Privacy policy
What we collect, why, how long we keep it and how to get it deleted. Written to be read rather than to be survived.
Last updated 11 August 2026
The short version
We collect what a marketplace needs to work and not more. Traveller trip requests are shared only with the matched companies. We do not sell personal data. Everything is processed and stored inside the EU. You can export or delete your data at any time from your account, and social media access tokens are never stored in our application database.
What we collect
Three categories, and nothing outside them:
- Account data — name, email, password hash, locale, and the role you signed up as.
- Marketplace content — trip requests, offers, messages, reviews, company profiles, campaign briefs and deliverables.
- Technical data — IP address, user agent and session identifiers, used for security, rate limiting and fraud prevention.
Who sees your trip request
Only the companies matched to it — at most eight — plus platform staff investigating a problem. Companies see the content of the request and the contact address you provided for offers. They do not see your other requests, your account history or your activity elsewhere on the platform.
Social media connections
When a creator connects a social account, the connection happens on the platform’s own login page. We never receive, transmit or store a password. The resulting access token is scoped to read-only analytics permissions, is stored encrypted in a vault separate from the application database, never reaches the browser, and is excluded from all logs and error reports. Disconnecting revokes the token at the provider and deletes it here.
Retention
- Trip requests and offers — 24 months after closure, then anonymised.
- Messages — 24 months after the last message in the conversation.
- Reviews — retained while the company listing exists; author identity can be anonymised on request.
- Technical logs — 90 days.
- Accounting records — as required by applicable law, typically 7–10 years.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, portability, and object to processing. Export and deletion are available directly in account settings; anything else, write to privacy@europeantravelcompanies.com and we will respond within 30 days. You may also complain to your national supervisory authority.
Cookies
Strictly necessary cookies for session and security are set without consent because the service cannot function without them. Analytics is privacy-first and aggregate, with no cross-site tracking and no advertising cookies. There is no advertising network embedded in this site.