solo, or not ✦

Privacy policy

Last updated:

Este texto solo está en inglés. Se rige por la ley española.

In short

  • Your trips are private by default. Only the people you invite to a trip see it.
  • Nobody else ever sees where you sleep, your email or your flights.
  • No ads, no tracking cookies, and your data is never sold or used to profile you.
  • You can delete your account from your profile whenever you like, and ask to see, fix or take away your data.

Who is responsible

The controller of your personal data is Marc Muñoz Gimeno, a private individual living in Spain who runs Solo, or not as a personal, non-commercial project. For anything about your data, write to hello@soloornot.com.

What data I keep

Only what you give me and what the site needs to work:

  • Your account: email, username and password (stored only as a secure hash, never readable). If you sign in with Google, Google shares your name, email, profile photo and account ID, and the sign-in tokens it issues.
  • Your profile: language and, if you add it, the country of your passport (to tell you which entry documents you need). I never ask for your passport number.
  • Your trips: destination and dates, stays (where and when you sleep, and the place if you pick one), the plan and ideas with their votes, flights (numbers, times and, if you add it, the booking reference) and who is on each, the entry documents you have ticked off, the trip's members and their roles, and invitation links.
  • Places: your reviews (rating, text and month of the visit), the places you save and your votes for destinations.
  • "Notify me" without an account: the email you leave on the home page, the destinations you picked and your language.
  • Emails sent to you: a record of each one (address, type, subject and whether it was delivered). Links in password emails are deleted once the email is sent.
  • Technical data: while you are signed in, your IP address and browser are stored with your session, for security. The server also logs requests (IP address, page and time) for a short time to keep it running and safe.

Why, and on what legal basis

  • To run your account and your trips, including sharing a trip with the people you invite: it's the service you sign up for (performance of a contract, art. 6.1.b GDPR).
  • To publish your reviews, with your username and profile photo, because you choose to post them (same basis). You can delete them whenever you like.
  • To email you when a destination opens, if you asked for it: your consent (art. 6.1.a). You can withdraw it at any time by writing to me.
  • To be found by other travellers, only if you turn it on for a trip: your consent. Even then they only see how many people are around, never who you are or where you sleep. Contact between travellers will always need both sides to accept.
  • To keep the site secure and working (sessions, logs, account emails such as password resets): my legitimate interest in protecting the service and its users (art. 6.1.f).

There are no ads, no profiling and no automated decisions about you. Your data is never sold or shared for marketing.

Who sees what

  • Anyone: your username, your profile photo (if it comes from Google) and the reviews you publish.
  • Members of a trip: the members' usernames and roles, the plan, the stays and the flights published to the trip. Your entry documents are only shown to you.
  • Everyone else: nothing. Your email, your trips and where you sleep are never public.
  • The site owner, as administrator, can access the database to run and fix the site, and only does so when needed.

Service providers

To run the site I rely on a few providers who process data on my behalf, only for these purposes and under data protection agreements:

  • Arsys (Spain): the server and database, and the domains.
  • Cloudflare (USA): DNS and the network every visit goes through (it sees your IP address), and the forwarding of emails sent to hello@soloornot.com.
  • Google (USA): "Continue with Google", only if you use it, and the mailbox where emails to hello@ arrive and are answered.
  • Resend (USA, data stored in the EU): sends the site's emails.

The owner also uses DeepSeek (AI drafts of place pages and social posts), GitHub (the project's task list) and Telegram (private alerts about the site), but no data about users is sent to them.

I will only hand data to authorities when the law requires it.

What your browser loads from others

To show the site, your browser fetches a few things straight from other services, which therefore see your IP address and browser (but set no cookies of ours):

  • destination photos from Unsplash (images.unsplash.com);
  • maps from OpenFreeMap (tiles.openfreemap.org);
  • airline logos on flights (pics.avs.io).

Links to other sites (Booking.com, Google Maps, a place's website…) only send you there if you click them. The site's emails load their font from Google Fonts when you open them.

Transfers outside the EU

Cloudflare, Google and Resend are US companies. Transfers to them rely on the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.

How long I keep it

  • Account, profile, trips, reviews and saved places: while your account exists. When it is deleted, everything linked to it goes too, along with your "Notify me" sign-ups. Trips you share with others stay with them without you: if you owned one, it passes to another member, and so do flights you added that others are on.
  • "Notify me" emails: until the destination opens and you've been told, or until you ask me to delete it.
  • Sessions: they expire after 7 days without use.
  • Email records and server logs: only as long as needed to handle deliveries, problems and abuse. When you delete your account, your address is erased from the email records straight away; the last email, telling you it's done, is erased as soon as it is sent.
  • Copies: a copy of the database is refreshed every night on the same server to develop the site, so deleted data disappears from it within a day.

To delete your account, go to your profile and choose Delete my account: it is deleted at once, and you get an email to confirm it. If you can't sign in, write to hello@soloornot.com from the address of your account and it will be deleted within 30 days at most.

Your rights

You can ask to access your data, correct it, delete it, restrict or object to its use, and get it in a portable format (portability). Where you gave consent, you can withdraw it at any time, without affecting what was done before.

Write to hello@soloornot.com, ideally from the email of your account; I may ask you to confirm it's you. You'll get an answer within a month.

If you think your data isn't being handled properly, you can complain to the Spanish Data Protection Agency (AEPD) or the authority in your country.

Age

Solo, or not is for people aged 18 or over (see the Terms). If I learn that an account belongs to someone younger, it will be deleted.

Security

Connections are encrypted (HTTPS), passwords are only stored as hashes, trips are private by default and only the owner has administrator access. No system is perfect: if something ever goes wrong with your data, you'll be told as the law requires.

Changes

If this policy changes, the date at the top will change too. Important changes will be announced on the site or by email before they apply.

Questions about this page? Write to hello@soloornot.com.