Loading…
Loading…
DRAFT — lawyer review required
This page captures Tuur’s intended policy in plain language to brief a lawyer. It has not been reviewed by counsel and must not be relied upon as legal advice. [TODO: review] tags mark questions for counsel.
How long Tuur keeps each type of data, and when it’s deleted. We aim to delete data as soon as it’s no longer needed for the purpose we collected it for.
| What | How long | Why |
|---|---|---|
| Guide profile + tour listings | While the account is active. Soft-deleted after closure; hard-deleted after 30 days. | Service delivery; brief window to restore an account closed in error. |
| Enquiries (traveller → guide messages) | 24 months from last reply, then deleted. | Lets guides reference prior correspondence; aligned with consumer-dispute limitation periods. |
| Reviews | Retained for the life of the guide profile. Anonymised if the reviewer requests deletion of personal data. | Reviews are part of the public directory. Reviewer name can be replaced with “a traveller” on request. |
| Billing records (invoices, payment receipts) | 10 years. | German tax/commercial law (HGB §257, AO §147) requires retention of accounting documents. |
| Authentication logs (sign-in events) | 90 days. | Security investigations + fraud detection. |
| Web/edge request logs | 30 days. | Debugging, abuse handling. |
| Email transactional log | 12 months. | Delivery troubleshooting. |
| Closed-account snapshot | 30 days after closure (then deleted). | Restore window if the closure was a mistake or contested. |
| Removed listings (per listing-rules action) | 12 months. | Evidence in case the suspension is appealed or a regulator asks. |
The schedule above is the intended default. We may keep data longer where we’re legally required (e.g. tax records), where there’s an active investigation, or where the data has been anonymised so it’s no longer personal data.TODO: confirm retention periods are appropriate; in particular review enquiry 24-month window vs. dispute-limitation rules and reviewer-anonymisation flow under GDPR Art. 17
To request earlier deletion, email privacy@tuur.guide. We’ll confirm within 30 days. Some data (billing, suspension records) we may need to keep for the periods above; we’ll tell you why if so.