Okurio
Privacy Policy
1. Data Controller
Personal data processed through the Okurio application is controlled by Thomas VIAL, an individual, located in Paris, France.
Privacy support is available on our support page.
2. Data We Collect
Okurio supports two kinds of account, and both create a record on our servers: the account without email (created when you simply enter your first name) and the full account (created with an email address or through Apple/Google). In both cases your wishlists and reservations are stored on our servers rather than only on your device, so they can be synchronised and shared.
Depending on your use of the service, we may process:
- Account data without email: first name, avatar, and date of birth when you provide them (date of birth is optional).
- Full account data: email, name, avatar, date of birth.
- Wishlist and item data: titles, descriptions, prices, images, URLs, and reservation status.
- Technical and security data: application logs, session information, auth tokens, password reset tokens, push tokens (if enabled).
- IP address: used at request time for two things — showing, in security emails, where a sensitive request (such as a password reset) came from, so you can judge whether it was really you; and deriving your country. It is attached neither to your profile nor to your wishlists; as on any web service, it appears temporarily in the server's technical logs, which roll over continuously.
- Country and language: your country is derived from your IP address, your language from the one the app displays. We never ask you for either. The country is visible and editable at any time in your profile: if the guess is wrong you correct it, and your choice is never overwritten afterwards — you can also hand it back to automatic detection. The language is only observed: your device or browser setting decides it, never a field in your profile.
- Transactional email data: delivery of technical links (password reset, notifications related to your wishlists and reservations).
3. Purposes and Legal Bases
- Service delivery (contract performance): account creation, authentication, wishlist management, reservation management.
- Security and abuse prevention (legitimate interest): account protection, incident detection, defense of legal rights.
- Understanding our audience (legitimate interest): knowing which countries and languages Okurio is used in, so we can decide what to translate and what to build. This is used in aggregate; it never profiles you and never personalises what you see.
- Legal obligations: limited retention where required by law.
4. Email and Technical Uses
We collect and use email addresses for technical purposes required to operate the service, including forgotten-password links and transactional emails.
5. Affiliate and External Links
Some external links may be affiliate links. Okurio may receive a commission after click and purchase, at no additional cost to users.
6. No Sale of Personal Data
Personal data is not sold to third parties.
7. Recipients and Data Location
Data is accessible only to authorized persons or services strictly required to run Okurio. Production data is hosted in France. Hosting provider: OVHcloud (OVH), France.
8. Retention Period
Data is retained while your account is active. When your account is deleted, associated data is deleted, subject to temporary technical backups and legal retention duties. Your IP address is the exception: we do not store it on your account, and the technical logs it appears in roll over continuously. Only the country derived from it is kept, and that is refreshed at most once a day for as long as you have not set it yourself. An account without email follows the same rule: it is retained as long as it is used from the device it was created on, and you can delete it at any time from the app. Without an email attached, it cannot be recovered once the app is removed.
9. Security Measures
Reasonable technical and organizational measures are implemented, including encrypted network transport in production, encryption at rest at infrastructure level, password hashing, and hashing of sensitive tokens.
10. Your Rights
Under GDPR, you have rights including access, rectification, erasure, restriction, objection, and portability where applicable. You can exercise your rights from our support page.
11. Minors
For users in France, the recommended minimum age to use the service is 15 years old.
12. CNIL Complaint
If you believe your rights are not respected, you may submit a complaint to the French supervisory authority (CNIL).
13. Policy Updates
This policy may be updated at any time. The "Last updated" date at the top of this page applies.