Privacy policy

Last updated: 8 August 2026

We collect what a booking needs, and nothing for advertising. No trackers, no analytics scripts, no data sold to anyone. Travellers don't get an account or a tracking cookie — you give a guide your name and email so they can confirm your tour, and that's the whole of it.

1. Who this covers

This policy covers data collected by All my tours, operated by Michal Acler, Stepní 346, Pouzdřany, Czechia, who is the data controller for it. It applies to guides who create a page and travellers who book a tour. It does not cover what a guide does with your information outside the app — once a guide has your details, they are responsible for how they use them.

2. What we collect

If you book a tour: your name, email, phone (only if the guide asks for it), party size, chosen language, and any notes you add. If you leave a review: your name, email, rating, and review text.

If you’re a guide: your name, email, and whatever you choose to put on your profile — photo, bio, languages, phone, city, social links. There is no password to collect: signing in works by emailing you a single-use link that expires after 15 minutes. If you connect Google Calendar, we store an encrypted token that lets us read your calendar's busy times and create or update events; we never see your Google password.

Automatically: one session cookie (gb_session, httpOnly and Secure, so page scripts can't read it and it only ever travels over HTTPS) that keeps a guide signed in, and a second short-lived one only when a site administrator is working inside a guide's account at their request. Travellers booking a tour get no cookie and no account. The booking form is protected from bots by Cloudflare Turnstile, which may briefly run a challenge in your browser. We keep a log of the emails we send, so a guide can see whether a confirmation actually went out. We do not run advertising trackers or third-party analytics scripts.

3. How we use it, and why we’re allowed to

To perform the booking you asked for — showing the guide your request, and sending confirmation, reminder, and cancellation emails. To sync a confirmed booking to the guide's Google Calendar, if they've connected one. To email you a review request after your tour ends. To let a guide keep their own notes on repeat customers, visible only to that guide.

Under the GDPR, our legal basis is performing the contract you entered into (the booking and the account), and our legitimate interest in running the platform safely — spam protection, the email log, and keeping a guide's business records intact. We don't use your data for marketing.

4. Who we share it with

The guide you book with sees your booking details — that's the point of the platform. Beyond them, we use a small number of providers purely to run the service:

  • Resend — delivers our transactional emails (confirmations, reminders, log-in links).
  • Hetzner — hosts the application and its database, on servers in the EU.
  • Cloudflare — DNS, and the Turnstile check that keeps bots out of the booking form.
  • Google — only if a guide connects Google Calendar, in which case a booking's date, time, and the details you entered are written to that guide's calendar.

We do not sell data, and we don't share it with advertisers. We will disclose data if the law requires it.

5. Where it’s stored

On servers in the EU. Some of the providers above are US companies operating EU infrastructure; where data reaches them outside the EU, it's covered by their standard contractual clauses.

6. How long we keep it

Bookings and reviews are kept as part of a guide's ongoing business records — their revenue history, repeat-customer recognition, and published reviews all depend on them. Sign-in links expire after 15 minutes and are then unusable.

The contents of the emails we send are kept for 90 days and then deleted automatically. The record that an email was sent — what kind, to which address, when, and whether it arrived — stays with the booking, because that's part of a guide's record of the booking. There's no reason to keep the wording beyond 90 days, so we don't.

When a guide's account is deleted, their page, tours, bookings, reviews, and email log go with it. If you're a traveller who wants your own details removed sooner, write to us and we'll delete them from the guide's records within 30 days, except where we have to keep something to comply with the law.

7. Your rights

You can ask us for a copy of the data we hold about you, have it corrected, have it deleted, or object to how we use it. Email support@allmytours.com and we'll handle it by hand — there's no self-service export or delete tool yet, and we'd rather say so than pretend otherwise. We aim to reply within 30 days.

If you think we've handled your data badly, you can complain to your local data protection authority. Ours is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).

8. Security

Sign-in is passwordless — we email a single-use link that expires quickly, so there's no password to steal or leak. Google Calendar tokens are encrypted at rest, and each part of the system uses its own derived key rather than one shared secret. All traffic is served over HTTPS. No system is perfectly secure, but we don't collect more than the booking flow needs.

9. Changes to this policy

We'll update the date at the top of this page when this changes, and post the new version here.

10. Contact

Questions, or a data access or deletion request: use the support form, or write to support@allmytours.com if you prefer. Both reach the same person.