Vayotrip
Trust & Safety

Security & Privacy

What we do to protect your data — and what we don't do.

HTTPS everywhere

All traffic to and from Vayotrip is encrypted using HTTPS with TLS 1.3. Our SSL certificate is provisioned and automatically renewed by Vercel. You can verify the certificate in your browser's address bar at any time — look for the padlock icon next to vayotrip.com.

We do not operate any HTTP (unencrypted) endpoints. All HTTP requests are automatically redirected to HTTPS at the infrastructure level.

We never handle payment data

Vayotrip is a comparison and referral site. We do not have a checkout, payment form, or card-processing integration of any kind. When you click a flight result, you are redirected to our affiliate partner's website (e.g. Kiwi.com) where the booking and payment are completed entirely under their infrastructure and privacy policy.

This means Vayotrip never sees, receives, stores, or transmits your credit card number, bank details, or any financial data. If you have a billing question about a booking, contact Kiwi.com support directly.

What data Vayotrip collects

In the course of operating the site, Vayotrip may process the following categories of data:

  • Search queries — origin, destination, and date inputs you enter into the search widget. These are used to display results and are not linked to a personal profile.
  • Server access logs — standard HTTP logs (IP address, user agent, timestamp, requested URL) retained for security monitoring and debugging purposes.
  • Analytics — aggregated, anonymised page-view counts used to understand which features are most useful. We do not use pixel tracking or fingerprinting.

We do not sell, rent, or share personal data with third parties for marketing purposes.

Cookies

Vayotrip uses a minimal number of cookies:

  • Session cookies — short-lived, necessary for the site to function (e.g. currency preference). Deleted when you close your browser.
  • Affiliate tracking cookies — set by our partners (Kiwi.com, Yesim) when you click through to their sites, so they can attribute any resulting bookings to Vayotrip. These are governed by the partners' own cookie policies.

We do not use persistent advertising cookies or third-party behavioural tracking on the Vayotrip domain.

Third-party services

Vayotrip uses the following third-party services which may process data in the course of delivering the site:

Reporting a security issue

If you discover a security vulnerability on the Vayotrip website, please report it responsibly by emailing security@vayotrip.com. We aim to acknowledge all reports within 48 hours and to resolve valid issues within 30 days. We do not operate a bug bounty programme at this time but we will credit responsible disclosures in our changelog.