Privacy Policy
Effective date: 1 October 2026
Lentii ApS operates lentii.com and blog.lentii.com. We are the data controller for the personal data described here. You can reach us at hello@lentii.com or at Ceresbyen 46, st. 2., 8000 Aarhus C, Denmark. Our company registration number is CVR 40600485.
What we collect, and why
When you create an account, we collect your email address and your name. You can add a profile picture, a country, a city and a date of birth if you want to — none of that is required. Lentii is for people aged 16 and over.
When you sign in with Google or Facebook, we receive your name, email address and profile picture from them, plus the account identifier that lets us recognise you next time. We never receive your password, and we never post anything on your behalf.
When you use the service, we store what you create: trip lists, ideas, the people you invite, and who has access to what. The service does not work without this.
Automatically, on every visit, our servers record your IP address, your browser and device, and which pages you open and when. This is ordinary web-server logging and happens whether or not you have an account.
When you accept our cookie banner, we also allow measurement and advertising cookies. If you decline, none of that runs, and everything else works exactly the same.
Why we are allowed to process it
We rely on our contract with you for everything needed to run your account: your login details, your trip lists, invitations, and the emails confirming something you did.
We rely on your consent for measurement and advertising cookies and for marketing emails. You can withdraw it at any time, without giving a reason.
We rely on legitimate interests for keeping the service secure and working: server logs, abuse prevention, and detecting which currency to show you.
We rely on legal obligations where the law requires us to keep something, such as accounting records.
Cookies
Cookies are small files a website stores in your browser. We also use similar technologies that store information in your browser without a cookie, such as local storage. We ask before we use any of them for anything other than making the site work.
When you first visit lentii.com or blog.lentii.com, a banner lets you choose per purpose: statistics and marketing. Allow selected with nothing switched on means no. Your choice is stored for 12 months and applies to both sites. You can change it at any time under Cookie settings in the menu on lentii.com, or at the bottom of every page on blog.lentii.com. Withdrawing deletes that purpose’s cookies from your browser, and declining changes nothing about the service you get.
Necessary — always on
These make the site work and contain no advertising identifiers.
| Name | Set by | Purpose | Expires |
|---|---|---|---|
| lentii_access_token | Lentii | Keeps you logged in | 1 hour |
| lentii_refresh_token | Lentii | Renews your login without asking you to sign in again | 14 days |
| cc_cookie | Lentii | Remembers your answer to the cookie banner | 12 months |
| language, currency (local storage) | Lentii | Remembers the language and currency you picked | Until you clear your browser |
When you create a trip list without an account, Google reCAPTCHA checks that you are not a robot and may store a token in your browser for that check only.
Statistics — only with your consent
Used on blog.lentii.com only. Google Analytics shows us which articles are read.
| Name | Set by | Purpose | Expires |
|---|---|---|---|
| _ga | Tells one visitor from another | 2 years | |
| _ga_* | Keeps the state of the current visit | 2 years |
Marketing — only with your consent
Meta measures our advertising and lets us reach people who have shown an interest in Lentii. HubSpot, on the blog only, connects a visit to a newsletter sign-up if you make one. Push notifications on the blog (SendPulse) are only offered after you accept marketing, and only start if you then allow them in your browser.
| Name | Set by | Purpose | Expires |
|---|---|---|---|
| _fbp | Meta | Tells one browser from another for ad measurement | 3 months |
| _fbc | Meta | Stores the ad you clicked to get here | 3 months |
| hubspotutk | HubSpot | Tells one visitor from another | 6 months |
| __hstc | HubSpot | Counts visits and when they happened | 6 months |
| __hssc | HubSpot | Keeps the state of the current visit | 30 minutes |
Videos on lentii.com play through Vimeo in “do not track” mode, so Vimeo sets no cookie.
Who receives your data
Hosting. Our servers run at DigitalOcean in Frankfurt, Germany. Everything the service stores lives there.
Email. SendPulse sends the emails the service needs — confirmations, invitations, password resets — and our newsletters if you asked for them.
Measurement and advertising. After you accept, Google Analytics and Google Tag Manager receive usage data, device data and your IP address. Under Google’s own advertising terms, Google decides some of its own purposes for that data rather than acting only on our instructions. The Meta pixel tells Meta which of our pages you visited so we can measure our advertising; for that, Meta and we decide together what happens.
Sign-in. Google and Meta provide the sign-in. Once your profile data reaches us, we are responsible for it.
Maps, translation and spam protection. Google provides map and place lookups, translation, and reCAPTCHA, which checks that a form is filled in by a person.
Video. Our videos are hosted by Vimeo. When a page with a player loads, Vimeo receives your IP address and can set its own cookies.
Content delivery. Parts of our pages load from jsDelivr, run by Volentio JSD Limited in the United Kingdom, and from Cloudflare’s cdnjs. Delivering a file requires your IP address, so those providers see it.
Currency. When you first arrive, we ask ipdata.co which country your IP address belongs to, so we can show prices sensibly. We send your IP address for that lookup.
Blog. blog.lentii.com uses HubSpot for contact forms and blog analytics.
Travel content. When you search for a destination, we pass your search words to Viator, part of Tripadvisor, to fetch matching experiences. We do not send your name, your IP address or your account details.
Images. Some images are served directly from Unsplash, which means Unsplash receives the IP address of whoever views the page.
We do not sell your personal data, and we share it with nobody outside this list except where the law requires it.
Data leaving the EU
Your account and everything you create sits on servers in Frankfurt. Some companies above are American, and data reaching them may be processed outside the EU. Where that happens, the transfer rests on the European Commission’s standard contractual clauses, or on the EU-US Data Privacy Framework where the provider is certified under it. Ask us and we will tell you which applies to a specific provider.
How long we keep it
We keep your account and its contents for as long as you have an account. When you delete your account, we delete its contents.
For everything else, we keep data for as long as the purpose requires and no longer. We are currently setting fixed retention periods for server logs, security records and sign-in tokens, and we will publish them here once they are set. Records we must keep for accounting purposes are kept for five years, as Danish law requires.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to limit what we do with it, object to processing based on legitimate interests, and ask for your data in a portable format. Where we rely on consent, you can withdraw it at any time.
You can also ask us for a copy of the content you created — your trip lists and what is in them — and we will send it to you free of charge.
Write to hello@lentii.com. We answer within one month, and there is no charge. If you think we have handled your data badly, you can also complain to Datatilsynet, the Danish Data Protection Agency, at datatilsynet.dk.
Age
Lentii is for people aged 16 and over. If we learn that we hold data about someone younger, we delete it. If you are a parent or guardian and believe your child has given us data, contact us and we will remove it.
Changes to this policy
When we change this policy in a way that matters, we will tell you by email at least 30 days before the change takes effect, and we will say plainly what changed. If a change affects something we do on the basis of your consent, we will ask for your consent again rather than simply informing you.
This document is also published in Danish. If the two versions differ, the Danish version applies.
Lentii ApS
Ceresbyen 46, st. 2.
8000 Aarhus C
Denmark
CVR 40600485
