Call Anytime
Call Anytime
Last updated: 30 September 2026
This policy explains what personal data StepinEurope UG (haftungsbeschränkt) collects when you use stepineurope.com, why we collect it, who it is shared with, and what rights you have.
It describes what this website actually does. We run no advertising trackers and no social media pixels, and analytics only run if you switch them on.
The controller for the purposes of the General Data Protection Regulation (GDPR) is:
Contact form. When you send us an enquiry we process the name, email address, telephone number, subject and message you provide, together with the page you sent it from. We use this only to answer you. The legal basis is Article 6(1)(b) GDPR (steps prior to entering a contract) or Article 6(1)(f) (our legitimate interest in responding to enquiries).
Booking enquiry form. Sending an enquiry from a tour page also records which package you asked about and, if you fill them in, the number of travellers and your preferred dates. Same purpose and legal basis as the contact form.
Your enquiry is stored in the database behind our blog site so that we can track and answer it, and a copy is emailed to our team. We do not record your IP address or browser details with the enquiry — only what you typed and the page you submitted from.
Server logs. Our hosting provider records technical data such as IP address, time of request, browser and referring page, in order to keep the service running and to defend against attacks. The legal basis is Article 6(1)(f) GDPR.
Cookie choice. When you answer the cookie banner we store your decision, and the time you made it, in a first-party cookie so we do not ask again and can show that consent was given.
Maps and analytics. Both are switched off until you allow them. See sections 4 and 6.
This site sets no advertising cookies. Analytics cookies are set only if you opt in. The complete list is:
Some tour pages can display a map provided by Google (Google Ireland Limited, and Google LLC in the United States). Loading it transmits your IP address to Google and allows Google to set cookies in your browser.
We do not load the map until you allow it — either for a single visit by clicking the placeholder, or permanently by enabling “Maps & external embeds” in the cookie settings. The legal basis is your consent under Article 6(1)(a) GDPR, which you can withdraw at any time using the “Cookie settings” link in our footer.
This involves a transfer of personal data to the United States. Google relies on the EU-US Data Privacy Framework and on Standard Contractual Clauses. A transfer outside the EEA can carry risks we cannot fully exclude, including access by public authorities. If you would rather not accept that, leave maps switched off — the rest of the site works normally.
Our enquiry forms are protected by Cloudflare Turnstile, which checks that the sender is a person rather than an automated script. When a form loads, Turnstile receives your IP address and limited technical signals from your browser.
This applies to the contact form and to the booking enquiry form that opens from a tour page. On tour pages nothing is loaded until you actually open that form — simply reading about a trip sends nothing to Cloudflare.
We rely on Article 6(1)(f) GDPR: we have a legitimate interest in keeping our forms usable and our inbox free of automated abuse. Because the check is necessary to provide the form itself, it loads without asking for consent, and only at the point you open a form.
If you allow the Analytics category in our cookie banner, we use Google Analytics 4 to understand which pages and trips people look at. It sets cookies and sends data to Google, including outside the EU, and we have IP anonymisation switched on.
Nothing analytics-related is loaded before you opt in — not the script, not a single request to Google. The legal basis is your consent under Article 6(1)(a) GDPR. If you withdraw it from “Cookie settings” we tell Google to stop and delete the analytics cookies already on your device.
We do not use Google Analytics for advertising, and advertising signals are switched off.
Typefaces are served from our own servers. Your browser does not connect to Google Fonts or any other font provider when you visit this site, so no data is shared with them.
Article images on the home page are loaded from our blog at blog.stepineurope.com. That request reveals your IP address to that server and to Cloudflare, which protects it.
We do not sell personal data. We share it only with the service providers needed to run the site, each acting as a processor for us under a data processing agreement:
Some of the providers above are based in the United States or process data there. Those transfers are covered by the EU-US Data Privacy Framework where the provider is certified under it, and otherwise by the European Commission's Standard Contractual Clauses together with additional safeguards.
A transfer to a country outside the EEA can carry risks that cannot be entirely excluded, including access by public authorities under local law.
Enquiries that do not lead to a booking are deleted after 12 months.
Where an enquiry becomes a booking, the records form part of our business correspondence and accounts, which German commercial and tax law requires us to retain — generally six years, and ten years for accounting records (§ 257 HGB, § 147 AO).
Server logs are short-lived and are kept only as long as needed for security and troubleshooting.
Your cookie choice is kept for six months, or until you change it.
Under the GDPR you have the right to request access to your personal data (Art. 15), correction (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Where we rely on consent you can withdraw it at any time, without affecting the lawfulness of what was done before.
To exercise any of these, email hello@stepineurope.com or write to us at the address in section 1. We answer within one month.
You also have the right to complain to a data protection supervisory authority. For us that is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), or the authority where you live or work.
We apply the standard described above to every visitor, wherever you are, because it is the strictest one we are subject to.
If you are a California resident, you have rights under the CCPA/CPRA including to know what personal information we hold, to have it deleted or corrected, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law.
This site is not directed at children and we do not knowingly collect their personal data. Bookings must be made by an adult.
We may update this policy when the site or the law changes. The date at the top shows when it was last revised. If we add anything that needs your consent, we will ask you again.