CoworkTours

GDPR

Privacy policy

Last updated July 2026

Template — review with legal counsel before launch (TBC)

This policy explains what personal data CoworkTours collects, why, and your rights under the EU General Data Protection Regulation (GDPR). Company details and the data controller are listed in our imprint (TBC).

What we collect

  • Waitlist & enquiries: your email, optional first name, and any trip interest you tell us.
  • Applications: name, email, country, profession, remote-work situation, room-tier preference, your answers, and how you heard of us.
  • Attribution: UTM parameters, referrer, and any referral code, so we understand which of our (non-paid) channels work.
  • Analytics: privacy-friendly, cookie-less analytics (Plausible) — no cross-site tracking, no personal profiles.

Why we use it (lawful bases)

  • To respond to you and run the application and booking process (contract / pre-contract).
  • To send you waitlist and trip emails you've opted into (consent — double opt-in).
  • To understand our channels and improve the site (legitimate interest).

Email & double opt-in

We only add you to the waitlist after you confirm your email. Every email includes a one-click unsubscribe. Transactional email is sent via Resend; broadcast lists are managed there too (TBC).

Sharing & storage

We share data only with the processors that run this service (e.g. hosting on Vercel, email via Resend, payments via Stripe, scheduling via Cal.com) under appropriate data agreements. We do not sell your data. Data may be processed outside the EU under standard contractual clauses (TBC).

Your rights

You have the right to access, correct, delete, restrict, or port your data, and to withdraw consent at any time. To exercise any of these, email hello@coworktours.com. You may also complain to your local data protection authority.

Retention

We keep enquiry and application data only as long as needed for the purpose above, or until you ask us to delete it (specific periods TBC).