Privacy Policy
Last updated: June 3, 2026
1. Introduction
Krakow.com ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you visit krakow.com (the "Website"). By using our Website, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide through our forms:
- Contact/Travel Inquiry Forms: Name, email address, travel dates, group size, budget preferences, interests, and any message you include.
- Newsletter Signup: Email address and subscription source.
- Partnership Applications: Business name, contact email, business type, website, and message.
- AI Trip Builder: Name, email (optional), travel preferences, and generated itinerary data.
2.2 Information Collected Automatically
When you visit our Website, we automatically collect:
- Usage Data: Pages visited, time spent, referral source, and navigation patterns via Google Analytics (anonymized IP addresses).
- Device Data: Browser type, operating system, screen resolution, and language preferences.
- Cookies: Essential cookies for site functionality and analytics cookies for understanding usage patterns.
3. How We Use Your Information
We use collected information to:
- Respond to your travel inquiries with personalized recommendations.
- Send newsletter updates and travel tips (only if you subscribed).
- Generate personalized trip itineraries via our AI Trip Builder.
- Process partnership applications.
- Improve our Website content and user experience through analytics.
- Send administrative emails related to your inquiries.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Third-Party Services
We use the following third-party services that may process your data:
- Google Analytics (Google LLC): Website usage analytics with anonymized IP. Google Privacy Policy
- Vercel Inc.: Website hosting and serverless functions. Vercel Privacy Policy
- Neon Inc.: Database hosting (stores form submissions and newsletter subscriptions). Neon Privacy Policy
- Brevo (Sendinblue): Newsletter email management. Brevo Privacy Policy
- SendGrid (Twilio): Transactional email delivery. Twilio Privacy Policy
- Anthropic: AI-powered trip itinerary generation. Your travel preferences (not personal identifiers) are sent to generate itineraries. Anthropic Privacy Policy
5. Affiliate Links & Advertising
Our Website contains affiliate links to third-party booking services including Booking.com, GetYourGuide, and TheFork. When you click these links, the third-party site may place cookies on your device. We earn a commission if you make a booking, but no personal data is shared from our side. Each service has its own privacy policy governing data collected on their platforms.
6. Cookies
We use the following types of cookies:
- Essential Cookies: Required for basic site functionality (no opt-out available).
- Analytics Cookies (Google Analytics): Help us understand how visitors use our site. You can opt out by installing the Google Analytics Opt-out Browser Add-on or by disabling cookies in your browser settings.
7. Data Retention
- Contact form submissions: Retained for 24 months, then deleted.
- Newsletter subscriptions: Retained until you unsubscribe.
- Analytics data: Google Analytics data is retained for 14 months (default setting).
- AI-generated itineraries: Trip preferences are processed in real-time and not stored beyond the lead record.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Unsubscribe: Opt out of newsletter emails at any time via the unsubscribe link in each email.
- Data Portability: Request your data in a machine-readable format.
To exercise any of these rights, contact us at hello@krakow.com.
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including encrypted database connections (SSL/TLS), rate-limited API endpoints to prevent abuse, and honeypot fields to prevent spam submissions. However, no method of transmission over the Internet is 100% secure.
10. Children's Privacy
Our Website is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. International Data Transfers
Your data may be processed in the United States (where our hosting and service providers are based). By using our Website, you consent to the transfer of your data to countries outside your jurisdiction.
12. Changes to This Policy
We may update this privacy policy from time to time. The "last updated" date at the top reflects the most recent revision. Continued use of the Website after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions, requests, or complaints:
- Email: hello@krakow.com
- Website: krakow.com/contact