Legal

Privacy Policy

This Privacy Policy explains how we process personal data on roamaustria.com and in the Roam Austria mobile app, in line with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1. Controller (Verantwortlicher)

Free Walking Tour Salzburg e.U.
Gerhard Reus
Ignaz-Härtl-Straße 8, 5020 Salzburg
Phone: +43 699 17799991
Email: [email protected]

2. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, www.dsb.gv.at). To exercise your rights, contact us at the address above.

3. Hosting and server log files

Our website is hosted by xCloud (managed hosting). On each visit the host automatically stores server log files transmitted by your browser: IP address, browser type and version, operating system, referrer URL, and date and time of access. This is based on our legitimate interest in the secure, stable operation of the site (Art 6(1)(f) GDPR). A data processing agreement is in place with our host. Server log files are kept only as long as necessary for security and stability monitoring and are then deleted automatically. All web fonts are hosted locally on our own server; no external font provider receives any data about you.

4. Content delivery and security (Cloudflare)

We use Cloudflare, Inc. to deliver the site securely and protect it against misuse. Cloudflare processes your IP address for this purpose on the basis of our legitimate interest in security (Art 6(1)(f) GDPR). Data may be transferred to the USA under the EU standard contractual clauses. See Cloudflare's privacy policy.

5. Cookies and consent

This site sets no cookies and loads no third-party embeds, so there is nothing to consent to and no consent banner is shown. Our Cookie Policy sets this out in full. If that ever changes, we will list what is set and ask you first.

6. Contact form

When you use our contact form we process the data you enter to answer your enquiry. The legal basis is Art 6(1)(b) GDPR or our legitimate interest in responding (Art 6(1)(f) GDPR). We keep enquiries only as long as needed to handle them and to meet legal retention duties.

7. External content

We embed nothing from third parties: no interactive maps, no videos, no social widgets, no external fonts. Every page is delivered whole from our own server, so no other company learns that you visited it. Where the site refers to a map or a video, it is an ordinary link you choose to follow.

8. Social media

Our site links to profiles on Instagram and YouTube. These are plain links carrying no tracking. Meta and Google process your data only once you follow one and arrive on their platform, under their own responsibility.

9. Booking and affiliate links

We link to third-party booking and experience partners. When you click such a link and book, the partner may set cookies and we may earn a commission at no extra cost to you. We do not receive personal data about your bookings.

10. Web analytics

We do not use web analytics or tracking technologies of any kind. We do not count you, profile you, or measure what you read.

11. Transfers outside the EU

Some services above may transfer data to the USA. Such transfers are safeguarded by the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

12. Roam Austria mobile app

The app works without an account for browsing downloaded travel content. If you create an optional account, we process your email address, consent record, authentication tokens and sessions, saved places, collections and trips, device push token if notifications are enabled, and messages you send through in-app support. Security and support records may contain your IP address, device or app information, and timestamps.

The Roam Austria API is hosted on an EU server managed through xCloud and protected by Cloudflare. The same backend service also supports Introducing Salzburg, which is operated by the same controller. The email identity can be shared so the same person may join both apps, while app-specific records carry an app identifier. Roam Austria memberships, sessions, consent, saves, support data and push registrations are separated from Introducing Salzburg data.

We use SMTP2GO to deliver sign-in and support email, Expo for app builds, updates and push delivery, Sentry for crash diagnostics, and Google Maps for map display. These providers process only the data needed for their service. Sentry receives an internal user identifier when you are signed in, not your email address. Google Maps may receive device, network and location information under Google's own privacy terms when you use map features and grant the relevant device permission.

Magic-link tokens expire after 15 minutes and are removed by scheduled cleanup. App sessions expire after 30 days; expired or revoked session records are later removed. Deleting a Roam Austria account immediately removes that app's sessions, tokens, push registrations, saved collections and authored support messages from the backend. Support-action logs are retained only after the link to your user record is removed. If Roam Austria is your final membership on this shared service, the remaining identity row enters a 30-day deletion period before permanent removal. See Account Deletion for the exact steps.

13. Changes to this policy

We may update this Privacy Policy to reflect changes to our services or the law. The current version always applies.

Last updated September 1, 2026