1. Data Controller
The data controller responsible for your personal data is:
Operated as a sole-trader tourism service
Location: Alicante, Comunitat Valenciana, Spain
Website: toursalicante.oneapp.dev
WhatsApp: +34 624 107 689
Email: available via contact form on the website
If you have any questions about this policy or about how we handle your data, please contact us using any of the methods above.
2. Data We Collect
2.1 Booking enquiries (via WhatsApp form)
When you use our booking request form, the following data is included in the WhatsApp message sent to us:
- Your name — to address you personally and confirm the booking
- Group size — to confirm vehicle capacity
- Tour choice — to prepare the itinerary
- Preferred date — to check availability
- Pick-up city and address — to collect you at the right location
- Language preference — to conduct the tour in your language
- Optional notes — any special requests, accessibility needs, or questions
2.2 Website analytics (via Google Analytics)
We use Google Analytics 4 to understand how visitors use our website. This includes:
- Pages visited and time spent on each page
- Country / region of origin (derived from IP address, not stored)
- Device type (mobile / desktop / tablet)
- Referral source (how you found our site)
- Scroll depth and interactions
This data is aggregated and anonymised. We do not use it to identify individual visitors. Analytics only activates after you give explicit cookie consent via our cookie banner.
2.3 Data we do NOT collect
- We do not collect payment card details (payments are handled via PayPal, Revolut, or in person)
- We do not collect passport or national ID numbers
- We do not collect data from social media profiles
- We do not use remarketing pixels or advertising trackers
- We do not build customer profiles for commercial sale
3. How We Use Your Data
We use the data you provide exclusively for the following purposes:
- Confirming your booking — responding to your enquiry, checking availability, and confirming your tour date and pick-up time
- Delivering the tour — knowing your pick-up location, language preference, and any special requirements on the day
- Sending booking confirmations and reminders — via WhatsApp or email, for the tour you have confirmed only
- Improving our service — using anonymised analytics data to understand which content is most useful to visitors
- Legal obligations — retaining transaction records as required by Spanish tax law (Ley 58/2003, General Tributaria)
4. Legal Basis for Processing
Under the EU General Data Protection Regulation (GDPR, Regulation 2016/679), we rely on the following legal bases:
| Processing activity | Legal basis | GDPR Article |
|---|---|---|
| Handling booking enquiries | Performance of a contract (pre-contractual steps) | Art. 6(1)(b) |
| Delivering confirmed tours | Performance of a contract | Art. 6(1)(b) |
| Retaining booking records | Legal obligation (tax law) | Art. 6(1)(c) |
| Website analytics (Google Analytics) | Consent (cookie banner) | Art. 6(1)(a) |
| Business improvement / service quality | Legitimate interests | Art. 6(1)(f) |
Where we rely on consent (analytics cookies), you may withdraw that consent at any time by clicking "Decline" on the cookie banner, clearing your browser cookies, or contacting us.
6. Third-Party Services
We use the following third-party services on this website. Each has its own privacy policy linked below.
| Service | Provider | Purpose | Data shared | Privacy policy |
|---|---|---|---|---|
| Google Analytics 4 | Google LLC (USA) | Website analytics | Anonymised usage data, aggregated | View → |
| Google Tag Manager | Google LLC (USA) | Tag management container | Script loading only; no additional personal data | View → |
| Cloudflare | Cloudflare, Inc. (USA) | CDN, security, email obfuscation | IP addresses (for bot protection, not retained) | View → |
| WhatsApp Business | Meta Platforms (USA) | Booking enquiries and communication | Booking details you enter in the form | View → |
| Google Fonts | Google LLC (USA) | Typography (DM Sans, Playfair Display) | IP address (for font delivery; Google states this is not retained) | View → |
7. Data Retention
We retain personal data for the minimum period necessary:
| Data type | Retention period | Reason |
|---|---|---|
| Booking enquiries (unanswered) | 30 days | Standard follow-up window |
| Confirmed booking details | 5 years | Spanish tax law (Ley 58/2003) |
| WhatsApp conversation history | Up to 4 years | Service improvement and dispute resolution |
| Analytics data (Google Analytics) | 14 months | Google Analytics default retention setting |
| Cookie consent record | 365 days | Proof of consent; banner suppression |
After the relevant retention period, personal data is deleted or anonymised.
8. International Data Transfers
Our primary business operations are in Spain (EU). However, some of the third-party services we use may transfer data outside the European Economic Area (EEA), in particular to the United States.
Where such transfers occur, they are protected by one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs) — approved by the European Commission under GDPR Article 46(2)(c)
- EU-US Data Privacy Framework — for providers certified under this framework
- Your explicit consent — when you use WhatsApp to send a booking message, you are consenting to Meta's data handling terms
9. Your Rights Under GDPR
As a data subject in the EU/EEA (or under equivalent legislation in the UK or Spain), you have the following rights. You can exercise any of these rights by contacting us using the details in Section 13.
We will respond to all rights requests within 30 days. In complex cases, we may extend this to 60 days with notification. We will never charge a fee for legitimate rights requests.
10. Children's Privacy
Our services are intended for adults booking on behalf of themselves or their family group. We do not knowingly collect personal data directly from children under the age of 16 without verifiable parental or guardian consent.
If you believe we have inadvertently collected data from a child under 16, please contact us immediately and we will delete it promptly.
11. Data Security
We take appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all website traffic (TLS 1.2+)
- Cloudflare CDN for DDoS protection and traffic security
- Email obfuscation — our email address is protected from automated harvesting
- Access limitation — booking data is accessible only to the guide (data controller)
- No plain-text storage — we do not store booking data in spreadsheets or unencrypted files; it lives only in our WhatsApp Business conversation history
12. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or best practices. When we make significant changes, we will update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of our website after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions, data access requests, or complaints, please contact us via any of the following channels. We aim to respond within 2 business days.
Get in touch about your data
We're a small, personal business and we take your privacy seriously. Whether you want to know what data we hold, have it deleted, or just have a question — just send us a message.
You also have the right to lodge a complaint with the Spanish Data Protection Authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
www.aepd.es · Tel: +34 901 100 099