Privacy Policy

This site is deliberately data-minimal: no analytics or marketing cookies, no embedded third-party content, no contact form, no newsletter, no comments. The following explains what data is nonetheless processed and on what legal basis.

Controller

The controller under the GDPR is the operator named in the imprint. Address and contact: <todo: same as the imprint>.

Hosting, database and image storage are provided by <todo: name of the hosting provider / processor behind travel2sunrise> as a processor under Art. 28 GDPR.

Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR), and the right to lodge a complaint with a supervisory authority. <todo: name the competent supervisory authority.>

Server log files

When you visit the site, the hosting provider processes technically necessary access data: IP address, date and time, the URL requested, the amount of data transferred and the user agent your browser sends. This is required for the secure and stable operation of the website (legal basis Art. 6(1)(f) GDPR, legitimate interest). Retention: <todo: log retention period at the hosting provider>.

Processors

The following providers process data on our behalf. Some are based in the USA; such transfers are safeguarded by the EU Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework.

  • Hosting, delivery and server logs: Vercel Inc. (Delaware), 440 N Barranca Ave #4133, Covina, CA 91723, USA. Transfers to the USA are safeguarded by the EU Standard Contractual Clauses (implementing decision 2021/914) under Vercel’s data processing addendum.

  • Database (stores the site content): Neon, LLC, a Databricks, Inc. company, 160 Spear Street, 15th Floor, San Francisco, CA 94105, USA. Data is stored in the eu-central-1 region (Frankfurt, Germany); as the provider is US-based, processing is additionally safeguarded by the EU Standard Contractual Clauses.

  • Image storage (serves photos and video): Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (EU representative: Cloudflare Germany GmbH, c/o Design Offices München Atlas, Rosenheimer Straße 143C, 81671 München). Cloudflare is certified under the EU-US Data Privacy Framework, supplemented by the EU Standard Contractual Clauses.

Cookies and local storage

The site sets no cookies for visitors. Your light/dark preference is stored only locally in your browser (localStorage); it never leaves your device and is never sent to us. A session cookie is set only when the operators sign in to edit the site — it is strictly necessary, does not concern visitors and is not used for analytics.

Fonts and maps

Fonts are served from our own server (no Google Fonts). Maps are generated on our server and shown without third-party map tiles, so viewing the site transfers no data to third parties.

Photos and metadata

Photos uploaded by the operators are stripped of their metadata before publication; in particular, any GPS location data (EXIF) is removed and never reaches the browser.

Last updated

<todo: date of last update>. We will update this policy if the site changes.