goholi.si
Privacy Policy
Last updated 2026-10-08
This policy explains which personal data goholi.si processes, why, and what rights you have. We keep it short and specific: we only describe what the app actually does.
Who is responsible
goholi.si is operated by Useable Consulting, Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42037922. Useable Consulting is the controller under the General Data Protection Regulation (GDPR).
Questions or requests: hello@useable.consulting.
What we collect
We use Plausible Analytics, a cookieless, EU-hosted service, to count visits and see which pages and sources are popular. Plausible does not use cookies, does not build profiles and does not store IP addresses; it only gives us aggregated statistics. We do not use advertising trackers or tracking pixels, and we do not store IP addresses or page-view logs ourselves. IP addresses are held briefly in memory to limit abuse (rate limiting) and are not written to disk.
- Account details: name, email address, profile photo, and a password stored only as a secure hash. If you sign in with Google or Facebook we receive your name, email address, profile photo and an account identifier from that provider.
- Security settings: two-step verification settings and recovery codes, stored securely.
- Journeys: destinations, dates, budget, interests, travel party, accommodation preferences, notes, changes and the itineraries generated for you.
- Content you add: photos you upload, comments, community journeys you publish, and messages to Noor (our in-app assistant) or to hosts.
- People you invite: the email address of a co-traveller you invite to a journey, used only to send that invitation.
- Payments: plan, amount, status and a Stripe customer reference. Card details are entered on Stripe and never reach our servers.
- A visitor identifier cookie so journeys you create before signing in stay yours.
Why we use it and on which legal basis
- To provide the service you ask for: your account, journeys, collaboration and memberships (performance of a contract, Art. 6(1)(b) GDPR).
- To generate itineraries and assistant replies with Super Intelligence (SI): the details of your journey request or message are sent to our model provider (performance of a contract).
- To process payments and keep the accounting records the law requires (contract and legal obligation, Art. 6(1)(b) and (c)).
- To keep the service secure and prevent abuse (legitimate interest, Art. 6(1)(f)).
- To publish a journey to the community, only when you choose to (consent, Art. 6(1)(a)); you can unpublish at any time.
Who we share it with
We do not sell personal data. We use these service providers, each bound by a data processing agreement or their own terms as an independent controller:
- Hosting provider: runs our servers and stores the database.
- Perplexity AI, Inc. (USA): generates itineraries and assistant replies from the details you enter.
- Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA): payments and subscriptions.
- Google Ireland Ltd. and Meta Platforms Ireland Ltd.: only when you choose to sign in with Google or Facebook.
- Resend, Inc. (USA): sends account and invitation emails.
- Unsplash (USA): destination photos are loaded directly from Unsplash, which receives your IP address and browser details when an image loads.
- OpenStreetMap Foundation (UK): map tiles on community pages are loaded from OpenStreetMap, which receives your IP address when the map loads.
- Activity and place data (Viator, Geoapify, Open-Meteo) is requested by our server; these providers receive the destination you search for, not your identity.
Transfers outside the EU
Some providers are based in the United States. Where data leaves the European Economic Area, we rely on the EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.
How long we keep it
- Account and journeys: as long as your account exists. After you ask us to delete your account we remove it within 30 days.
- Sign-in sessions: 30 days. Visitor cookie: 1 year.
- Journeys created without an account: kept until you or we delete them; the visitor cookie that links them to your browser expires after 1 year.
- Payment and invoice records: 7 years, as required by Dutch tax law.
- Cached photo search results contain no personal data and expire after 7 days.
Your rights
You can ask to access, correct, delete or export your data, to restrict or object to processing, and to withdraw consent at any time. Email hello@useable.consulting; we answer within one month. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the authority in your own country.
Automated decisions and children
SI suggests itineraries, but it makes no decisions with legal or similarly significant effects about you.
goholi.si is not intended for children under 16. Do not create an account if you are younger.
Security and changes
Traffic is encrypted with HTTPS, passwords are hashed, and access to the database is restricted. If we change this policy we update the date at the top and, for material changes, tell signed-in users in the app.