Last updated: December 1, 2026
1. Introduction
Amsterdam Local Gems (“we”, “our”, or “us”) is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR). This privacy policy explains how we collect, use, and protect your personal data when you use our website and services.
Data Controller: Amsterdam Local Gems
Contact: [email protected]
DPO: [email protected]
2. Information We Collect
Personal Data You Provide
- Name and email address (for bookings, reviews, newsletters)
- Phone number (for tour bookings)
- Payment information (processed securely by third-party payment providers such as Stripe)
- Travel preferences and itinerary details
- Communications with our support team
Automatically Collected Data
- IP address and device information
- Browser type and version
- Pages visited and time spent on our site
- Referral sources and search terms
- Cookies and similar tracking technologies
3. How We Use Your Information
We use your personal data for the following purposes:
- Process bookings and payments
- Provide customer support and respond to inquiries
- Send newsletters and marketing communications (with consent)
- Improve our website and services
- Comply with legal obligations
- Prevent fraud and ensure security
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent (newsletter subscriptions, marketing emails)
- Contract performance (bookings and services)
- Legitimate interests (website improvement, analytics)
- Legal compliance (tax and accounting records)
5. Data Sharing and Third Parties
We may share your data with trusted third-party service providers:
- Payment processors (Stripe, PayPal)
- Email marketing services (Mailchimp)
- Analytics providers (Google Analytics)
- Booking platforms and tour partners
We do not sell your personal data to third parties. All service providers are contractually obligated to protect your data.
6. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy or as required by law. Booking and payment records are kept for 7 years for tax compliance.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to access your data
- Right to correct inaccurate data
- Right to delete your data (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
8. Cookies and Tracking
We use cookies and similar technologies to enhance your browsing experience. You can manage your cookie preferences through our cookie settings.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. This includes SSL encryption, secure payment processing, and regular security audits.
10. International Transfers
Some of our service providers may be located outside the EU/EEA. When this happens, we apply recognized safeguards for cross-border transfers.
Depending on the provider and service, this can include European Commission Standard Contractual Clauses (SCCs) and assessment of applicable transfer frameworks, such as the EU-U.S. Data Privacy Framework.
We periodically review vendor safeguards and update our approach as regulatory guidance evolves.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes by email or through a notice on our website.
12. Contact Us
If you have any questions about this privacy policy or your data rights, please contact us at [email protected] or visit our contact page.