Privacy Policy
Last updated: 17 April 2026
Legal Information
Ninkio
Legal Form: SAS (Société par Actions Simplifiée)
Share Capital: 1 000 €
Registered Office: 47 rue Vivienne, 75002 Paris, France
RCS: Paris 103 443 446
VAT Number: Pending (en cours d'attribution)
Président: Baptiste Guichard
Director of Publication: Baptiste Guichard
Hosting Provider: Vercel, Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
Email: [email protected]
This Privacy Policy covers:
- the public marketing website (ninkio.co)
- the application dashboard (app.ninkio.co)
- the embedded booking widget and related booking APIs (the "Widget")
- Ninkio-hosted storefront and checkout pages (book.ninkio.co)
1. What Ninkio does (in plain English)
Ninkio is a platform that helps:
- Creators promote travel experiences and make them bookable, either by embedding a booking Widget on their websites ("Creator Sites") or through Ninkio-hosted storefront pages (book.ninkio.co).
- Suppliers (the businesses who provide the product) receive bookings and fulfill them.
The Supplier is responsible for the product delivery and customer support for the product. Ninkio provides the booking technology and may facilitate payment processing and booking operations.
2. Personal data we collect
2.1 Public marketing website (ninkio.co)
Depending on the features you use, we may collect:
- Contact/demonstration requests: name, email, website, message content.
- Technical/usage data: basic device and usage information (e.g., pages viewed, referrer, approximate location) depending on the analytics tooling configured on the website.
We use PostHog Analytics (EU cloud) for website traffic analysis and user behavior tracking. PostHog processes data on EU-based servers and does not set cookies on this website. You can learn more about their privacy practices at posthog.com/privacy.
2.2 Application (app.ninkio.co): creators and suppliers
We may collect:
- Account and profile data: name, email, phone, business name, website, country, currency, onboarding details.
- Authentication and security data: sign-in events, access logs, and security signals.
- Usage data: interactions with the dashboard to operate and improve the service.
- Payment data: payment-related data processed via Stripe (see "Payment processing" below).
- Legal and invoicing data (Suppliers): SIREN (or equivalent company ID), VAT number, legal form, registered company name, billing address, and billing email, collected to issue commission invoices and credit notes.
- Legal, invoicing, and payout data (Creators): SIRET / SIREN (or equivalent company ID), VAT number, legal name, billing address, and billing email, collected to issue self-billing invoices for Creator commissions; and payout details such as the Creator's chosen payout method and account information (e.g., IBAN and account holder name for bank transfers, or PayPal email address), collected to send commission payouts.
2.3 Widget and Storefront (end-customers booking)
When an end-customer books through the Widget or a Ninkio-hosted storefront page, we may collect:
- Booking details: product selected, date/time, quantity, price, taxes, booking status, identifiers.
- Customer contact details (provided in the Widget form): first name, last name, email, phone number, country.
- Technical and analytics data: device type, user agent, referrer domain, page URL (host page), UTM parameters, visitor/session identifiers, and approximate geolocation derived from headers.
- Legal acceptance data: timestamps and IP address related to acceptance of booking terms, and an opt-in flag for creator email sharing (see Section 5).
3. How we use personal data (purposes)
We use personal data to:
- Provide the service: operate the dashboard, widget, booking flows, and related features.
- Process and manage bookings: create reservations, confirm bookings, and handle booking lifecycle events.
- Follow up on unfinished bookings: if you start a booking, provide your contact details, and do not complete payment, we may send you one reminder email (on behalf of the creator whose page you booked from) with a link to resume your booking. Every such email includes an opt-out link, and your details are never added to marketing lists.
- Transmit booking/customer details to Suppliers: so Suppliers can deliver the product and provide operational support.
- Enable creator reporting: provide creators with booking reporting and (only if the customer opted in) an email address for creator communications.
- Security and fraud prevention: rate limiting, abuse prevention, debugging, monitoring.
- Customer support: respond to support requests and operational issues.
- Product improvement: analyze usage and performance to improve the platform.
4. Legal bases (GDPR)
Where GDPR applies, we rely on one or more of the following legal bases:
- Performance of a contract: (e.g., processing bookings and enabling Suppliers to fulfill them).
- Legitimate interests: (e.g., security, preventing abuse, monitoring performance, improving the service).
- Consent: (only where required, e.g., end-customer opt-in to share their email with a Creator for creator communications).
- Legal obligations: (e.g., accounting/financial record keeping where applicable).
5. Data sharing: who receives what
5.1 Suppliers
For bookings made through the Widget or Storefront, we share relevant booking details and customer contact details with the Supplier so they can:
- fulfill the product,
- provide customer support,
- send operational communications (confirmation/instructions/changes/cancellations).
Suppliers process customer data under their own privacy policy and are responsible for complying with applicable data protection laws for their own processing.
5.2 Creators
Creators receive:
- booking/reporting information about bookings attributed to them.
Creators do not receive the customer's phone number through the dashboard.
Creators receive the customer's email address only if the customer explicitly opts in during checkout (email-sharing consent). If the customer does not opt in, we do not share the email address with the Creator.
If a customer opts in, the Creator may use the email address for their own communications and is responsible for complying with applicable marketing and data protection laws.
5.3 Payment processing providers (Stripe)
Payments are processed via Stripe. Ninkio does not store full card numbers. Depending on the booking/payment flow, Stripe may process payment data and associated identifiers.
5.4 Infrastructure and service providers
We may share data with vetted service providers acting as processors/sub-processors, such as:
- Vercel: hosting and delivery
- Supabase: database, authentication
- Upstash: caching and rate limiting
- Resend: email delivery for contact forms
- Slack: operational notifications for errors/bookings; typically includes identifiers and diagnostic context, not customer contact details
- Booking system providers / APIs: used by Suppliers (e.g., Bokun, Ventrata) to create/confirm bookings and transmit customer contact details for fulfillment
Some providers may process data outside your country. Where required, we rely on appropriate safeguards (e.g., standard contractual clauses) and contractual protections.
We do not sell or rent personal data.
6. Cookies, local storage, and tracking
6.1 Marketing website (ninkio.co)
The marketing website may use analytics tooling to understand website usage and improve content. The exact cookies/trackers depend on the configuration of the public website.
We use PostHog Analytics (EU cloud) for website traffic analysis and user behavior tracking. PostHog processes data on EU-based servers and does not set cookies on this website. You can learn more about their privacy practices at posthog.com/privacy.
You can opt out of analytics tracking by using a browser extension that blocks tracking scripts, or by contacting us at [email protected].
6.2 Widget, Storefront & App
The Widget, Storefront, and their tracking may use:
- session identifiers (e.g., session_id),
- visitor identifiers (e.g., visitor_id),
- UTM parameters,
- referrer and page URLs (host page where the widget is embedded),
- IP-based rate limiting for security and abuse prevention.
These identifiers help us measure conversions, prevent abuse, and improve reliability.
7. Data retention
Data retention is kept simple:
- Accounts and business data: retained while your account is active.
- Booking records: retained for operational purposes and may be retained longer for legal/accounting needs.
- Unfinished checkouts: if you start a booking and do not complete payment, the contact details and selections you already submitted are kept for up to 30 days (to enable the reminder email above and support follow-up), then deleted.
- Logs and security data (e.g., rate limiting): retained as needed for security and troubleshooting.
If you request deletion, we will delete or anonymize data where possible, subject to legal obligations and legitimate retention needs.
8. Security
We implement reasonable technical and organizational measures, including access controls, server-side API key handling where applicable, and rate limiting on sensitive endpoints. No system is perfectly secure; we continuously improve.
9. Your rights
Depending on your location and applicable law (including GDPR), you may have rights to:
- access your data,
- correct inaccurate data,
- request deletion,
- object to or restrict processing,
- data portability,
- withdraw consent (where processing is based on consent),
- lodge a complaint with your local data protection authority (in France: CNIL).
To exercise these rights, contact [email protected].
10. Changes to this policy
We may update this policy as the product evolves. The "Last updated" date indicates the latest revision. For major changes, we may provide additional notice in the app or on the website.
11. Contact
For privacy questions or requests: [email protected]