Privacy policy
This policy explains what Adin Experiences collects and processes, why we use it, who receives it, how long we keep it, and the choices available to you across our website, Ask Adin AI, and the Adin Experiences ChatGPT app and MCP tools.
Effective and last updated: August 28, 2026
1. Scope and important boundaries
Adin Experiences is owned and operated by Yariv Adin through Multifunnels, Inc., a Delaware corporation — 131 Continental Dr, Suite 305, Newark, DE 19713, USA. For purposes of applicable privacy law, Multifunnels, Inc. is the controller of data processed by Adin Experiences. You can search the public website without an account. Connecting the ChatGPT app creates a random guest authorization; it does not ask us for your real name, email address, phone number, password, or full ChatGPT conversation.
We provide discovery, comparison, and tracked links to Viator. Viator, a Tripadvisor company, completes bookings, payments, cancellations, and customer service under its own privacy policy. We do not receive or store your payment-card details. Please do not place sensitive personal information in a search prompt.
2. Data collected, purpose, and recipients
| Category | Data | Why we use it | Who receives it |
|---|---|---|---|
| Experience searches and trip preferences | Search words, destination, dates, party size, filters, selected language and currency, and optional trip context such as hotel area or arrival and departure times. | To search provider inventory, rank relevant results, display experience details, and keep your selected preferences. | Viator, a Tripadvisor company, receives the search parameters needed to return inventory. Netlify processes requests as our hosting provider. Neon receives search-measurement records only when analytics consent is active. |
| ChatGPT app and MCP activity | Tool inputs selected by ChatGPT, such as search terms, destination, dates, travelers, language, currency, product code, and the tool output returned to ChatGPT. We do not request or receive your full ChatGPT conversation. | To run the requested search or product lookup, return current results, secure the connection, prevent abuse, and diagnose failures. | OpenAI processes your ChatGPT interaction under its own terms. Viator receives the minimum provider query. Netlify processes the MCP request. Adin does not retain MCP search prompts as analytics unless you separately use the website and consent to analytics. |
| Ask Adin AI | The prompt and filters you submit, plus provider results used to prepare the answer. | To understand the request and generate a concise comparison of matching experiences. | OpenAI receives the prompt and necessary search context. Requests are made with provider-side storage disabled. Viator receives the inventory query; Netlify processes the request. |
| Consent-based product measurement | When you accept analytics: a random session identifier, search terms and filters, result count, response timing, source surface, and experiment or usability-study labels when applicable. | To measure whether searches return useful results, improve relevance and usability, and identify technical problems. Scripted or moderated research is excluded from natural-behavior metrics. | Neon stores the measurement record for Adin. Netlify processes the request. We do not sell this data or use it for third-party advertising. |
| Viator referrals and attribution | Random click ID and campaign value, selected product code, source channel, destination host, encrypted handoff URL, redirect status, and timestamps. | To create a secure tracked handoff to Viator, attribute affiliate bookings, prevent unsafe redirects, and reconcile commission reporting. | Viator receives the campaign value and referral parameters. Neon stores the Adin referral record. Netlify performs the redirect. |
| Viator booking reporting | For bookings attributed to Adin: Viator booking reference, product and option, status and event type, travel date or time, currency, price, estimated commission, amendment or cancellation status, campaign value, and the provider reporting event. | To report confirmed, amended, cancelled, rejected, and completed bookings; calculate estimated commissions; reconcile affiliate performance; and investigate support issues. | Viator supplies this data. Neon stores it for Adin. OpenAI does not receive booking-reporting records through the MCP tools. Adin does not receive or store payment-card details. |
| Anonymous OAuth and security records | Random guest identifier, authorization grant, access and refresh tokens, consent record, token timestamps, and short-lived pseudonymous rate-limit digests. We do not ask for a name, email address, phone number, or password to connect the ChatGPT app. | To authenticate the MCP connection, remember authorization, let you disconnect, enforce limits, and protect the service. | Neon stores authorization records; Netlify processes the authorization flow; OpenAI receives the resulting authorization needed to call the MCP server. |
| Cookies, preferences, and temporary trip context | Essential consent choice, optional analytics session ID, language and currency preferences, and a signed short-lived trip-context token when another MoodTrip surface sends destination or itinerary context. | To remember your choices, apply consent, and prefill a search without transferring traveler names, email, booking references, room details, or payment information. | Stored in your browser and processed by Netlify. Only the minimum verified trip context is used by Adin services. |
| Support communications | Your email address and any information you choose to include when contacting us. | To answer your request, investigate an issue, and maintain a support record. | Adin personnel and service providers needed to deliver email and investigate the request; Viator or OpenAI only when necessary and with data minimized. |
| Network and security data | Internet Protocol address, user-agent or device information, requested URL, request time, response status, and security signals that may appear in hosting, firewall, or authentication logs. | To deliver the service, prevent abuse, investigate failures, protect accounts and systems, and meet legal obligations. | Netlify and other infrastructure or security providers process these records for Adin. We do not use raw network data for advertising profiles. |
3. Service providers and independent platforms
- Viator / Tripadvisor supplies product content, photos, pricing, referral destinations, and attributed booking reports, and independently operates checkout and bookings.
- OpenAI operates ChatGPT and processes ChatGPT interactions under its own terms. For Ask Adin AI, OpenAI processes the prompt and minimum necessary context with storage disabled in our API request.
- Netlify hosts the website and server functions, delivers content, and may maintain infrastructure and security logs needed to operate and protect the service.
- Neon hosts our serverless PostgreSQL database for consented measurement, referrals, booking reporting, and anonymous authorization records.
We disclose data to authorities or professional advisers only when required by law or reasonably necessary to protect users, rights, or service security. We do not sell personal data, create advertising profiles, or share search activity for third-party targeted advertising.
If ownership of the service changes through a merger, financing, acquisition, reorganization, or sale of assets, relevant data may be transferred to the successor subject to this policy and applicable law. We will provide notice where required.
4. Legal bases
Where applicable law requires a legal basis, we process data to provide the service you request and perform our agreement with you; with your consent for optional analytics; for our legitimate interests in service security, fraud prevention, troubleshooting, and affiliate reconciliation; and to meet legal obligations. You may withdraw analytics consent at any time without affecting earlier lawful processing.
Adin Experiences does not make decisions that produce legal or similarly significant effects about you. Search ranking and AI summaries help compare experiences; you choose whether to open a provider link or complete a booking with Viator.
5. Retention
We keep each category only for the period needed for the stated purpose. Backups and legal holds may delay final deletion for a limited period, with access restricted.
- Consent-based search measurement
- Up to 180 days, then search text and session identifiers are deleted or irreversibly pseudonymized.
- Referral click not matched to a booking
- Up to 180 days.
- Referral and booking-reporting record matched to a booking
- Up to 24 months after the last booking event, unless a longer period is required for tax, fraud prevention, dispute resolution, or legal compliance.
- OAuth access token
- Up to 1 hour.
- OAuth session and refresh token
- Up to 30 days; the random guest authorization record remains until you disconnect or request deletion where technically identifiable.
- Pseudonymous security and rate-limit digest
- Up to 24 hours.
- Language and currency preferences
- Up to 1 year in your browser, or until you clear site data.
- Consent choice and optional analytics session cookie
- Consent choice: up to 180 days. Analytics session: up to 30 days and removed when you choose essential only.
- Signed trip-context token
- Up to 10 minutes; only a replay-prevention identifier is retained until the token expires.
- Support communication
- Normally up to 24 months after the request is closed, unless law or an active dispute requires longer.
- Hosting and security logs
- Application-level security records are kept for up to 30 days unless needed longer for an active incident, fraud investigation, legal hold, or legal obligation. Infrastructure logs controlled by Netlify follow Netlify's applicable service retention. Our application does not copy raw IP addresses into product analytics.
6. Your choices and controls
- Use Privacy settings on the website to accept optional analytics or select essential cookies only. Choosing essential only removes the analytics session cookie.
- Change language and currency from the site menu, or clear site data in your browser to remove stored preferences.
- Review, edit, or remove optional trip context before searching. Trip-context tokens expire automatically.
- Disconnect Adin Experiences from ChatGPT to stop future MCP access. You can reconnect later with a new authorization.
- Email us to request access, correction, deletion, restriction, portability, or objection where applicable. Because MCP access is anonymous, include the relevant connection or referral identifier if available; we will not ask for unnecessary data.
- You may complain to your local data-protection authority. We will not discriminate against you for exercising privacy rights.
7. Security and international processing
We use encrypted transport, server-only provider credentials, scoped OAuth tokens, signed short-lived context, strict redirect allowlists, access controls, and database role separation. No internet service is risk-free. Our providers may process data in countries outside yours; where required, transfers use recognized safeguards or other lawful mechanisms.
8. Children
Adin Experiences is not directed to children under 13, and we do not knowingly collect personal data from children. Traveler counts and age bands are search parameters and should not include a child's name or contact details.
9. Changes to this policy
We will update the date above when this policy changes. Material changes will be highlighted on the site or in the connection flow before they take effect where required.
10. Contact
For privacy questions or requests, contact Multifunnels, Inc. at yariv@multifunnels.com. You may also write to 131 Continental Dr, Suite 305, Newark, DE 19713, USA. You can also review our support page.
