Privacy policy
Last updated: 27 September 2026
Data controller
The controller of the data collected on etaperia.com is Kylian Surget, sole trader, registered office 6 rue d'Armaillé, 75017 Paris, France.
For any question or request regarding your data: contact@etaperia.com.
No data protection officer has been appointed: the activity falls under none of the cases making that appointment mandatory.
The principle: the strict minimum
The site only collects the data you enter yourself, and only for the uses that justify it: sending you the release announcements you signed up for, delivering an itinerary you purchased, and answering the requests you send by email, including requests for a tailor-made itinerary.
No data is sold, rented or exchanged. No advertising profiling, no automated decision-making, no resale to data brokers.
Signing up for release announcements
When you leave your address in the upcoming-destinations announcement form, that address is stored with the date of the sign-up, the language of the page at the time of sign-up, the page of the site you signed up from (itinerary page, country page, home page, blog, footer or thank-you page) and a technical token used to generate your unsubscribe link. If you ask for that link to be sent again, the timestamp of your latest request is stored too: it is used solely to limit the frequency of these emails and prevent abuse, on the basis of the controller's legitimate interest (security, article 6.1.f of the GDPR). At sign-up itself, a pseudonymised fingerprint of your IP address is kept for at most twenty-four hours, on the same legal basis, solely to cap the number of sign-ups per connection and keep bots out: your IP address is never stored in readable form, and an automatic hourly task deletes fingerprints older than twenty-four hours. Nothing else.
Purpose: notifying you of the release of new itineraries. Legal basis: your consent, article 6.1.a of the GDPR. You can withdraw it at any time: through the unsubscribe link present in every message, from the page etaperia.com/desinscription/ which emails you that link, or by a simple request to contact@etaperia.com.
Retention period: until you withdraw your consent, exercised through the unsubscribe link in every message, the site's unsubscribe page or a simple request to contact@etaperia.com, and at the latest three years after your sign-up: an automatic weekly task then deletes the address from the list.
Purchasing an itinerary
Payment is processed by Stripe on a page hosted by Stripe. Your bank details are entered with Stripe, pass through Stripe, and are at no point received or stored by the seller.
The seller receives from Stripe the data needed for the order: email address, name, billing country, amount, date and reference of the transaction.
Purposes: delivering the purchased itinerary, issuing the invoice, answering customer service requests, meeting accounting and tax obligations. Legal bases: performance of the contract, article 6.1.b of the GDPR, and a legal obligation for the retention of accounting records, article 6.1.c.
Retention period: order data is kept for the duration of the commercial relationship, then archived for ten years under accounting obligations (article L123-22 of the French Commercial Code).
Customer account
Access to purchased itineraries goes through a customer account, created with your email address and a password. The password is never readable by the seller: only a cryptographic hash of it is stored.
You can also sign in via Google, an optional identity provider: Google then shares with the site your email address and your basic profile data (name, profile picture), and no other data from your Google account is collected. Using this button remains subject to Google's privacy policy.
At each sign-in, the authentication service (Supabase) also records the IP address and browser used, in the list of your active sessions and in an audit log: this data serves solely to secure the account and detect abnormal access. Legal basis: the controller's legitimate interest (security), article 6.1.f of the GDPR.
Purpose: identifying you to give you access to the itineraries you purchased. Legal basis: performance of the contract, article 6.1.b of the GDPR.
Retention period: as long as the account exists. You can request its deletion at any time at contact@etaperia.com; the associated order data then remains kept for the periods stated in the previous section.
Email requests and tailor-made itineraries
When you write to contact@etaperia.com, for a question, a complaint or a tailor-made itinerary request, the seller processes the data contained in your message: your email address, your name if you give it, and the content of the request (country, dates, duration, travel constraints, group composition).
Purposes: answering you, drawing up a quote and, if you accept it, carrying out the tailor-made order. Legal basis: pre-contractual steps taken at your request and performance of the contract, article 6.1.b of the GDPR.
Retention period: three years after the last exchange if no order follows. If an order is placed, the exchanges and the quote are kept for the duration of the commercial relationship, then archived for ten years under accounting obligations (article L123-22 of the French Commercial Code), like the order data.
Technical server logs
The site's host automatically records connection logs: IP address, date and time, page requested, browser type.
Purpose: ensuring the security and proper operation of the site. Legal basis: the controller's legitimate interest, article 6.1.f of the GDPR. These logs are not used to identify you or to measure the audience.
Retention period: the one applied by the host, within a limit of twelve months.
Cookies and audience measurement
The site uses Google Analytics 4 (Google Ireland Ltd) to measure its audience: pages viewed, origin of visits, device type. These cookies are only set after your agreement, given through the banner displayed on your first visit. Without an answer from you, or if you refuse, no tracker is set and the site remains fully usable.
Legal basis: your consent, article 6.1.a of the GDPR. Your choice is kept for six months in your browser, then the question is asked again. You can change it at any time via the "Cookies" link in the footer; if you withdraw, the audience measurement cookies are deleted. The cookies set expire at the latest thirteen months after being set.
The site also uses your browser's local storage (localStorage), which is transmitted to no server: to remember your answer to the consent banner, to remember your language preference, and to keep your sign-in session to the customer account once signed in. This information is strictly necessary to the service you request, serves no tracking, and is deleted when you sign out or clear your browsing data.
No advertising pixel or social network button is present on the site. The fonts are hosted on the site itself. Some pages of the site, including the home page, the destination pages and the itinerary pages, display an interactive map whose base map is provided by CARTO (OpenStreetMap data): displaying this map transmits your IP address to this provider, like any image loaded from a third-party server. No cookie is set and no identifier is shared with it.
Affiliate links to booking sites
As of today, no hotel booking link, on the site as in the delivered itineraries, is an affiliate link. Clicking one of these links takes you to the site of the hotel or of the booking platform, which then applies its own privacy policy and may set its own trackers.
The seller receives no data about you from these sites.
Who has access to your data
The data is only accessible to the site's publisher and to the following technical providers, which act as processors within the meaning of article 28 of the GDPR:
- Stripe Payments Europe Ltd — payment processing
- Supabase Inc. — hosting of the site's data: newsletter sign-ups, customer accounts and purchase history (Ireland region, eu-west-1)
- Resend Inc. — sending of order confirmation emails and newsletter-related emails (unsubscribe link); company established in the United States, where data is processed under standard contractual clauses
- Vercel Inc. — site hosting, 440 N Barranca Avenue #4133, Covina, CA 91723, United States
- Google Ireland Ltd — audience measurement (Google Analytics 4), only if you consented to it; data may be transferred to Google LLC, United States
- CARTO — base map of the interactive maps (OpenStreetMap data); receives your IP address when a map is displayed, without any cookie or identifier; possible transfer outside the European Union, governed by standard contractual clauses
Transfers outside the European Union
Some of these providers are established outside the European Union or may transfer data there. These transfers are governed by the safeguards provided for in chapter V of the GDPR: the European Commission's standard contractual clauses, supplemented where applicable by the provider's certification under the Data Privacy Framework.
You can obtain a copy of the applicable safeguards by writing to contact@etaperia.com.
Security
The site is served exclusively over HTTPS. The sign-up database can be neither read nor written from the browser: sign-ups go through a server function, the sole holder of the write key, and the list can only be viewed from the controller's administration interface.
Despite these measures, no transmission over the internet can be guaranteed to be completely secure. In the event of a data breach likely to create a high risk for your rights, you would be informed in accordance with article 34 of the GDPR.
Your rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights over your data:
- Right of access: obtaining confirmation that your data is processed and receiving a copy of it
- Right to rectification: having inaccurate or incomplete data corrected
- Right to erasure: having your data deleted, subject to legal accounting retention obligations
- Right to restriction of processing
- Right to data portability: receiving your data in a structured, machine-readable format
- Right to object, in particular to any processing based on legitimate interest
- Right to withdraw your consent at any time, without calling into question the lawfulness of the processing carried out before that withdrawal
- Right to set directives on the fate of your data after your death
How to exercise them
Send your request to contact@etaperia.com, specifying the right you wish to exercise. A reply is provided within one month, extended to three months if the request is complex, in which case you are informed.
Proof of identity may be requested in the event of reasonable doubt about the identity of the requester.
If the reply does not satisfy you, you can lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr.
Updates to this policy
This policy may evolve with the site and its tools. The last-updated date appears at the top of the page. Any substantial change in purposes would be brought to the attention of the people concerned.