Privacy policy

This policy explains what Adin Experiences collects and processes, why we use it, who receives it, how long we keep it, and the choices available to you across our website, Ask Adin AI, and the Adin Experiences ChatGPT app and MCP tools.

Effective and last updated: August 28, 2026

1. Scope and important boundaries

Adin Experiences is owned and operated by Yariv Adin through Multifunnels, Inc., a Delaware corporation — 131 Continental Dr, Suite 305, Newark, DE 19713, USA. For purposes of applicable privacy law, Multifunnels, Inc. is the controller of data processed by Adin Experiences. You can search the public website without an account. Connecting the ChatGPT app creates a random guest authorization; it does not ask us for your real name, email address, phone number, password, or full ChatGPT conversation.

We provide discovery, comparison, and tracked links to Viator. Viator, a Tripadvisor company, completes bookings, payments, cancellations, and customer service under its own privacy policy. We do not receive or store your payment-card details. Please do not place sensitive personal information in a search prompt.

2. Data collected, purpose, and recipients

CategoryDataWhy we use itWho receives it
Experience searches and trip preferencesSearch words, destination, dates, party size, filters, selected language and currency, and optional trip context such as hotel area or arrival and departure times.To search provider inventory, rank relevant results, display experience details, and keep your selected preferences.Viator, a Tripadvisor company, receives the search parameters needed to return inventory. Netlify processes requests as our hosting provider. Neon receives search-measurement records only when analytics consent is active.
ChatGPT app and MCP activityTool inputs selected by ChatGPT, such as search terms, destination, dates, travelers, language, currency, product code, and the tool output returned to ChatGPT. We do not request or receive your full ChatGPT conversation.To run the requested search or product lookup, return current results, secure the connection, prevent abuse, and diagnose failures.OpenAI processes your ChatGPT interaction under its own terms. Viator receives the minimum provider query. Netlify processes the MCP request. Adin does not retain MCP search prompts as analytics unless you separately use the website and consent to analytics.
Ask Adin AIThe prompt and filters you submit, plus provider results used to prepare the answer.To understand the request and generate a concise comparison of matching experiences.OpenAI receives the prompt and necessary search context. Requests are made with provider-side storage disabled. Viator receives the inventory query; Netlify processes the request.
Consent-based product measurementWhen you accept analytics: a random session identifier, search terms and filters, result count, response timing, source surface, and experiment or usability-study labels when applicable.To measure whether searches return useful results, improve relevance and usability, and identify technical problems. Scripted or moderated research is excluded from natural-behavior metrics.Neon stores the measurement record for Adin. Netlify processes the request. We do not sell this data or use it for third-party advertising.
Viator referrals and attributionRandom click ID and campaign value, selected product code, source channel, destination host, encrypted handoff URL, redirect status, and timestamps.To create a secure tracked handoff to Viator, attribute affiliate bookings, prevent unsafe redirects, and reconcile commission reporting.Viator receives the campaign value and referral parameters. Neon stores the Adin referral record. Netlify performs the redirect.
Viator booking reportingFor bookings attributed to Adin: Viator booking reference, product and option, status and event type, travel date or time, currency, price, estimated commission, amendment or cancellation status, campaign value, and the provider reporting event.To report confirmed, amended, cancelled, rejected, and completed bookings; calculate estimated commissions; reconcile affiliate performance; and investigate support issues.Viator supplies this data. Neon stores it for Adin. OpenAI does not receive booking-reporting records through the MCP tools. Adin does not receive or store payment-card details.
Anonymous OAuth and security recordsRandom guest identifier, authorization grant, access and refresh tokens, consent record, token timestamps, and short-lived pseudonymous rate-limit digests. We do not ask for a name, email address, phone number, or password to connect the ChatGPT app.To authenticate the MCP connection, remember authorization, let you disconnect, enforce limits, and protect the service.Neon stores authorization records; Netlify processes the authorization flow; OpenAI receives the resulting authorization needed to call the MCP server.
Cookies, preferences, and temporary trip contextEssential consent choice, optional analytics session ID, language and currency preferences, and a signed short-lived trip-context token when another MoodTrip surface sends destination or itinerary context.To remember your choices, apply consent, and prefill a search without transferring traveler names, email, booking references, room details, or payment information.Stored in your browser and processed by Netlify. Only the minimum verified trip context is used by Adin services.
Support communicationsYour email address and any information you choose to include when contacting us.To answer your request, investigate an issue, and maintain a support record.Adin personnel and service providers needed to deliver email and investigate the request; Viator or OpenAI only when necessary and with data minimized.
Network and security dataInternet Protocol address, user-agent or device information, requested URL, request time, response status, and security signals that may appear in hosting, firewall, or authentication logs.To deliver the service, prevent abuse, investigate failures, protect accounts and systems, and meet legal obligations.Netlify and other infrastructure or security providers process these records for Adin. We do not use raw network data for advertising profiles.

3. Service providers and independent platforms

  • Viator / Tripadvisor supplies product content, photos, pricing, referral destinations, and attributed booking reports, and independently operates checkout and bookings.
  • OpenAI operates ChatGPT and processes ChatGPT interactions under its own terms. For Ask Adin AI, OpenAI processes the prompt and minimum necessary context with storage disabled in our API request.
  • Netlify hosts the website and server functions, delivers content, and may maintain infrastructure and security logs needed to operate and protect the service.
  • Neon hosts our serverless PostgreSQL database for consented measurement, referrals, booking reporting, and anonymous authorization records.

We disclose data to authorities or professional advisers only when required by law or reasonably necessary to protect users, rights, or service security. We do not sell personal data, create advertising profiles, or share search activity for third-party targeted advertising.

If ownership of the service changes through a merger, financing, acquisition, reorganization, or sale of assets, relevant data may be transferred to the successor subject to this policy and applicable law. We will provide notice where required.

Where applicable law requires a legal basis, we process data to provide the service you request and perform our agreement with you; with your consent for optional analytics; for our legitimate interests in service security, fraud prevention, troubleshooting, and affiliate reconciliation; and to meet legal obligations. You may withdraw analytics consent at any time without affecting earlier lawful processing.

Adin Experiences does not make decisions that produce legal or similarly significant effects about you. Search ranking and AI summaries help compare experiences; you choose whether to open a provider link or complete a booking with Viator.

5. Retention

We keep each category only for the period needed for the stated purpose. Backups and legal holds may delay final deletion for a limited period, with access restricted.

Consent-based search measurement
Up to 180 days, then search text and session identifiers are deleted or irreversibly pseudonymized.
Referral click not matched to a booking
Up to 180 days.
Referral and booking-reporting record matched to a booking
Up to 24 months after the last booking event, unless a longer period is required for tax, fraud prevention, dispute resolution, or legal compliance.
OAuth access token
Up to 1 hour.
OAuth session and refresh token
Up to 30 days; the random guest authorization record remains until you disconnect or request deletion where technically identifiable.
Pseudonymous security and rate-limit digest
Up to 24 hours.
Language and currency preferences
Up to 1 year in your browser, or until you clear site data.
Consent choice and optional analytics session cookie
Consent choice: up to 180 days. Analytics session: up to 30 days and removed when you choose essential only.
Signed trip-context token
Up to 10 minutes; only a replay-prevention identifier is retained until the token expires.
Support communication
Normally up to 24 months after the request is closed, unless law or an active dispute requires longer.
Hosting and security logs
Application-level security records are kept for up to 30 days unless needed longer for an active incident, fraud investigation, legal hold, or legal obligation. Infrastructure logs controlled by Netlify follow Netlify's applicable service retention. Our application does not copy raw IP addresses into product analytics.

6. Your choices and controls

  • Use Privacy settings on the website to accept optional analytics or select essential cookies only. Choosing essential only removes the analytics session cookie.
  • Change language and currency from the site menu, or clear site data in your browser to remove stored preferences.
  • Review, edit, or remove optional trip context before searching. Trip-context tokens expire automatically.
  • Disconnect Adin Experiences from ChatGPT to stop future MCP access. You can reconnect later with a new authorization.
  • Email us to request access, correction, deletion, restriction, portability, or objection where applicable. Because MCP access is anonymous, include the relevant connection or referral identifier if available; we will not ask for unnecessary data.
  • You may complain to your local data-protection authority. We will not discriminate against you for exercising privacy rights.

7. Security and international processing

We use encrypted transport, server-only provider credentials, scoped OAuth tokens, signed short-lived context, strict redirect allowlists, access controls, and database role separation. No internet service is risk-free. Our providers may process data in countries outside yours; where required, transfers use recognized safeguards or other lawful mechanisms.

8. Children

Adin Experiences is not directed to children under 13, and we do not knowingly collect personal data from children. Traveler counts and age bands are search parameters and should not include a child's name or contact details.

9. Changes to this policy

We will update the date above when this policy changes. Material changes will be highlighted on the site or in the connection flow before they take effect where required.

10. Contact

For privacy questions or requests, contact Multifunnels, Inc. at yariv@multifunnels.com. You may also write to 131 Continental Dr, Suite 305, Newark, DE 19713, USA. You can also review our support page.