Legal

Privacy Policy

Last updated: 22 April 2026

Levi Finland Adventures (“we”, “us”, “our”) operates levifinland.com. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have. We are the data controller for the personal data described here.

We are based in Finland and operate under Finnish law and the EU General Data Protection Regulation (GDPR). If you have questions, contact us at hello @ levifinland.com.

What data we collect

Account data

When you create an account, we collect your email address, a display name, and a password (stored as a hashed value — we never see your plaintext password). If you apply to join as a local resident or local business, we also collect the information you submit in the application form: your city, a brief description of your Levi connection, and optionally your social profile links and business details.

Community profile data

If you publish content on the platform — itineraries, trip tips, photos, or videos — that content is associated with your account and displayed publicly under your name. Photos and videos are stored via Cloudinary (see “Third parties” below). You can request deletion of your published content at any time.

Usage data

When you use the site, our servers log standard request data including your IP address, browser type, pages visited, and timestamps. This data is used for security monitoring and diagnosing technical problems. We do not use it to build behavioural profiles.

AI interaction data

If you use the trip planner or Ask a Local features, your input is sent to Anthropic’s API to generate a response. We do not store the content of your AI conversations beyond the immediate session unless you explicitly save an itinerary to your account.

Cookies and similar technologies

We use very few, and we do not use any for advertising, profiling or cross-site tracking. There are three kinds on this site and no others.

Strictly necessary — always on

If you sign in, we set a session cookie so you stay signed in. It is stored as an HttpOnly cookie, which means JavaScript cannot read it. It exists only because you asked to sign in, and it is removed when you sign out.

Visitor statistics — no cookie at all

We count page views using Vercel Web Analytics. It stores nothing on your device: no cookie, no identifier, no profile, and no way to follow you to another site. We can see that a page was read; we cannot see that it was you. This is a deliberate choice — it is why there is no cookie banner asking you about analytics.

The chat

Our live chat is provided by Zoho SalesIQ, and it loads when a page opens so that the chat button is there if you want it. Two cookies come with it: a security token, and one that keeps you connected to the same server so a conversation is not lost between messages.

They are there to make the chat work. They are not used for advertising, and we have visitor tracking switched off in SalesIQ, so it is not used to follow you around the site or build a profile of you.

You can remove them at any time by clearing site data for this site in your browser settings, and you can stop them being set at all by blocking third-party cookies — everything else on the site works normally either way. Zoho’s own privacy notice covers what they do with the chat service itself.

Bot protection

Our forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script. We use it in a mode that does not set a cookie and does not track you across sites.

Why we collect it and the legal basis

  • Account and authentication data — to provide the service you signed up for. Legal basis: contract (Article 6(1)(b) GDPR).
  • Community profile and published content — to display your contributions on the platform in line with the community rules you agreed to. Legal basis: contract.
  • Application form data — to assess and process local or business applications. Legal basis: contract.
  • Server logs — to maintain platform security and diagnose technical issues. Legal basis: legitimate interests (Article 6(1)(f) GDPR).
  • Transactional emails — to send password resets, application status updates, and other service messages you have requested. Legal basis: contract.

Third parties

We use the following processors to operate the platform. Each is bound by a data processing agreement and complies with GDPR:

  • Supabase — database and authentication. Stores account data, community profiles, and platform content. Data is hosted in the EU.
  • Cloudinary — media storage and delivery for photos and videos you upload.
  • Anthropic— AI inference for trip planning and Ask a Local features. Your input is processed to generate a response and is subject to Anthropic’s usage policies.
  • Resend — transactional email delivery (password resets, application notifications). We share only your email address and the content of the specific email.

We do not sell your data. We do not share your data with any third party for their own marketing purposes.

How long we keep your data

Account data is kept for as long as your account exists. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal reasons (for example, financial records where applicable). Published community content is deleted on request; if it has been included in an itinerary created by another user, a de-attributed version may remain.

Server logs are retained for 90 days. AI conversation data is not retained beyond the session.

Your rights

Under the GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure— ask us to delete your personal data (“right to be forgotten”), subject to legal retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — ask us to restrict processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email hello @ levifinland.com. We will respond within one month. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

Security

We use HTTPS throughout, passwords are hashed and salted, and access to production data is restricted to authorised personnel. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but we take reasonable precautions proportionate to the nature of the data we hold.

Changes to this policy

If we make material changes, we will update the “last updated” date at the top of this page and, where the change affects how we process account data, notify you by email. Continued use of the platform after a change is published constitutes acceptance.

Contact

For any privacy question or to exercise your rights: hello @ levifinland.com