not just tours
ExcursionsTransfersAboutContact
Sign in
not just tours

Handpicked excursions and reliable transfers — book unforgettable experiences with trusted local guides.

Chat on WhatsApp

Typically replies within minutes

Explore

  • Excursions
  • Transfers
  • Top rated
  • Wishlist

Company

  • About us
  • How it works
  • Why choose us
  • Become a partner
  • Careers
  • Contact

Support

  • FAQ
  • Booking status

Legal

  • Terms of service
  • Privacy
  • Cookies
  • Imprint
Secure paymentsVISAMastercardAmexPayPalApple Pay

© 2026 not just tours · Made with care for travellers

Prices include taxes where applicable. Excursions operated by independent local suppliers.

Legal

Privacy Policy

What we collect when you book, why we need it, who sees it, and how to get it back or have it deleted. In plain language.

Last updated 29 July 2026

On this page

  1. 01Who we are
  2. 02What we collect
  3. 03Why we use it, and our legal basis
  4. 04Who we share it with
  5. 05International transfers
  6. 06Cookies
  7. 07How long we keep it
  8. 08Your rights
  9. 09How we protect it
  10. 10Children
  11. 11Changes to this policy
  12. 12Contact us about privacy

01Who we are

Not Just Tours (“not just tours”) is the data controller for the personal data described here — meaning we decide why and how it is used.

albertstraße , 44649 Herne, North Rhine-Westphalia, Germany
Privacy enquiries: info@notjusttours.com

We are established in Germany, so the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) apply to everything described here — wherever in the world you book from, and wherever you travel to.

This policy covers our website, our booking flow and the support we provide around your trip. It does not cover third-party sites we link to, which have their own policies.

02What we collect

We collect only what we need to sell you a trip and get you on it.

  • Booking details — name, email, phone number, the passengers travelling, your hotel or pickup address, flight number, and any accessibility, dietary or medical needs you choose to tell us.
  • Account details — if you create an account: your email, a securely hashed password, your language and currency preferences, and your saved favourites.
  • Payment details — handled by our payment provider. We receive a confirmation, the last four digits and the card brand. We never see or store your full card number.
  • Support messages — the content of tickets, chats and emails you send us.
  • Reviews — what you write, plus the first name and country shown alongside it.
  • Technical data — IP address, device and browser type, and the pages you visited, used to keep the site secure and to understand which experiences people look for.

Health and accessibility information

If you tell us about a medical condition, a mobility need or a dietary requirement, that is sensitive data. We use it only to make your experience safe and suitable, share it only with the supplier delivering that experience, and keep it no longer than the trip requires.

03Why we use it, and our legal basis

  • To deliver your booking — confirming it, passing the details to your guide or driver, and supporting you before and during the trip. Basis: performance of our contract with you.
  • To take payment and prevent fraud. Basis: contract, and our legitimate interest in protecting against fraudulent transactions.
  • To keep legal and tax records. Basis: our legal obligations.
  • To improve the site — which experiences are viewed, where a booking flow is abandoned. Basis: our legitimate interest in running a service people can use. Non-essential analytics run only with your consent.
  • To send marketing — occasional offers and new experiences. Basis: your consent, which you can withdraw from any email in one click.
  • To handle a health or accessibility need. Basis: your explicit consent.

We do not sell your personal data, and we do not use automated decision-making that produces legal effects for you.

04Who we share it with

  • The supplier delivering your experience — the guide, boat operator or driver receives the passenger names, passenger count, pickup details and any need relevant to safety. Nothing more.
  • Our payment provider, to take the payment and process any refund.
  • Service providers that run our infrastructure — hosting, email delivery, error monitoring and customer support tooling — under contracts that permit them to act only on our instructions.
  • Authorities, where the law requires it or to establish or defend a legal claim.
  • A buyer, if the business is ever sold or reorganised — with the same protections carrying over.

05International transfers

We hold your data in the European Economic Area (EEA). But we sell trips worldwide, and a trip can only happen if the people running it know who is coming — so some of your data necessarily travels to the destination.

  • To your destination supplier. Where that country has no EU adequacy decision, the transfer is made under Art. 49(1)(b) GDPR: it is necessary to perform the contract you entered into with us. We send only what the supplier needs to run your trip safely.
  • To our service providers. Where one operates outside the EEA, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with appropriate technical and organisational measures.

Countries outside the EEA may not offer the same level of protection as EU law, and in some the authorities have broader access rights. You can ask us at any time which safeguards apply to a specific transfer.

06Cookies

We keep cookies to a minimum and group them into three kinds.

  • Essential — your session, your cart, security tokens, and your language and currency choices. The site cannot work without these, so they need no consent.
  • Analytics — how the site is used, in aggregate, so we can improve it. Set only with your consent.
  • Marketing — measuring whether a campaign led to a booking. Set only with your consent.

You can change your choice at any time from the cookie settings link in the footer, or clear cookies in your browser. Blocking essential cookies will stop checkout from working.

07How long we keep it

  • Booking and payment records — retained for the period required by tax and accounting law.
  • Account data — for as long as your account is open, and deleted or anonymised after a period of inactivity.
  • Support conversations — kept for a limited period after the case closes, so we have context if you come back to us.
  • Health and accessibility notes — deleted shortly after the trip they relate to.
  • Marketing consent — until you withdraw it.

When a retention period ends we delete the data or irreversibly anonymise it.

08Your rights

You have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct anything inaccurate or incomplete;
  • erase your data, where we have no overriding obligation to keep it;
  • restrict or object to how we use it, including profiling for marketing;
  • port your data to another provider in a machine-readable format;
  • withdraw consent at any time, without affecting anything done before you withdrew it.

If you think we have handled your data badly, please tell us so we can put it right. You also have the right to complain to a supervisory authority — either the one where you live, or the one competent for us: the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

Exercising your rights

Email info@notjusttours.com. We respond within one month, and it is free. We may ask you to confirm your identity first, so that nobody else can request your data.

09How we protect it

Traffic to this site is encrypted in transit. Passwords are stored hashed, never in readable form. Access to personal data inside our team is limited to the people who need it to do their job, and payment card data never touches our servers.

No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the relevant authority within 72 hours and tell you directly without undue delay.

10Children

Our services are sold to adults. Children travel with us often, but their details are always provided by the adult making the booking, and we do not knowingly collect data directly from a child. If you believe a child has given us data, contact us and we will remove it.

11Changes to this policy

We update this policy when our services or the law change. The date at the top shows the latest revision, and we will tell you directly if a change materially affects how we use your data.

12Contact us about privacy

Email info@notjusttours.com for anything on this page, or info@notjusttours.com for everything else.

Not Just Tours
albertstraße

44649 Herne

North Rhine-Westphalia, Germany

You can also use the contact page, or read our terms & conditions.

Still have questions?

Our team answers in minutes, every day of the week. Check the help centre for the quick answers, or message us and a real person will pick it up.

Contact usVisit the help centre