Privacy Policy
This Privacy Policy explains how we handle your personal data when you use the Yayando website (yayando.com) and the Yayando app (together, the "Service"). We take your privacy seriously and process personal data only in accordance with the EU General Data Protection Regulation (GDPR) and applicable Austrian law.
Last updated: 5 August 2026
1. Who is responsible
The controller responsible for your personal data is:
IG Next e.U.
Vorgartenstraße 120B/18, 1020 Vienna, Austria
Email: ask@yayando.com
We have not appointed a Data Protection Officer, as we are not legally required to do so. For any privacy question, please contact us at the address above.
2. What data we collect
Account & profile
When you create an account: your email address, name, a securely hashed password, and — if you sign in with a third-party provider — the identifier that provider shares with us. You may optionally add profile details.
Location
With your permission, we use your device's approximate location to show activities and places near you and to centre the map. You can disable this at any time in your device settings.
Bookmarks & preferences
The places and activities you save, and app preferences such as language.
Bookings & inquiries
When you book or contact a provider: the names and contact details you enter, the details of your request, and your messages. These entries may include the names of the people an activity is for (which may include children). Please share only what is necessary.
Loyalty & points
If you use loyalty features: your points balance, stamps, and redemption history.
Community photos
If you submit a photo, we store the image and related metadata and review it before it is shown, to keep the Service safe and relevant.
Messages
The content of chats you exchange through the Service (for example with a provider).
Newsletter
If you subscribe: your email address and the fact that you consented. You can unsubscribe at any time via the link in every newsletter.
Usage & device data
Technical data generated automatically when you use the Service: IP address, device and browser type, pages and screens viewed, and interaction events. Details on cookies and analytics are in section 4.
Business (partner) accounts
If you manage a business listing, we also process the business details you provide and, for paid plans, billing data handled by our payment processor (see section 5).
3. Why we use your data and our legal basis
- Running your account and providing bookmarks, bookings, loyalty and messaging — performance of a contract (GDPR Art. 6(1)(b)).
- Showing nearby results using your location, sending push notifications, non-essential analytics, and the newsletter — your consent (Art. 6(1)(a)), which you can withdraw at any time.
- Keeping the Service secure, preventing abuse and fraud, moderating content, and improving the product — our legitimate interests (Art. 6(1)(f)).
- Handling partner billing and keeping invoices and accounting records — contract and legal obligation (Art. 6(1)(b) and (c)).
4. Cookies & analytics
We use cookies and similar technologies. Essential ones (for example to keep you signed in) are always active and rely on our legitimate interest in providing the Service. Analytics and other non-essential technologies run only after you agree via our cookie banner, and you can change your choice at any time.
For analytics we use Mixpanel (product analytics) and Google Analytics with Google Tag Manager (website analytics). These help us understand how the Service is used so we can improve it. They are loaded only with your consent.
5. Who we share data with
We do not sell your personal data. We share it only with service providers ("processors") who help us run the Service under contract and on our instructions. They store the relevant data in EU data centres:
- Supabase — database, authentication and file storage.
- Directus — content and directory data (listings, articles, pages).
- Vercel — hosting and delivery of the website.
- Google Firebase / Firestore — mobile sign-in, in-app messaging and push notifications.
- Mixpanel — product analytics (with your consent).
- Google Analytics and Google Tag Manager — website analytics (with your consent).
- Sentry — error and performance monitoring.
- Stripe — payment processing for business/partner subscriptions only.
- OpenStreetMap — map tiles.
We may also disclose data where legally required (for example to authorities acting within their powers).
6. International data transfers
The data above is hosted in the EU. However, some of our providers are part of groups with a parent company outside the EU (in particular Google, Mixpanel, Sentry, Stripe and Vercel in the USA). Where a transfer outside the EU/EEA can occur, we rely on appropriate safeguards — the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. You can request a copy of these safeguards from us.
7. How long we keep your data
- Account data — until you delete your account, then removed or anonymized without undue delay.
- Bookings, invoices and accounting records — for the statutory retention period under Austrian tax law (currently 7 years).
- Analytics data — kept only as long as needed for the purpose, in aggregated or limited form.
- Server and error logs — a short period for security and troubleshooting.
8. Your rights
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to its processing; receive it in a portable format; and withdraw any consent at any time (without affecting processing already carried out). To exercise these rights, contact ask@yayando.com.
You also have the right to lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria · www.dsb.gv.at · dsb@dsb.gv.at
9. Children
The Service is intended for parents and guardians, not for children. We do not knowingly collect personal data directly from children. If a booking or inquiry includes a child's name, it is provided by the adult making the request. In Austria, consent for information-society services can be given from the age of 14. If you believe a child has provided us data without the required consent, please contact us and we will delete it.
10. How we protect your data
We use encryption in transit (TLS), encryption at rest for stored data, access controls, and other technical and organisational measures appropriate to the risk.
11. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22). Search results and recommendations are ranked automatically, but this does not have such effects.
12. Changes to this policy
We may update this policy as the Service evolves or the law changes. The current version is always available here, with the "last updated" date at the top. Significant changes will be communicated appropriately.
Contact
IG Next e.U. · Vorgartenstraße 120B/18, 1020 Vienna, Austria · ask@yayando.com