Last updated: August 5, 2026
Vamos A Venezuela (“VAV,” “we,” “us”) operates a tourism marketplace connecting travelers with accommodations, experiences, and travel agents across Venezuela. This policy describes how we collect, use, store, and protect your personal data when you use our website at vamosavenezuela.com and related services.
We have not yet published the registered legal entity that acts as data controller for this service, or its registered address. That is a gap, and we would rather name it than paper over it. Our Terms of Service choose Florida, United States law as the governing law for disputes about the service; that is a choice of law and not a statement of where we are established. Until the entity details are published here, every matter covered by this policy — including requests from the EU and the UK — reaches us at privacy@vamosavenezuela.com, which is the contact point for all data protection correspondence.
When you create an account, we collect your name, email address, phone number, preferred language, and nationality. Providers and travel agents additionally supply business details (business name, tax ID, social media handles, commission preferences).
When you make a booking, we collect guest name, email, phone, travel dates, party size, special requests, and payment method selection. Payment card details are processed directly by Stripe and never stored on our servers.
If you communicate with a provider via our WhatsApp integration, message content, phone number, and conversation metadata (timestamps, read status) are stored to facilitate the booking process and provide AI-assisted responses.
We use PostHog, a first-party product analytics tool, to understand how the platform is used. PostHog only runs after you actively accept analytics cookies in the consent banner shown on your first visit — if you decline or dismiss it without accepting, no PostHog analytics events are collected in your browser. When active, it collects page views, device type, browser, approximate location (country level), and interaction events. PostHog is configured to keep its identifier in your browser's localStorage rather than in a cookie, and there is no cross-site tracking or sharing with ad networks. We also use Vercel Analytics, which collects aggregated, privacy-preserving performance and traffic metrics and does not use cookies.
Separately from the analytics described above, our servers log technical data about requests to the platform: your IP address, your browser's user-agent string, the path requested, the response status, and timing. This is security and reliability logging — abuse detection, rate limiting, and debugging — and it happens on server requests whether or not you accept analytics cookies, because it is not analytics. Where a link carries a referral or affiliate code, we store a hashed form of your IP and user-agent alongside the click rather than the raw values.
If you join our pre-launch waitlist, we store your email address, the source of signup (e.g. which page or campaign referred you), and, if you choose to provide one, your Instagram handle. Joining the waitlist uses a double opt-in flow: we email you a confirmation link, and your signup is only counted as confirmed once you click it. That same email includes an unsubscribe link, which stops further waitlist communications and removes you from the public waitlist count. Confirmed subscribers can also receive a personal referral code to share with others; if someone signs up using your code, we record that referral link (which code referred which new signup) so we can recognize referrers — we do not disclose who referred whom to anyone other than internal team members administering the waitlist.
Our platform uses AI (powered by Anthropic Claude and Groq) to generate travel itineraries, assist with WhatsApp conversations, and provide recommendations. When you use these features, your inputs (travel preferences, messages) are sent to those providers for processing, under their standard API terms. We have not negotiated zero-retention terms with either of them, so we cannot tell you they retain nothing — what we can tell you is that we do not send them more than the feature needs, and we do not use your conversations to train anyone's model.
Messages sent to you over WhatsApp are not currently labelled as AI-generated. An AI marker exists on the provider's side of the inbox, but you do not see it, so treat any WhatsApp reply from a provider on this platform as possibly AI-assisted. We consider traveler-facing labelling a gap and intend to close it.
We do not sell your personal data to third parties. We do not share data with advertisers.
Your data is stored in Supabase (PostgreSQL) with row-level security policies that restrict access by role. All data is transmitted over HTTPS/TLS. Authentication uses secure, HttpOnly session cookies.
Third-party credentials that providers give us — principally WhatsApp API tokens — are being migrated into an encrypted vault, and that migration is not finished. Where it has not yet been applied, the token is held in the database with access restricted by row-level security but not separately encrypted. This affects provider accounts, not traveler accounts, and it is not a place we are content to leave things.
While we implement industry-standard security measures, no system is perfectly secure. If you discover a vulnerability, please contact us at security@vamosavenezuela.com.
?ref= parameter) or through a partner portal, we set a cookie recording which link you came from, so the referrer is credited if you later book. The referral cookie lasts 24 hours, extended to 30 days if you start a booking. It is set on arrival, before and independently of the consent banner, because it is attribution for a commercial relationship rather than analytics about you. It is not used for advertising, is not shared with ad networks, and it is not set on these legal pages at all.We do not use third-party advertising cookies or cross-site trackers.
We keep each category of data only as long as we need it for the purposes described in this policy, and for as long as we are required to keep it by law:
We are working toward publishing a concrete retention period for each category above, and we would rather state the standard we actually apply than a specific number we cannot yet show is enforced. If you want to know what we hold about you right now, ask us using the rights process in Section 9 and we will tell you.
You have the right to:
About deletion, specifically. A deletion request anonymizes your user profile. It does not yet reach the contact details attached to individual bookings you made — the name, email and phone you gave when booking are still held on those booking records, and removing them is something we currently do by hand. So: ask us to delete your account and we will action it, including the parts the automation does not yet cover, but we are not going to tell you it is all automatic when it is not. The self-serve deletion form lives in your account area, which is behind our pre-launch countdown until launch; in the meantime, and at any time after, email us and we will honor the request.
To exercise any of these rights, email privacy@vamosavenezuela.com and we will respond within 30 days.
Our infrastructure is hosted in the United States (Vercel, Supabase). If you access our services from outside the US, your data will be transferred to and processed in the US. Some of the processors listed in Section 5 receive data directly from your browser rather than through our servers — map tiles from Mapbox are the main example — which means your IP address reaches them wherever they operate, without passing through us first. Our service providers maintain appropriate safeguards for international transfers.
Our services are not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
We may update this privacy policy from time to time. We will notify you of material changes by email or a prominent notice on our platform. Your continued use of our services after changes take effect constitutes acceptance.
For privacy-related questions or requests: