1. Controller (Verantwortlicher)
Free Walking Tour Salzburg e.U.
Gerhard Reus
Ignaz Härtl-Straße 8, 5020 Salzburg, Austria
Phone: +43 699 17799991
Email: [email protected]
2. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, www.dsb.gv.at). To exercise your rights, contact us at the address above.
3. Hosting and server log files
Our website is hosted by xCloud (managed hosting). On each visit the host automatically stores server log files transmitted by your browser: IP address, browser type and version, operating system, referrer URL, and date and time of access. This is based on our legitimate interest in the secure, stable operation of the site (Art 6(1)(f) GDPR). A data processing agreement is in place with our host. Server log files are kept only as long as necessary for security and stability monitoring and are then deleted automatically. All web fonts are hosted locally on our own server; no external font provider (such as Google Fonts) receives any data about you.
4. Content delivery and security (Cloudflare)
We use Cloudflare, Inc. to deliver the site securely and protect it against misuse. In particular, our contact form is protected by Cloudflare Turnstile, a privacy-friendly bot protection that uses no tracking cookies. Cloudflare processes your IP address for this purpose on the basis of our legitimate interest in security (Art 6(1)(f) GDPR). Cloudflare also serves as the content delivery network and reverse proxy for the entire website, processing your IP address to deliver and secure the site. Data may be transferred to the USA under the EU standard contractual clauses. See https://www.cloudflare.com/privacypolicy/
5. Cookies and consent
We use cookies and comparable technologies. Strictly necessary cookies are required for the site to work. Non-essential cookies and third-party embeds (such as maps and videos) are loaded only after you consent through our cookie consent banner. You can review and withdraw consent at any time via the cookie settings. The legal basis for non-essential cookies is your consent (Art 6(1)(a) GDPR).
6. Contact form
When you use our contact form we process the data you enter (such as name, email address, and message) to answer your enquiry. The legal basis is Art 6(1)(b) GDPR (pre-contractual steps) or our legitimate interest in responding (Art 6(1)(f) GDPR). The form is provided by the SureForms plugin and protected against spam by Cloudflare Turnstile. We keep enquiries only as long as needed to handle them and to meet legal retention duties.
7. Maps (Google Maps)
On some pages we show interactive maps via Google Maps, a service of Google Ireland Ltd. Maps load only after you consent through our cookie banner. When loaded, Google receives your IP address and may set cookies; data may be transferred to the USA under the EU standard contractual clauses. Legal basis: your consent (Art 6(1)(a) GDPR). See https://policies.google.com/privacy
8. Embedded videos (YouTube)
We embed videos from YouTube, a service of Google Ireland Ltd. Videos load only after you consent through our cookie banner. When a video loads, YouTube receives your IP address and may set cookies; data may be transferred to the USA under the EU standard contractual clauses. Legal basis: your consent (Art 6(1)(a) GDPR). See https://policies.google.com/privacy
9. Social media
Our site links to our profiles on Instagram and Facebook (Meta Platforms Ireland Ltd.). These are plain links; Meta processes your data only once you visit those profiles, under Meta responsibility. See https://www.facebook.com/privacy/policy
10. Booking and affiliate links
We link to third-party booking and experience partners (such as GetYourGuide, Tiqets, Stay22, and Viator). When you click such a link and book, the partner may set cookies and we may earn a commission at no extra cost to you. We do not receive personal data about your bookings. Please see each partner privacy policy for details.
11. Web analytics
We do not use web analytics or tracking technologies beyond the consented third-party embeds described above.
12. The Introducing Salzburg app
Sections 12 to 17 cover the Introducing Salzburg mobile app and the API at api.introducingsalzburg.com that the app talks to. Sections 1 to 11 cover this website. The controller named in section 1 is the controller for both, and sections 18 and 19 apply to everything on this page.
The app works without an account. You can sign in with your email address, and only then do your saved places and trip plans sync between devices. There is no advertising in the app, no ad SDK, no analytics SDK, no attribution or install tracking, and no profiling. We do not sell or trade your data, and no third party receives it for its own purposes.
The app is not aimed at children under 13. We do not knowingly collect data from children. If you believe a child has signed up, email us and we will delete the account.
13. What the app collects, why, and how long we keep it
- Your email address. Used to sign you in (we send a one-time link, there are no passwords) and to tie your saved places and trip plans to your account. Legal basis: Art 6(1)(b) GDPR. Kept until you delete your account. If you request a sign-in link and never open it, the account row created by that request currently stays, because we do not yet run an automatic purge for sign-ins that were never completed. Email us and we will remove it.
- Magic-link tokens. The one-time codes inside sign-in links. They stop working 15 minutes after they are issued, and a nightly job deletes the row once it is more than 24 hours past expiry.
- The IP address and browser user-agent of the device that requested a sign-in link. Used for per-IP rate limiting, so nobody can burn through our email-sending quota. Legal basis: Art 6(1)(f) GDPR. Stored on the token row, so it is deleted together with that row.
- Session tokens, plus the IP address and user-agent of the device that signed in. Used to keep you signed in and to let you see your own active sessions in the data export. A session lasts 30 days and is refreshed each time you use the app. A nightly job deletes the row once it is more than 30 days past expiry.
- Your saved places and trip plans. The reason to sign in at all. Legal basis: Art 6(1)(b) GDPR. Kept until you remove them or delete your account.
- Your two email preferences (whether you opted in to marketing emails and to product-update emails). Both start switched off and stay off unless you turn them on. Legal basis: Art 6(1)(a) GDPR. Kept until you delete your account.
- Your device’s push-notification token and platform (ios or android). Used only for the trip reminders you switch on. Legal basis: Art 6(1)(a) GDPR. Deleted when you sign out, turn notifications off, or delete your account.
- Support messages you send through the in-app form, including the message text, your email address, and the submitting device’s IP address and user-agent. Used to reply to you, fix what you reported, and prevent abuse. Legal basis: Art 6(1)(b) and Art 6(1)(f) GDPR. Deleted immediately when you delete your account. Messages sent without an account have no automatic purge job yet, so they stay until we clear them by hand.
- Which in-app contact buttons you tapped (an operational log: action type, label, target, city, entity). Used to see which support paths people actually use, and to investigate abuse. Legal basis: Art 6(1)(f) GDPR. Kept indefinitely. When you delete your account these rows stay, but the link to your identity is removed.
- Crash reports and app diagnostics. See section 16, which describes exactly when these are sent and what is stripped out first. Kept by Sentry for up to 90 days.
The app does not collect: your name (we never ask), your phone number, your postal address, payment details (the app takes no payments), your location history, your contacts, your photos, files outside the app, or advertising identifiers.
On location specifically: the app asks for your location while you are using it, so it can centre the map and sort places by distance. That happens on your phone. No coordinate is ever written to our database or sent to our API, and the app never tracks your location in the background.
14. What stays on your device only
Some information never leaves your phone: the Salzburg content pack, which is downloaded once and cached so the app works offline; your saved places and trip plans while you are signed out, which live in a local database on the phone and only sync after you sign in; your recent searches, which you can clear from the Search screen; and your language, theme and onboarding preferences.
Your session token, and the account details stored beside it, are held in the platform’s secure storage (Android Keystore, iOS Keychain, hardware-backed where the device supports it). Uninstalling the app removes all of this on-device data.
15. Processors for the app
Five companies process app data on our behalf, because they run the infrastructure the app needs. Each of them acts on our instructions under a data processing agreement.
- Hetzner (Germany), our server host. The API and its PostgreSQL database run on a single dedicated server in Hetzner’s Helsinki data centre, inside the EU. Everything above that is stored server-side lives there.
- Cloudflare, Inc. (USA), which sits in front of the API as a reverse proxy and TLS terminator. Every request from the app passes through it, so it processes your device’s IP address in transit. It is not used for advertising or analytics.
- SMTP2GO, which delivers our transactional email. Your email address, and the sign-in link inside the message, pass through it whenever you request a magic link. It is not a newsletter tool and we keep no mailing list there.
- Sentry (sentry.io), our crash-reporting and app-diagnostics service. See section 16.
- Expo (650 Industries, Inc., USA), the platform the app is built on. It touches your data in two ways. First, over-the-air updates: every time the app launches it asks
u.expo.devwhether a newer version of the app’s code is available, so Expo receives that request including your device’s IP address, the app version and the platform. Second, push notifications: if you switch reminders on, the notification token for your device is issued by Expo’s push service, and a reminder we send is handed to Expo, which passes it to Google’s or Apple’s push service for delivery to your phone.
One further case, and it only happens if you ask for it: if you switch on marketing emails or product-update emails in the app, your email address is passed to our email system so you can be added to that list. Both switches are off by default and you can switch them off again at any time.
16. Crash reports and app diagnostics (Sentry)
Sentry hears from the app only when something goes wrong. Opening the app, using it and closing it send nothing. One kind of thing is transmitted:
- An error report when the app actually fails, containing the stack trace plus a small set of context fields: app version, build number, device model, operating system and your language setting. Recent screen names are attached as breadcrumbs so we can see the path that led to the failure.
Two things Sentry is capable of doing that we have deliberately switched off. It can record a session every time the app is opened, to calculate what share of sessions are crash-free. It can also sample performance traces from ordinary app launches, measuring how long screens take to appear. Both would mean the app contacting us during normal, successful use. Neither tells us anything we need in order to fix a crash, so both are off, and if we ever turn one on we will say so here before we do.
Before anything is transmitted, the app strips out email addresses, session tokens, magic-link tokens, request bodies, cookies and authorization headers. The user record attached to an event contains your internal account ID and nothing else, never your email address. If you are signed out, there is no account ID either. Sentry is also configured not to store the IP address a report arrives from, which it would otherwise record automatically.
Legal basis: Art 6(1)(f) GDPR, our legitimate interest in an app that does not crash. Our Sentry organisation is hosted in Sentry’s EU region (de.sentry.io), so these events are processed inside the EU. Sentry keeps events for up to 90 days and then deletes them. See https://sentry.io/privacy/.
17. Your rights in the app, export and deletion
The rights in section 2 apply in full to app data. Two of them are wired directly into the app, so you do not have to ask us:
- Export your data. Account tab, “Export my data”. You retype your email address to confirm, and you get a JSON file containing your email address, your sign-up date, your two email preferences, your sessions, your saved places and trip plans including their full contents, your support messages, and your registered push tokens. (Art 20 GDPR.)
- Delete your account and your data. Account tab, “Delete account”, then retype your email address to confirm. (Art 17 GDPR.) What exactly is erased, what is kept, and what happens during the 30 days that follow is set out in full on our account deletion page. That page also works if you have already uninstalled the app.
Beyond your own actions, the API runs nightly cleanup jobs: magic-link tokens more than 24 hours past expiry are deleted along with the IP address and user-agent stored on them; sessions more than 30 days past expiry are deleted the same way; and accounts deleted more than 30 days ago are permanently erased together with every remaining record attached to them.
Two things are not on an automatic schedule yet, and we would rather say so than imply otherwise: support messages sent without an account, and accounts created by a sign-in request that was never completed. Both are deleted on request.
You can also exercise any of these rights by writing to [email protected].
18. Transfers outside the EU
Some services above may transfer data to the USA. On the website these are Google, Meta and Cloudflare. In the app they are Cloudflare, Inc. and Expo (650 Industries, Inc.), both established in the United States, and SMTP2GO, which may route the delivery of our emails through infrastructure outside the EU. Such transfers are safeguarded by the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
The rest of the app’s data stays in the EU: the API and its database run on a dedicated server in Finland, and our Sentry organisation is on Sentry’s EU region.
19. Changes to this policy
We may update this Privacy Policy to reflect changes to our services or the law. The current version always applies. The app links to this page from its Account and Support screens, but it does not pop up a notice when the page changes, so the “last updated” date at the bottom is the thing to watch.