Last updated: June 25, 2026
Operated by VC Innovations Group LLC d/b/a WhereTo Trips
Effective Date: June 25, 2026 | Last Updated: June 25, 2026
VC Innovations Group LLC, a Texas limited liability company doing business as WhereTo Trips ("WhereTo Trips," "Company," "we," "us," or "our"), provides the WhereTo Trips travel application (the "App") and the website at wheretotrips.com (the "Site," and together with the App, the "Services"). References in this Privacy Statement to "WhereTo Trips" mean VC Innovations Group LLC, the legal entity that operates the Services. This Privacy Statement explains how we collect, use, disclose, and protect personal information when you access or use the App or the Site, and describes the choices and rights available to you. References to the App include the Site except where the context requires otherwise, such as descriptions of booking and payment, which take place only in the App.
The Services are offered only in the United States, to individuals who are at least 18 years of age. The App is distributed only through the United States storefronts of the Apple App Store and Google Play, which are determined by the billing address associated with your store account, and reservations made through the App must originate in the United States. United States residency is not a requirement. This Privacy Statement is intended to satisfy applicable disclosure requirements under U.S. federal and state law, including comprehensive state privacy laws such as the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), and similar laws in other states. We do not market or offer the Services outside the United States, and this Privacy Statement does not address obligations under the laws of other jurisdictions, such as the EU General Data Protection Regulation or the UK GDPR. If we expand the Services to other regions in the future, we will update this Privacy Statement accordingly before doing so.
By creating an account, accessing, or using the App or the Site, you acknowledge that you have read and understood this Privacy Statement. If you do not agree with our practices, please do not use the Services.
This Privacy Statement applies to the App and to the Site. The Services are intended for individuals who are at least 18 years of age. The App is distributed only through the United States storefronts of the Apple App Store and Google Play, which are determined by the billing address associated with your store account, and reservations made through the App must originate in the United States, meaning that the first segment of your itinerary departs from a location in the United States. International destinations are supported, and traveling outside the United States does not affect your account or your ability to use the Services. United States residency is not required. By using the Services, you represent that you are at least 18 years old. We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected personal information from a user under 18, we will take reasonable steps to delete that information promptly. If you believe this has occurred, please contact us using the information in Section 13.
We collect the categories of personal information described below, depending on how you use the App.
| Category | Examples | Source | Purpose | Retention |
|---|---|---|---|---|
| Account credentials | Username and password (stored in hashed/encrypted form) | You, directly | Authentication, account security | Life of your account; deleted within 30 days of account closure |
| Third-party login data | Name, email address, and profile ID from Google or Facebook, if you choose that sign-in method | Google / Meta (Facebook), with your authorization | Authentication, account creation | Life of your account; deleted within 30 days of account closure |
| Contact information | Email address, name | You, directly | Account management, booking confirmations, customer support | Life of your account, then only as needed for completed bookings and legal requirements |
| Travel booking details | Traveler names, contact details, booking dates, itinerary preferences and special requests. For flights: full name as shown on government-issued ID, date of birth and gender. For international itineraries: passport number, nationality and expiration date | You, directly | Completing and managing travel reservations | 7 years after travel is completed, for tax, accounting and dispute-resolution requirements |
| Payment information | None. Card details are entered into our booking partner's secure payment interface. WhereTo receives only confirmation that payment was completed | Not collected by WhereTo | Not applicable; payment is collected by our booking partner as merchant of record | Not retained by WhereTo |
| Approximate location | IP-based or coarse location (e.g., city or region level) | Your device, automatically | Localizing search results, fraud prevention, account security | 13 months |
| Device and usage data | Device type, operating system, app version, crash logs, interaction data | Your device, automatically | App functionality, diagnostics, improving the App | 24 months |
You may create a WhereTo account in one of three ways:
Your use of Google or Facebook to sign in is also governed by that provider's own privacy policy and terms, which we encourage you to review.
If you complete a travel reservation through the App, payment is collected by our booking partner, Nuitée (which operates the liteAPI platform), acting as the merchant of record for your booking. Card details are entered into a secure, PCI-DSS-compliant payment interface provided by Nuitée and its payment processor. WhereTo Trips is not a party to the card transaction.
WhereTo does not collect, receive, transmit through its systems, or store your card number, card verification value (CVV), cardholder name, billing address, or any other payment card data at any time. The only payment information we receive is confirmation that payment for your booking was completed. Our booking partner's and its payment processor's handling of your payment data is governed by their own privacy policies.
We collect approximate location information, such as the location associated with your device's IP address, to localize search results, to help detect and prevent fraud, and to support the security of your account. We do not collect precise GPS location data.
Like most apps, we automatically collect certain technical information when you use the App, including device identifiers, operating system and version, app version, language settings, log and diagnostic data, and general usage and interaction data (such as features used and pages viewed). This information helps us operate, secure, troubleshoot, and improve the App.
When you search for or complete a booking, we collect the information needed to make and service that reservation. For hotel bookings, this typically includes traveler names, contact details, stay dates, and any preferences or special requests you provide. For flight bookings, airlines and the Transportation Security Administration require additional identifying information, including each traveler's full name as it appears on their government-issued identification, date of birth, and gender. For international itineraries, this also includes passport number, nationality, and passport expiration date. We may also collect a Known Traveler Number or Redress Number if you choose to provide one.
Some of this information is sensitive personal information under California law. Your account log-in credentials in combination with your password, your passport number, and your nationality all fall into that category, and special requests such as dietary or accessibility needs may reveal information about your health or beliefs. We collect and use sensitive personal information only as necessary to provide the App and the travel services you request, and we do not use or disclose it for any other purpose.
You may provide information about other travelers, such as family members or colleagues traveling with you. When you do, you represent that you have the authority to provide their information to us. We handle information about other travelers in the same way we handle information about you.
We use the personal information described above for the following purposes:
WhereTo Trips does not sell personal information, and we do not share your personal information with third parties for their own independent marketing purposes. We disclose personal information only in the limited circumstances described below, and only to the extent necessary for the stated purpose.
| Recipient | What We Share | Why |
|---|---|---|
| Nuitée (booking platform and agent of record) and travel booking suppliers | Traveler name, contact information, and itinerary details necessary to fulfill your reservation, including the traveler identifiers airlines require for flight bookings | To complete and service the travel booking you requested |
| Nuitée and its payment processor | Payment details you enter at checkout, collected and processed by Nuitée as merchant of record through its payment processor | To process payment for your booking; WhereTo is not a party to the card transaction and receives only confirmation of payment |
| Google / Meta (Facebook) | Authentication tokens exchanged if you choose to sign in with these services | To verify your identity and let you log in without a separate password |
| Service providers (hosting, analytics, customer support tools) | Limited data necessary for the provider to perform its function | To operate, secure, and improve the App, under contractual confidentiality and use restrictions |
| Legal and safety authorities | Information as required to comply with law, enforce our terms, or protect rights and safety | Legal compliance and protection of users, the public, and the Company |
| Government agencies (TSA, U.S. Customs and Border Protection) | Passenger identifying information required for aviation security and border screening, including full name, date of birth, gender, and for international travel passport and nationality details | To comply with the TSA Secure Flight program and Advance Passenger Information System requirements |
We may also disclose information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of WhereTo Trips, our users, or the public, or in connection with a merger, acquisition, financing, or sale of company assets, subject to standard confidentiality protections. In addition, when you book air travel, passenger identifying information is transmitted to the Transportation Security Administration under the Secure Flight program, and for international itineraries to U.S. Customs and Border Protection under Advance Passenger Information System requirements. These transmissions are required by law and occur on every applicable booking.
We store the personal information associated with your WhereTo account on infrastructure located in the United States. Completing a reservation, however, requires that we transmit your booking information to our booking partner, Nuitée, which is established in Ireland and processes and supports bookings from facilities both inside and outside the United States. Your booking information is therefore processed outside the United States. Wherever personal information is processed outside the United States, we require by contract that the recipient maintain safeguards appropriate to protect it.
We retain personal information for as long as your account remains active or as needed to provide the App, fulfill the purposes described in this Privacy Statement, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we securely delete, anonymize, or otherwise dispose of it in accordance with our written data retention schedule. The retention period for each category of personal information is set out in the table in Section 2. Where a fixed period is not practical, we decide how long to keep information based on how long your account remains active, how long the information is needed to service or document a completed booking, the period during which a dispute or chargeback may arise, and any tax, accounting, or other legal retention requirement that applies.
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including encryption of stored passwords, encrypted transmission of data, and use of a PCI-DSS-compliant payment processor for handling payment card data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
As a U.S. resident, you may have certain rights regarding your personal information under applicable federal and state law, which may include the right to:
To exercise any of these rights, please contact us using the information in Section 13. We will respond to verifiable requests within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf. We will ask the agent for written authorization signed by you, and we may ask you to verify your identity with us directly before we act. If we decline to act on your request, we will tell you why, and you may appeal by replying to our response or by writing to privacy@wheretotrips.com with "Appeal" in the subject line. We will respond to an appeal within 45 days and explain the reasons for our decision. You may also lodge a complaint with your state attorney general or other applicable regulator at any time, including if an appeal is denied.
Residents of certain U.S. states (including California, Colorado, Connecticut, Virginia, Utah, and others with comprehensive privacy laws) may have additional rights, including the right to know, delete, correct, and opt out of certain processing, including the use of certain cookie-based or cross-context advertising technologies, to the extent applicable. As stated above, WhereTo Trips does not sell or share personal information. We collect certain sensitive personal information, described in Section 2.5, and we use it only as necessary to provide the App and the travel services you request. Because our use is limited to those purposes, we are not required to offer a separate right to limit the use of sensitive personal information.
You have the right to access, correct, and delete your personal data at any time. To request access to, correction of, or deletion of your personal information, or to request deletion of your account and all associated data, you may email us at privacy@wheretotrips.com.
When you request account deletion, we will deactivate your account and delete the personal information associated with it, except where we are required or permitted to retain certain information, such as:
We will verify your identity before processing a deletion request (typically by confirming the request comes from the email address or account associated with your WhereTo account) and will complete verified requests within the timeframe required by applicable law, generally within 45 days, which may be extended where applicable law permits. We will let you know if any limited information must be retained and why.
The App and the Site may use cookies, SDKs, and similar technologies to support authentication, remember preferences, analyze usage, and maintain security. Where required by applicable law, we will provide additional notice and obtain consent for non-essential technologies.
The App integrates with third-party services, including Google, Facebook (Meta), Stripe, and our travel booking suppliers. These third parties are responsible for their own privacy practices, and we encourage you to review their respective privacy policies. This Privacy Statement does not apply to the practices of third parties that we do not own or control.
The App is not directed to, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal information from children, and we do not sell or share the personal information of consumers under 16 years of age. See Section 1 for additional information.
We may update this Privacy Statement from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated version in the App with a revised "Last Updated" date, and, where required by law, will provide additional notice or obtain consent before making material changes. Your continued use of the App after an update constitutes acceptance of the revised Privacy Statement.
If you have questions, concerns, or requests regarding this Privacy Statement or our data practices, please contact us at:
VC Innovations Group LLC d/b/a WhereTo Trips
Attn: Privacy Department
Email: privacy@wheretotrips.com
Account or Data Deletion Requests: privacy@wheretotrips.com
Mailing Address: [insert company mailing address]