Santorini Curator

Legal

Privacy Policy

Last updated: 7 June 2026

Who we are

Santorini Best Tours is a tour booking platform based in Fira, Santorini, Greece (postal code 847 00). We connect visitors with carefully selected local hosts and experiences across the island.

For any questions about this policy or your personal data, contact us at bookings@santorinicurator.com.

What data we collect

We collect data in the following situations:

  • Booking data — when you make a booking we collect your name, email address, the date of your experience, and the number of guests. This is needed to process and manage your booking.
  • Payment data — payments are processed by Stripe. We do not store your card details. Stripe's privacy policy applies to payment processing.
  • Cookie and analytics data — only if you accept cookies, we collect anonymised usage data through Google Analytics and may use Google Ads to show relevant adverts. You can decline this in the cookie banner when you first visit the site.
  • Contact data — if you contact us by email or WhatsApp, we retain those messages to help resolve your enquiry.

Legal basis for processing

  • Contract performance (Article 6(1)(b) GDPR) — booking and payment data are processed because they are necessary to fulfil your booking.
  • Consent (Article 6(1)(a) GDPR) — analytics and advertising cookies are only set after you give explicit consent.
  • Legal obligation (Article 6(1)(c) GDPR) — we are required to keep financial records for a minimum of five years under Greek and EU tax law.

How long we keep your data

  • Booking records: five years from the date of the booking (legal requirement).
  • Contact messages: until your enquiry is resolved, then deleted.
  • Analytics data: as set in Google Analytics retention settings (default: 14 months).

Third parties

We share data only with the following trusted processors:

  • Stripe — payment processing. Stripe operates under Standard Contractual Clauses for EU data transfers.
  • Supabase — database hosting, EU region (Frankfurt). Your booking data is stored here.
  • Google — analytics and advertising, only if you have accepted cookies. Google operates under Standard Contractual Clauses for EU data transfers.

We do not sell your data to any third party.

Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to legal retention requirements).
  • Withdraw consent for analytics at any time by clearing your cookie preference.
  • Lodge a complaint with the Hellenic Data Protection Authority (HDPA).

To exercise any of these rights, email us at bookings@santorinicurator.com. We will respond within 30 days.

Cookies

We use two types of cookies:

  • Essential cookies — needed for the site to function (for example, your cookie preference itself). These are set without consent.
  • Analytics and advertising cookies — set by Google Analytics and Google Ads only if you accept in the cookie banner.

You can change your preference at any time by clearing your browser's local storage for this site.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. Continued use of the site after a change constitutes acceptance of the updated policy.