This Cookie Policy explains how NXVOY Trips ("NxVoy", "we", "us", or "our") uses cookies, local storage, and similar tracking technologies when you visit or use our website at nxvoytrips.ai and our related services. We are a UK-based company and comply with the UK Privacy and Electronic Communications Regulations 2003 (PECR) and the UK General Data Protection Regulation (UK GDPR).
By continuing to use our platform, you acknowledge that you have read and understood this policy. Where cookies are not strictly necessary for the operation of our service, we will ask for your consent before placing them.
1. What Are Cookies?
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work efficiently, to improve the user experience, and to provide information to site owners.
In addition to cookies, we also use other browser storage mechanisms such as localStorage and sessionStorage to store data locally on your device. These work similarly to cookies but can hold larger amounts of data and are not automatically sent to the server with each request.
2. Why We Use Cookies and Similar Technologies
We use cookies and similar technologies for the following purposes:
- Essential operation — to authenticate you, protect against fraud, maintain your session, and ensure our platform functions correctly.
- Security — to protect your account and detect fraudulent payment activity.
- Analytics and performance — to understand how visitors use our platform so we can improve the experience.
- Functionality — to remember your preferences, itinerary selections, and booking progress so you do not lose your work.
- Payment processing — to securely process payments through our third-party payment providers.
3. Cookie Categories
3.1 Strictly Necessary Cookies
These cookies are essential for the website to function. They enable core features such as user authentication, security protections, and session management. Without these cookies, the services you have requested cannot be provided. These cookies do not require your consent under UK PECR, as they are necessary for the service you have requested.
3.2 Analytics and Performance Cookies
These cookies collect information about how you use our platform, such as which pages you visit, how long you spend on them, and any errors you encounter. This data helps us improve the performance and usability of our service. We use PostHog for analytics, hosted on EU servers. These cookies require your consent.
3.3 Functionality Cookies
These cookies and local storage entries allow us to remember choices you make (such as your itinerary edits, selected hotels, flight preferences, and traveller details) and provide enhanced, personalised features. They persist your booking progress so you can return to it later. These cookies require your consent where they go beyond what is strictly necessary.
3.4 Fraud Prevention and Security Cookies
These cookies are set by our fraud prevention and security partners to protect you against fraudulent transactions, verify your identity, and prevent bot abuse. They are considered strictly necessary for the security of payment processing and do not require separate consent.
3.5 Advertising and Retargeting Cookies
NxVoy does not currently use any advertising, retargeting, or third-party marketing cookies. If this changes in the future, we will update this policy and request your consent before placing any such cookies.
4. Detailed Cookie Table
The following table lists the specific cookies and similar technologies used on our platform:
4.1 Strictly Necessary Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
next-auth.session-token / __Secure-next-auth.session-token | NxVoy (NextAuth) | Stores your encrypted session token to keep you signed in. The __Secure- prefix is used in production for enhanced security. | Session / 30 days | HTTP cookie (httpOnly, secure in production) |
__Host-csrf_token / csrf_token | NxVoy | CSRF (Cross-Site Request Forgery) protection using the double-submit cookie pattern. Prevents unauthorised actions on your behalf. | 24 hours | HTTP cookie (httpOnly, secure in production) |
next-auth.csrf-token | NxVoy (NextAuth) | Additional CSRF protection for the authentication flow. | Session | HTTP cookie |
next-auth.callback-url | NxVoy (NextAuth) | Stores the redirect URL so you are returned to the correct page after signing in. | Session | HTTP cookie |
nxvoy_device_id | NxVoy | Unique device identifier (UUID) used for session security and device recognition. Does not contain personal information. | 30 days (rolling) | HTTP cookie (secure on HTTPS) |
4.2 Analytics and Performance Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
PostHog cookies (various, prefixed ph_) | PostHog (eu.i.posthog.com) | Product analytics to understand how users interact with our platform. Collects browser type, device type, operating system, language, country, city, page views, and session flow data. Hosted on EU servers. | 1 year | HTTP cookie / localStorage |
4.3 Fraud Prevention and Security Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Riskified cookies | Riskified (beacon.riskified.com, c.riskified.com) | Fraud detection and prevention for payment transactions, specifically for activity bookings processed through Viator. | Session / up to 1 year | HTTP cookie / JavaScript |
| Google reCAPTCHA cookies | Google (www.google.com, www.gstatic.com) | Bot protection on authentication flows. Uses reCAPTCHA v3 to distinguish genuine users from automated abuse without requiring user interaction. | Up to 6 months | HTTP cookie |
4.4 Payment Processing Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Stripe cookies | Stripe (js.stripe.com, api.stripe.com) | Secure payment processing for flight, hotel, and holiday package bookings. Stripe may set cookies for fraud detection and to remember your payment preferences. | Session / up to 1 year | HTTP cookie |
| Viator payment cookies | Viator / TripAdvisor (checkout-assets.payments.tamg.cloud) | Processes activity booking payments through a secure payment iframe. Card details are handled entirely by Viator and never touch our servers. | Session | HTTP cookie (within iframe) |
| Cardinal / Braintree cookies | Cardinal Commerce (*.cardinalcommerce.com, *.braintree-api.com) | 3D Secure (3DS) verification for card payments, providing an additional layer of authentication to protect against unauthorised card use. | Session | HTTP cookie |
4.5 Authentication Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Google Sign-In cookies | Google (accounts.google.com) | Enables single sign-on (SSO) so you can sign in with your Google account. | Session | HTTP cookie |
| Apple Sign-In cookies | Apple (appleid.apple.com, appleid.cdn-apple.com) | Enables single sign-on (SSO) so you can sign in with your Apple ID. | Session | HTTP cookie |
4.6 Maps Cookies
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Mapbox cookies | Mapbox (api.mapbox.com, events.mapbox.com) | Displays interactive maps for destinations, hotels, activities, and itinerary planning. Mapbox may collect anonymous usage data to improve its mapping services. | Session / up to 1 year | HTTP cookie |
5. Third-Party Cookies
Some cookies on our platform are set by third-party services that we use to provide specific functionality. We do not control the cookies set by these third parties, and their use is governed by their own privacy and cookie policies. The third-party services we use include:
- PostHog (analytics) — PostHog Privacy Policy
- Stripe (payments) — Stripe Privacy Policy
- Viator / TripAdvisor (activity payments) — Viator Privacy Policy
- Riskified (fraud prevention) — Riskified Privacy Policy
- Google (reCAPTCHA, Sign-In) — Google Privacy Policy
- Apple (Sign-In) — Apple Privacy Policy
- Mapbox (maps) — Mapbox Privacy Policy
- Cardinal Commerce / Braintree (3DS) — Cardinal Privacy Policy
6. Local Storage and Session Storage
In addition to cookies, we use your browser's localStorage and sessionStorage to store data that helps our platform work. Unlike cookies, this data is not sent to our servers automatically. It stays on your device and is used by the application running in your browser.
6.1 localStorage
Data stored in localStorage persists until you clear it or we remove it programmatically.
| Key | Purpose | Duration |
|---|---|---|
nxvoy_itinerary_{id} | Stores the base itinerary generated by our AI trip planner, including destinations, days, and suggested activities. Allows you to return to your plan without re-generating it. | Until cleared by user or itinerary is deleted |
nxvoy_user_data_{id} | Stores your edits and customisations to an itinerary, such as added hotels, changed flights, or activity selections. | Until cleared by user or itinerary is deleted |
| Zustand store data (various keys) | Persists UI state and user selections across page reloads, including booking progress, traveller counts, selected options, and currency preferences. | Until cleared by user |
| PostHog data | Anonymous user identification and session tracking for analytics. | Until cleared by user |
6.2 sessionStorage
Data stored in sessionStorage is automatically cleared when you close the browser tab.
| Key | Purpose | Duration |
|---|---|---|
geoLocation | Caches your approximate location (determined from your IP address) to provide localised currency and destination suggestions. No precise GPS data is stored. | Browser tab session |
flow_id | A unique identifier for your current browsing session, used by PostHog analytics to group page views into a single user journey. | Browser tab session |
7. How to Manage Your Cookie Preferences
You have the right to decide whether to accept or reject optional cookies. Here are the ways you can exercise that right:
7.1 Cookie Consent Banner
When you first visit our website, we display a cookie consent banner that allows you to accept or reject optional cookies (such as analytics). You can change your preferences at any time by clicking "Cookie Preferences" in the footer of any page.
7.2 Browser Controls
Most web browsers allow you to control cookies through their settings. You can typically:
- View what cookies are stored on your device
- Delete individual cookies or all cookies
- Block cookies from specific websites or all websites
- Block third-party cookies while allowing first-party cookies
- Clear cookies automatically when you close your browser
Here are links to cookie management instructions for common browsers:
Please note: If you block or delete strictly necessary cookies, some parts of our website may not function correctly. You may be unable to sign in, make bookings, or complete payments.
7.3 Clearing Local and Session Storage
To clear localStorage and sessionStorage data, you can use your browser's developer tools (usually accessed by pressing F12) and navigating to the "Application" or "Storage" tab. Alternatively, clearing your browser's site data for nxvoy.com will remove all stored data.
Warning: Clearing localStorage will remove any unsaved itinerary progress and booking selections. Make sure you have completed any in-progress bookings before clearing this data.
7.4 Opting Out of Analytics
You can opt out of PostHog analytics tracking by:
- Declining analytics cookies via our cookie consent banner
- Enabling "Do Not Track" in your browser settings
- Using a browser extension that blocks tracking scripts
8. Legal Basis for Cookies
Under the UK Privacy and Electronic Communications Regulations 2003 (PECR), the rules for cookies are as follows:
- Strictly necessary cookies — We can set these without your consent because they are essential for the service you have requested. This includes session cookies, CSRF protection, device identification for security, payment processing cookies, fraud prevention cookies, and authentication cookies.
- All other cookies — We must obtain your informed consent before setting these cookies. This applies to analytics and performance cookies (PostHog) and any functionality cookies that go beyond what is strictly necessary. We obtain this consent through our cookie consent banner.
Where cookies involve the processing of personal data, we rely on the following legal bases under the UK GDPR:
- Legitimate interests (Article 6(1)(f)) — for strictly necessary cookies and fraud prevention, where processing is necessary for the security and proper functioning of our service.
- Consent (Article 6(1)(a)) — for analytics and optional functionality cookies, where you have given clear, informed consent.
- Contract performance (Article 6(1)(b)) — for cookies that are necessary to fulfil our contractual obligations to you, such as processing your travel bookings and payments.
9. International Data Transfers
Some of our third-party cookie providers may process data outside the UK. Where this occurs:
- PostHog is hosted on EU servers (eu.i.posthog.com), which benefits from the UK adequacy decision for EEA countries.
- Stripe, Google, Apple, and Mapbox may transfer data to the United States, subject to appropriate safeguards such as Standard Contractual Clauses (SCCs) or the UK Extension to the EU-US Data Privacy Framework.
- Riskified is headquartered in Israel, which has a UK adequacy finding.
For more information about international transfers, please see our Privacy Policy.
10. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies we use, changes in the law, or updates to our practices. When we make significant changes, we will:
- Update the "Last updated" date at the top of this page
- Display a notice on our website to inform you of the change
- Where required, ask for your consent again for any new optional cookies
We recommend that you check this page periodically for any updates.
11. Contact Us
If you have any questions about our use of cookies or this Cookie Policy, you can contact us at:
- Email: privacy@nxvoy.ai
- Website: nxvoytrips.ai
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
- Website: ico.org.uk
- Telephone: 0303 123 1113