Privacy Policy

Privacy Policy

Last updated: 21 July 2026

We take your privacy seriously. This policy explains what personal data Brasov Day Trips (the "Operator", "we") collects, why we collect it, how we use it and what rights you have under the EU General Data Protection Regulation (GDPR).

1. Data controller

Brasov Day Trips, Brașov, Romania. Contact for any privacy question: info@brasovdaytrips.ro.

2. What we collect

  • Booking details — name, email, phone, hotel or pickup address, number of guests, tour date and any notes you send us.
  • Payment metadata — the amount, currency, status and reference of the payment. Full card details are handled directly by our payment processor (Viva.com); we never see or store them.
  • Communications — messages you send us by email, WhatsApp or the contact form.
  • Website usage — basic technical data (IP address, browser, pages visited) via essential and, where you accept, analytics cookies. See our Cookie Policy for details.

3. Why we use it (legal basis)

  • To take, confirm and deliver your booking — performance of a contract (Art. 6(1)(b) GDPR).
  • To reply to questions and provide customer support — legitimate interest (Art. 6(1)(f)).
  • To meet Romanian tax, accounting and consumer-protection obligations — legal obligation (Art. 6(1)(c)).
  • For optional analytics and marketing, and non-essential cookies — your consent (Art. 6(1)(a)), which you can withdraw at any time.

4. Who we share it with

We share data only with parties who need it to run your booking or the site:

  • Viva.com — card payment processing.
  • Our WordPress/WooCommerce backend host (shop.brasovdaytrips.ro) — order storage and invoicing.
  • Google — hosting fonts and, if you accept, analytics.
  • Cloudflare / hosting providers — website delivery and security.
  • Romanian tax and public authorities — when required by law.

We do not sell your data and we do not use it for automated decisions.

5. International transfers

Some of the services above are operated from outside the European Economic Area. When that happens, transfers are protected by the European Commission's Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

  • Booking and invoicing records — 10 years, as required by Romanian tax law.
  • Support messages — up to 3 years after the last contact.
  • Analytics data — up to 26 months.
  • Cookie consent choice — up to 12 months.

7. Your rights

Under the GDPR you can ask us to: access the data we hold about you, correct it, erase it, restrict or object to its processing, or receive it in a portable format. To exercise any right, email info@brasovdaytrips.ro — we reply within 30 days. If you believe we mishandle your data, you can complain to the Romanian Data Protection Authority (ANSPDCP), www.dataprotection.ro.

8. Security

We use HTTPS everywhere, restrict access to booking data to the people who need it, and rely on reputable processors with their own security programs. No system is 100% secure, but we take reasonable care.

9. Children

Our tours are family-friendly, but bookings must be made by an adult (18+). We do not knowingly collect data from children directly.

10. Changes

We may update this policy. The version in force is the one shown on this page.