Privacy policy
Last updated: 18 August 2026
Draft, not yet reviewed. This text was prepared from what the site actually does, but it has not been checked by a qualified adviser, and the highlighted values still have to be filled in. It must not be relied on, and this page should not be published in this state.
This policy explains what we collect, why, who else sees it, and how to make us stop. It describes what the site actually does, and it is short because the site does little.
Who is responsible
TODO: legal entity name, TODO: street, postcode, town, Switzerland, is the controller of the personal data described here. Swiss data protection law (nDSG) applies. Where visitors are in the EU or the UK, the GDPR applies too, and this policy is written to satisfy both.
What we collect, and why
If you take the travel style quiz
We store the email address you give at the end, together with:
- the thirteen answers you chose, kept as the option numbers;
- the travel style calculated from them;
- the date and time you ticked the consent box, and the exact wording you agreed to;
- the IP address the submission came from.
The legal basis is your consent, which you give by ticking that box. We store which version of the wording you agreed to so that changing the text later cannot silently change what you are recorded as having accepted. The IP address is kept only to investigate abuse of the form. We use this address to send you your result and, because you asked for them, Monica's travel emails. You can unsubscribe at any time and we delete the record on request.
If you buy the course
We store:
- the email address you entered at checkout;
- the identifiers Stripe gives the payment, so a specific order can be found again;
- the amount and currency charged, and whether it was later refunded.
The legal basis is the contract between us: without this record we cannot give you the access you paid for. We never see or store your card details. The payment happens on Stripe's own pages and your card number never reaches our servers.
When you sign in
There is no password. We email you a link, and following it creates a session. For that we store your email address, the session itself, and, attached to it, the IP address and browser you signed in from. The legal basis is again the contract, and the security of your own account.
While you use the course
We record which lessons you have finished, what you scored on the quizzes inside the course, and roughly where you paused a video, against your account. This is what makes the course resume where you left it on a different device, and what the certificate of completion is based on. The legal basis is the contract: it is part of the course you bought.
It is not used for anything else. We do not build a profile from it, we do not measure you against anyone, and nobody outside the two of us sees it.
What we do not do
No analytics. No advertising or social media pixels. No profiling, and no automated decisions about you. No third-party fonts: the typefaces are served from our own server, so loading a page does not tell anyone else that you were here. We do not sell or rent your data to anyone, for any purpose.
Who else processes it
- Stripe
- Takes the payment and holds the order. Stripe is a payment provider with entities in Ireland and the United States, so buying the course involves a transfer of your email address and payment details outside Switzerland, covered by Stripe's own data protection commitments.
- Hostpoint
- Delivers our email, in Switzerland.
- Hetzner Online
- Runs the server this site is on, in Nuremberg, Germany. Everything described above is there: the database, the accounts, and the course videos. TODO: an earlier plan assumed a Swiss host. Confirm Germany is acceptable, and that a processing agreement with Hetzner is in place.
- TODO: content delivery network
- Serves the course videos from a location near you. It sees the IP address making the request. TODO: name it once chosen, and check where its logs are kept.
How long we keep it
- Quiz submissions: 24 months from the day you sent them, or until you ask us to delete them, whichever comes first.
- Purchase records: 10 years. This one is not our choice. Swiss law requires business records to be kept, and that obligation outweighs a deletion request for the accounting parts of the record.
- Sessions: they expire after thirty days, and are deleted when they do.
- Your progress through the course: for as long as you have access to the course, since it is what lets you pick the course back up. Deleted with your account, on request.
Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to hand it to you in a portable form, or to stop using it. If you gave consent you can withdraw it at any time, and withdrawing it does not affect what we did while it was valid. Write to monica@yourtravelschool.com and we will answer within thirty days.
If you think we have got it wrong, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, in the EU or UK, to your national supervisory authority.
Changes
If we change this policy we update the date at the top. If a change affects what we do with data you have already given us, we tell you before it takes effect.
Contact
TODO: legal entity name
TODO: street, postcode, town, Switzerland
monica@yourtravelschool.com