1. Introduction
At AdventureLab ("we", "us", adventurelab.ai), we are committed to protecting your privacy. This Privacy Policy explains what information is processed when you use our website — searching for flights, reading our guides and blog, or contacting us — and what rights you have over it.
AdventureLab is operated by an individual based in Bulgaria, who acts as the data controller for the processing described in this policy. You can reach the controller at support@adventurelab.ai.
The short version: we run no user accounts, we keep no database of visitors, and we collect only what is needed to answer your messages, to run the flight search you ask for, and — if you choose to subscribe — to send you our newsletter.
2. Information We Collect
Contact form. When you write to us we receive the name, email address, subject, and message you provide. This is delivered to our support mailbox as an email; it is not stored in any database.
Newsletter. If you subscribe to our newsletter we process the email address you enter and your language preference (so we can write to you in English or Bulgarian). Subscription uses double opt-in: you are only added to the list after you click the confirmation link we email you. The subscriber list is stored with our email service provider, Brevo (see Section 5).
Flight searches. When you search for flights we process the route, dates, passenger counts, cabin class, and currency you enter, solely to fetch results for you. Searches are not linked to your identity and we do not build any history of what you search.
Technical data. Our servers briefly process your IP address to protect the service from abuse (rate limiting). These counters live in server memory for at most a few minutes and are never written to permanent storage. Our hosting provider may additionally keep standard, short-lived server logs.
Error reports. When something on the site fails, an automatic error report is sent to our error-monitoring provider, Sentry (see Section 5), so we can find and fix the fault. These reports describe the technical failure — the error message, which page or function it happened in, and the browser or server involved. They are deliberately configured not to include the contents of what you submitted (for example the text of a contact-form message) or to identify you as a user.
Audience measurement. We use Vercel Web Analytics to see which pages are visited and how the site is used overall. It is cookieless: it sets no cookies and stores nothing on your device. It records the page visited, the referring page, and coarse technical details such as browser, device type, and country, which are aggregated into visitor counts. It does not build a profile of you and does not follow you to other websites.
Preferences. Your chosen language, currency, and light/dark theme are stored in your own browser (a locale cookie and browser localStorage). They never leave your device except to display the site in your preferred form.
We do not collect sensitive personal data, we do not use advertising trackers, and we do not profile visitors. The one analytics tool we use is the cookieless, aggregate measurement described above.
3. How We Use Your Information
- Customer support — to respond to inquiries sent through the contact form or by email.
- Flight search — to retrieve the results you requested from our flight data provider.
- Newsletter — to send flight deals, travel inspiration, and platform updates to confirmed subscribers.
- Service protection — to rate-limit abusive traffic and keep the site available.
- Error monitoring — to detect faults on the site and fix them.
- Audience measurement — to understand which pages are useful, in aggregate.
We do not use your information for automated decision-making or profiling. We send marketing email (our newsletter) only to people who have confirmed their subscription via the double-opt-in link, and every issue contains an unsubscribe link.
4. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process contact-form data on the basis of your consent (you choose to write to us), newsletter data on the basis of your consent (given explicitly through the double-opt-in confirmation), and technical data such as IP addresses on the basis of our legitimate interest in keeping the service secure and available. You may withdraw consent at any time — for the newsletter, the unsubscribe link in any issue does this instantly; for anything else, contact us.
5. Data Sharing and Disclosure
We do not sell, rent, or share your personal data for marketing purposes. Data is shared only with the service providers required to operate the site:
- Flight data provider (SerpAPI / Google Flights). Your search parameters (route, dates, passengers, cabin class, currency) are sent to retrieve results. Your name or contact details are never included.
- Email delivery (GoDaddy SMTP). Contact-form messages are transmitted as email to our support mailbox.
- Newsletter (Brevo). If you subscribe, your email address and language preference are stored with Brevo, a French email service provider, on servers in the European Union, and used solely to deliver our newsletter. Brevo does not use your address for its own purposes.
- Bot protection (Cloudflare Turnstile). When you submit the newsletter form, Cloudflare briefly processes technical signals from your browser (including your IP address) to distinguish people from automated abuse. Turnstile is Cloudflare's privacy-focused CAPTCHA alternative: it does not use advertising cookies and does not track you across websites.
- Audience measurement (Vercel Web Analytics). Page views and the coarse technical details above are processed by Vercel to produce aggregate statistics for us. No cookies are set and no cross-site tracking takes place; we see visitor numbers, not individuals.
- Error monitoring (Sentry). When an error occurs, a technical report is sent to Sentry, on servers in the European Union (Germany), so we can diagnose it. We have configured Sentry not to collect submitted content or user-identifying information; the reports describe the fault, not the person who encountered it.
- Hosting. Our hosting provider processes requests to serve the site, which includes your IP address, as any web host does.
Each provider processes this data only to deliver its service and in compliance with data protection law.
6. International Data Transfers
Our service providers (hosting and flight data) are international companies, so technical data such as your IP address and flight-search parameters may be processed outside the European Economic Area, including in the United States. Where that happens, transfers rely on the safeguards provided by the GDPR — an adequacy decision (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses. Two exceptions stay within the European Economic Area: newsletter data is stored by Brevo within the European Union, and error reports are processed in Sentry's European Union (Germany) region. Neither is transferred outside the EEA.
7. How We Store Your Data
We operate without a user database of our own (the newsletter list lives in our Brevo account, not in our systems):
- Contact messages exist as emails in our support mailbox. We retain them for as long as needed to handle your inquiry and for a reasonable period afterwards, then delete them.
- Newsletter subscriptions (your email address and language) are kept with Brevo until you unsubscribe or ask us to delete them. Unconfirmed sign-ups are never added to the list at all — the confirmation link simply expires after 48 hours.
- Flight search results are held in a short-lived server cache (up to a few hours) so that repeated identical searches respond faster. Cached results contain flight data only — no personal identifiers.
- Rate-limit counters (IP-based) live in server memory for at most a few minutes.
- Error reports are retained in our Sentry account under that service's standard retention period and are deleted automatically when it expires.
- Your preferences (language, currency, theme) stay in your own browser and can be cleared by you at any time via your browser settings.
8. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Withdraw your consent at any time
- Object to or restrict certain types of processing
- Lodge a complaint with your local supervisory authority — in Bulgaria: the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, kzld@cpdp.bg, cpdp.bg
To exercise any of these rights, contact us at support@adventurelab.ai. For the newsletter specifically, the fastest route is the unsubscribe link at the bottom of every issue — it takes effect immediately, no email to us needed. For everything else, given how little we store, most requests amount to deleting the emails you have sent us — which we will confirm to you.
9. Cookies and Similar Technologies
We use only strictly necessary, functional storage:
- a locale cookie remembering your language choice (English/Bulgarian)
- browser localStorage entries for your currency and theme preferences
We set no analytics, advertising, or tracking cookies. Our audience measurement (Section 2) is deliberately cookieless, which is why this site needs no cookie-consent banner. If we ever introduce a tracking cookie, we will update this policy and ask for your consent first via a banner.
10. Children
Our website is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
11. Policy Updates
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Significant changes will be indicated by the effective date at the top of this page.
12. Contact Us
For any questions about this Privacy Policy or your personal data, contact us at support@adventurelab.ai.