraw at any time
Tax, accounting, and other legal obligationsLegal obligation (Art. 6(1)(c))

5. AI & automated processing

Destinations, itineraries, day stories, and recommendations are composed by AI from real places and live availability. When you use the concierge you are interacting with an AI system, not a human, and AI-composed content is labeled as such. Zestli does not fabricate prices, reviews, or availability, and AI does not author traveler reviews. Verify details before you rely on them; bookings are confirmed by the operator (see the Terms).

We use automated tools to personalize what we suggest to you. These suggestions do not produce legal or similarly significant effects, and you are always free to accept, ignore, or change them. You can ask us to explain or review a personalized output, or object to this personalization, by contacting privacy@zestli.ai.

6. Voice & transcripts

When you use voice features, we record and transcribe your speech to understand and fulfill your requests. We do not create voiceprints and do not use voice recordings to identify you biometrically. You can review, redact, and delete transcripts, and we ask for consent before recording where the law requires it. Voice data is never sold.

7. Processors & sharing

We share personal data only with service providers who process it on our behalf under contract, and only as needed. We share data by category of recipient:

We do not name every individual sub-processor here to keep this policy readable; a current list of the categories and the specific processors we use is available on request from privacy@zestli.ai.

8. International transfers

Zestli is based in the United States and uses service providers in the United States and other countries. When we transfer the personal data of EU, UK, or Swiss residents outside their home jurisdiction, we rely on legally recognized transfer mechanisms — including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and the Swiss addendum to those clauses — together with supplementary safeguards where required. Where a recipient is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), we may also rely on that certification. You may request a copy of the relevant safeguards from privacy@zestli.ai.

9. Retention

We keep personal data only as long as we need it for the purposes above:

DataRetention
Guest-session dataExpires automatically after the session / a short inactivity window
Account, trip, preference, transcript dataWhile your account is active, and a reasonable period afterward, then deleted on request or by schedule
Booking & payment recordsAs long as required for tax, accounting, and dispute resolution (typically several years), even after account deletion
Security & abuse-prevention logsA limited period needed to keep the Service safe

You can erase your data at Manage your data; what is retained for legal reasons is explained there.

10. Your rights

Subject to your local law, you have the right to access your data, rectify it, erase it, restrict or object to processing, receive it in a portable format (portability), and withdraw consent at any time (without affecting processing already carried out). Exercise these at /data or via privacy@zestli.ai — we verify identity with a magic link, and additionally your second factor (MFA) for export or deletion. We respond within the time the law allows (generally one month under the GDPR; within 45 days under US state laws, extendable as permitted), and we will not discriminate against you for exercising a right.

If you are in the EU, UK, or Switzerland and believe we have mishandled your data, you may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to resolve it first.

11. US state privacy rights

If you are a resident of a US state with a comprehensive privacy law (including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others), you have the rights to know/access, correct, delete, and obtain a portable copy of your personal information, to opt out of the sale of personal information, targeted advertising, and profiling with legal or similarly significant effects, and to appeal a denied request. Exercise them at /data or privacy@zestli.ai; you may use an authorized agent.

We do not sell or share your personal information (including for cross-context behavioral advertising), and we do not use sensitive personal information beyond what is needed to provide the Service you asked for. Because of this, there is nothing to opt out of — but we still honor opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out where applicable. California residents can review these choices through the Cookie settings control and Manage your data (a “Your Privacy Choices” mechanism). The categories of personal information we collect, our purposes, and our retention are described in sections 2–9 above; we do not knowingly process the personal information of consumers under 16 for sale, sharing, or targeted advertising.

12. Other regions

If you are in Canada (including Québec), Brazil (LGPD), Australia, or Switzerland, you have rights to access, correction, deletion, and information about how your data is shared, broadly equivalent to those above, and you may contact your national privacy regulator. Direct any request to privacy@zestli.ai.

13. Children

The Service is intended for users aged 18 and over. We do not direct the Service to children and do not knowingly collect their personal data. If we learn we have collected data from a child, we will delete it — contact privacy@zestli.ai.

14. Security & breach

We protect data with encryption in transit, least-privilege and deny-by-default access controls, PII redaction in logs, and ongoing security review. No system is perfectly secure, but if a breach is likely to affect your rights we will notify you and the relevant authorities without undue delay, as required by law. Report a vulnerability via security.txt or security@zestli.ai.

15. Contact & changes

Questions or requests: privacy@zestli.ai (general: hello@zestli.ai). The controller is Zestli, Inc. (Delaware, United States). We post material changes here with a new effective date and, where appropriate, tell you directly. This policy was last updated on 4 June 2026.