Your information

Privacy policy

How we handle your information when you explore Gibraltar, book a tour or contact us.

Draft dated

1. Who we are

Gibraltar Guided Tours (“we”, “us” or “our”) operates this website and arranges the tours and experiences offered through it. The organisation responsible for deciding how and why your personal information is used (the data controller) is Calypso Tours Limited.

Our postal address is Cloister Building, Market Lane, Gibraltar, GX11 1AA. For privacy questions or to exercise your rights, email calypsotours@mhbland.com or write to this address, marked “Privacy”. You can also call +350 200 12730.

This notice covers visitors, people making enquiries, account holders, booking contacts and passengers. It explains our handling of information under the Gibraltar General Data Protection Regulation and Data Protection Act 2004. Other data-protection laws may also apply depending on the circumstances.

2. Information we collect

  • Contact and account information: your name, email address, telephone number, account identifier, sign-in history and account status. Sign-in uses a code or link sent by email rather than a password. Checkout can create an account associated with your email.
  • Booking information: your booking reference, tour and experience selections, dates, departure times, numbers of adults, children and infants, pricing tier, currency, amounts, booking status and check-in records.
  • Payment information: transaction and checkout references, payment provider, amount, currency, payment and refund status, timestamps and information needed to investigate a failed payment or dispute.
  • Correspondence: enquiries, support requests and booking communications, including records of delivery of service emails.
  • Technical information: IP address, browser and device information, requested URLs, request identifiers, timestamps, authentication events and error or performance information.
  • Preferences and usage: language, currency, saved cart and checkout details, and, when analytics is enabled, page visits and interactions associated with an analytics identifier.

We receive information directly from you, automatically from your browser, from the person booking for your party, and from payment providers confirming payments or refunds. Tour staff and experience providers may supply operational updates relating to your booking.

Our standard booking form records child and infant counts, rather than their names or dates of birth. Please do not send passport copies, full card details or sensitive medical information through ordinary email or booking enquiries.

3. Why we use information

We use information only for a defined purpose and an applicable lawful basis:

  • Arranging and delivering your booking: handling enquiries, creating your booking, taking payment, issuing tickets, allocating capacity, checking passengers in, arranging selected experiences and processing changes or refunds. This is necessary to enter into or perform our contract with you.
  • Accounts and service messages: authenticating you, showing your bookings and sending sign-in codes, tickets, reminders and booking updates. This supports our contract and our legitimate interests in providing secure, reliable customer service.
  • Other passengers: where the booking contact supplies information about someone else, our legitimate interest is to organise and deliver that party’s tour safely and accurately.
  • Security and support: preventing misuse and duplicate transactions, diagnosing failures, resolving complaints and protecting legal claims. Our legitimate interests are to protect customers and operate a dependable service.
  • Records and legal requests: meeting applicable accounting, tax and other legal duties, and responding to lawful requests from authorities, on the basis of the relevant legal obligation.
  • Website analytics: counting visits and seeing which pages and campaigns work, so we can improve the site. By default this happens without cookies or other storage on your device (sections 8 and 9), on the basis of our legitimate interest in running and improving the website.
  • Advertising measurement: only if you accept analytics and marketing cookies — recognising returning visitors and measuring our Meta (Facebook and Instagram) advertising. You can withdraw this consent at any time.

Where we rely on legitimate interests, we must balance those interests against your rights. Where we rely on consent, you can withdraw it without affecting earlier lawful processing. Essential booking and contact information is needed to provide a booking; without it we may be unable to arrange the tour or take payment.

This notice is not a request for marketing consent. Booking or signing in does not, by itself, subscribe you to promotional messages. Any future marketing programme should explain its choices and provide an unsubscribe method separately.

4. Payments

Card payments are handled by the provider offered at checkout: SumUp through an embedded payment form, or Paylands through its hosted payment page. The provider and its banking or payment partners process card details, authentication and fraud checks. Our booking database stores transaction records, not your full card number or card security code.

We exchange the booking or transaction reference, amount, currency and relevant customer identifiers with the payment provider, and receive payment, failure and refund results. The provider may also process information for its own regulatory and security purposes under its own privacy notice. Check the provider’s notice in the payment journey for those activities.

5. Who receives information

  • Authorised staff, guides and drivers: information needed to manage bookings, contact the lead passenger, operate tours and validate tickets. Passenger manifests can include the lead name, email, phone number, booking reference and party counts.
  • Selected experience providers: the lead contact’s name, email and phone number, booking reference, party counts, tour date and time, and chosen experience, so they can fulfil that part of your booking and contact you about it.
  • Technical suppliers: Hetzner Online GmbH hosts the website and its database in Germany. [Name the email delivery provider and its location.]
  • Payment providers: SumUp or Paylands and relevant payment partners, as described above.
  • Analytics and monitoring suppliers: PostHog for website analytics (without cookies unless you consent) and Sentry for error and performance monitoring.
  • Meta Platforms: only if you accept analytics and marketing cookies, the Meta Pixel sends page views and completed purchases (amount and currency) to Meta to measure our advertising.
  • Professional advisers and authorities: where necessary for legal advice, accounting, disputes, protecting rights or complying with the law.

Recipients should receive only the information needed for their role. Suppliers acting on our instructions require appropriate data-protection arrangements; some payment and experience providers may act as separate controllers for their own activities. [Confirm those roles against the supplier contracts.]

6. International processing

Some suppliers process information outside Gibraltar:

  • Website and database: Hetzner, in Germany (European Economic Area).
  • Error monitoring: Sentry, in the United States.
  • Analytics: PostHog, in [the EU or the US — the region of our PostHog project].
  • Advertising measurement: Meta, which may process data in the United States and elsewhere. This only happens if you accept marketing cookies.
  • Payments: Paylands and SumUp, in [confirm each provider’s processing locations].
  • Email delivery: [provider and location].

[For each transfer outside Gibraltar and the European Economic Area, state the adequacy decision or safeguard relied on (for example standard contractual clauses), and explain how customers can obtain a copy through the privacy contact.]

7. How long information is kept

Retention must reflect the purpose of the information, the length of the customer relationship, applicable accounting and tax duties, and the time needed to resolve disputes or establish legal claims. Cancelling a booking or signing out does not automatically erase its records.

  • Sign-in codes: valid for 10 minutes; expired authentication-code records are eligible for automatic database cleanup.
  • Sessions: use a 30-day expiry that can be renewed with activity. Expired database sessions are eligible for automatic cleanup; physical removal need not happen at the exact expiry instant.
  • Accounts, bookings, payments and correspondence: [confirm the retention period or precise criteria for each category, including unsuccessful or cancelled bookings].
  • Security logs, diagnostic events and analytics: [confirm the configured retention periods with each supplier].
  • Backups and copies held by operational providers: [confirm deletion cycles, access restrictions and any legal holds].

Browser storage has separate lifetimes, described below. Expiry of a browser item does not delete the corresponding booking or payment record.

8. Cookies and browser storage

Cookies are small values sent with website requests. Local storage stays in your browser between visits; session storage normally lasts for the browser tab’s session. This site uses these technologies for the following purposes:

Sign-in — gi_session
A signed, HTTP-only cookie used to authenticate you, with a 30-day lifetime. Session expiry can be renewed through activity. Signing out ends the current sign-in.
Language and currency — ggt_lang and ggt_ccy
Preference cookies saved for up to 365 days when your choices are updated.
Cart — ggt_cart
Local storage holding your tour, party and experience selections. It has no automatic time limit and remains until the cart is cleared, a successful checkout clears it or you remove browser data.
Checkout details — ggt_checkout_contact
Local storage used to prefill your name, email and phone number. New entries have a 30-day expiry checked when read and are cleared after a successful booking. Older entries without an expiry timestamp can remain until overwritten or cleared.
Duplicate-payment protection — ggt_checkout_idem
Session storage holding a checkout identifier, tied to the contents of your cart, to prevent the same checkout being created twice.
Your cookie choice — ggt_consent_v1
Local storage remembering whether you accepted or rejected analytics and marketing cookies, until you change it or clear site data.
Purchase counting — ggt_purchase_reported_…
Session storage that stops a completed booking being counted twice if you reload the confirmation page.
Analytics — PostHog (only with your consent)
If you accept analytics and marketing cookies, PostHog stores an identifier in a cookie and local storage named ph_…_posthog for up to 365 days, so repeat visits can be recognised. Without your consent PostHog stores nothing on your device (section 9).
Advertising — Meta Pixel _fbp, _fbc (only with your consent)
If you accept analytics and marketing cookies, the Meta Pixel sets these cookies for up to 90 days to measure our Meta advertising.

We ask before setting any analytics or advertising cookies. A banner offers “Accept” and “Reject” equally; you can change your choice at any time with “Cookie settings” at the foot of every page. Withdrawing consent stops the tracking and deletes the analytics and advertising cookies we are able to remove. If your browser sends a Do Not Track or Global Privacy Control signal, we do not load analytics at all.

You can delete or block cookies and site storage through your browser settings. Blocking sign-in storage can prevent account access; clearing cart or checkout storage removes saved selections and prefilling. Clear site data after using a shared device. Payment forms and hosted payment pages may use their own storage for payment security; consult their notices.

9. Analytics and diagnostics

PostHog records page views: the page address (with everything after the “?” removed, except campaign “utm_” tags), the referring page, approximate location derived from your IP address, and browser and device type. When a booking is paid it records a “booking paid” event with the amount and currency only. It does not record your clicks automatically, record your session or build a profile of you.

By default PostHog works without cookies: it counts visits using an identifier that PostHog’s servers derive each day from your IP address and browser details, so a returning visitor is counted again on a new day. Only if you accept analytics and marketing cookies does it store an identifier on your device (section 8).

With your consent, the Meta Pixel receives page views and completed purchases (amount and currency). Sentry may receive browser or server errors and sampled performance traces. Request logs can include IP addresses, URLs and identifiers; checkout diagnostic logs may also contain contact details.

10. Keeping information secure

The application uses access permissions, expiring sign-in codes and signed session cookies to restrict account access. Payment details are entered into payment-provider forms. We must also maintain appropriate organisational and technical safeguards for our systems and suppliers; no internet service can guarantee absolute security.

Keep sign-in codes, sign-in links and ticket QR codes private. If you believe your account or booking information has been accessed improperly, contact us promptly using the privacy contact above.

11. Your rights

Subject to applicable conditions and exemptions, you can request access, correction, erasure, restriction or a portable copy of your personal information. You can object to processing based on legitimate interests and to direct marketing, and withdraw consent where processing relies on it.

Send requests to the privacy contact in section 1. We may ask for proportionate identity checks. We normally respond within one month; where a lawful extension is needed, we will explain it. Requests are normally free. Some records may need to be retained to meet legal duties or deal with claims.

12. Automated booking processes

The site automatically checks availability, allocates a booking to a suitable trip, expires unpaid reservations and validates payment results. These processes support the booking service. Payment providers may carry out their own fraud screening. If an automated result appears incorrect or prevents you from booking, contact us for assistance and review.

13. Children and other passengers

An adult should arrange bookings involving children. If you provide information about another passenger, make sure you are entitled to do so and share this notice with them or their parent or guardian. Provide only what is needed for the booking. If an accessibility arrangement requires sensitive information, contact us first so we can explain the necessary information, lawful basis, recipients and handling arrangements.

14. Other websites

Links to social networks, experience providers and other external sites take you to services with their own privacy practices. Their notices apply to information you provide directly to them. Our use of an external link does not mean we control that service.

15. Questions and complaints

You can contact us about any concern. You may also complain directly to the Gibraltar Regulatory Authority, Gibraltar’s data-protection regulator, without first contacting us. Other competent supervisory authorities may also be available under applicable law.

16. Changes to this notice

We will update this page when our handling of information changes and show the revised date. Material changes will be brought to your attention where appropriate. Any new processing that requires consent will need a separate choice; updating this notice does not supply that consent.

Return to the homepage

SANDBOX MODEPayments are in test mode — bookings made now will not be charged real money.