Legal
Privacy Policy
The legally binding version of this policy is German. The following is a courtesy translation.
1. Privacy at a glance
This website deliberately uses no tracking, no analytics services, no advertising networks and no cookies. Fonts, images and films are served directly from this website; no services are embedded that transfer personal data to third parties when you simply visit.
We only process personal data that you actively share with us — by phone, email, WhatsApp or via the contact form on this website.
2. Controller
Reisebörse BensheimManaging Director: Christian Göbel
Gerbergasse 4
64625 Bensheim, Germany
Phone: +49 6251 1797-0
Email: christian@deluxe.travel
3. Hosting (Cloudflare)
This website is hosted as a static website with Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for the EEA: Cloudflare Portugal, Unipessoal Lda.). When you access the website, Cloudflare collects technical access data in server log files (e.g. IP address, browser type, time of access) transmitted automatically by your browser. This data serves exclusively the secure, error-free and performant delivery of the website; the legal basis is our legitimate interest (Art. 6 (1) (f) GDPR). A data processing agreement (Art. 28 GDPR) is in place with Cloudflare; transfers to the USA are based on the EU-US Data Privacy Framework and EU standard contractual clauses. Details: Cloudflare privacy policy Opens in a new tab..
4. No cookies, no tracking
This website sets no cookies and uses no analytics or tracking services. Your favourites list, colour-scheme preference and map consent are stored exclusively locally in your browser (localStorage); this data never leaves your device and is not visible to us. A cookie banner is therefore not required.
5. Maps
On hotel, destination and contact pages we show location maps. The map data comes from OpenStreetMap (© OpenStreetMap contributors, ODbL) but is stored on our own storage with our hosting provider Cloudflare and loaded from there. No third-party servers are contacted. Your IP address is processed when the map loads in the same way as when any other page of this website loads (section 3).
6. Contact form
If you use the contact form, we process the data you provide (first name, last name, phone number, optional email address, preferred call-back time, your message) exclusively to handle your inquiry and for follow-up questions. The legal basis is Art. 6 (1) (b) GDPR (steps prior to entering into a contract, taken at your request).
Technically, your inquiry is received by a server function of our hosting provider Cloudflare and delivered to us by email. For email delivery we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as a processor (Art. 28 GDPR); transfers to the USA are based on EU standard contractual clauses. Your details are not stored permanently with Cloudflare or Resend; they are delivered to our mailbox and deleted there once your inquiry has been fully handled and no statutory retention obligations apply. If you provided an email address, you receive a short confirmation of receipt.
To protect against automated spam submissions, the server function checks technical characteristics of the submission (an invisible control field, a minimum completion time, a short-term limit on requests per IP address) and uses Cloudflare Turnstile. A short-lived security token and the IP address are transmitted to Cloudflare for abuse detection. We do not store IP addresses permanently or link them to your inquiry.
7. Contact by phone, email, WhatsApp
If you contact us by phone, email or WhatsApp, we process your details exclusively to handle your travel inquiry and possible follow-up questions (Art. 6 (1) (b) GDPR). We do not pass this data on without your consent. For communication via WhatsApp, the privacy policy of WhatsApp Ireland Ltd. additionally applies; please note that data is transferred to WhatsApp in the process.
8. Travel letter (newsletter)
If you subscribe to our travel letter, we store your email address, your chosen language, and the time and IP address of both your sign-up and your confirmation. The subscription only takes effect once you click the link in our confirmation email (double opt-in). Unconfirmed sign-ups are deleted after 48 hours.
The legal basis is your consent (Art. 6(1)(a) GDPR). We keep the time and IP address so that we can demonstrate your consent (Art. 7(1) GDPR).
The data is held in a database with our hosting provider Cloudflare. Emails are sent by Resend (see section 6) as our processor.
You can unsubscribe at any time using the link in every issue or by sending us a short message. After you unsubscribe we will not write to you again. We keep the record of your sign-up and unsubscription for three years and then delete it; we delete it immediately on request.
9. Our own videos, our own fonts
All films and greeting videos embedded on this website are stored on our own servers; no third-party video platforms (such as YouTube or Vimeo) are embedded. The fonts used are also served by this website itself; there is no retrieval from Google Fonts or other font services.
10. Your rights
You have the right to obtain information about your stored personal data (Art. 15 GDPR), to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future. To do so, contact the controller named above.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: Der Hessische Beauftragte für den Datenschutz und die Informationsfreiheit (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de Opens in a new tab..
12. Data security
This website uses TLS encryption. Please note that data transmission on the internet (e.g. communication by email) can have security gaps; complete protection of data against access by third parties is not possible.