Privacy Policy
Effective date: 1 October 2026
Lentii ApS operates lentii.com and blog.lentii.com. We are the data controller for the personal data described here. You can reach us at hello@lentii.com or at Ceresbyen 46, st. 2., 8000 Aarhus C, Denmark. Our company registration number is CVR 40600485.
What we collect, and why
When you create an account, we collect your email address and your name. You can add a profile picture, a country, a city and a date of birth if you want to — none of that is required. Lentii is for people aged 16 and over.
When you sign in with Google or Facebook, we receive your name, email address and profile picture from them, plus the account identifier that lets us recognise you next time. We never receive your password, and we never post anything on your behalf.
When you use the service, we store what you create: trip lists, ideas, the people you invite, and who has access to what. The service does not work without this.
Automatically, on every visit, our servers record your IP address, your browser and device, and which pages you open and when. This is ordinary web-server logging and happens whether or not you have an account.
When you accept our cookie banner, we also allow measurement and advertising cookies. If you decline, none of that runs, and everything else works exactly the same.
Why we are allowed to process it
We rely on our contract with you for everything needed to run your account: your login details, your trip lists, invitations, and the emails confirming something you did.
We rely on your consent for measurement and advertising cookies and for marketing emails. You can withdraw it at any time, without giving a reason.
We rely on legitimate interests for keeping the service secure and working: server logs, abuse prevention, and detecting which currency to show you.
We rely on legal obligations where the law requires us to keep something, such as accounting records.
Cookies
Some cookies are necessary and are set without asking: they keep you signed in, remember your currency, and store your answer to the cookie banner itself.
Everything else waits for your yes. On lentii.com, nothing else loads until you accept — no measurement, no advertising tags, no cookies from those services.
On our blog, blog.lentii.com, that gating is not in place yet. Analytics and advertising tools currently load when you open a blog page. We are changing this, and we are removing two tools we no longer use — Hotjar and Segment — in the process. Until that work is finished, the blog behaves as described here rather than as described above.
Who receives your data
Hosting. Our servers run at DigitalOcean in Frankfurt, Germany. Everything the service stores lives there.
Email. SendPulse sends the emails the service needs — confirmations, invitations, password resets — and our newsletters if you asked for them.
Measurement and advertising. After you accept, Google Analytics and Google Tag Manager receive usage data, device data and your IP address. Under Google’s own advertising terms, Google decides some of its own purposes for that data rather than acting only on our instructions. The Meta pixel tells Meta which of our pages you visited so we can measure our advertising; for that, Meta and we decide together what happens.
Sign-in. Google and Meta provide the sign-in. Once your profile data reaches us, we are responsible for it.
Maps, translation and spam protection. Google provides map and place lookups, translation, and reCAPTCHA, which checks that a form is filled in by a person.
Video. Our videos are hosted by Vimeo. When a page with a player loads, Vimeo receives your IP address and can set its own cookies.
Content delivery. Parts of our pages load from jsDelivr, run by Volentio JSD Limited in the United Kingdom, and from Cloudflare’s cdnjs. Delivering a file requires your IP address, so those providers see it.
Currency. When you first arrive, we ask ipdata.co which country your IP address belongs to, so we can show prices sensibly. We send your IP address for that lookup.
Blog. blog.lentii.com uses HubSpot for contact forms and blog analytics.
Travel content. When you search for a destination, we pass your search words to Viator, part of Tripadvisor, to fetch matching experiences. We do not send your name, your IP address or your account details.
Images. Some images are served directly from Unsplash, which means Unsplash receives the IP address of whoever views the page.
We do not sell your personal data, and we share it with nobody outside this list except where the law requires it.
Data leaving the EU
Your account and everything you create sits on servers in Frankfurt. Some companies above are American, and data reaching them may be processed outside the EU. Where that happens, the transfer rests on the European Commission’s standard contractual clauses, or on the EU-US Data Privacy Framework where the provider is certified under it. Ask us and we will tell you which applies to a specific provider.
How long we keep it
We keep your account and its contents for as long as you have an account. When you delete your account, we delete its contents.
For everything else, we keep data for as long as the purpose requires and no longer. We are currently setting fixed retention periods for server logs, security records and sign-in tokens, and we will publish them here once they are set. Records we must keep for accounting purposes are kept for five years, as Danish law requires.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to limit what we do with it, object to processing based on legitimate interests, and ask for your data in a portable format. Where we rely on consent, you can withdraw it at any time.
You can also ask us for a copy of the content you created — your trip lists and what is in them — and we will send it to you free of charge.
Write to hello@lentii.com. We answer within one month, and there is no charge. If you think we have handled your data badly, you can also complain to Datatilsynet, the Danish Data Protection Agency, at datatilsynet.dk.
Age
Lentii is for people aged 16 and over. If we learn that we hold data about someone younger, we delete it. If you are a parent or guardian and believe your child has given us data, contact us and we will remove it.
Changes to this policy
When we change this policy in a way that matters, we will tell you by email at least 30 days before the change takes effect, and we will say plainly what changed. If a change affects something we do on the basis of your consent, we will ask for your consent again rather than simply informing you.
This document is also published in Danish. If the two versions differ, the Danish version applies.
Lentii ApS
Ceresbyen 46, st. 2.
8000 Aarhus C
Denmark
CVR 40600485
