Vestigia
MapExploreTripsMemoriesItineraryWikiGamesFriendsAchievements
Vestigia

Discover cultural landmarks, plan your adventures, and connect with travelers worldwide.

New: explore page, editorials and leaderboards!

Features

  • Map
  • Editorials
  • Games
  • Trips
  • Memories
  • Itinerary

Company

  • About
  • Contact
  • Documentation

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Vestigia. All rights reserved.

vestigia@yahoo.com
Vestigia Logo

Privacy Policy

Learn how we collect, safeguard, and respect your personal exploration details.

Last Updated: May 24, 2026

Table of Contents

Plain English summaries are provided on the right for quick reference.

1. Information We Collect

We collect personal information to provide and improve our Services. This includes:

  • Account Credentials: Username, email address, and encrypted passwords used for authentication.
  • Profile Information: Optional information you provide, such as your biography, location, and profile photograph.
  • User Content: Landmark reviews, itinerary itineraries, photographs, messages shared with friends, and trivia responses.
  • Device & Usage Information: IP addresses, browser types, operating systems, and platform interaction histories.
  • Location Data: With your permission, we collect precise or approximate geographic coordinates to power mapping features. You can disable this in your device settings.

In Plain English

We collect information you explicitly provide (like account info, travel reviews, and photos) and technical usage data (like your IP address and optional location data).

2. How We Use Your Information

We process your personal data for the following operational and legal purposes:

  • To provide, personalize, and improve our core Services.
  • To run interactive maps, trivia challenges, and custom itinerary suggestions.
  • To manage your account, authenticate sessions, and protect against security breaches.
  • To facilitate communications between you and other community members.
  • To communicate updates, security alerts, and support messages.
  • To comply with regulatory guidelines and legal demands.

In Plain English

We use your data to power the interactive map, authenticate your login, suggest routes, and make sure the application stays secure.

3. Sharing of Information

We do not sell, rent, or trade your personal data. We only share information with:

  • Infrastructure Providers: Supabase processes database storage, assets, and authentication (see Supabase Privacy Policy). Netlify processes web hosting and serverless routines (see Netlify Privacy Policy).
  • Map APIs: OpenStreetMap and MapLibre provide map tiling services. No personal details are transferred.
  • Wiki Partners: Wikipedia/Wikimedia are referenced for historical context. No personal details are transferred.
  • Legal Compulsion: If required to respond to subpoenas, court orders, or active law enforcement investigations.

In Plain English

We never sell your data. We share it only with essential service providers like database managers (Supabase) and hosting networks (Netlify), or if legally required.

4. Cookies & Local Storage

Vestigia uses strictly necessary cookies and local storage tokens. These are mandatory for the application to function correctly.

Cookie NamePurposeProviderLifespan
sb-*-auth-tokenMaintains signed-in user session credentials.SupabaseSession / 1 Week
sb-*-auth-token-code-verifierSecures PKCE OAuth registration flow.SupabaseSession
vestigia-cookie-noticeRemembers if you dismissed the cookie notice banner.Vestigia1 Year

In Plain English

We set strictly necessary cookies to keep you logged in. No advertising, behavior profiling, or tracking cookies are used.

5. Data Retention & Erasure

We retain your personal data for as long as your account remains active or as required to fulfill the purposes highlighted in this policy.

You can delete your account at any time. When deleted, all profile details, saved trips, and location data are permanently purged from active databases, subject to standard backup recovery retention periods.

In Plain English

Your data stays as long as you keep your account. If you choose to delete your account, your data is erased from our servers.

6. Your Rights (GDPR & CCPA/CPRA)

Depending on your location (such as the European Union under GDPR or California under CCPA/CPRA), you possess specific statutory rights regarding your personal information:

For EEA/UK Residents (GDPR):

  • Right of Access & Portability: Request copies of your data in structured formats.
  • Right to Rectification & Erasure: Edit incorrect data or request permanent deletion (right to be forgotten).
  • Right to Object & Restrict Processing: Limit how we compute your information.

For California Residents (CCPA/CPRA):

  • Right to Know: Request disclosures of what personal data we collect and share.
  • Right to Delete: Request deletion of your collected details.
  • Right to Correct: Rectify inaccurate personal information.
  • Right to Non-Discrimination: Equal service quality even if you exercise privacy rights.

To exercise any of these rights, please contact us at vestigia@yahoo.com.

In Plain English

Users in the EU and California have rights to access, correct, delete, or export their personal data. We respect these globally.

7. Children's Privacy

Vestigia is not intended for children under 13 years of age. We do not knowingly collect personal data from anyone under 13.

If we become aware that we have collected information from a child under 13 without verified parental consent, we will take immediate steps to delete those records.

In Plain English

We don't knowingly collect data from children under 13. Please contact us if you believe a minor has shared info with us.

8. Security Measures

We use robust technical and administrative security measures (including HTTPS transit encryption, database-level encryption at rest, and secure role-level authentication policies) to protect your personal details.

While we take all reasonable precautions, no internet-based service can guarantee complete protection against all unauthorized breaches.

In Plain English

We use secure HTTPS connections and database encryption via Supabase to shield your data. No system is completely unhackable, but we follow industry standards.

9. Changes to This Policy

We may update this Privacy Policy periodically to reflect shifts in technology, regulation, or services.

We will revise the "Effective Date" at the top and distribute notifications if modifications are significant.

In Plain English

We will update this page for major revisions. Check the date at the top to see when it was last changed.

10. Contact Us

If you have questions, complaints, or request queries concerning your privacy on Vestigia, please contact our team:

Email: vestigia@yahoo.com

In Plain English

Reach out to vestigia@yahoo.com for privacy concerns or details requests.