The short version
- We only collect what we need to run this directory — your account, the content you post, and basic usage statistics.
- Your data is stored in the European Union (Frankfurt, Germany).
- Our own visit statistics are anonymous — we never store your IP address.
- Google Analytics runs only if you accept cookies in our banner. Decline and it never loads.
- We never sell your personal data.
- You can delete your account yourself at any time, and everything goes with it.
1. Who we are
Rhodes Things To Do (rhodesthingstodo.com) is a travel directory for the island of Rhodes, Greece, operated from Greece. We are the data controller for the personal data described in this policy. For anything privacy-related you can reach us at info@rhodesthingstodo.com or by phone at +30 694 360 0527.
This policy applies to the website and its services: browsing listings, creating an account, listing a business, sending booking requests and writing reviews. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR).
2. What data we collect
Account & profile. When you register we collect your email address and password (stored only as a secure hash). If you sign in with Google, we receive your name, email address and profile picture from your Google account instead of a password. You can optionally add a phone number, address, biography, website and social media links to your profile.
Business listings. If you list a business we collect the details you submit: business name, description, category, address, coordinates, phone, website and photos. Listings are public by design.
Booking requests. When you request a booking we collect your contact name, phone number, requested dates and number of guests. This information is shared with the business you are booking with — that is the purpose of the request.
Reviews & bookmarks. We store the reviews you write (shown publicly with your profile name and picture) and the listings you bookmark.
Technical & usage data. Our own visit counter records the page visited, the referring page and an anonymous daily identifier derived from a one-way hash. Your raw IP address is never stored by us, and the identifier cannot be reversed or linked across days. Standard server logs (kept briefly by our hosting provider for security) may include IP addresses.
3. Why we use it — and our legal bases
- To provide the service (contract, Art. 6(1)(b) GDPR): creating and managing your account, publishing your listings and reviews, delivering booking requests to businesses, and letting businesses respond to you.
- To keep the site working and safe (legitimate interest, Art. 6(1)(f)): security, fraud prevention, debugging, and our anonymous visit statistics.
- To measure and improve with Google Analytics (consent, Art. 6(1)(a)): only after you accept cookies. You can withdraw at any time.
- To meet legal obligations (Art. 6(1)(c)): where we must keep or disclose information by law.
4. Cookies & analytics
We use two kinds of cookies. Essential cookies keep you signed in — the site cannot work without them and they require no consent. Analytics cookies (Google Analytics 4) help us understand how visitors use the site and are disabled by default: we use Google Consent Mode v2 with everything set to “denied” until you press accept in the cookie banner. If you decline, Google Analytics does not track you. You can change your mind at any time by clearing the site’s cookies in your browser.
Full details are in our Cookie Policy.
5. Who we share data with
We never sell personal data, and we never share it with advertisers. We use a small number of service providers (processors) to run the site:
- Supabase — database, authentication and file storage. Your data lives in Supabase’s EU region (Frankfurt, Germany).
- Vercel — website hosting and delivery.
- Google — Google Sign-In (only if you choose it), Google Analytics (only with your consent) and Google Fonts.
- Resend — sending transactional emails such as booking notifications.
- OpenStreetMap / CARTO — the map tiles shown on our maps. Loading a map requests tiles from their servers, like loading any image.
Each provider only receives what it needs to perform its function, under a data processing agreement. Booking requests are additionally shared with the specific business you contact, so it can respond to you.
6. International transfers
Your account data and content are stored in the EU. Some of our providers (such as Google, Vercel and Resend) are US companies and may process limited technical data outside the EU; where that happens it is covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
7. How long we keep data
- Account, profile, listings, bookmarks: for as long as your account exists. Delete your account and they are removed immediately.
- Booking requests: kept while relevant to you and the business, and removed with your account.
- Reviews: removed together with your account.
- Visit statistics: anonymous from the moment of collection — they contain no personal data to delete.
- Emails to support: kept as long as needed to handle your request.
8. Your rights
Under the GDPR you have the right to access, correct, delete and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time.
Deleting your account is self-service: go to Dashboard → My Profile → Danger zone, type DELETE and confirm. This permanently removes your account, profile, listings, bookings, bookmarks and reviews.
For anything else, email info@rhodesthingstodo.com — we respond within 30 days. If you believe we have mishandled your data, you can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or your local EU supervisory authority.
9. Security
All traffic to the site is encrypted with HTTPS. Passwords are stored only as secure hashes. Database access is protected with row-level security so users can only reach their own data, and administrative access is limited to what is strictly necessary to operate the service.
10. Children
The site is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
When we change this policy we update the “Last updated” date at the top of this page, and for significant changes we will highlight them on the site. Questions? Write to us at info@rhodesthingstodo.com.