Privacy Policy for Web Purchase Pages (Voucher Purchase)
We are pleased that you wish to purchase tours and vouchers for the Red Thread app. The protection of your personal data is important to us. Below, you will find information on how we process your personal data during the purchase process and payment on our purchase pages and for what purposes.
Data Controller:
Voltaire Vision UG (haftungsbeschränkt)
Bäckerbreitergang 6
20355 Hamburg
Germany
E-Mail: privacy@voltaire.vision
1. Access to our Website and Purchase Pages
When accessing our purchase pages, information is automatically transmitted from your browser to our server. This data is technically necessary to display the checkout process correctly to you and to ensure stability and security.
The following data is processed:
- IP address (anonymized, as far as technically possible)
- Date and time of access
- Name and URL of the accessed file / page
- Website from which access originates (Referrer URL)
- Browser type, browser version, and operating system
This data is used exclusively to ensure operation, prevent misuse, and perform error analysis.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functioning purchase process).
2. Cookies and Consent Management
We use cookies and similar technologies (e.g., local storage). Some are technically necessary to execute the checkout process and payment. Others – such as analytics or marketing cookies to measure the performance of advertising campaigns – are primarily used based on your explicit consent.
When accessing the purchase pages, a consent banner appears, allowing you to manage your settings and grant or deny your consent.
Note: Without the respective consent, analytics and marketing tags are not loaded and no events or cookieless pings are sent to Google or Meta.
3. Necessary Technologies
To ensure that the purchase page and order form function properly, we use, among other things:
- Tailwind CSS (locally embedded)
- Font Awesome (locally embedded)
- Google Fonts (locally embedded, no connection to Google servers)
These integrations take place exclusively locally from our server, meaning that no personal data is transferred to third parties.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional and user-friendly presentation of the checkout process).
4. Data Processing for Purchase Execution and Voucher Generation
When you buy a voucher via our website, we process the contact details and order details you enter to initiate, execute, and fulfill the purchase contract as well as to deliver the voucher.
The following data is processed by us:
- Email address (for sending the purchase confirmation and voucher code)
- First and last name (if provided in the order form)
- Selected product / voucher type (e.g., single tour, city pass)
- Order date, time, and order number
- Billing and transaction data (amount, currency, payment status)
Collecting this data is strictly necessary to provide you with the purchased voucher code and to fulfill the contract.
Legal bases:
- Art. 6(1)(b) GDPR (fulfillment of the purchase contract for the voucher).
- Art. 6(1)(c) GDPR (fulfillment of legal and tax retention obligations under statutory commercial and tax laws, e.g., HGB and AO).
5. Payment Processing via Stripe and Connected Payment Service Providers
To process payments during the purchase process, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland / Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA).
All payment data (e.g., credit card numbers, bank details, security codes, PayPal account data, Apple Pay, or Klarna connections) are entered and processed directly in encrypted form via a secure interface (e.g., Stripe Elements or iFrame) by Stripe. We ourselves do not store full credit card or payment data on our servers at any time.
Transmitted Data:
In the context of payment processing, we or your browser transmit the following data to Stripe:
- Order details (amount, currency, order ID, email address)
- Payment details (credit card data, selected payment method)
- Customer master data (if required for invoicing or the selected payment method)
- IP address, device type, and location data (for fraud prevention and risk analysis)
Connected Payment Services:
Depending on the selected payment method, Stripe forwards the transaction to appropriately connected financial service providers (e.g., PayPal, Apple, Google, Klarna, SOFORT / Sofortüberweisung). The privacy policies of the respective payment provider apply additionally.
Third-Country Transfer:
Stripe may transfer data to its parent company, Stripe, Inc., in the USA. Stripe is certified under the EU-U.S. Data Privacy Framework (DPF) and uses EU Commission standard contractual clauses to ensure an adequate level of data protection.
Legal bases:
- Art. 6(1)(b) GDPR (contract fulfillment for processing your payment).
- Art. 6(1)(f) GDPR (legitimate interest in providing a secure, efficient, and user-friendly payment option, as well as preventing default and fraud attempts).
Further information on data protection at Stripe can be found at: https://stripe.com/privacy.
6. Conversion Tracking & Analytics with Google Analytics
On our purchase pages, we use the web analytics service Google Analytics provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) to analyze the usage of the checkout process and record successful purchases (conversions).
Google Analytics processes data in two different ways, depending on your privacy settings (consent status):
a) Usage with Consent
If you have given your explicit consent in the consent banner, Google Analytics uses cookies and similar tracking technologies. Detailed e-commerce data is processed (e.g., purchased voucher category, purchase value, transaction ID, campaign origin) to understand purchase abandonments and optimize marketing measures.
We use Google Analytics exclusively with activated IP anonymization. Your IP address is shortened by Google within member states of the EU or in other contracting states to the Agreement on the European Economic Area prior to transmission. Data may also be transferred to servers of Google LLC in the USA. Google is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(a) GDPR (consent).
b) Usage without Consent
Without your consent to “Analytics”, the Google Analytics tag is not loaded. No analytics cookies are set and no events or cookieless pings are sent to Google Analytics.
7. Conversion Tracking & Marketing with Meta Ads (Meta Pixel)
On our purchase pages, we use the Meta Pixel, provided by Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). We do not currently use the Meta Conversions API on these pages.
a) Usage with Consent
If you give consent to “Advertising” in the consent banner, the Meta Pixel sends a PageView. When you click “Book now”, it also sends the InitiateCheckout standard event with product ID, product name, value and currency. This event describes the start of checkout. After server-side confirmation of payment on our success page, the Pixel sends the Purchase standard event with the same product data and a random transaction ID generated in the browser to prevent duplicate counting. The Stripe session ID and voucher code are not sent to Meta. The data helps us measure the success of our advertising on Facebook and Instagram and optimise campaigns.
Meta may also process data in the USA. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(a) GDPR (consent).
b) Usage without Consent
Without your consent to “Advertising”, the Meta Pixel is not loaded and no events or cookieless pings are sent to Meta.
8. Contact Form and Support Requests
If you have questions before or during the purchase process and contact us (e.g., via email or contact form), we process your details (name, email address, subject, message) to handle the request and in case of follow-up questions.
Legal bases:
- Art. 6(1)(b) GDPR (pre-contractual measures or contractual inquiries regarding voucher purchases).
- Art. 6(1)(a) GDPR (voluntary consent for other inquiries).
9. Retention Period
We store your personal data only as long as necessary for the respective purposes:
- Contract and billing data: Stored for 6 to 10 years in accordance with statutory retention periods under commercial and tax laws (HGB and AO).
- Voucher administration data: Stored for the duration of the voucher's validity (2 years from creation) and until the expiry of any civil statute of limitations.
- Analytics and marketing data: In case of consent, deleted or anonymized automatically according to the respective settings in the consent tool or standard provider deletion periods (e.g., max. 2 to 14 months for Analytics).
10. Your Rights under the GDPR
Regarding your processed data, you have the following rights at any time:
- Access to your stored data (Art. 15 GDPR)
- Rectification of incorrect or incomplete data (Art. 16 GDPR)
- Erasure of your data, provided no statutory retention obligations conflict (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing on grounds relating to your particular situation (Art. 21 GDPR)
- Withdrawal of granted consent at any time with effect for the future (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a competent data protection supervisory authority (Art. 77 GDPR). For our registered office in Hamburg, this is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
Website: https://datenschutz-hamburg.de
Current technical implementation: Google Analytics, Google Ads and Meta Pixel
With your consent to “Analytics”, we record the start of checkout as a begin_checkout event and, after server-side confirmation of payment, a purchase event in Google Analytics. With your consent to “Advertising”, clicking “Book now” sends a checkout conversion to Google Ads as well as the Meta standard event InitiateCheckout. After confirmed payment, we also send a separate purchase conversion to Google Ads and the Meta standard event Purchase. Google Ads receives a random, non-secret transaction ID generated in the browser to prevent duplicate counting, as well as purchase value and currency; Google Analytics and Meta additionally receive product ID and product name. The Stripe session ID and voucher code are not sent to Google or Meta. To associate the purchase after returning from the payment provider, we store this tracking context for up to seven days in session storage, local storage and a first-party cookie where consent has been given. Without the respective consent, the relevant tags are not loaded, no tracking context is created and no events or cookieless pings are sent to Google or Meta.
Legal basis: Art. 6(1)(a) GDPR (consent).