Privacy Policy
Last updated: August 26, 2026 · Version 2.0
1. Introduction
TravelTribe GmbH (hereinafter referred to as "TravelTribe", "we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy describes how we collect, use, process, and protect the personal information of individuals who visit our website, use our services, or otherwise interact with us.
2. Legal Framework
The processing of your personal data is governed by:
- The Swiss Federal Act on Data Protection (FADP / nDSG, in force since 1 September 2023) for all data subjects.
- The EU General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) for data subjects located in the European Economic Area (EEA), pursuant to Article 3(2)(a) GDPR (offering of goods and services to individuals in the EEA).
- Other applicable laws for data subjects located in third countries, where applicable.
3. Data Controller
The data controller responsible for the processing of your personal data is:
TravelTribe GmbH
Erlachstrasse 46, 8003 Zürich, Switzerland
UID/VAT: CHE-156.905.250 MWST
Handelsregister Kanton Zürich: CH-020.4.085.604-2
Email: [email protected] · Phone: +41 77 807 09 51
4. EU Representative (Art. 27 GDPR)
Pursuant to Article 27(2) GDPR, TravelTribe is exempt from appointing an EU representative, as its processing is occasional, does not include on a large scale the processing of special categories of data or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of natural persons.
5. Collection of Personal Data
We collect various types of personal data depending on your interaction with us. This may include:
- Contact Information: Your name, email address, phone number, postal address, and other contact details you provide when making a booking, creating an account, subscribing to our newsletter, or contacting us.
- Booking Information: Details of the travel services, events, or experiences you book with us, including dates of travel, destinations, accommodation preferences, flight information, participant names, and any special requests.
- Payment Information: Payment card details or other payment information necessary to process your bookings. Please note that we may use third-party payment processors who have their own privacy policies.
- Website Usage Data: Information about how you use our website, such as your IP address, browser type, operating system, referring website, pages you visit, and the dates and times of your visits. This information may be collected using cookies and other tracking technologies (see Section 11).
- Communication Data: Records of our communication with you, including emails, phone calls, and chat logs.
- Marketing Preferences: Information about your preferences for receiving marketing communications from us.
- Demographic Information: Optional information such as your age, gender, interests, or travel preferences that you may choose to provide.
- Health and Dietary Information: If necessary for the provision of specific services (e.g., allergies for catering during an event), we may collect health or dietary information with your explicit consent.
6. Purposes of Data Processing
We process your personal data for the following purposes:
- Providing and Managing Services: To process your bookings, confirm your reservations, manage your travel arrangements, and provide you with the services you have requested.
- Communication: To communicate with you regarding your bookings, respond to your inquiries, provide customer support, and send you important information about our services.
- Personalization: To personalize your experience on our website and tailor our services and offers to your interests and preferences.
- Marketing and Promotions: With your consent where required by law, to send you newsletters, promotional emails, and other marketing communications about our services, special offers, and travel-related information. You can opt-out of receiving such communications at any time (see Section 10).
- Improving Our Website and Services: To analyze website usage data to understand how our website is used and to improve its functionality and content.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Security and Fraud Prevention: To protect our website and services from fraud, unauthorized access, and other illegal activities.
- Internal Operations: For our internal administrative and operational purposes, such as record-keeping, data analysis, and audits.
7. Legal Basis for Processing
We will only process your personal data when we have a lawful basis for doing so, which may include:
- Consent: When you have given us your explicit consent to process your personal data for a specific purpose (e.g., for marketing communications or the processing of sensitive data like health information).
- Contractual Necessity: When the processing is necessary for the performance of a contract to which you are a party (e.g., to process your booking and provide you with the requested services).
- Legal Obligation: When we are required to process your personal data to comply with a legal obligation.
- Legitimate Interests: When the processing is necessary for our legitimate interests or the legitimate interests of a third party, provided that your interests and fundamental rights do not override those interests. Our legitimate interests may include improving our services, personalizing your experience, and preventing fraud.
8. Sharing of Personal Data
We may share your personal data with the following categories of recipients:
- Third-Party Service Providers: We may share your personal data with third-party service providers who assist us in providing our services, such as hotels, airlines, transportation companies, activity providers, payment processors, IT service providers, and marketing agencies. These providers are contractually obligated to protect your personal data and to use it only for the purposes for which it was disclosed. A list of our main processors is provided in Section 9.
- Affiliated Companies: We may share your personal data with our affiliated companies for internal business purposes, such as customer support and marketing.
- Legal Authorities: We may disclose your personal data to legal authorities, government agencies, or other third parties if we are required to do so by law or legal process, or if we believe in good faith that such disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
- Business Transfers: In the event of a merger, acquisition, or other business transfer, your personal data may be transferred to the acquiring entity.
- With Your Consent: We may share your personal data with other third parties with your explicit consent.
9. Data Processors · Third-Party Service Providers
We share personal data with the following processors, each bound by a Data Processing Agreement (DPA). International transfers outside Switzerland or the EEA are governed by appropriate safeguards, including EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework certification of the recipient.
| Processor | Purpose | Data Location | Transfer Safeguard |
|---|---|---|---|
| Stripe Payments Europe Ltd | Payment processing (cards, TWINT, Apple/Google Pay) | Ireland (EU) + US backup | SCCs + EU-US DPF |
| Supabase Inc. | Website database (customer accounts, bookings) | United States | SCCs |
| Fly.io (backend) & Vercel Inc. (frontend) | Website and application hosting | United States | SCCs |
| Cloudflare Inc. | CDN, TLS, and security (edge firewall, DDoS mitigation) | Global edge network | SCCs |
| Amazon Web Services (AWS) | Media/image storage and content delivery | EU / US regions | SCCs |
| Google Ireland Ltd (Google Workspace) | Email hosting and transactional email | Ireland (EU) + US | SCCs + EU-US DPF |
| The Rocket Science Group LLC (Intuit Mailchimp) | Newsletter and marketing emails | United States | SCCs + EU-US DPF |
| Meta Platforms Ireland Ltd | Advertising and conversion measurement (Meta Pixel, see Section 12) | Ireland (EU) + US | SCCs + EU-US DPF |
| Bexio AG | Accounting, invoicing, financial records | Switzerland (Rapperswil) | Domestic processing (nDSG) |
| Functional Software Inc. (Sentry) | Error monitoring (technical diagnostics) | US / EU | SCCs |
10. Your Rights Regarding Your Personal Data
Under the nDSG and the GDPR, you have the following rights regarding your personal data:
- Right to information / access (art. 15 GDPR · art. 25 nDSG): to obtain access to the personal data we hold about you and a copy of it.
- Right to rectification (art. 16 GDPR · art. 32 nDSG): to have inaccurate or incomplete personal data corrected.
- Right to erasure / "right to be forgotten" (art. 17 GDPR): to request deletion of your personal data in certain circumstances.
- Right to restriction of processing (art. 18 GDPR): to request that we limit the processing of your personal data.
- Right to data portability (art. 20 GDPR · art. 28 nDSG): to receive your personal data in a structured, commonly used, machine-readable format.
- Right to object (art. 21 GDPR): to object to the processing of your personal data, including for direct marketing.
- Right to withdraw consent (art. 7 GDPR): to withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint with a supervisory authority:
- For Swiss residents: Federal Data Protection and Information Commissioner (FDPIC).
- For EU residents: your national Data Protection Authority.
To exercise any of these rights, please contact us at [email protected] (see Section 17). We may require you to verify your identity before responding to your request, and we will respond within the timeframes required by applicable law.
11. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to make the site work, to understand how it is used and, with your consent, for marketing and advertising purposes. Cookies are small text files that are stored on your device when you visit a website.
- Essential cookies: These cookies are necessary for the operation of our website and enable you to use its core features (for example to maintain a login session or remember your booking steps). You cannot disable them via our cookie settings.
- Preference and performance cookies: These cookies help us remember your choices (such as language and currency) and collect anonymised usage information to improve the performance and usability of our website.
- Marketing and analytics cookies: With your consent, we use cookies and similar technologies to measure the effectiveness of our marketing campaigns and to show you relevant advertising on other platforms (for example via Meta Pixel).
When you first visit our website, you can choose whether to allow non-essential cookies (such as marketing and analytics cookies) via our cookie banner. You can withdraw your consent at any time with effect for the future by using the cookie settings below or changing your browser settings. If you block or delete cookies, some features of our website may not function properly.
12. Use of Meta (Facebook) Pixel
We use the Meta Pixel of Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Meta") on our website. The Meta Pixel allows us to understand how users interact with our website after seeing or clicking on our ads on Facebook or Instagram, to measure the effectiveness of those ads and to improve our marketing.
For this purpose, the following information may be processed by Meta when you visit our website: IP address and other device information, browser type and version, visited pages, clicked elements and actions on our website (for example bookings or sign ups), referrer URL and date and time of the visit. If you are logged in to Facebook or Instagram, Meta can associate this information with your account and display personalised advertising to you on Meta products.
The processing by Meta takes place under Meta's responsibility in accordance with Meta's privacy policy, which you can find at https://www.facebook.com/privacy/policy.
We only use the Meta Pixel with your consent. The legal basis under Swiss data protection law (nFADP) and, where applicable, the GDPR is your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw your consent at any time with effect for the future by adjusting your cookie preferences in our cookie settings or by changing your browser settings. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
In connection with the use of the Meta Pixel, data may be transferred to servers of Meta Platforms Inc. in the USA or other countries. Meta relies, among other things, on the EU–US Data Privacy Framework and standard contractual clauses approved by the European Commission to ensure an adequate level of data protection.
13. Data Security
We take the protection of your personal data seriously and apply technical and organizational measures aligned with our internal Security Posture. In particular:
- Your password is protected using industry-standard one-way hashing (BCrypt) and is never stored in a readable form.
- Login sessions are protected with secure cookies that are inaccessible to scripts, and we offer passwordless login with passkeys (WebAuthn) as a phishing-resistant option.
- All traffic to and from our website and app is encrypted in transit (HTTPS/TLS).
- Our infrastructure is protected by an edge firewall with DDoS and bot mitigation. Access to our database is limited to our backend application only and is never made directly from your browser.
- Your data is encrypted at rest by our database provider, with managed daily backups.
- Card payments are handled by our PCI-compliant payment processor (Stripe); we do not store full card numbers on our systems, and payment notifications are cryptographically verified.
- We minimize the personal data included in our technical logs and error monitoring.
- Access to administrative functions is restricted by role and is logged.
Detailed technical and organizational measures are documented internally in our Security Posture, available on request for audit or data protection purposes (DPO). However, no method of transmission over the internet or method of electronic storage is completely secure, and while we strive to protect your personal data, we cannot guarantee its absolute security.
14. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:
- Booking and financial records: 10 years (Swiss Code of Obligations, art. 958f).
- Customer accounts: until you request deletion, or up to 24 months after your last activity.
- Marketing consent and newsletter data: until you withdraw your consent or unsubscribe.
- Website and app analytics: retained for a limited period (our own analytics up to 90 days; third-party tools such as Meta according to their own retention policies).
When personal data is no longer needed, it is deleted or anonymized. Where records must be retained for legal reasons (for example, accounting obligations), we restrict their use to that purpose.
15. Third-Party Links
Our website may contain links to third-party websites that are not operated by us. We are not responsible for the privacy practices of these third-party websites. We encourage you to review the privacy policies of any website you visit.
16. Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. The updated version will be posted on our website with the date of the last revision. We encourage you to review this Privacy Policy periodically.
17. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
TravelTribe GmbH
Erlachstrasse 46, 8003 Zürich, Switzerland
Email: [email protected]
Phone: +41 77 807 09 51