Privacy notice
Last updated: 28 September 2026
1. Who is responsible
The controller for Vacation Mode On is Fancircle GmbH, Blintendorf 10a, 07926 Gefell, Germany. For privacy questions or to exercise your rights, contact us at info@fancircle.io.
2. Visiting the website and hosting
We use Cloudflare Workers and file delivery from Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Technically necessary connection data is processed when you visit a page. This includes your IP address, the time and destination of the request, browser and device information sent with it, and technical response and error data. Checking which website features are available also generates this connection data.
This processing delivers the website, maintains its availability and helps identify attacks or disruptions. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure and reliable operation. The website cannot be displayed without transmitting the necessary connection data.
Cloudflare processes data on our behalf to deliver our website and store the account and trip data described below. Its Data Processing Addendum is incorporated into Cloudflare’s standard terms. Cloudflare also processes certain network and security data as an independent controller under its Privacy notice .
Cloudflare operates a global network; processing outside the European Economic Area, particularly in the USA, is possible. Cloudflare states that it participates in the EU–US Data Privacy Framework for transfers to the USA. Its data protection terms provide EU Standard Contractual Clauses and, where appropriate, supplementary safeguards for other covered transfers to third countries. The contractual safeguards and subprocessors can be found in the linked addendum and Cloudflare’s list of subprocessors .
3. Retention periods and technical security
Our application does not keep its own permanent logs of your page visits. This does not exclude Cloudflare’s technical operational and security data. Retention depends on the purpose, particularly providing the service, investigating disruptions or security incidents, and legal obligations. Cloudflare explains these criteria in the ‘Data retention’ section of its privacy policy. That information does not specify one uniform period for all data processed there.
The connection to this website is encrypted using HTTPS.
4. Free account and personal trip file
When you request an account, we process your email address, a technical account key, the login time and the version of the data notice you confirm. We send you a single-use login link. A new account is created only after you confirm it. The link is valid for 15 minutes and is bound to the browser in which you requested it.
Your trip file stores the destinations, travel dates and time zones you enter, plus optional flight numbers, flight dates and departure airports. When you select and save a weather location, we also store its place identifier, name, country, region, coordinates and time zone; we may also store destination coordinates you provide. Other data includes the trip status you confirm and technical creation and modification details. The data is assigned to your account and stored at Cloudflare. Your email address is additionally encrypted in the application database.
This processing gives you access to your free travel area and lets you manage your trip file. The legal basis is Article 6(1)(b) GDPR. Use is voluntary. An email address is required for an account; mandatory trip details are required to save that trip.
If you explicitly choose to remember your holiday mood, travel pace or budget range for later, we store these optional preferences and the time of confirmation based on your consent under Article 6(1)(a) GDPR. You can remove them using ‘Delete saved preferences’. Without that choice, we do not create a permanent preference profile.
Your account, trip files and saved preferences remain stored until the account or the relevant data is deleted. Simply marking a trip as cancelled does not delete its file. ‘Export my data’ lets you download your stored account data. ‘Delete account’ removes your account, trip files, preferences and sessions from the active application database. Separate email delivery logs and technical backups held by service providers are not automatically deleted at the same time; contact us at the address above about those records.
AI chat and WhatsApp sending are disabled in this version. Creating an account does not subscribe you to a newsletter. Below, we explain which external travel data you can request and which details are transmitted.
5. Login, necessary cookies and abuse prevention
We use two technically necessary cookies for the login you request. They contain random security identifiers, no email address or trip data, and are not used for advertising.
| Cookie | Purpose | Validity |
|---|---|---|
__Host-vmo-login | Binds the login link to the requesting browser. | 15 minutes; removed after successful login. |
__Host-vmo-session | Maintains your confirmed login. | 12 hours; removed on logout or account deletion. |
These cookies cannot be read by website JavaScript and are transmitted only over HTTPS. They are necessary for the signed-in area you expressly request (section 25(2)(2) TDDDG); the related processing is based on Article 6(1)(b) GDPR. Blocking these cookies prevents login.
To protect against automated login attempts, we count requests using pseudonymous identifiers cryptographically derived from IP and email addresses. These counters do not store those addresses in plain text. The legal basis is Article 6(1)(f) GDPR; our interest is protecting accounts and the service against abuse. Pseudonymous identifiers are not anonymous data.
Login and session records become invalid after 15 minutes and 12 hours respectively; a used login link is consumed immediately. Login counters expire at the end of their hourly window; a non-personal overall counter uses a daily window. The application removes expired records in a cleanup run normally scheduled every five minutes. Technical delays may postpone deletion, but an expired login remains invalid. General hosting connection and security data is separate.
6. Email login links via Brevo
We use Brevo’s transactional email service for the login links you request. Under Brevo’s current terms for companies based in Germany, the provider is Brevo GmbH, Köpenicker Str. 126, 10179 Berlin. Brevo receives the recipient address, the message including the time-limited login link, and technical sending details. Your trip file and saved preferences are not included in the message.
The email enables account login (Article 6(1)(b) GDPR). Brevo processes sending data on our behalf; its contractual terms, including data processing terms, describe the processing. For possible processing by affiliates or subprocessors outside the European Economic Area, the terms provide Standard Contractual Clauses and supplementary measures, and applicable adequacy arrangements where relevant. These safeguards and the Brevo privacy information are available through these links.
Brevo maintains technical sending and delivery logs, for example acceptance, delivery and error records. These support reliable delivery and troubleshooting; our legitimate interest is based on Article 6(1)(f) GDPR. The login link’s validity does not determine retention of these logs. Storage of logs and any message previews depends on the rules configured in the sending account. According to Brevo’s retention information, transactional logs are not automatically deleted after a period unless a deletion rule is configured. You can contact us to request access or deletion.
6a. Flight and weather information you request
These additional features work only when the respective service is enabled and available. The website shows its current status. We explain below how each request is triggered. These features do not continuously monitor your trip, refresh periodically in the background or automatically send messages.
Requests go through our server at Cloudflare. We do not send your email address, account identifier, login cookies or IP address to the flight or weather provider. The provider receives the search details described below, necessary server connection data and our provider credentials. We process this information to provide the information you request; our legal basis is Article 6(1)(b) GDPR. The query is optional and is not required simply to manage your trip file.
When you open or select a saved trip with flight details, the website automatically loads the available flight status. You can also explicitly refresh it. No passenger names, booking references or complete trip files are sent to the provider.
Flight data via AeroDataBox and API.Market
Our server queries AeroDataBox, registered in British Columbia, Canada, through the API.Market intermediary service. API.Market is operated by MagicAPI Inc (Noveum.ai), 548 Market St PMB 49761, San Francisco, CA 94104-5401, USA. The request includes your flight number, selected flight date and technical query parameters. We use a saved departure airport to match results. API.Market forwards the request to AeroDataBox; both may process the request and response. We do not include your email address or other personal account details.
According to the AeroDataBox privacy information, API requests, the requesting server’s IP address and our marketplace account identifier may be stored for access control, operation and monitoring. It does not specify a fixed deletion period for all API logs. The API.Market privacy information describes logging of complete requests and responses. Content is removed after a limited period, typically 30 days; metadata such as endpoint paths, timestamps and billing details may be retained indefinitely. These provider logs are separate from our short-term cache.
Processing outside the European Economic Area, particularly in the USA and Canada, is possible. API.Market’s privacy information describes potential adequacy arrangements and contractual safeguards for international transfers. This general provider information does not promise a specific individually concluded agreement. For access or deletion requests, contact us at the address above.
To avoid repeated provider requests, we cache the flight response prepared for display for up to five minutes in access-protected storage at Cloudflare, associated with your trip and account. It contains no provider credentials and is inaccessible to other accounts. The display may use this response during that period. After expiry, the response is no longer used; cleanup removes the record, possibly later if there are technical delays. Deleting your account also removes these cached records from the active application database. We do not create a continuous flight history.
You explicitly select and save a weather location for your trip. We store its place identifier, name, country, region, coordinates and time zone. We do not access your device’s location permission. When you open or select a trip with a saved weather location, the website automatically loads the available forecast. It also loads after you save a new weather location. You can refresh it manually; there is no periodic background refresh. The loaded display can be reused in the open browser tab for up to five minutes.
Location search with GeoNames and weather via MET Norway
Location search uses a directory of larger places from GeoNames stored on our server. Your search term and selected location are not sent to GeoNames or another external geocoding service. The directory does not contain every place or accommodation. You can explicitly select a nearby city as the weather location. The GeoNames location data is used under CC BY 4.0 in a shortened and processed form.
For forecasts, our server calls Locationforecast from the Norwegian Meteorological Institute (MET Norway) in Oslo, Norway. It sends only destination coordinates limited to four decimal places, technical server connection data and our website identifier with a link to the legal notice. No personal account data, search terms, travel dates or user IP addresses are sent. MET Norway’s terms and privacy information describe API access logs stored in its own data centre in Oslo. They do not specify a general fixed deletion period for those logs.
Public weather values are cached on our server by destination coordinates and shared between requests. This cache contains no names, account identifiers or trip files. We reuse values until the provider’s stated refresh time, then check for new data when needed. Values are generally retained to check for changes for up to 24 hours after the last successful check, but at least until the provider’s expiry time. Expired records are removed during technical cleanup. The weather data is displayed under CC BY 4.0 with attribution and a note explaining our summaries by travel day.
Historical weather guidance via NASA POWER
For travel dates beyond the forecast period, we provide guidance explicitly labelled as historical, using NASA POWER. Our server queries public daily values for the last ten complete calendar years. It sends only destination coordinates rounded to a regional weather grid of approximately 0.5° latitude and 0.625° longitude, the fixed historical year range and technical request parameters. Your actual future travel dates, place names, account data and user IP address are not sent to NASA. We select and calculate the calendar period relevant to your trip on our own server.
NASA POWER is provided by NASA Langley Research Center in the USA. Server requests generate technical connection data. The general NASA privacy information describes temporary technical access logs for operations and security; it does not promise a fixed deletion period for POWER API logs. Your browser does not connect directly to NASA when these weather values load.
Public historical daily values are cached jointly by grid point and reference period for up to 30 days. The cache contains no account identifiers, trip files or future travel dates and is removed during technical cleanup. The display summarises the relevant calendar period as averages and identifies the data basis, source and CC BY 4.0. These regional model data are not a forecast for your trip.
Returned information is used for the current display. Saved flight details and your chosen weather location remain part of your trip file and can be deleted as described in section 4. To prevent abuse and limit provider requests, we keep time-limited account query counters and overall counters without trip content. These are based on our legitimate interest in reliable operation (Article 6(1)(f) GDPR); account counters expire at the end of the hour and overall counters at the end of the day. Technical cleanup follows section 5.
6b. Tripadvisor ratings at your request
For selected attractions, you can explicitly choose ‘View ratings’ in your signed-in travel area. Only then does our server request the selected place’s rating through Tripadvisor Terra from Tripadvisor LLC. It transmits the public Tripadvisor place identifier, the requested language and technical server connection data. Your email address, account identifier, travel date and IP address are not sent to Tripadvisor in this server request.
After your click, your browser loads the original Tripadvisor logo and rating graphics from Tripadvisor’s image service. This sends the service your IP address and technical browser and connection data. We suppress sending our page address as a referrer. The display is optional; these graphics are not loaded without your click. Transfers outside the European Economic Area, particularly to the USA, are possible. Information on the provider’s processing, recipients, retention and rights is available in the Tripadvisor privacy policy.
The requested display is a feature of your travel area (Article 6(1)(b) GDPR). We do not store Tripadvisor ratings or reviews in your trip file, our knowledge database or the application’s browser storage. Displayed values are removed when you switch trips or places or leave the page. Another click is needed to request them again. Browser caching of original graphics follows Tripadvisor’s image service response settings. Ratings are not used for AI tips.
To control costs and abuse, we count request attempts: a maximum of five per account per UTC day, at least 30 seconds between requests, and shared daily and overall limits. Account counters are removed when the account is deleted or otherwise expire with their time window; a technical overall counter contains no account data. These limits serve our legitimate interest in reliable and economical operation (Article 6(1)(f) GDPR).
7. Features in your browser
The leave request generator processes your entries, such as names and travel dates, solely in your browser. The generator does not send them to us, Cloudflare or an AI provider. Choosing ‘Copy’ or ‘Download’ writes the result to your clipboard or a file on your device. Nothing is sent automatically.
The website does not store these entries in cookies, local storage or session storage. You manage browser functions such as form restoration, saved files and clipboard contents through your device and browser.
These local processing steps provide the feature you requested. Where personal data is processed, we rely on Article 6(1)(f) GDPR and our interest in providing your chosen tool. Section 25(2)(2) TDDDG applies to any strictly necessary access to your device for that purpose.
8. No analytics or advertising trackers
We do not use analytics or advertising trackers on this website. Fonts and our own images are delivered through our website hosting. External videos, maps and social media content are not embedded automatically. The data flows described above apply to provider graphics you explicitly request. Clicking an external link leaves our website; the destination provider’s privacy information then applies.
9. If you email us
When you email us, we process your sender address, message and the details you provide to respond to your request. Access is limited to people responsible for handling it and the service providers used for email communication.
If your request concerns a contract or pre-contractual action you requested, the legal basis is Article 6(1)(b) GDPR. We handle other enquiries under Article 6(1)(f) GDPR; our interest is reliable communication. Providing information is voluntary, but we cannot reply without a way to contact you.
We delete correspondence once your request is resolved and further retention is unnecessary. Legal retention obligations or retention needed to establish, exercise or defend legal claims may prevent earlier deletion.
10. Your rights
Subject to the legal conditions, you have rights of access, rectification, erasure, restriction of processing and data portability (Articles 15–20 GDPR). Contact us at the address above. You may withdraw consent at any time for the future; this does not affect the lawfulness of earlier processing.
Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing unless we demonstrate overriding compelling grounds or the processing is necessary for legal claims (Article 21 GDPR).
You may lodge a complaint with a data protection supervisory authority, particularly where you normally live, work or believe an infringement occurred. The authority responsible for our registered office is the Thuringian State Commissioner for Data Protection and Freedom of Information, Häßlerstraße 8, 99096 Erfurt, Germany.
We do not make decisions about you solely by automated means that have legal or similarly significant effects.
Language and manual language selection
For an address without a language prefix, our server reads the language preference sent by your browser. German leads to the German version; English and unsupported languages lead to the English version. Explicitly opened German or English addresses are preserved. No external translation service is called.
Only when you choose a language using the language selector do we store “de” or “en” in the vmo_language cookie for 180 days. It contains no user identifier and is not used for advertising or analytics. Storage serves the language view you explicitly requested (section 25(2)(2) TDDDG); related processing is based on Article 6(1)(f) GDPR, our interest in a user-friendly presentation. You can change language or delete the cookie in your browser at any time.
Test offers and optional sharing via WhatsApp
Test offers are fictional examples with no booking function. Only after your click does the WhatsApp link pass the displayed public example text and test-page address to WhatsApp. It contains no account or trip-record data. You select the recipient and confirm sending in WhatsApp yourself. Opening or sharing does not give us marketing consent or activate a countdown.
When opened, WhatsApp processes its own connection data and, where applicable, account data. For users in the European Economic Area, the provider is WhatsApp Ireland Limited. Its own privacy notice applies, including information on recipients, possible international transfers and retention. Our website loads no WhatsApp scripts or message pixels.
Google Search Console and partnerships in preparation
We are preparing website administration in Google Search Console. Ownership is verified through a DNS record. This does not embed a Google analytics or advertising script on this website or set such a cookie. Google processes its own search and crawling data under its terms. We do not send account or trip data to Search Console.
Applications and confirmed partnerships with CJ do not activate tracking or promotional messages on this website. This also applies to the confirmed Oojo and AXA-PARTNERS.PL programmes: no tracking links, scripts or pixels for these two programmes are currently embedded here. New providers are described according to the actual data flow before integration. Approved affiliate links and their notices are identified separately.
WhatsApp privacy notice · Google privacy policy
Your trip overview as PDF
At your request, your browser creates a PDF from your confirmed, saved trip and previously loaded flight and weather information. Before downloading, we recheck your sign-in and saved trip details. Generation uses program files, fonts and the logo served only by our website; no external PDF service is involved. We do not store an additional PDF copy on our server or send it automatically. The downloaded file stays on your device even if you later delete your account. It contains personal travel information; you decide how to store, share and delete it.
Record of agreed terms
On confirmed sign-in we record the accepted terms version, selected language and confirmation time in your account. This documents the service contract and provides the appropriate language version (Article 6(1)(b) GDPR). These details remain in the active application database until account deletion and are included in your data export. Agreement to the terms is not consent to promotional messages.
