Privacy policy
Last updated: July 25, 2026
Setup note (remove before taking real bookings): the registered trader
name, address and tax ID are still placeholders in
src/lib/contact.ts. EU consumer law requires a real trader
identity on these pages once you accept deposits.
We collect only what we need to arrange your tour: your name, email, ship and date of port call, guest count, and anything you choose to tell us. We do not sell or share it for marketing, we set no cookies, and we run no analytics or advertising trackers on this site. You can ask us to delete everything we hold about you at any time and we will do it within 30 days. This notice explains the detail, under the EU General Data Protection Regulation (GDPR).
Who is responsible
Greece Shore Excursions is the data controller for the information described here. Full registered details are published on this page before any deposit is taken.
What we collect, and why
- Enquiry details — email address, date of port call, cruise line and ship, number of guests, and your message. We need these to check availability and quote a price. Legal basis: steps taken at your request before entering a contract.
- Booking details — the above plus your name, a contact phone number, the meeting point and any accessibility or dietary needs you tell us. Legal basis: performance of our contract with you.
- WhatsApp messages — if you message us on WhatsApp, we hold that conversation. WhatsApp itself is operated by Meta under its own privacy terms, which we do not control.
- Payment records — we keep the record of a deposit payment as required by Greek tax law. We never see or store your full card details.
What we do not do
- We set no cookies on this website — there is nothing to consent to.
- We run no analytics, heatmaps, session recording, or advertising pixels.
- We do not sell, rent or trade your data, and we do not do automated decision-making or profiling.
- We do not add you to a mailing list from an enquiry. If we ever offer one, it will be opt-in.
Who processes your data for us
- Web3Forms — delivers the enquiry form to our inbox. It processes the form contents in transit and does not retain them for its own purposes.
- Cloudflare — hosts this website and serves it worldwide. Cloudflare processes server request logs, including IP addresses, for security and abuse prevention.
- Our email provider — stores the enquiry and booking correspondence.
- The guide or driver assigned to your tour — receives your name, meeting point, guest count and any needs relevant to the day. Never your payment details.
Some of these providers operate outside the European Economic Area. Where they do, transfers rely on the European Commission's standard contractual clauses.
How long we keep it
- Enquiries that never became a booking: 12 months, then deleted.
- Booking records: kept for the period Greek tax and accounting law requires.
- WhatsApp conversations: deleted on request, otherwise 12 months after the last message.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Write to us and we will respond within 30 days, free of charge. You also have the right to complain to your national data protection authority — in Greece, the Hellenic Data Protection Authority.
Children
This site is not directed at children, and we do not knowingly collect data from anyone under 16. Children travel on tours as guests of the adult who books, and we hold only the guest count.
Changes to this notice
If we add anything that processes your data differently — analytics, an online payment step, a newsletter — we will update this page before it goes live and change the date at the top.