Politique de confidentialité
Cette page n’existe qu’en allemand et en anglais. Voici la version anglaise.
1. Controller
Timo Zonewicz, c/o flexdienst – #21332, Kurt-Schumacher-Straße 74, 67663 Kaiserslautern, Germany, email: timo.appdev@gmail.com, phone: +49 156 78688183. See the legal notice for further details.
2. Hosting and server logs
The site is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Server functions run in Frankfurt am Main; pages are delivered through Vercel’s worldwide network. To deliver and secure the site, Vercel processes technically necessary data (IP address, time, page, browser, operating system, referring page) in server logs, kept only as long as needed for that purpose. The legal basis is our legitimate interest in a secure and reliable service (Art. 6 (1) (f) GDPR).
A data processing agreement under Art. 28 GDPR is in place with Vercel. Vercel is certified under the EU-U.S. Data Privacy Framework; transfers to the US additionally rely on the EU standard contractual clauses.
3. Cookieless analytics
We use Vercel Web Analytics, a service of our host Vercel Inc. (see section 2). It sets no cookies and stores nothing on your device. Visitors are told apart only by a value built from the incoming request and discarded after 24 hours, so nobody can be recognised across several days or across other websites. We count page views (the path only, without your inputs from the address), the referring page, the label of the link that brought you here, country and region, device type, operating system and browser. We also count how the site is used: which question of the planner was reached, the key figures of a plan in coarse steps (travel style, departure airport, month, budget step, number of travellers, nights; never the exact amount and never a date), which sections of the plan were viewed, clicks on partner buttons (which partner, which element), sharing and saving the plan and ticked checklist items. None of these counts can be linked to a person. The legal basis is our legitimate interest in anonymous reach measurement (Art. 6 (1) (f) GDPR).
4. Cookies and local storage
We set one cookie, “lang”, with your language choice (one year) and keep in your browser’s localStorage whether you have seen the notice at the bottom of the page, which checklist items you have ticked and which plan you opened last. When you open a plan, your browser keeps a copy of that plan, its images and the pages that belong to it (food spots, money tips, how we calculate) on your device (service worker, Cache Storage) so it also works offline, for example as an app on your home screen. This data never leaves your device and is not sent to us; you can delete it at any time in your browser’s site data settings. All of this is strictly necessary for the function you requested (Section 25 (2) no. 2 TDDDG) and is not used for tracking. We set no other cookies.
5. Affiliate links
Buttons marked “Ad” lead to partners (Aviasales, Kiwi.com, Booking.com, GetYourGuide, Viator, Tiqets, TodayTix, New York CityPASS, Go City New York Pass, Airalo, Holafly, HanseMerkur, SafetyWing, Welcome Pickups, Bounce, Radical Storage, Hanseatic Bank GenialCard, easybank Visa, Wise). Many of these links pass through the redirect servers of an affiliate network, mainly Travelpayouts (Go Travel Un Limited, Hong Kong; according to them the data is stored on servers in the Netherlands). On a click, the network processes technically necessary data (IP address, time, browser, the offer clicked and an identifier for the page and button the click came from) so that a later booking can be attributed to us. We do not pass on personal details such as your name. The legal basis is our legitimate interest in funding the site through commissions (Art. 6 (1) (f) GDPR). On the partners’ sites their own privacy policies apply, and they set cookies there for attribution. The ESTA link goes exclusively to the official US CBP site, without commission.
6. Maps
The day maps are drawn by us from map data hosted on our own server. No map tiles and no third-party scripts are loaded. Only when you tap “Open the walking route in Google Maps” do you leave our site, and Google’s privacy policy applies from there.
7. Your trip lives in the URL
Your inputs (budget, travellers, airport, dates, style) are part of the result page address. We do not store them; anyone who receives the link sees them. Share links deliberately.
8. Location-based defaults
Our host derives your country and an approximate position from your IP address so we can suggest a currency, a language and the nearest airport. This is used only for the response and not stored (Art. 6 (1) (f) GDPR).
9. Fonts, social networks and third-party content
Fonts are served from our own server. There is no embedded third-party content, no videos and no social plugins. The references to our Instagram and TikTok profiles are plain links; only when you tap one do you go to that network, and its privacy policy applies.
10. Contact by email or phone
If you write to us or call, we process your details (such as name, email address, phone number and the content of your message) to answer your request (Art. 6 (1) (b) and (f) GDPR). Our mailbox is provided by Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We delete the details once the request is settled, unless statutory retention duties apply.
11. Your rights
You have the right to access, rectification, erasure, restriction of processing and data portability (Art. 15 to 20 GDPR). Where we rely on legitimate interests, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). You can withdraw any consent at any time with effect for the future. You may also lodge a complaint with a data protection supervisory authority. For anything else, use the contact details above.
12. Last updated
October 2026.