Legal

Privacy Policy

What this site and the app collect, who controls it, how long it is kept, and how to have it erased. The contact form takes only your name, address and message, and uses them to answer you.

1. Controller (Verantwortlicher)

Free Walking Tour Salzburg e.U.
Gerhard Reus
Ignaz Härtl-Straße 8, 5020 Salzburg, Austria
Phone: +43 699 17799991
Email: [email protected]

2. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, www.dsb.gv.at). To exercise your rights, contact us at the address above.

3. Hosting and server log files

Our website is hosted by xCloud (managed hosting). On each visit the host automatically stores server log files transmitted by your browser: IP address, browser type and version, operating system, referrer URL, and date and time of access. This is based on our legitimate interest in the secure, stable operation of the site (Art 6(1)(f) GDPR). A data processing agreement is in place with our host. Server log files are kept only as long as necessary for security and stability monitoring and are then deleted automatically. All web fonts are hosted locally on our own server; no external font provider (such as Google Fonts) receives any data about you.

4. Content delivery and security (Cloudflare)

We use Cloudflare, Inc. to deliver the site securely and protect it against misuse. In particular, our contact form is protected by Cloudflare Turnstile, a privacy-friendly bot protection that uses no tracking cookies. Cloudflare processes your IP address for this purpose on the basis of our legitimate interest in security (Art 6(1)(f) GDPR). Cloudflare also serves as the content delivery network and reverse proxy for the entire website, processing your IP address to deliver and secure the site. Data may be transferred to the USA under the EU standard contractual clauses. See https://www.cloudflare.com/privacypolicy/

5. Cookies

This website sets no cookies of its own. It is a static site with no login and no session to remember. The only cookies you may encounter are strictly-necessary security cookies set by Cloudflare (__cf_bm, cf_clearance) and the bot check on our contact form. There is no cookie banner because there is nothing here that requires your consent: we run no advertising, no tracking pixels, and no third-party embed that profiles you, and our visitor statistics are collected without cookies (section 10). Legal basis: Art 6(1)(f) GDPR and § 165 Abs. 3 TKG 2021. Full detail is in our Cookie Policy.

6. Contact form

When you use our contact form we process the data you enter (such as name, email address, and message) to answer your enquiry. The legal basis is Art 6(1)(b) GDPR (pre-contractual steps) or our legitimate interest in responding (Art 6(1)(f) GDPR). The form posts to our own forms service at portal.introducingsalzburg.com, which runs on our infrastructure, and is protected against spam by Cloudflare Turnstile. We keep enquiries only as long as needed to handle them and to meet legal retention duties.

7. Maps (OpenFreeMap)

On some pages we show interactive maps. The map tiles come from OpenFreeMap, an open map service that sets no cookies, needs no account, and does not profile you. Loading a map means your IP address reaches that service, as it would for any image on the page. Google Maps is not used on this website. Where a page offers a "directions" link, that is an ordinary outbound link to Google Maps and nothing is sent to Google until you click it. Legal basis: our legitimate interest in showing you a working map (Art 6(1)(f) GDPR).

8. Social media and video

This site embeds nothing. There are no YouTube players, no social feeds, and no third-party widgets anywhere on it. We link to our profiles on YouTube (Google Ireland Ltd.) and on Instagram and Facebook (Meta Platforms Ireland Ltd.), and those are plain links: nothing loads from those companies, and they receive no data about you, until you choose to click. From that point their own policies apply. See https://policies.google.com/privacy and https://www.facebook.com/privacy/policy

9. Booking and affiliate links

We link to third-party booking and experience partners (such as GetYourGuide, Tiqets, Stay22, and Viator). When you click such a link and book, the partner may set cookies and we may earn a commission at no extra cost to you. We do not receive personal data about your bookings. Please see each partner privacy policy for details.

10. Web analytics

We use Cloudflare Web Analytics to see roughly how many people visit this website and which pages they read. It is a deliberately privacy-preserving service: it sets no cookie, stores no identifier on your device, and does not track you across websites, so it cannot build a profile of you and we cannot use it to recognise you on a later visit. That is why it requires no consent and why this site shows no banner. We do not use Google Analytics; it was removed. Legal basis: our legitimate interest in understanding whether our work is read (Art 6(1)(f) GDPR).

11. The Introducing Salzburg app

Sections 11 to 16 cover the Introducing Salzburg mobile app and the API at api.introducingsalzburg.com that the app talks to. Sections 1 to 10 cover this website. The controller named in section 1 is the controller for both, and sections 17 and 18 apply to everything on this page.

The app works without an account. You can sign in with your email address, and only then do your saved places and trip plans sync between devices. There is no advertising in the app, no ad SDK, no analytics SDK, no attribution or install tracking, and no profiling. We do not sell or trade your data, and no third party receives it for its own purposes.

The app is not aimed at children under 13. We do not knowingly collect data from children. If you believe a child has signed up, email us and we will delete the account.

12. What the app collects, why, and how long we keep it

  • Your email address. Used to sign you in (we send a one-time link, there are no passwords) and to tie your saved places and trip plans to your account. Legal basis: Art 6(1)(b) GDPR. Kept until you delete your account. If you request a sign-in link and never open it, the account row created by that request currently stays, because we do not yet run an automatic purge for sign-ins that were never completed. Email us and we will remove it.
  • Magic-link tokens. The one-time codes inside sign-in links. They stop working 15 minutes after they are issued, and a nightly job deletes the row once it is more than 24 hours past expiry.
  • The IP address and browser user-agent of the device that requested a sign-in link. Used for per-IP rate limiting, so nobody can burn through our email-sending quota. Legal basis: Art 6(1)(f) GDPR. Stored on the token row, so it is deleted together with that row.
  • Session tokens, plus the IP address and user-agent of the device that signed in. Used to keep you signed in and to let you see your own active sessions in the data export. A session lasts 30 days and is refreshed each time you use the app. A nightly job deletes the row once it is more than 30 days past expiry.
  • Your saved places and trip plans. The reason to sign in at all. Legal basis: Art 6(1)(b) GDPR. Kept until you remove them or delete your account.
  • Your two email preferences (whether you opted in to marketing emails and to product-update emails). Both start switched off and stay off unless you turn them on. Legal basis: Art 6(1)(a) GDPR. Kept until you delete your account.
  • Your device's push-notification token and platform (ios or android). Used only for the trip reminders you switch on. Legal basis: Art 6(1)(a) GDPR. Deleted when you sign out, turn notifications off, or delete your account.
  • Support messages you send through the in-app form, including the message text, your email address, and the submitting device's IP address and user-agent. Used to reply to you, fix what you reported, and prevent abuse. Legal basis: Art 6(1)(b) and Art 6(1)(f) GDPR. Deleted immediately when you delete your account. Messages sent without an account have no automatic purge job yet, so they stay until we clear them by hand.
  • Which in-app contact buttons you tapped (an operational log: action type, label, target, city, entity). Used to see which support paths people actually use, and to investigate abuse. Legal basis: Art 6(1)(f) GDPR. Kept indefinitely. When you delete your account these rows stay, but the link to your identity is removed.
  • Crash reports and app diagnostics. See section 15, which describes exactly when these are sent and what is stripped out first. Kept by Sentry for up to 90 days.

The app does not collect: your name (we never ask), your phone number, your postal address, payment details (the app takes no payments), your location history, your contacts, your photos, files outside the app, or advertising identifiers.

On location specifically: the app asks for your location while you are using it, so it can centre the map and sort places by distance. That happens on your phone. No coordinate is ever written to our database or sent to our API, and the app never tracks your location in the background.

13. What stays on your device only

Some information never leaves your phone: the Salzburg content pack, which is downloaded once and cached so the app works offline; your saved places and trip plans while you are signed out, which live in a local database on the phone and only sync after you sign in; your recent searches, which you can clear from the Search screen; and your language, theme and onboarding preferences.

Your session token, and the account details stored beside it, are held in the platform's secure storage (Android Keystore, iOS Keychain, hardware-backed where the device supports it). Uninstalling the app removes all of this on-device data.

14. Processors for the app

Five companies process app data on our behalf, because they run the infrastructure the app needs. Each of them acts on our instructions under a data processing agreement.

  • Hetzner (Germany), our server host. The API and its PostgreSQL database run on a single dedicated server in Hetzner's Helsinki data centre, inside the EU. Everything above that is stored server-side lives there.
  • Cloudflare, Inc. (USA), which sits in front of the API as a reverse proxy and TLS terminator. Every request from the app passes through it, so it processes your device's IP address in transit. It is not used for advertising or analytics.
  • SMTP2GO, which delivers our transactional email. Your email address, and the sign-in link inside the message, pass through it whenever you request a magic link. It is not a newsletter tool and we keep no mailing list there.
  • Sentry (sentry.io), our crash-reporting and app-diagnostics service. See section 16.
  • Expo (650 Industries, Inc., USA), the platform the app is built on. It touches your data in two ways. First, over-the-air updates: every time the app launches it asks u.expo.dev whether a newer version of the app's code is available, so Expo receives that request including your device's IP address, the app version and the platform. Second, push notifications: if you switch reminders on, the notification token for your device is issued by Expo's push service, and a reminder we send is handed to Expo, which passes it to Google's or Apple's push service for delivery to your phone.

The map in the app comes from Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google is listed separately from the five above because it does not work on our instructions: it handles what it receives under its own privacy policy. When you open the map, Google receives your device's IP address and, if you have allowed location access, roughly where you are, so it can send you the right map tiles. Your location never reaches our servers. Saved places live on your phone, and if you sign in they sync to us as a list of place names only. On this website the map is not Google’s at all: it is drawn with OpenFreeMap and sets no cookies (section 7). In the app the map is Google Maps and it loads when you open the screen, because there the map is a main feature you open on purpose rather than an embed inside a page. Legal basis: Art 6(1)(f) GDPR, our legitimate interest in showing you a working map. Google's privacy policy: https://policies.google.com/privacy

One further case, and it only happens if you ask for it: if you switch on marketing emails or product-update emails in the app, your email address is passed to our email system so you can be added to that list. Both switches are off by default and you can switch them off again at any time.

15. Crash reports and app diagnostics (Sentry)

Sentry hears from the app only when something goes wrong. Opening the app, using it and closing it send nothing. One kind of thing is transmitted:

  • An error report when the app actually fails, containing the stack trace plus a small set of context fields: app version, build number, device model, operating system and your language setting. Recent screen names are attached as breadcrumbs so we can see the path that led to the failure.

Two things Sentry is capable of doing that we have deliberately switched off. It can record a session every time the app is opened, to calculate what share of sessions are crash-free. It can also sample performance traces from ordinary app launches, measuring how long screens take to appear. Both would mean the app contacting us during normal, successful use. Neither tells us anything we need in order to fix a crash, so both are off, and if we ever turn one on we will say so here before we do.

Before anything is transmitted, the app strips out email addresses, session tokens, magic-link tokens, request bodies, cookies and authorization headers. The user record attached to an event contains your internal account ID and nothing else, never your email address. If you are signed out, there is no account ID either. Sentry is also configured not to store the IP address a report arrives from, which it would otherwise record automatically.

Legal basis: Art 6(1)(f) GDPR, our legitimate interest in an app that does not crash. Our Sentry organisation is hosted in Sentry's EU region (de.sentry.io), so these events are processed inside the EU. Sentry keeps events for up to 90 days and then deletes them. See https://sentry.io/privacy/.

16. Your rights in the app, export and deletion

The rights in section 2 apply in full to app data. Two of them are wired directly into the app, so you do not have to ask us:

  • Export your data. Account tab, "Export my data". You retype your email address to confirm, and you get a JSON file containing your email address, your sign-up date, your two email preferences, your sessions, your saved places and trip plans including their full contents, your support messages, and your registered push tokens. (Art 20 GDPR.)
  • Delete your account and your data. Account tab, "Delete account", then retype your email address to confirm. (Art 17 GDPR.) What exactly is erased, what is kept, and what happens during the 30 days that follow is set out in full on our account deletion page. That page also works if you have already uninstalled the app.

Beyond your own actions, the API runs nightly cleanup jobs: magic-link tokens more than 24 hours past expiry are deleted along with the IP address and user-agent stored on them; sessions more than 30 days past expiry are deleted the same way; and accounts deleted more than 30 days ago are permanently erased together with every remaining record attached to them.

Two things are not on an automatic schedule yet, and we would rather say so than imply otherwise: support messages sent without an account, and accounts created by a sign-in request that was never completed. Both are deleted on request.

You can also exercise any of these rights by writing to [email protected].

17. Transfers outside the EU

Some services above may transfer data to the USA. On the website this is Cloudflare, which delivers and protects the site and provides our cookieless visitor statistics; Google and Meta appear there only as ordinary outbound links, so nothing reaches them unless you click one. In the app they are Cloudflare, Inc. and Expo (650 Industries, Inc.), both established in the United States, and SMTP2GO, which may route the delivery of our emails through infrastructure outside the EU. Such transfers are safeguarded by the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

The rest of the app's data stays in the EU: the API and its database run on a dedicated server in Finland, and our Sentry organisation is on Sentry's EU region.

18. Changes to this policy

We may update this Privacy Policy to reflect changes to our services or the law. The current version always applies. The app links to this page from its Account and Support screens, but it does not pop up a notice when the page changes, so the "last updated" date at the bottom is the thing to watch.