01Who we are
Not Just Tours, trading as not just tours, is the data controller for the personal data described here — meaning we decide why it is used and how. We are a sole trader established in Germany rather than a company, and our full statutory details, including the postal address for formal correspondence, are published in the imprint.
Privacy enquiries: info@notjusttours.com
Because we are established in Germany, the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) apply to everything described here — wherever in the world you book from, and wherever you travel to.
We are far below the size at which German law requires a designated data protection officer, so a privacy request goes to the address above and is answered by the owner.
This policy covers this website, the booking flow and the support we provide around your trip. It does not cover third-party sites we link to, which have their own policies.
02What we collect
Only what we need to sell you a trip and get you on it. Concretely:
- Your account — your email address, your first and last name, your phone and WhatsApp number, your nationality and date of birth, your language and currency, your saved favourites, the activity levels and any dietary or accessibility notes you choose to store, and the record of whether you agreed to marketing. Your password is kept as a one-way hash and is never readable, including by us.
- Your booking — who is travelling, your hotel or pickup address, your flight number, and the answers to the questions the experience itself asks. That last part varies by experience. Where a site, a border crossing or an airline requires it, the form may ask for identity-document details, and those are printed in full on the voucher you download — the person checking it has to be able to read them.
- Payment — handled by Stripe. We receive the outcome, the amount, the card brand and the last four digits. We never see or store your full card number.
- Support — the messages you send us, and any files or photos you attach to them.
- Reviews — what you write and the rating you give. Your name appears only if you asked for it when you submitted, and then only as a first name and an initial; otherwise the review is anonymous. We do not publish your country.
- How the site is used — which experiences were viewed, from what kind of device, in which language, from which country, and whether the visitor was signed in. We do not store your IP address. It is used in the moment to rate-limit sign-in attempts, and it appears in our hosting provider's short-lived server logs.
03Why we use it, and our legal basis
- To deliver your booking — confirming it, producing your voucher, passing the details to your guide or driver, and supporting you before and during the trip. Basis: performance of our contract with you.
- To take payment and prevent fraud. Basis: contract, and our legitimate interest in protecting against fraudulent transactions.
- To keep legal, tax and accounting records. Basis: our legal obligations.
- To see which experiences people look for — which ones are viewed, from what device and country. This runs on our own servers, stores nothing on your device, and feeds no profile about you. Basis: our legitimate interest in knowing what to offer.
- To measure how the site performs, using Google Analytics. This one does store cookies on your device, so it runs only after you agree — and nothing at all is requested from Google before you do. Basis: your consent.
- To send marketing, if you agree to it. Basis: your consent. We record when you gave it and through which action, and you can withdraw it at any time in your profile. Withdrawing it does not undo anything sent beforehand.
- To act on a health, dietary or accessibility need. Basis: your explicit consent, given when you tell us.
We do not sell your personal data, and we make no automated decisions about you that produce legal effects.
05International transfers
Your data is held in the European Economic Area: the database, the stored files and the backups all sit in Google Cloud's `europe-west1` region.
Two things leave it.
- What your destination supplier needs. A trip cannot happen unless the people running it know who is coming, so the travellers' names, the pickup details and anything relevant to safety go to the supplier in the destination — today Egypt, for which there is no EU adequacy decision. We send the minimum the trip requires, for that trip only, and we are putting the European Commission's Standard Contractual Clauses in place with our suppliers as the durable basis for these transfers.
- What our processors need. Google is certified under the EU–US Data Privacy Framework, so transfers to it rest on the Commission's adequacy decision for the United States. For any processor not covered by an adequacy decision we use the Standard Contractual Clauses together with appropriate technical and organisational measures.
Countries outside the EEA may not protect data to the standard EU law sets, and in some the authorities have broader rights of access. You can ask us at any time which safeguards apply to a particular transfer.
07How long we keep it
- Booking, payment and invoice records — for as long as German tax and commercial law requires, which runs to ten years from the end of the year a record belongs to. We cannot delete these sooner, even if you ask.
- Your account — while your account exists. Ask us to close it and we delete or anonymise everything we are not required to keep.
- Support conversations and their attachments — after a case closes, so we still have the context if you come back to us about it.
- Health, dietary and accessibility notes on your profile — yours to change or clear whenever you like; they go when your account goes.
- Marketing consent — the record of the consent and of any withdrawal is kept even after you withdraw, because proving you were unsubscribed on time needs the date you unsubscribed.
- Site-usage records — kept to follow trends over time.
When a retention period ends we delete the data or irreversibly anonymise it.
08Your rights
You have the right to:
- access the personal data we hold about you, and receive a copy;
- correct anything inaccurate or incomplete — much of it you can edit yourself in your profile;
- erase your data, except where the law requires us to keep it (see how long we keep it, above);
- restrict or object to how we use it, including anything we do on the basis of a legitimate interest;
- port your data to another provider in a machine-readable format;
- withdraw consent at any time, without affecting anything done before you withdrew it.
If you think we have handled your data badly, please tell us first so that we can put it right. You also have the right to complain to a supervisory authority — either the one where you live, or the one competent for us: the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
09How we protect it
Traffic to and from this site is encrypted. Passwords are stored as one-way hashes and are never readable. Card details never reach our servers — they go from your browser to Stripe. Administrative access to personal data requires a separate account with its own permissions, and what that account may see is limited to what the work needs.
No system is perfectly secure. If a breach ever puts your rights at risk we will report it to the supervisory authority within 72 hours and tell you directly without undue delay.
10Children
We sell to adults. Children travel with us often, but their details are always given to us by the adult making the booking, and we do not knowingly collect data directly from a child. If you believe a child has given us data, contact us and we will remove it.
11Changes to this policy
We update this policy when our services or the law change. The date at the top shows the latest revision, and we will tell you directly if a change materially affects how we use your data.
12Contact us about privacy
Email info@notjusttours.com for anything on this page, or info@notjusttours.com for everything else. Both reach the same place.
Our legal name and the postal address for formal correspondence are in the imprint.
You can also use the contact page, or read our terms & conditions and our cookie policy.