Privacy Policy
Last updated: 8 May 2026
Data controller
Tilen Godeša s.p.
Unec 117, 1381 Rakek, Slovenia
VAT ID: SI34826696 · Registration: 9199349000
Email: info@tilen-tours.com
This privacy policy explains how Tilen Godeša s.p. ("we", "us", "Tilen Tours") collects, uses and protects your personal data when you use the website tilen-tours.com or book a tour.
1. Data we collect
- Booking information you submit: full name, email address, phone number, tour date, group size, dietary preferences (vegetarian count), optional notes / special requests, music preference.
- Payment information: handled entirely by Stripe Payments Europe Ltd. We never see or store your full card number; Stripe sends us only confirmation that payment succeeded plus the last 4 digits of the card.
- Technical data: IP address, browser type, language preference. Used only to deliver the site. We do not run analytics, advertising or tracking tools.
2. Why we collect it (legal basis)
- To prepare and deliver the tour you booked - performance of contract, GDPR Art. 6(1)(b).
- To send booking confirmation and pre-tour information by email - performance of contract.
- To comply with Slovenian tax and accounting law, which requires retention of invoice records for 10 years - legal obligation, GDPR Art. 6(1)(c).
3. Who we share data with
We use the following processors, all bound by EU-compatible Data Processing Agreements:
- Stripe Payments Europe Ltd - payment processing
- Resend, Inc. - transactional email delivery
- Neon, Inc. - database hosting (EU region)
- Netlify, Inc. - website hosting
We never sell your data and we never share it with anyone for marketing purposes.
4. How long we keep it
- Booking and invoice records: 10 years (Slovenian Tax Procedure Act).
- Email correspondence: up to 3 years from last contact, then deleted.
- Technical/server logs: 30 days.
5. Your rights under GDPR
- Right of access - request a copy of the data we hold about you.
- Right of rectification - correct inaccurate data.
- Right of erasure - delete data we hold about you (subject to legal retention obligations above).
- Right to restrict or object to processing.
- Right of data portability - receive your data in a structured, machine-readable format.
- Right to lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec).
To exercise any of these rights, email info@tilen-tours.com. We respond within 30 days.
6. Cookies
We use only strictly necessary cookies:
- Locale preference - remembers your chosen language (set by next-intl).
- Stripe checkout session - set by checkout.stripe.com only during the payment flow.
- Admin authentication - used only for authorised admin users.
We do not use any tracking, analytics or advertising cookies. Under GDPR and the ePrivacy Directive, strictly necessary cookies do not require prior consent.
7. Changes to this policy
We may update this policy occasionally. The "Last updated" date at the top reflects the current version.