01Who we are
Not Just Tours (“not just tours”) is the data controller for the personal data described here — meaning we decide why and how it is used.
albertstraße , 44649 Herne, North Rhine-Westphalia, Germany
Privacy enquiries: info@notjusttours.com
We are established in Germany, so the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) apply to everything described here — wherever in the world you book from, and wherever you travel to.
This policy covers our website, our booking flow and the support we provide around your trip. It does not cover third-party sites we link to, which have their own policies.
02What we collect
We collect only what we need to sell you a trip and get you on it.
- Booking details — name, email, phone number, the passengers travelling, your hotel or pickup address, flight number, and any accessibility, dietary or medical needs you choose to tell us.
- Account details — if you create an account: your email, a securely hashed password, your language and currency preferences, and your saved favourites.
- Payment details — handled by our payment provider. We receive a confirmation, the last four digits and the card brand. We never see or store your full card number.
- Support messages — the content of tickets, chats and emails you send us.
- Reviews — what you write, plus the first name and country shown alongside it.
- Technical data — IP address, device and browser type, and the pages you visited, used to keep the site secure and to understand which experiences people look for.
03Why we use it, and our legal basis
- To deliver your booking — confirming it, passing the details to your guide or driver, and supporting you before and during the trip. Basis: performance of our contract with you.
- To take payment and prevent fraud. Basis: contract, and our legitimate interest in protecting against fraudulent transactions.
- To keep legal and tax records. Basis: our legal obligations.
- To improve the site — which experiences are viewed, where a booking flow is abandoned. Basis: our legitimate interest in running a service people can use. Non-essential analytics run only with your consent.
- To send marketing — occasional offers and new experiences. Basis: your consent, which you can withdraw from any email in one click.
- To handle a health or accessibility need. Basis: your explicit consent.
We do not sell your personal data, and we do not use automated decision-making that produces legal effects for you.
05International transfers
We hold your data in the European Economic Area (EEA). But we sell trips worldwide, and a trip can only happen if the people running it know who is coming — so some of your data necessarily travels to the destination.
- To your destination supplier. Where that country has no EU adequacy decision, the transfer is made under Art. 49(1)(b) GDPR: it is necessary to perform the contract you entered into with us. We send only what the supplier needs to run your trip safely.
- To our service providers. Where one operates outside the EEA, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with appropriate technical and organisational measures.
Countries outside the EEA may not offer the same level of protection as EU law, and in some the authorities have broader access rights. You can ask us at any time which safeguards apply to a specific transfer.
07How long we keep it
- Booking and payment records — retained for the period required by tax and accounting law.
- Account data — for as long as your account is open, and deleted or anonymised after a period of inactivity.
- Support conversations — kept for a limited period after the case closes, so we have context if you come back to us.
- Health and accessibility notes — deleted shortly after the trip they relate to.
- Marketing consent — until you withdraw it.
When a retention period ends we delete the data or irreversibly anonymise it.
08Your rights
You have the right to:
- access the personal data we hold about you, and receive a copy;
- correct anything inaccurate or incomplete;
- erase your data, where we have no overriding obligation to keep it;
- restrict or object to how we use it, including profiling for marketing;
- port your data to another provider in a machine-readable format;
- withdraw consent at any time, without affecting anything done before you withdrew it.
If you think we have handled your data badly, please tell us so we can put it right. You also have the right to complain to a supervisory authority — either the one where you live, or the one competent for us: the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
09How we protect it
Traffic to this site is encrypted in transit. Passwords are stored hashed, never in readable form. Access to personal data inside our team is limited to the people who need it to do their job, and payment card data never touches our servers.
No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the relevant authority within 72 hours and tell you directly without undue delay.
10Children
Our services are sold to adults. Children travel with us often, but their details are always provided by the adult making the booking, and we do not knowingly collect data directly from a child. If you believe a child has given us data, contact us and we will remove it.
11Changes to this policy
We update this policy when our services or the law change. The date at the top shows the latest revision, and we will tell you directly if a change materially affects how we use your data.
12Contact us about privacy
Email info@notjusttours.com for anything on this page, or info@notjusttours.com for everything else.
Not Just Tours
albertstraße
44649 Herne
North Rhine-Westphalia, Germany
You can also use the contact page, or read our terms & conditions.