Privacy Policy
Last updated: September 7, 2026
1. Who we are
Sotto is operated by Sean Gjos, an individual carrying on business as a sole proprietorship in British Columbia, Canada ("Sotto," "we," "us").
Questions, requests, or complaints about privacy: hello@sottocollection.com
Sean Gjos is the person responsible for the protection of personal information, and acts as the data controller for the purposes of the UK and EU GDPR where those apply.
2. What this policy covers
This policy covers the Sotto application and the website at sottocollection.com.
Sotto is invitation-only and restricted to adults. It is a private collection of travel recommendations shared among a closed network of people connected by invitation. It is not a public review site, and content contributed to Sotto is not published publicly or indexed by search engines.
3. Information we collect
3.1 Information you give us
When you join: your name, and either an email address or a mobile phone number, depending on which you choose to use for sign-in. Sotto has no passwords — you sign in with a one-time code sent to your email or phone.
Optionally, in your profile: your home city, how you would like your name shown to other members (full name, or first name and last initial), and whether you want to receive our weekly email summary.
When you contribute a recommendation (a "gem"): the name of the place, the country, a category, and a note of up to 225 characters. Optionally an address, a website link, and a locality, and whether you consider it a must-see.
When you interact with recommendations: places you save, vouches you add (with an optional comment), and post-trip feedback (a rating, whether you found it a must-see, and an optional comment).
When you declare a trip: the country, city, and dates of travel you plan, whether that trip is visible to your network, to your household, or to no one, and the precision at which you have chosen to show the dates.
When you invite someone: their name and their email address or phone number, plus an optional personal message. See §6 — this is information about a person who has not yet agreed to anything.
When you link a household: the identity of the other member and, if you choose, an adjusted start date agreed between you.
When you contact us: your name, your message, and your email address if you provide one for reply.
3.2 Information generated as you use Sotto
Connection information. Who invited you, and your resulting position in the network of invitations. This determines how far you are from other members and is fundamental to how Sotto works — recommendations are shown with their source and the path connecting you to it.
Activity information. When you last used Sotto, whether you have completed onboarding steps, what notifications you have been sent and whether you have viewed them, and when feedback prompts were shown to you.
Usage measurements. We compute and store summary facts about how Sotto is being used — for example, whether a member had an active trip and an unseen recommendation on a given visit, or whether someone they invited went on to join. These are used to understand whether the product works. We do not use any third-party analytics service, advertising network, or tracking technology.
Push notification details. If you enable notifications, we store the subscription your browser issues, which includes an endpoint address unique to that browser or device and two cryptographic keys used to encrypt messages to it.
3.3 What we do not collect
We do not access your device's contacts or address book. There is no contact import, no contact permission request, and no bulk invitation feature. Every invitation is created by an inviter typing a name and a single contact detail by hand.
We do not request or collect your device's location. Every location in Sotto is either typed by a member or comes from a place a member deliberately selected from a search.
We do not use advertising, advertising identifiers, or third-party trackers, and we do not sell personal information.
3.4 Sensitive information — travel plans
Declared trips can reveal when you expect to be away from home. We treat this as the most sensitive information in Sotto, and we limit it in three ways:
- You choose who sees each trip — your network, your household only, or no one.
- By default, other members see only the month or months of your trip, not the exact dates. For any individual trip, at any time, you may choose to show your exact dates to your network instead. A household partner you have linked with always sees exact dates, since you are travelling together.
- You can withdraw a declaration at any time.
Reduced precision governs what other members are shown, not what we hold. You enter exact dates when you declare a trip, and we store them either way.
We never put a trip in an email. Our weekly summary (§5) names countries only — never who is travelling, never a city, and never a date or a month. Your trip is visible only inside Sotto, to the people you chose, and only after they sign in.
We do not disclose declared trips outside Sotto for any purpose.
4. Why we collect it, and on what basis
Under Canadian law we rely on your consent, which you give by creating an account and by choosing to contribute, save, vouch, declare a trip, or invite someone. Contributing anything to Sotto is voluntary; you can use Sotto without adding a recommendation or declaring a trip.
Where the UK or EU GDPR applies to a member, our lawful bases are:
| Purpose | Basis |
|---|---|
| Creating and operating your account; authenticating you | Performance of a contract |
| Showing recommendations with their source and connection path | Performance of a contract — this is the core function of the service |
| Sending one-time sign-in codes | Performance of a contract |
| Push notifications | Consent, given when you enable them, withdrawable at any time |
| Sending you a weekly email summary of activity in your network | Legitimate interests — keeping you informed about activity in the network you joined. Every summary carries a one-click unsubscribe, and you can turn it off in Settings at any time |
| Declared trips and household links | Consent |
| Understanding whether the product works (usage measurements) | Legitimate interests — operating and improving a service we provide |
| Retaining records of who invited whom | Legitimate interests — the integrity of the network structure other members depend on |
| Responding to your requests, and meeting legal obligations | Legal obligation / legitimate interests |
We do not use your information for automated decision-making that produces legal or similarly significant effects.
5. Who else receives your information
We use the following service providers. Each receives only what it needs to perform its function. Except as described in the notes below, none is permitted to use your information for its own purposes.
| Provider | Function | What it receives |
|---|---|---|
| Supabase | Database, authentication | All information described in §3 |
| Netlify | Hosting and delivery | Web traffic, including IP addresses, at the infrastructure level |
| Resend | Email delivery | Email addresses and message content for sign-in codes, invitations, the weekly summary described below, and messages you send us |
| Twilio | SMS delivery | Mobile phone numbers, for one-time sign-in codes |
| Google (Places) | Place search | Text you type into a place search, sent directly from your browser |
| Your browser's push service (Google, Mozilla, Apple, or another) | Notification delivery | Notification content and your subscription endpoint |
About place search. When you search for a place while adding a recommendation, your browser sends what you type directly to Google. This happens as you type, before you select anything. Google's handling of that information is governed by Google's own privacy policy, not this one.
About SMS delivery. If you sign in by phone, Twilio delivers your one-time codes. As a telecommunications provider, Twilio also handles the phone number and the delivery records generated in sending each message for its own purposes — operating and securing its network, preventing fraud and abuse, billing, meeting its regulatory obligations, and developing its own services — under its own terms rather than solely on our instructions. It receives nothing else about you: no name, no content beyond the sign-in code itself, and nothing you contribute to Sotto.
About the weekly summary. Once a week we send you a short email telling you there has been activity in your network. It names countries only — how many recommendations were added and which countries they are in, and which countries members near you have declared trips to.
It deliberately leaves out everything else. No member is named. No city, no date, and no timing is given for any trip. Nothing about you appears in anyone else's summary except as an unnamed count against a country. To see who added what, or who is travelling where, you have to sign in to Sotto — where the visibility choices described in §3.4 and §7 still apply, exactly as they always have.
We send nothing in a week with no activity. Every summary carries a one-click unsubscribe that works without signing in, and you can turn it off in Settings at any time. Turning it off never affects your sign-in codes, which are part of how you access your account.
We do not share your information with anyone else, and we do not sell it. We may disclose information if we are legally required to, or where necessary to protect the safety of a person.
6. Information about people who are not members
This section describes information about you if a Sotto member has invited you but you have not joined.
When a member invites someone, they enter that person's name and one contact detail — an email address or a mobile number — so we can deliver the invitation. That person has not agreed to anything at that point.
We limit this as follows:
- We collect only a name and one contact detail. Nothing else.
- We use it only to deliver that invitation and to recognise the person if they accept.
- We do not send marketing, reminders, or any communication other than the invitation itself.
- We do not share it, and we do not use it to build any profile.
- If the invitation is not accepted within 60 days, it expires. The name and contact detail are deleted, and the invitation link stops working.
- Anyone may ask us to delete their information at any time by writing to hello@sottocollection.com, whether or not they were ever a member. We do not require an account to make that request.
We ask members to invite only people they know personally and who they reasonably expect will welcome the invitation.
7. What other members can see
Sotto works by attribution. A recommendation you contribute is shown to other members with your name attached, along with how you are connected to them. This is deliberate and is the reason Sotto exists — a recommendation from a known person is the product.
Members within your network can see:
- Your name, shown according to your display preference
- Your home city, if you have provided one and have not chosen to hide it
- Recommendations you have contributed, and vouches and comments you have added
- Who invited you, and the chain of invitations connecting you to them
- Declared trips, to the extent and precision you have chosen for each one
Other members cannot see your email address, your phone number, what you have saved privately, your post-trip ratings and feedback except as aggregated signal on a recommendation, or trips you have marked as not visible.
Sotto is closed. Nothing you contribute is published publicly.
8. Where your information is stored
Your information is stored and processed in the United States. Although Sotto is operated from British Columbia, the services we rely on are located there:
| Provider | Location |
|---|---|
| Supabase — our database and authentication | Ohio, United States |
| Netlify — hosting | Northern Virginia, United States |
| Resend — email delivery | United States |
| Twilio — SMS delivery | United States |
Information stored in the United States is subject to United States law, and may be accessible to United States courts, law enforcement, and government authorities under legal process — including in circumstances where Canadian law would not permit the same access. This is true regardless of your own location or ours.
By using Sotto, you consent to your information being stored and processed in the United States. If you are not comfortable with that, please do not create an account, and tell us if you would like an existing account removed.
Where the GDPR applies, transfers outside the UK/EEA are made under the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
9. How long we keep it, and how to have it removed
We keep your information for as long as you have an account.
Deleting your account or your information. Write to hello@sottocollection.com and we will act on your request within 30 days.
We will tell you clearly what we can and cannot remove before we act, because some of what you contribute has become part of what other members see:
- Your account, your profile, your saved places, your declared trips, your notification settings, and your usage measurements are deleted.
- Your recommendations are deleted, or removed from view while other members' saves and feedback on them are preserved — your choice, and we will explain the difference when you ask.
- Your vouches and feedback on other members' recommendations are deleted. Other members will see the recommendation change accordingly.
- The record that you were invited by a particular person, and that particular people were invited by you, is retained in a form that no longer identifies you. Sotto calculates every member's connection to every other member by tracing the chain of invitations. Removing your position entirely would break the connection between people who were invited through you and everyone above you — people who have not asked to be affected. We retain the structural position, without your name or contact information attached.
We will confirm in writing when your request is complete.
10. Your rights
You may ask us to:
- Access the personal information we hold about you, and be told how it has been used and who it has been shared with
- Correct anything inaccurate or incomplete
- Delete your information, as described in §9
- Withdraw your consent, which for most of Sotto means closing your account
- Receive a copy of the information you provided, in a portable format
- Object to, or ask us to restrict, particular uses
Write to hello@sottocollection.com. We respond within 30 days. We will not charge you, and we will not treat you differently for asking.
If you are in Quebec, you additionally have the right to have information about you de-indexed or ceased to be disseminated in defined circumstances, and to be informed before any decision based exclusively on automated processing (we do not make such decisions).
If you are unsatisfied with our response, you may complain to:
- The Office of the Information and Privacy Commissioner for British Columbia, at oipc.bc.ca
- The Office of the Privacy Commissioner of Canada, at priv.gc.ca
- The Commission d'accès à l'information du Québec, if you are in Quebec
- Your national supervisory authority, if you are in the UK or EEA
11. Security
Sotto has no passwords. You sign in with a single-use code sent to your email or phone, which removes the risk of a password being reused or stolen.
Information is stored in a database with row-level access rules that restrict what each member's session can read, enforced at the database rather than only in the application. Traffic is encrypted in transit. Access to production systems is limited to the operator.
No system is completely secure. If a breach occurs that presents a real risk of significant harm, we will notify affected individuals and the relevant privacy commissioners as required, without undue delay.
12. Children
Sotto is for adults. You must be 18 or older to hold an account. We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.
13. Changes to this policy
If we change this policy materially, we will notify members in the application before the change takes effect. The date at the top shows when it was last updated.
14. Contact
Sean Gjos, responsible for the protection of personal information.