Cyprus Bucketlist
TownsActivitiesAirport BusesGuidesAbout
Cyprus Bucketlist

Discover unforgettable experiences across Cyprus. Curated tours, local experts, easy booking.

Add as a preferred source on Google Opens Google in a new tab.

Destinations

  • Ayia Napa
  • Larnaca
  • Limassol
  • Paphos
  • Protaras
  • View all destinations→

Activities

  • Blue Lagoon
  • Boat Trips
  • Culture
  • Kayak
  • Safari
  • Swim With Turtles
  • View all activities→

Quick Links

  • Paphos
  • Ayia Napa
  • Larnaca
  • Protaras
  • Limassol
  • Blue Lagoon
  • Beaches
  • Latchi & Polis Restaurants
  • Cyprus Spirits
  • Turtle Watching
  • Safari Tours
  • Member Discounts
  • Boat Trips
  • Food
  • Contact
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
© 2025-2026 Cyprus Bucketlist. All rights reserved.

We use cookies

We use cookies to keep the site working, remember your language, and — only with your permission — understand how visitors use the site and measure our advertising. Read our Cookie Policy.

Privacy Policy

Version v2 — 2026-09-15

Privacy Policy

Effective date: 15 September 2026 Last updated: 15 September 2026

1. Who we are

This Privacy Policy explains how DEMCYN LTD (“we”, “us”, “Cyprus Bucketlist”) collects, uses, and shares personal data when you use cyprusbucketlist.com (the “Site”) or make a booking through it.

  • Registered office: Vavyla 3, Block A, Flat/Office 204, Pera Chorio Nisou, 2572 Nicosia, Cyprus

  • Company number: HE 491561

  • Jurisdiction of incorporation: Cyprus

  • Contact for privacy matters: support@cyprusbucketlist.com

  • Data Protection Officer: not appointed — we are below the Article 37 GDPR thresholds (our core activities involve neither large-scale regular monitoring nor large-scale special-category processing). We review this assessment annually.

We are the data controller for the personal data described in this Policy, except where we act as a processor on behalf of a third party (rare; flagged in §5).

2. The short version

  • We collect the data you give us at booking (name, email, phone, payment details via Stripe), what you do on the Site, and what you tell us in messages. For Tours that legally require a passenger manifest (for example boat trips), we also collect each participant’s date of birth, passport or ID number, and nationality — and delete those details shortly after the Tour.

  • If you allow Advertisement cookies, we also keep the advertising click identifier and campaign labels from the link that brought you here, the address of the page you first landed on (with no personal tokens), and the address of the website that referred you. We use these only to work out which advertisement or source led to a booking, and, when we run Google Ads campaigns, to report paid bookings back to Google Ads. If you do not allow Advertisement cookies, none of this is recorded.

  • If you message us on WhatsApp, or reply to a WhatsApp message from us, the conversation is stored by us and copied into our private Slack workspace so our team can answer you. See §9.3.

  • We use it to deliver the booking, run our service, comply with the law, remind you about a booking you started but did not finish (you can opt out of these reminders at any time), and — only with your separate consent — send marketing.

  • We share booking details with the relevant Operator so they can run the Tour, with Stripe to take payment, with Twilio and Resend to message you, with Clerk to manage your account, and with our hosting providers (Vercel, Neon), with Slack to run our team workspace (§5.2), and, only with your Advertisement consent and when we run Google Ads campaigns, a paid-booking report to Google Ads. We do not sell your data.

  • We keep most booking and payment records for 6 years (accounting/tax, and to defend claims), then delete or anonymise them.

  • You have rights to access, correct, delete, port, restrict, and object — see §11.

3. What we collect

3.1 You give us, directly

  • At checkout: first name, last name, email, phone number, number and ages of participants, pickup location (if applicable), free-text notes (allergies, special requests, accessibility), and participant names for Tours that require them.

  • Transfer bookings only: when you book a transfer (point-to-point transport, such as an airport-to-port transfer), the booking form asks for your pickup and drop-off addresses and, optionally, the flight or sailing number of your arrival (so the Operator can track it and time the pickup) and any access notes you choose to add, such as a gate code, entry instructions, or the name of your villa or hotel. The flight or sailing number and the access notes are optional. All of it is passed to the Operator (§5.1) and kept as part of the booking record (§7). If no listing covers the route you want, we may ask operators to quote for it. To do that we send the pickup and drop-off addresses, the date and time, and the party size to the operators whose service area covers your route — but not your name, contact details, flight or sailing number, or access notes. More than one operator normally receives it, and operators who do not get your booking must delete those details as soon as their quote lapses or another quote is accepted.

  • Passenger-manifest details, only where the Tour legally requires them: some Tours — typically boat trips — are legally required to file a passenger manifest. For those Tours the booking form additionally asks for each participant’s date of birth, passport or identity-document number, and nationality. The form tells you when this applies. These fields are passed to the Operator (§5.1), are never sent by SMS or WhatsApp, and are deleted shortly after the Tour (§7).

  • Payment: card details and billing address — entered on the Stripe payment page; we do not see or store full card data. We store a Stripe customer ID and a payment-method reference so we can issue refunds.

  • Account (optional): the data above plus an authentication identifier from Clerk. If you sign in with Google or another social provider, we receive the basic profile fields that provider gives us.

  • Customer messages: the content of emails you send us and replies to SMS messages.

  • Contact form: if you submit our contact form, your first name, last name (optional), email address, phone number (optional for a general enquiry) and message; for a private-experience enquiry the phone number is required, and we also collect your preferred activity types, locations, number of people, and preferred date. We record the language of the page you used and your browser's user-agent string. The form uses a hidden anti-bot field, a submission rate limit, and Cloudflare Turnstile (§5.2) to filter out automated submissions; a submission caught by these checks is not stored, and neither the anti-bot field's value nor the Turnstile token is kept.

  • WhatsApp conversations: if you send a WhatsApp message to our business number, or reply to one of ours, we store the conversation as a thread kept under your phone number: your number, the display name your WhatsApp profile shows us, the text of every message we receive and every reply we send (including which team member sent it), and a count of any attachments. Photos, voice notes and files you send are not kept in our own database: they are held by our messaging provider and copied into our private Slack workspace (§5.2, §9.3) so our team can see them. Messages from numbers we cannot match to a booking or Operator are stored in the same way. The whole thread is copied into our private Slack workspace (§5.2, §9.3). Internal notes our team writes in the thread are never sent to you and are not added to the stored conversation; they remain in our Slack workspace. Anything you volunteer in chat about health, dietary, mobility or similar needs (§3.5) is used only to answer you or to deliver the service you booked, and for nothing else.

3.2 We collect automatically

  • Technical data: IP address, user-agent string, device type, language, browser settings — used for security, abuse prevention, and basic analytics.

  • Usage data: pages visited, searches performed, Tours viewed, items in cart, click and scroll signals — used to improve the Site and (with consent where required) for remarketing.

  • Advertising and referral source (only with Advertisement consent): if you arrive from a link that carries an advertising click identifier (Google gclid, wbraid or gbraid; Meta fbclid) or campaign labels (utm_source, utm_medium, utm_campaign, utm_term, utm_content), we keep those values. If you arrive from another website, with or without an advertisement, we also keep that website’s address (for example https://chatgpt.com), never the page or search you came from, and the address of the page on our Site you arrived at (our domain, the page path, and any campaign labels or advertising click identifiers in the link; everything else in the link is discarded, and no landing page is recorded at all if it was a checkout, account, unsubscribe or confirmation page). Hops through our payment or sign-in providers are ignored. Nothing is recorded if you arrive by typing our address or from a bookmark. We keep these for the visit we treat as your first contact; a later visit from a Meta advertisement replaces an earlier plain referral, and a later advertising click renews the click identifier and campaign labels. These values are held in the first-party cookies gag_ad_click, gag_utm and gag_touch (§8) for up to 90 days and are copied to your booking record if you book. They are written only after you accept the Advertisement category in the cookie banner (immediately, if you accepted it on an earlier visit); until then the browser holds them in memory only and discards them if you refuse. If you never accept Advertisement cookies, nothing from the link or the referring website is stored.

  • Cookies and similar: see §8.

3.3 From third parties

  • Stripe — payment-result codes, fraud signals, partially-masked card details (last four digits, expiry, brand).

  • Operators — confirmation/decline messages and any notes they send us about your booking. Where the Operator keeps the Tour’s availability in its own reservation system, that system also sends us the confirmation of your place, any ticket or voucher it issues, and any change or cancellation of your booking made on the Operator’s side.

  • Operators, for bookings they take themselves — if you book directly with an Operator, for example by telephone, the Operator may record the booking on our platform so that its availability, its daily list and, where the law requires it, its passenger manifest stay correct. The Operator then gives us your name and, where it chooses to add them, your phone number and email address and, for Tours that legally require a passenger manifest, your date of birth, passport or identity-document number and nationality. That booking is between you and the Operator: we do not contact you, we take no payment, and it is not a booking made through the Site. We hold those details on the Operator’s behalf so that its records stay correct, and we delete the identity-document details on the same schedule as for any other booking (§7).

  • Booking platforms and resellers — if you book an Operator’s Tour on a booking platform or with a reseller that uses us to hold the Operator’s availability, it sends us the details we need to hold your place with the Operator: your name, email address, phone number, your party size by age category (adult, child, infant), its booking reference and, where the Tour collects you from your accommodation, the accommodation you gave it; no dates of birth or individual ages. The platform or reseller sold you the Tour, holds your customer relationship, and is an independent controller of your data. We hold the details it sends us on the Operator’s behalf, to hold your booking with the Operator, to keep the Operator’s calendar accurate and, where the Operator records attendance, to record whether you arrived; where the accommodation you gave matches one of the Operator’s recorded pickup points, we tell the Operator which point it is. We do not contact you about such a booking unless the platform or reseller has asked us to.

  • Affiliate partners (where applicable): the referral code showing which affiliate brought you to us (§5.7).

  • Advertising platforms: we do not receive data about you from Google Ads or Meta. The click identifiers in §3.2 are read from the link you clicked, not sent to us by the platform. The referring website’s address is read from your browser’s referrer header, not from that website.

  • Auth providers (Clerk and the social providers behind it) — profile data you authorise on sign-in.

We do not buy contact lists and we do not enrich profiles from data brokers.

3.4 Data we do not collect

For the avoidance of doubt, we do not collect:

  • full payment-card numbers, CVCs, or PINs (Stripe handles all of this — we see only masked references);

  • biometric data, genetic data, or health data beyond what you voluntarily put in the customer-notes field;

  • precise geolocation from your device (we do not request the browser location permission);

  • the contents of your address book, photos, files, or other apps on your device;

  • social-media data beyond the basic profile fields the auth provider returns on sign-in;

  • information about you from third parties for the purpose of building a profile.

3.5 Special-category data in the customer-notes field

Where you voluntarily disclose special-category data (Article 9 GDPR — including health information, allergies, religious dietary requirements, disability information) in the customer-notes field so the Operator can accommodate you, you are giving explicit consent to that disclosure for that specific purpose. We pass it to the relevant Operator, treat it with the same care as the rest of your data, and use it for no other purpose.

3.6 Booking for other people

If you book for other people, you give us their personal data (names and, for manifest Tours, dates of birth, passport/ID numbers, and nationalities). You confirm that you are authorised to do so, that you have informed them how their data will be used (this Policy), and — for any co-traveller’s special-category or identity-document data — that you have their consent to share it with us and the Operator. We rely on you, as the lead booker, to pass on to your party any information we send about the booking.

4. Why we use it and on what legal basis

Purpose

Data

Legal basis (GDPR Art. 6 / 9)

Take, confirm and fulfil your booking

Contact, payment, participant, pickup, notes

Contract (Art. 6(1)(b))

Pass booking details to the Operator so they can run the Tour

Contact + booking details, customer notes

Contract (Art. 6(1)(b)); for health info in notes, explicit consent (Art. 9(2)(a))

Hold a booking that a booking platform or connected reseller sold you with the Operator, and show it to the Operator to run the Tour (§3.3, §5.1)

Name, email, phone number, party size by age category, platform booking reference and, where applicable, your stated accommodation or pickup point

Legitimate interests (Art. 6(1)(f)) — providing the reservation service the Operator has asked us for; your booking itself is governed by the platform’s terms

Keep an Operator’s availability, daily list and passenger manifest correct for a booking the Operator took itself and recorded with us (§3.3)

Name; phone number and email where the Operator entered them; for manifest Tours, date of birth, identity-document number and nationality

Processing on the Operator’s behalf under its agreement with us; the Operator is the controller and its own legal basis applies

Ask operators to quote for a transfer you have requested, and show you their quotes (§3.1, §5.1)

Pickup and drop-off addresses, date and time, party size — no name or contact details

Contract (Art. 6(1)(b)) — steps taken at your request before a contract is made

Send transactional emails/SMS/WhatsApp (confirmation, reminders, changes, cancellation, review request)

Contact + booking

Contract (Art. 6(1)(b))

Remind you about a booking you started but did not finish — up to three emails over seven days, opt-out link in every one (§9.4)

Email + the saved booking details

Legitimate interests (Art. 6(1)(f)) + the ePrivacy “soft opt-in” (Art. 13(2) Directive 2002/58/EC as transposed in Cyprus)

Collect and pass passenger-manifest details where maritime law requires a manifest (§3.1, §5.1)

Participant names, dates of birth, passport/ID numbers, nationality

Legal obligation (Art. 6(1)(c) — Directive 98/41/EC) + Contract (Art. 6(1)(b))

Record and evidence your consents (cookie-banner choices; Terms/Privacy acceptance at booking)

Choice made, timestamp, truncated IP, opaque consent ID, document version

Legal obligation (Art. 6(1)(c), Art. 7(1) — demonstrating consent)

Administer customer credits (issue, redeem at checkout, restore on eligible cancellations, expiry)

Account, booking, credit ledger

Contract (Art. 6(1)(b))

Attribute a booking to the affiliate whose link brought you to us, and pay their commission (§5.7)

Referral code, booking reference, date, value

Legitimate interests (Art. 6(1)(f)) — measuring and paying for genuine referrals

Attribute a booking to the advertisement or source that brought you to the Site (§3.2, §8)

Click identifiers, campaign labels, first landing page, referring website, and a flag recording whether you had granted Advertisement consent at checkout

Consent (Art. 6(1)(a)) via the Advertisement category of the cookie banner; withdrawable at any time (§8)

Report a paid booking back to Google Ads, when we run Google Ads campaigns, so we can measure which advertisements work (§5.2)

Google click identifier, booking reference, booking value and currency, time of upload, and a flag confirming that you granted Advertisement consent at checkout; no name, email or phone

Consent (Art. 6(1)(a)), same Advertisement consent; the report is sent only where you had granted it at checkout

Answer your WhatsApp messages and keep a record of what was agreed (§3.1, §9.3)

Phone number, WhatsApp display name, message text in both directions, attachment count, our reply and who sent it; copies of attachments in Slack

Contract (Art. 6(1)(b)) for customers with a booking; legitimate interests (Art. 6(1)(f)) in responding to enquiries for everyone else; for health or similar details you volunteer, explicit consent (Art. 9(2)(a)) as in §3.5

Process payments and refunds

Payment, Stripe tokens

Contract (Art. 6(1)(b)) + Legal obligation for financial records (Art. 6(1)(c))

Keep records for tax and accounting

All transactional records

Legal obligation (Art. 6(1)(c))

Customer account, sign-in, sign-out

Auth identifier, account-linked bookings

Contract (Art. 6(1)(b))

Customer support, dispute and refund handling

Whatever data is relevant to the case

Legitimate interests (Art. 6(1)(f)) — running our service responsibly

Answer a message sent through the contact form (§3.1)

Contact-form fields (§3.1), user-agent

Legitimate interests (Art. 6(1)(f)) — responding to enquiries

Fraud prevention, abuse and chargeback handling

Technical, payment, behavioural

Legitimate interests (Art. 6(1)(f))

Service analytics, error monitoring

Technical, aggregated or pseudonymous usage

Legitimate interests (Art. 6(1)(f)); cookie-based analytics by consent (see §8)

Marketing emails about new Tours, offers

Email, basic interest signals

Consent (Art. 6(1)(a)) — opt-in, opt-out at any time

Post-Tour review request (one email; opt-out link inside — §9.1)

Contact + booking

Contract / legitimate interests (Art. 6(1)(b) / (f))

Reviews published on the Site, and possibly re-used in our own marketing materials (§9.1)

First name, review text, optional photo

Consent at the moment you submit

Cookies that are not strictly necessary

Various, per §8

Consent via the cookie banner

We do not rely on legitimate interest for anything that materially overrides your privacy.

5. Who we share data with

5.1 Tour Operators — independent data controllers

For every booking, the relevant Operator receives: your first name, last name, phone number, email; party size and any participant names you provided; pickup location, time slot, customer notes (allergies, special requests); for Transfer bookings, the exact pickup and drop-off addresses (including coordinates where you give them), the flight or sailing number and time you provided, and any access notes you added, such as a gate code, entry instructions, or the name of your villa or hotel; the booking reference and the total payable to them.

Transfer quotes. If you ask for a transfer that no listing covers, we send a quote request to the operators whose recorded service area, or the routes of their published transfer listings, covers it. That request contains the pickup and drop-off addresses, the date and time, and the party size, so that they can price the journey. It does not contain your name, contact details, flight or sailing number, or access notes, and more than one operator will normally receive it. Only the operator whose quote you accept receives your identity and contact details, and only once the booking is made. Operators who do not get the booking are required by their agreement with us to delete the request details as soon as their quote lapses, is withdrawn, or another quote is accepted.

For Tours that legally require a passenger manifest, the Operator additionally receives each participant’s date of birth, passport/ID number, and nationality (§3.1) so it can file the manifest. We send identity-document details to the Operator only through secured channels (the Operator portal, the booking-notification email, and the printable manifest) — never by SMS or WhatsApp, which carry participant names at most.

Sharing can also run the other way: where it is necessary to deliver the Tour or to handle a dispute between you and an Operator (for example over a cancellation or a refund), we may pass relevant information from the Operator to you — such as meeting-point instructions, schedule changes, or the Operator’s response to a complaint — and relevant booking information from you to the Operator.

The Operator uses this data to deliver the Tour. The Operator is an independent data controller for its own processing of your data after handover — including for its own legal record-keeping. Operators are required by their agreement with us to comply with applicable data-protection law and to use the data only to deliver the Tour.

Operators’ own reservation systems. Some Operators keep their availability and bookings in their own reservation system, run for them by a software provider. Where you book such a Tour, we place your booking in that system at checkout: the lead traveller’s first name, last name, email address, phone number, and language, the number and categories of participants, any note you entered at checkout, and our booking reference. No participant names or payment details are sent there. The Operator is the controller of that copy and its software provider is the Operator’s processor. We cannot delete or correct data inside the Operator’s system; the Operator is required by its agreement with us to act on any deletion or correction request we pass on.

Our Operators are currently based in Cyprus (within the EEA), so sharing booking data with them is not an international transfer. If we onboard an Operator outside the EEA, or an Operator tells us that it uses a subcontractor or supplier outside the EEA, we will put a valid transfer safeguard in place before booking data reaches them, and update this Policy.

After the Tour, the Operator keeps its own copy under its own retention policy and law, subject to the limits our Supplier Agreement places on it — in particular, for Transfer bookings the Operator must delete the pickup and drop-off details, your contact details, flight or sailing details, and any access notes within 5 days of the Transfer, unless a dispute about the booking is open or the law requires it to keep them for longer. That copy is otherwise the Operator’s responsibility, and a subject-access request about data the Operator holds should be directed to the Operator. We can supply the Operator’s contact details on request.

Photographs taken by Operators. Operators frequently photograph or film Tours for their own marketing. To the extent these recordings contain identifiable images of you, the Operator is the controller for that processing — speak to the Operator about consents, takedowns, and copies. Where we have asked the Operator for a copy of an image for our own marketing, we are the controller for that specific copy and you may also contact us.

5.2 Service providers and advertising partners

We share only what each provider needs. We have data-processing terms in place with each, or rely on their standard data-processing terms incorporated into the service contract. Stripe, Twilio, Resend, Clerk, Vercel, Neon, Slack, Google Analytics and Cloudflare act as our processors. Meta and Google Ads do not: for the collection carried out through the Meta Pixel we and Meta are joint controllers within the meaning of Article 26 GDPR, and Google acts as a separate controller in respect of the conversion data we report to it. The essence of our arrangement with Meta is available on request, and each of them applies its own controller terms to what it does with the data afterwards.

Provider

Role

Data it processes

Where

Transfer safeguard

Stripe Payments Europe Ltd (EU contracting entity)

Payment processing, fraud screening

Payment + contact data

Ireland; US group entity Stripe, LLC

DPF Active (EU + UK + Swiss; certified 2026-05-11); SCCs in Stripe’s DPA as fallback

Twilio Inc. (contracting via Twilio Ireland Ltd)

SMS and WhatsApp delivery; receipt of WhatsApp messages and attachments you send us

Name, phone number, message content, attachments you send

Ireland; group entities incl. USA

DPF Active (EU + UK + Swiss)

Resend (legal entity Plus Five Five, Inc.)

Transactional email delivery

Name, email, message content

USA

DPF Active (EU + UK; no Swiss cert); DPA also incorporates the EU SCCs

Clerk, Inc.

Authentication and account management

Auth identifier, email, name

USA

DPF Active (EU + UK + Swiss); DPA includes SCCs

Vercel Inc.

Application hosting and CDN

Technical data, anything in requests

USA; EU edge

DPF Active (EU + UK + Swiss)

Neon (Neon, LLC, an affiliate of Databricks, Inc.)

Database hosting (EU region)

All stored personal data, at rest in the EU

EU region; US parent

DPF Active via Databricks, Inc. (Neon, LLC is a listed covered entity); terms via the Databricks DPA

Slack Technologies, LLC (a Salesforce company)

Our private team workspace: (a) booking-lifecycle alerts (new booking, Operator decline, payment failure, dispute, cancellation, email-delivery failure); (b) a copy of every WhatsApp conversation with customers and Operators, which our team reads and replies to from Slack

(a) Customer name, phone, email, booking reference, Tour title, date and time, party size and any free-text notes you gave at booking; (b) phone number, your name (where we can match the number to a booking) or WhatsApp display name, booking reference and Tour title, full message text in both directions, and a copy of any photo, voice note or file you send

Ireland; group entities incl. USA

DPF Active via Salesforce, Inc. (Slack is a listed covered entity)

Google Ireland Ltd / Google LLC: (a) Google Analytics 4, loads only after Analytics consent; (b) Google Ads conversion reporting, when we run Google Ads campaigns and only after Advertisement consent

(a) Usage analytics; (b) a server-to-server report that a booking was paid, retracted if the booking is cancelled before payment is taken or fully refunded (partial refunds are not reported)

(a) Technical + usage data (Consent Mode v2, default-denied); (b) Google click identifier, booking reference, booking value and currency, upload time, and a flag confirming that you granted Advertisement consent at checkout. No name, email, phone or other identity field is sent

Ireland; group entities incl. USA

DPF Active (EU + UK + Swiss)

Meta Platforms Ireland Ltd / Meta Platforms, Inc. (Meta Pixel) — active; loads only after Advertisement consent

Advertising measurement

Technical + event data

Ireland; group entities incl. USA

DPF Active (EU + Swiss; no UK Extension — UK-origin transfers rely on Meta’s UK addendum/IDTA)

Cloudflare, Inc.

Bot protection on the contact form (Turnstile)

IP address and browser signals needed to tell people from bots

USA

DPF Active (EU + UK + Swiss)

We do not send booking or identity data to Meta from our servers. The Meta click identifier (fbclid) is stored on your booking record for our own attribution only.

Booking platforms and resellers. They are not our processors and do not act on our instructions; each is a separate, independent controller. Where your booking was made on such a platform, we exchange with it only the operational messages that booking needs: confirmation, amendment, cancellation, and the booking reference. We do not send it your data for marketing.

5.3 Authorities

We disclose data to courts, regulators, tax authorities, or law-enforcement bodies where legally required, or where necessary to protect our or a third party’s rights, property, or safety.

5.4 Business transfers

If we reorganise, merge, or are acquired, your data may transfer to the successor entity. We will notify Account holders before any such transfer takes effect.

5.5 What we do not do

We do not sell personal data. Apart from the Meta Pixel described in §5.2 and in our Cookie Policy — which loads only if you accept the Advertisement category, and which Meta may use to build advertising audiences — we do not share personal data with advertising networks for cross-site profiling. The only data we send to an advertising platform from our servers is the Google Ads conversion report described in §5.2, sent when we run Google Ads campaigns. It contains a click identifier, a booking reference and the booking value, but no name, email address or phone number, and it is sent only where you granted Advertisement consent at checkout. We do not pass your data to a sister site or third party for their own marketing. The operational exchange with a booking platform or reseller, or with an Operator’s reservation system, described in §3.3, §5.1, and §5.2 is not marketing. We honour the Global Privacy Control browser signal as an opt-out of any sale or sharing of personal data.

5.6 Profiling and personalisation

We may rank Tours, surface “popular” or “trending” results, and recommend Tours based on which destination and date you searched for, which Tours you have viewed or booked, and aggregated booking patterns across all customers. How ranking works is also explained in our Terms of Service.

This is personalisation, not automated decision-making with legal effects under Article 22 GDPR. You can browse without an Account; if you have an Account you can ask us to disable personalisation by emailing support@cyprusbucketlist.com. We do not build psychographic profiles for marketing and do not share profile data with third parties.

5.7 Affiliates who referred you

If you arrive at the Site through an affiliate’s link (a ?ref= parameter) and later book, we record the referral so the affiliate can be credited (see §8 for the cookie involved). The referring affiliate can see, in their dashboard: the booking reference, the booking date, and the booking value, together with the commission due to them. The affiliate is never shown your name, email, phone number, or any other identifying detail. Legal basis: our legitimate interest in measuring and paying for genuine referrals (Art. 6(1)(f)).

6. International transfers

Our Operators are currently in Cyprus, within the EEA — sharing booking data with them is not an international transfer. See §5.1 for what happens if that changes.

Several of our service providers (§5.2) are US-headquartered. Where we transfer personal data outside the EEA we rely on:

  • the European Commission’s adequacy decisions where one exists;

  • the EU-US Data Privacy Framework for certified US recipients;

  • the European Commission’s Standard Contractual Clauses otherwise;

  • in all cases, supplementary measures (encryption in transit and at rest, access controls) appropriate to the risk.

You can request the safeguards in place for any specific transfer by emailing support@cyprusbucketlist.com.

7. How long we keep data

Category

Retention

Booking records (incl. customer details on a booking)

6 years after the booking date — for tax, VAT and accounting (Article 6(1)(c)), and for our legitimate interest in defending claims within the Cyprus limitation period (Article 6(1)(f))

Reservation records for bookings sold by a booking platform or reseller, and bookings an Operator recorded itself

Held on the Operator’s behalf for as long as the booking record exists; identity-document details for manifest Tours are deleted 30 days after the Tour; deleted or returned to the Operator when its agreement with us ends, as that agreement provides

Advertising click identifiers, campaign labels, landing page and referring website on a booking

Kept with the booking record (6 years, see above). When we run Google Ads campaigns, the Google Ads report for a booking is sent when your payment is taken (retried if the first attempt fails, for up to 30 days) and retracted if the booking is cancelled before payment or fully refunded; partial refunds are not reported. Withdrawing Advertisement consent deletes the cookies (§8) and stops any further capture. Identifiers already copied to a completed booking are kept with that booking on the basis of the Advertisement consent under which they were collected; if you withdraw that consent we delete them from the booking record too, and keep only aggregate spend figures that no longer identify you

Advertising cookies gag_ad_click, gag_utm, gag_touch

90 days from when they were last set (a later advertising click renews gag_ad_click and gag_utm; gag_touch is replaced only by a stronger signal, see §3.2), or immediately when you refuse or withdraw Advertisement consent

Passenger-manifest identity fields (date of birth, passport/ID number, nationality)

Purged 30 days after the Tour date (hard maximum 60 days, per Directive 98/41/EC); participant names remain part of the booking record

Unfinished (draft) bookings

14 days after capture, then deleted

Transfer quote requests that do not lead to a booking (addresses, date and time, party size, and the quotes we received)

14 days after the quoting deadline passes, then deleted — the same period as unfinished bookings above

Payment records

6 years, same reason

Consent records (cookie-banner choices; Terms/Privacy acceptance at booking)

6 years, to evidence consent (truncated IP, opaque consent ID, document version)

Reminder-email opt-out list

Kept indefinitely — the suppression entry is what honours your opt-out

Account data (no booking activity)

Deleted 30 days after Account closure

Customer credits

Until expiry (per Terms §11) or 6 years after issue, whichever is later

Marketing email subscribers

Until you unsubscribe; suppressed indefinitely after that to honour the opt-out

Customer-service emails, including contact-form messages

3 years after the case is closed

WhatsApp conversations (message text, attachment count, display name, phone number, our replies)

24 months after the last message in the conversation. Deleting a booking does not delete the conversation; use the erasure route in §11

Reviews

Indefinitely while published; removed within 30 days of a valid takedown request

Server logs (IP, user-agent)

90 days for security; anonymised in aggregate after that

Analytics data

24 months, then aggregated

Analytics identifiers on a booking (Google Analytics client and session identifiers, an opaque consent identifier, and a flag recording whether Analytics consent was granted at checkout), recorded only with Analytics consent so we can send pseudonymous purchase and refund events to Google Analytics 4 (§8)

Kept with the booking record (6 years, see above)

Cookies

See §8 — each cookie’s lifespan is published in the cookie banner

After the retention period we delete or anonymise the data. Some records may persist longer where we must keep them by law or are using them in a live dispute.

Aggregated and anonymised data. Where data has been anonymised so you can no longer be identified, it falls outside the scope of personal data and we may retain and use it indefinitely for service improvement and trend analysis.

Operator-held data. Once data has been shared with an Operator (§5.1), the Operator’s own retention policy applies to its copy, within the limits our Supplier Agreement places on it (including the 5-day deletion rule for Transfer details described in §5.1); our deletion does not delete the Operator’s copy.

8. Cookies and similar technologies

Cookies have their own policy: the Cookie Policy at cyprusbucketlist.com/cookies lists every cookie we set, what it does, how long it lives, and the legal basis for each. The short version:

  • When you first visit the Site you are shown a consent banner with equal-weight Accept / Reject / Customise options across six categories (Necessary, Functional, Analytics, Performance, Advertisement, Other). Non-essential cookies are not deployed until you consent.

  • You can change or withdraw your choice at any time via the Cookie Consent link in the footer; we re-ask after 12 months, or sooner if the Cookie Policy materially changes.

  • Your banner choices are recorded in a consent audit log (see §4 and §7) so we can demonstrate consent.

  • The affiliate referral cookie (ref_code) is set only when you arrive through an affiliate’s link. It sits in the Functional category and is set only if you accept that category, because it serves our commission arrangement with the affiliate rather than a service you asked us for. It stores a partner code only, lives 90 days, and is never used to track you across sites. See §5.7 for what the affiliate can see.

  • Advertising attribution cookies (gag_ad_click, gag_utm, gag_touch) are first-party cookies in the Advertisement category. They are set only after you accept that category, live 90 days from when they were last set, are readable only by our server (HttpOnly, SameSite=Lax, Secure), and hold the click identifier, campaign labels, first landing page and referring website described in §3.2. If you refuse or later withdraw Advertisement consent, your browser immediately asks our server to delete them. After a grant we also keep one small entry in your browser’s local storage (gag_touch_sent) recording only that a first-touch record exists and when; it holds no attribution data and is removed when you withdraw. At checkout we also record whether Advertisement consent was in force, so every identifier on a booking sits next to the consent that allowed it.

  • Google Analytics 4 and Meta Pixel are active on the Site, but each loads only after you consent to the relevant category: Analytics for Google Analytics 4 and Advertisement for Meta Pixel. Google Consent Mode v2 is set to default-denied.

  • With Analytics consent, GA4 records pseudonymous journey events such as searches and result counts, Tour and list views, checkout steps, successful account creation, and genuinely paid or refunded booking value. We do not send names, email addresses, phone numbers, form contents, free-text search terms, or selected booking dates and times to GA4. Our application does not supply customer or form fields to GA4 as user-provided data.

8.1 Other tracking technologies

  • Local storage and session storage — used in the browser for the same purposes as cookies (preferences, cart state). Treated the same way for consent purposes.

  • Server-side logs — every request is logged with IP, user-agent, URL, and response code, for 90 days, for security and abuse prevention.

  • Anti-fraud signals — Stripe runs its own device-fingerprinting on the payment page (Radar), as part of Stripe’s processing under its privacy policy.

9. Email and message tracking

9.1 Email open and click tracking

Our transactional emails are delivered by Resend and contain a small tracking pixel and link-rewriting that lets us see whether an email was opened and which links were clicked. We use this only to detect delivery failures (so we can resend by SMS/WhatsApp) and to diagnose support issues (“I never got the email”). We do not aggregate this into marketing profiles. You can defeat the tracking by viewing emails in plain-text mode or blocking remote images.

Marketing emails (where offered) carry the same pixel; the unsubscribe link in every marketing email removes you from the list with one click.

Review-request emails. After your Tour we send one email inviting you to review it. We treat this as part of delivering the service (see §4). If you would rather not receive review invitations, the opt-out link in the email stops them; reviews you do submit are published under your first name and may also appear in our own marketing materials, as explained at the moment you submit.

9.2 SMS messages

SMS notifications are sent from our alpha-sender ID “Bucketlist” through Twilio — typically a confirmation, a 24-hour reminder, and notices of changes or cancellation. Carrier charges may apply depending on your network and roaming status. To opt out of further SMS messages, reply STOP. We will continue to send time-critical operational notices (cancellation, change) by another channel for the duration of an active Booking.

9.3 WhatsApp messages

We may send WhatsApp messages through Twilio’s WhatsApp Business API where you have given us your number. The first message in a conversation is a pre-approved template; the WhatsApp client lets you block or report at any time. To opt out, reply STOP, block the number, or email us. WhatsApp itself processes message metadata under its own privacy policy.

If you write back. Replies and new messages you send to our WhatsApp number are received through Twilio, stored by us as a conversation thread under your phone number (§3.1), and copied into a private channel in our Slack workspace (§5.2) so a team member can answer. The copy shows your name where we can match the number to a booking (otherwise your WhatsApp display name or number), your booking reference and Tour title, each message in full, and a copy of any photo, voice note or file you send. Our replies are typed in Slack, sent back to you through Twilio, and stored in the same thread with a record of which team member sent them. Internal notes our team writes in the thread are never sent to you and are not added to the stored conversation; they remain in our Slack workspace. The same applies to WhatsApp conversations with Operators (see the Supplier Privacy Notice). Please do not send identity documents, card details or health information over WhatsApp unless we ask for something specific to deliver your booking; anything of that kind you do send is used only for that purpose (§3.5). Retention is set out in §7 and erasure in §11.

9.4 Abandoned-booking reminder emails

If you enter your email address and start a booking on the Site but do not complete it, we may send you up to three reminder emails over the following week to give you a chance to finish. We only remind you about that specific booking — we do not use your email for general marketing without your separate consent. A notice next to the email field on the booking form tells you this at the moment we collect the address.

Legal basis: the ePrivacy “soft opt-in” for messages about a sale you began (Article 13(2) of Directive 2002/58/EC, as transposed into Cyprus law), combined with our legitimate interest under Article 6(1)(f) GDPR in completing a sale negotiation you started. You can opt out at any time using the unsubscribe link in every reminder email; we keep your address on a suppression list (§7) so the opt-out sticks.

10. Security

We protect personal data with measures appropriate to the risk, including:

At the application layer — TLS 1.2+ for all traffic, HTTPS strictly enforced; session cookies marked Secure, HttpOnly, and SameSite=Lax by default; CSRF protection on state-changing actions; protection against common web vulnerabilities (XSS, SQL injection, SSRF).

At the data layer — encryption at rest for the production Postgres database (Neon, EU region); encrypted daily backups; payment-card data never received by our servers; tokenisation of cancel-links, supplier-action links, and rebook links so URLs do not leak primary keys.

At the operations layer — role-based access control with least privilege; multi-factor authentication on admin Accounts and third-party dashboards; audit logging of sensitive operations (refunds, account changes, supplier changes, data exports); secrets stored in encrypted environment variables; regular dependency updates; regular review of access lists.

No system is perfectly secure. If we discover a personal-data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware, and where the breach is high-risk to you, notify you directly without undue delay.

If you discover a security issue with the Site, please report it to support@cyprusbucketlist.com before disclosing it publicly. We will not pursue claims against good-faith security researchers who follow this responsible-disclosure approach.

11. Your rights

Under the GDPR you have the right to:

  • Access — a copy of the personal data we hold about you.

  • Rectification — correction of inaccurate or incomplete data.

  • Erasure — deletion of your data where a GDPR ground applies. We cannot delete records we are legally required to keep (for example financial records during the 6-year retention window). For WhatsApp conversations, tell us the phone number you messaged from; we will delete the stored conversation and its copy in our Slack workspace, except for anything we must keep to evidence a booking or a dispute, and we will instruct our messaging provider to delete its copy.

  • Restriction — to ask us to suspend processing while a dispute is resolved.

  • Portability — a copy of the data you provided, in a structured, machine-readable format.

  • Objection — to object to processing based on legitimate interests, including direct marketing (we will stop processing for direct marketing in all cases).

  • Withdraw consent — to withdraw any consent at any time, without affecting processing already carried out. Withdrawing Advertisement consent via the footer link deletes the attribution cookies and stops further capture (§8); it does not undo a Google Ads report already sent for a completed booking.

  • Lodge a complaint with a supervisory authority. Our lead authority is the Office of the Commissioner for Personal Data Protection (Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Iasonos 1, 1082 Nicosia, Cyprus — dataprotection.gov.cy. You may also complain to the data-protection authority in your own country of residence. If you are in the United Kingdom, that includes the Information Commissioner’s Office (ico.org.uk).

11.1 Right to object — direct marketing

Article 21(2) GDPR gives you an absolute right to object to processing of your data for direct-marketing purposes. Where you exercise it, we will stop processing your data for direct marketing immediately and indefinitely, with no need to give a reason. The unsubscribe link in every marketing email is one way to exercise it; emailing us is another.

11.2 How to make a request

Email support@cyprusbucketlist.com with enough detail for us to locate your data (your email address, booking reference, or Account email, or, for WhatsApp conversations, the phone number you messaged from). We may need to verify your identity before responding. We respond within one month; complex or numerous requests may take up to three months in total, in which case we will tell you within the first month. There is no charge, except where requests are manifestly unfounded or excessive (Article 12(5) GDPR).

The data you submit when exercising a right (your message, proof of identity) is itself processed so we can fulfil the request and evidence our compliance — legal basis Article 6(1)(c) GDPR.

11.3 Automated processing in our fraud and payment checks

Some checks in our payment and fraud-prevention process are automated. Our payment processor, Stripe (including Stripe Radar), screens transactions for fraud, and a transaction assessed as high-risk may be automatically declined — which means a Booking may not complete.

If an automated decline affects you, you can ask us to review it, give us your point of view, and contest the outcome, by emailing support@cyprusbucketlist.com. Apart from this fraud-screening, we do not make decisions that produce legal or similarly significant effects on you based solely on automated processing.

12. Third-party links and embedded content

Pages on the Site may link to, or embed content from, third-party services — for example map tiles, embedded videos, or links to Operator social-media profiles. Where third-party content is embedded, the third party may set its own cookies and collect technical data as soon as the content loads. We disclose this in the cookie banner and, where consent is required, load the embed only after you consent.

Following an external link takes you outside the Site. We are not responsible for the privacy practices of third-party sites — please read their own policies.

13. Children

The Service is intended for adults. We do not direct the Site at children under 16, as our Cookie Policy also states. We do not knowingly collect personal data of children except as part of a booking made by an accompanying adult (for example children’s names — or, for manifest Tours, dates of birth and passport details — on a family Tour). We collect a child’s data only where it is provided by and with the consent of a parent or guardian as part of their own booking. Children cannot create Accounts. If we discover we hold a child’s data collected outside this case, or without valid parental consent, we will delete it — and if you believe that has happened, contact us.

14. Changes to this Policy

We may update this Policy from time to time. The current version is always at cyprusbucketlist.com/privacy with the effective date at the top. We will post any material change on this page at least 14 days before it takes effect. Account holders may also be notified by email.

This Policy is drafted in English. Any translation is provided for convenience only; if the versions diverge, the English version prevails.

15. Contact

Privacy questions or requests: support@cyprusbucketlist.com Postal: Vavyla 3, Block A, Flat/Office 204, Pera Chorio Nisou, 2572 Nicosia, Cyprus

We aim to acknowledge within 3 working days and resolve within the GDPR’s one-month window (see §11.2). For reporting illegal content on the Site, see Terms of Service §16.