Privacy policy
How we process personal data under GDPR Regulation (EU) 2016/679 and Act No. 110/2019 Coll.
Effective from 28 August 2026 · version 2.6
1. Data controller
The data controller is the operator of the Vistario portal. For all enquiries, requests to exercise rights, or complaints, contact the controller electronically:
- Controller
- Ben Barkai, sole trader
- Business ID (IČO)
- 22073264
- Registered address
- V kapslovně 2770/5, 130 00 Prague 3 – Žižkov, Czech Republic
- Data-protection e-mail
- support@vistario.eu
2. Personal data we process
Depending on how you use the portal, we process the following categories of data:
- Registration data: e-mail address, password hash, preferred language, registration date, and the version and server timestamp of the minimum-age confirmation. To evidence formation of the contract, we also retain the account ID, server timestamp, language and acceptance channel, the exact version and cryptographic digest of the Terms and Privacy Policy, and the exact wording of the confirmation control; we do not store a raw IP address or user-agent for this purpose. If the user voluntarily chooses marketing e-mails, we also store a unique choice ID, its time, language, channel, the version of the displayed notice, and the time it was confirmed by e-mail verification. We do not request or store a date of birth.
- Profile and listing data: name/company, business ID (advertisers), phone number (optional), listing content including photos.
- Transaction and billing data: payment records and limited internal technical identifiers for an event, payment, session or invoice, together with amount, currency, time, status and fee. We do not store card numbers, names or e-mail addresses from payment webhooks; Stripe handles card data. We also process a billing address where needed for an invoice.
- Operational and technical data: IP address in network, access, and security logs, browser type, session cookie, login records, and sanitised error records. Moderation audits store the actor ID and decision, not a raw IP; an anti-abuse identity may be stored as a one-way HMAC/pseudonymous digest.
- Analytics and potential advertising data (with consent): page and defined conversion events, permitted UTM parameters and gclid/fbclid click identifiers, and limited browser or device data. Google Analytics 4 is consent-gated; Meta Pixel is currently unconfigured and inactive. We do not send form text, contact data, account/admin URLs, or URL query strings in events.
- Communications and support: the content of enquiries, messages, reports, reviews, and support requests, contact data selected by the user, attachments, handling status, and the necessary audit trail.
- Voluntary advertiser verification: only where the advertiser chooses to upload evidence, we process the encrypted evidence, metadata, decision status, and access audit. The evidence is not public, no biometric recognition is used, and verification is not a condition of ordinary core features.
- Search, maps, and first-party statistics: search query, language, public listing data, approximate location, sanitised campaign source, and a one-way HMAC visitor bucket. We do not store the raw AI query in the Vistario database.
3. Legal basis for processing
We always process data on the basis of one of the legal grounds below:
- Contract performance (Art. 6(1)(b) GDPR)
- Operating accounts, forming and recording the contract including the user's acceptance of the Terms and confirmation of the contractual age threshold, displaying listings, processing an ordered paid service, and sending transactional e-mails (e-mail verification, password reset, registration or payment confirmation).
- Legitimate interest (Art. 6(1)(f) GDPR)
- Portal security, limited first-party statistics without a cross-site profile, technical monitoring and reconciliation of payment events, fraud and abuse prevention, moderation, the necessary audit of legal-document acceptance, enforcement of Terms, and defence of legal claims.
- Legal obligation (Art. 6(1)(c) GDPR)
- Archiving accounting documents (Act No. 563/1991 Coll.) and fulfilling other statutory obligations.
- Consent (Art. 6(1)(a) GDPR)
- Google Analytics, any future Meta Pixel, campaign attribution in browser storage, marketing e-mail campaigns, and the voluntary upload of verification evidence – only after an explicit choice, withdrawable at any time. The sign-up marketing choice is optional, unticked by default, and becomes active only after the e-mail address is verified. A necessary audit trail and defence of legal claims may continue for a limited period on another legal basis after withdrawal.
4. Cookies and analytics
The portal uses technical cookies required for operation. Google Analytics 4 loads only after explicit analytics consent and never on account/admin or unsafe URLs. Meta Pixel is currently unconfigured and inactive; any future activation will require advertising consent and an update to this Policy. Withdrawal clears the analytics runtime, related first-party cookies, and local campaign attribution. Details are in the Cookies section.
5. Processors and recipients
Depending on the feature selected, we use the providers and recipients below. Where a provider acts as a processor, processing is governed by its contractual terms and an agreement under Art. 28 GDPR; the exact role may depend on the service:
- Hetzner
- Server hosting, databases, encrypted backups, and private object storage in the EU.
- Cloudflare
- CDN, DNS, TLS, and attack protection; it processes mainly the network metadata needed for delivery and security.
- Resend
- Transactional e-mail (verification, password reset, notifications) and marketing e-mails only to recipients with active documented consent. Resend handles delivery, unsubscribe, and delivery events; data is not shared for the provider's own marketing.
- Sentry
- Sentry for sanitised server error diagnostics. Browser Sentry currently has no production DSN, and any future startup is additionally tied to analytics consent.
- OpenAI
- OpenAI for user-initiated AI search: the query, language, and public listing catalogue. We do not intentionally send the user's identity or contact data.
- MapTiler / Geoapify
- MapTiler for map tiles and geocoding, and Geoapify for server-side POI/routing using approximate public coordinates. MapTiler may receive the visitor's IP when the map loads directly.
- Google Analytics
- Google Analytics 4 for portal traffic and defined conversions only after analytics consent; Google Signals and advertising personalisation are disabled.
- Meta Pixel
- Meta Pixel is currently unconfigured and inactive. Any future measurement will start only after advertising consent, without contact data or free-text fields, and after this Policy is updated.
- Stripe
- Advertiser payment processing through Stripe and limited internal records of technical payment events in a private dashboard hosted on EU servers. Neither the portal nor the dashboard stores raw webhook payloads or payment card numbers.
- Google / Apple OAuth
- Sign-in via Google or Apple. The portal receives only an e-mail address and identifier; the third party's password is never shared.
- Apple APNs / Expo
- Apple APNs or Expo for push messages only after the feature is active and the device grants permission. APNs delivery is currently disabled and Expo is not configured.
- YouTube
- YouTube is contacted only after external video content is selected and uses a privacy-enhanced embed; the provider may receive IP and ordinary browser metadata.
- Enquiry recipient
- An advertiser or another expressly selected recipient receives the content and contact data the user sends to that recipient. After transfer, the recipient acts as an independent controller for its own communication.
6. Transfers outside the EU/EEA
Data is primarily processed within the EU/EEA. Some providers, particularly Cloudflare, Resend, Sentry, OpenAI, Google, Apple, Stripe, YouTube, and Meta after any future activation, may involve organisations or subprocessors outside the EEA. Depending on the specific organisation and service, we use a valid adequacy decision including the DPF only for a currently certified participant, Standard Contractual Clauses (SCC), or another applicable safeguard. Users may request information about the specific safeguard from the controller.
7. Retention periods
Personal data is retained only for as long as necessary for the purpose for which it was collected:
- Active account: for the duration of the contractual relationship.
- After account deletion: operational logs up to 90 days; listing content up to 30 days.
- Technical payment-webhook identifiers and deduplication keys: 24 months; related WP-10 operational logs: 30 days. After automatic deletion, a record may remain for no more than 30 additional days in an encrypted backup. Accounting and billing documents are retained separately for 10 years under Act No. 563/1991 Coll.
- Google Analytics data: 14 months (configured in the GA4 console).
- Campaign attribution and conversion deduplication identifiers stored by Vistario in the browser: 90 days or until consent is withdrawn. A pending paid-conversion record stays in session storage for up to 48 hours while awaiting webhook confirmation. Meta is currently inactive; any upstream retention will be stated again before activation.
- Communications and support: conversation content typically 180 days and the technical record up to 365 days; contact/support content typically 180 days and the record 365 days. HMAC/IP anti-abuse identity is typically kept for 30 days.
- Voluntary verification: pending evidence up to 180 days; accepted evidence for 30 days after the decision; rejected, withdrawn, revoked, or approved early-deletion evidence without undue delay. Governance audit up to 730 days and a specific time-limited hold up to 365 days.
- First-party listing statistics: pseudonymous events for up to 400 days. We do not store the raw AI query in the database; the HMAC result cache normally stays for 6 hours, at most 24 hours, and the HMAC rate-limit record for 2 days.
- Evidence of acceptance of the Terms and acknowledgement of the Privacy Policy: for the lifetime of the account and for up to 10 years after termination where necessary to prove formation of the contract, demonstrate compliance, or establish, exercise, or defend legal claims. Marketing e-mail: an active contact is kept for the duration of consent. After unsubscribe, suppression and the necessary consent, withdrawal, delivery, and complaint audit are retained for up to 6 years to demonstrate compliance; the address remains blocked against unintended re-enrolment.
8. Rights of data subjects
As a data subject you have the following rights, exercisable by submitting a request to support@vistario.eu:
- Right of access – to find out whether your data is being processed and to obtain a copy.
- Right to rectification – to request correction of inaccurate or completion of incomplete data.
- Right to erasure (right to be forgotten) – under the conditions of Art. 17 GDPR.
- Right to restriction of processing – in the cases set out in Art. 18 GDPR.
- Right to data portability – to receive data in a machine-readable format.
- Right to object – in particular to processing based on legitimate interest.
- Right to withdraw consent at any time – without affecting the lawfulness of processing before withdrawal; marketing e-mail can be unsubscribed in one step using the link in every message.
- Right to lodge a complaint – with the Czech Data Protection Authority (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.cz.
9. Security
The portal employs transport encryption (TLS), password hashing (Argon2id), role-based least-privilege controls, MFA for sensitive admin access, encrypted backups on a separate EU server, and restore tests. Where a personal-data breach is likely to result in a risk to people's rights and freedoms, the controller will notify ÚOOÚ where feasible within 72 hours after becoming aware. Affected people will be informed without undue delay where a high risk is likely.
10. Automated processing and AI
The portal uses automated processing (AI filters, listing recommendations) as a user aid. This processing does not result in automated decisions within the meaning of Art. 22 GDPR that would have legal or similarly significant effects on users.
11. Contact and policy updates
For enquiries, rights requests, or complaints, write to support@vistario.eu. We will respond without undue delay and within one month. For a complex or multiple request, the period may be extended by a further two months; we will explain the extension and reason within the first month. This Policy may be updated; for changes that affect users' rights, we will provide at least 14 days' notice by e-mail or a prominent notice on the portal.