TravelLove Athens (“we”, “us”) is a small-group tour operator based in Athens, Greece, run by licensed guide Maria Papadopoulou. This policy explains what personal data the TravelLove Athens app and website collect, why, and the choices you have. We are the data controller for the information described here.
We keep data collection to the minimum a booking needs — enough to get you on the right tour at the right time. We never sell your personal data.
Information we collect
We collect only what a booking needs:
- Account details — your name and email address, shared by Apple or Google when you sign in. Optionally a phone number, profile photo, date of birth and preferred language, if you choose to add them.
- Booking details — the tour, date, time, party size, price, any notes you add and your booking history.
- Payment details — handled entirely by Stripe, our payment processor. We never see or store your full card number; we keep only a payment reference and the amount.
- Device details — if you turn on notifications, a push token for your device; plus your app language and standard technical logs (such as IP address and timestamps) kept briefly for security.
How we sign you in
We offer Sign in with Apple and Sign in with Google. We never create or store a password for you. From the provider we receive a unique identifier and the name and email you agree to share — that is all we use to recognise your account.
How we use your information
We use your data to:
- take and confirm your bookings and email you receipts and reminders;
- run the traveller group chat for a shared tour, so you can coordinate with the guide and other guests;
- answer your questions and provide customer support;
- send push notifications you have opted into — you can turn these off any time in your device settings;
- meet our legal, tax and accounting obligations.
Payments
Card payments are processed by Stripe. Your card details go straight to Stripe over an encrypted connection and are never stored on our servers. Stripe processes this data as an independent controller under its own privacy policy (stripe.com/privacy).
Who we share data with
We share personal data only with the providers that make the app work, and only as much as each needs:
- Stripe — payment processing;
- Apple and Google — sign-in and delivery of push notifications (Apple Push Notification service / Firebase Cloud Messaging);
- OpenStreetMap — map tiles shown on tour location cards;
- our email and hosting providers — to store data and send the emails you expect.
We do not sell your data and we do not share it for advertising.
Where your data is stored
Our servers are located in the European Union. Where a provider (such as Apple, Google or Stripe) processes data outside the EU/EEA, they do so under safeguards recognised by EU data-protection law.
How long we keep it
We keep your account data for as long as your account exists. When you delete your account we anonymise it right away (see “Deleting your account” below). We retain booking and payment records in anonymised form for as long as tax and accounting law requires — these records are no longer linked to you.
Your rights
Under the EU General Data Protection Regulation (GDPR) you can ask us to:
- access the personal data we hold about you;
- correct anything that is wrong — most fields you can edit yourself under Profile;
- delete your account and personal data;
- receive a copy of your data, or restrict or object to certain processing.
To exercise any of these, email info@travelloveathens.com. You also have the right to complain to the Hellenic Data Protection Authority (dpa.gr).
Deleting your account
You can delete your account and personal data at any time — directly in the app under Profile → Delete account, or by request if you no longer have the app. Full instructions are on our Account & data deletion page: travelloveathens.com/delete-account.
Children
The app is intended for adults booking travel experiences and is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will remove it.
Security
All traffic between the app and our servers is encrypted with HTTPS. Sign-in tokens are held in your device’s secure storage (Apple Keychain / Android EncryptedSharedPreferences). Because card data never reaches our servers, we cannot expose it.
Changes to this policy
We may update this policy as the app evolves. When we make a material change we will update the date at the top and, where appropriate, notify you in the app.
Contact us
Questions about your privacy? Email info@travelloveathens.com or write to TravelLove Athens, Athens, Greece. You can also reach us on WhatsApp or Instagram (@travellove_athens).