Privacy Policy
Last updated: 3 September 2026
Legal Information
Ninkio
Legal Form: SAS (Société par Actions Simplifiée)
Share Capital: 1 000 €
Registered Office: 47 rue Vivienne, 75002 Paris, France
RCS: Paris 103 443 446
VAT Number: Pending (en cours d'attribution)
Président: Baptiste Guichard
Director of Publication: Baptiste Guichard
Hosting Provider: Vercel, Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
Email: [email protected]
This Privacy Policy covers:
- the public marketing website (ninkio.co)
- the application dashboard (app.ninkio.co)
- the embedded booking widget and related booking APIs (the "Widget")
- Ninkio-hosted storefront and checkout pages (book.ninkio.co)
1. What Ninkio does (in plain English)
Ninkio is a platform that helps:
- Creators promote travel experiences and make them bookable, either by embedding a booking Widget on their websites ("Creator Sites") or through Ninkio-hosted storefront pages (book.ninkio.co).
- Suppliers (the businesses who provide the product) receive bookings and fulfill them.
The Supplier is responsible for the product delivery and customer support for the product. Ninkio provides the booking technology and may facilitate payment processing and booking operations.
2. Personal data we collect
2.1 Public marketing website (ninkio.co)
Depending on the features you use, we may collect:
- Contact/demonstration requests: name, email, website, message content.
- Technical/usage data: basic device and usage information (e.g., pages viewed, referrer, approximate location) depending on the analytics tooling configured on the website.
We use DataFast for website analytics. It records the pages you view, the referring site or campaign you arrived from, your approximate location, and basic device and browser information. It sets four first-party cookies (datafast_visitor_id, datafast_session_id, datafast_visitor_first_seen_at and datafast_visitor_session_count) so that repeat visits from the same browser are counted as one person rather than several. Analytics requests are served from ninkio.co itself rather than from a third-party domain.
When you submit a creator or business application, we also send your name and email address to DataFast, so that the application can be linked to the visit it came from. We use this to understand which channels bring people to Ninkio. We do not use it for advertising, and we do not track you across other websites.
2.2 Application (app.ninkio.co): creators and suppliers
We may collect:
- Account and profile data: name, email, phone, business name, website, country, currency, onboarding details.
- Authentication and security data: sign-in events, access logs, and security signals.
- Usage data: interactions with the dashboard to operate and improve the service.
- Payment data: payment-related data processed via Stripe (see "Payment processing" below).
- Legal and invoicing data (Suppliers): SIREN (or equivalent company ID), VAT number, legal form, registered company name, billing address, and billing email, collected to issue commission invoices and credit notes.
- Legal, invoicing, and payout data (Creators): SIRET / SIREN (or equivalent company ID), VAT number, legal name, billing address, and billing email, collected to issue self-billing invoices for Creator commissions; and payout details such as the Creator's chosen payout method and account information (e.g., IBAN and account holder name for bank transfers, or PayPal email address), collected to send commission payouts.
2.3 Widget and Storefront (end-customers booking)
When an end-customer books through the Widget or a Ninkio-hosted storefront page, we may collect:
- Booking details: product selected, date/time, quantity, price, taxes, booking status, identifiers.
- Customer contact details (provided in the Widget form): first name, last name, email, phone number, country.
- Technical and analytics data: device type, user agent, referrer domain, page URL (host page), UTM parameters, visitor/session identifiers, and approximate geolocation derived from headers.
- Legal acceptance data: timestamps and IP address related to acceptance of booking terms, and an opt-in flag for creator email sharing (see Section 5).
3. How we use personal data (purposes)
We use personal data to:
- Provide the service: operate the dashboard, widget, booking flows, and related features.
- Process and manage bookings: create reservations, confirm bookings, and handle booking lifecycle events.
- Follow up on unfinished bookings: if you start a booking, provide your contact details, and do not complete payment, we may send you one reminder email (on behalf of the creator whose page you booked from) with a link to resume your booking. Every such email includes an opt-out link, and your details are never added to marketing lists.
- Transmit booking/customer details to Suppliers: so Suppliers can deliver the product and provide operational support.
- Enable creator reporting: provide creators with booking reporting and (only if the customer opted in) an email address for creator communications.
- Security and fraud prevention: rate limiting, abuse prevention, debugging, monitoring.
- Customer support: respond to support requests and operational issues.
- Product improvement: analyze usage and performance to improve the platform.
4. Legal bases (GDPR)
Where GDPR applies, we rely on one or more of the following legal bases:
- Performance of a contract: (e.g., processing bookings and enabling Suppliers to fulfill them).
- Legitimate interests: (e.g., security, preventing abuse, monitoring performance, improving the service).
- Consent: (only where required, e.g., end-customer opt-in to share their email with a Creator for creator communications).
- Legal obligations: (e.g., accounting/financial record keeping where applicable).
5. Data sharing: who receives what
5.1 Suppliers
For bookings made through the Widget or Storefront, we share relevant booking details and customer contact details with the Supplier so they can:
- fulfill the product,
- provide customer support,
- send operational communications (confirmation/instructions/changes/cancellations).
Suppliers process customer data under their own privacy policy and are responsible for complying with applicable data protection laws for their own processing.
5.2 Creators
Creators receive:
- booking/reporting information about bookings attributed to them.
Creators do not receive the customer's phone number through the dashboard.
Creators receive the customer's email address only if the customer explicitly opts in during checkout (email-sharing consent). If the customer does not opt in, we do not share the email address with the Creator.
If a customer opts in, the Creator may use the email address for their own communications and is responsible for complying with applicable marketing and data protection laws.
5.3 Payment processing providers (Stripe)
Payments are processed via Stripe. Ninkio does not store full card numbers. Depending on the booking/payment flow, Stripe may process payment data and associated identifiers.
5.4 Infrastructure and service providers
We may share data with vetted service providers acting as processors/sub-processors, such as:
- Vercel: hosting and delivery
- Supabase: database, authentication
- Upstash: caching and rate limiting
- Resend: email delivery for contact forms
- DataFast: website analytics for ninkio.co, including the application records described in section 2.1
- Slack: operational notifications for errors/bookings; typically includes identifiers and diagnostic context, not customer contact details
- Booking system providers / APIs: used by Suppliers (e.g., Bokun, Ventrata) to create/confirm bookings and transmit customer contact details for fulfillment
Some providers may process data outside your country. Where required, we rely on appropriate safeguards (e.g., standard contractual clauses) and contractual protections.
We do not sell or rent personal data.
6. Cookies, local storage, and tracking
6.1 Marketing website (ninkio.co)
The marketing website uses DataFast for analytics. It sets the cookies datafast_visitor_id, datafast_session_id, datafast_visitor_first_seen_at and datafast_visitor_session_count, which identify your browser so that repeat visits are recognized as the same person. They are not used to follow you to other websites, and they are not shared with advertisers.
DataFast also records events describing how the site is used, for example reaching a particular section of a page, opening an FAQ answer, starting an application, or submitting one. If you submit an application, your name and email address are attached to that record, as described in section 2.1.
You can opt out of analytics tracking by using a browser extension that blocks tracking scripts, or by contacting us at [email protected].
6.2 Widget, Storefront & App
The Widget, Storefront, and their tracking may use:
- session identifiers (e.g., session_id),
- visitor identifiers (e.g., visitor_id),
- UTM parameters,
- referrer and page URLs (host page where the widget is embedded),
- IP-based rate limiting for security and abuse prevention.
These identifiers help us measure conversions, prevent abuse, and improve reliability.
7. Data retention
Data retention is kept simple:
- Accounts and business data: retained while your account is active.
- Booking records: retained for operational purposes and may be retained longer for legal/accounting needs.
- Unfinished checkouts: if you start a booking and do not complete payment, the contact details and selections you already submitted are kept for up to 30 days (to enable the reminder email above and support follow-up), then deleted.
- Logs and security data (e.g., rate limiting): retained as needed for security and troubleshooting.
If you request deletion, we will delete or anonymize data where possible, subject to legal obligations and legitimate retention needs.
8. Security
We implement reasonable technical and organizational measures, including access controls, server-side API key handling where applicable, and rate limiting on sensitive endpoints. No system is perfectly secure; we continuously improve.
9. Your rights
Depending on your location and applicable law (including GDPR), you may have rights to:
- access your data,
- correct inaccurate data,
- request deletion,
- object to or restrict processing,
- data portability,
- withdraw consent (where processing is based on consent),
- lodge a complaint with your local data protection authority (in France: CNIL).
To exercise these rights, contact [email protected].
10. Changes to this policy
We may update this policy as the product evolves. The "Last updated" date indicates the latest revision. For major changes, we may provide additional notice in the app or on the website.
11. Contact
For privacy questions or requests: [email protected]