Privacy policy
Last updated: 3 October 2026
This privacy policy explains how romapass.info ("we", "us") collects and processes personal data when you use the website romapass.info (the "website"). By using the website you confirm that you are at least 18 years old. We collect as little personal data as possible: the website consists of static pages, with no user accounts, no login, no newsletter, no comments and no checkout.
Controller
The controller under the General Data Protection Regulation (GDPR) is the operator named in our Impressum (legal notice). You can reach us at .
Personal data means any information that can identify a person; anonymised data is not included. If you have written to us and your details change, please let us know so that our records stay accurate.
What data we collect and why
The website has no user accounts and no login. We may process the following, narrowly limited categories of personal data:
- Communication data: if you contact us by email, your name, your email address and the content of your message. We use it to reply to you and to keep a record of the correspondence, based on our legitimate interest in handling enquiries (Art. 6(1)(f) GDPR).
- Technical and usage data: such as your IP address, browser type, the pages you view and the time of your visit. Your IP address is processed automatically by our hosting provider Cloudflare; our privacy-friendly analytics only records anonymised, aggregated figures. We use this data to run, secure and improve the website, based on our legitimate interest in a fast, secure website and in knowing which pages are read (Art. 6(1)(f) GDPR).
We do not collect payment or card details; these are processed only by the booking partner at checkout. Nor do we collect special categories of data such as information about health, ethnic origin, religion or political opinions.
How we collect data
We collect data directly from you when you send us an email, and automatically when your browser requests pages of the website, through server logs and the services described below. We set no cookies of our own and run no advertising or cross-site tracking.
Cookies and analytics
Hosting. The website is hosted and delivered by Cloudflare (Cloudflare, Inc., USA). To deliver a page, Cloudflare necessarily processes your IP address and the request data your browser sends, and keeps technical logs for a limited time to run the website reliably and securely. We do not use these logs to identify visitors.
Visitor statistics. To understand how the website is used, we use Simple Analytics (Simple Analytics B.V., Netherlands), a privacy-friendly analytics service. It sets no cookies and collects no personal data or cross-site identifiers, only aggregated, anonymised figures such as page views, referring pages, browser type and country. Your browser's "Do Not Track" setting is respected. Because the service uses no cookies and stores no personal data, no consent banner is needed; you can see exactly what is collected at simpleanalytics.com/what-we-collect.
Booking partners. If you click "Check availability" and book with one of our affiliate partners (mainly Headout), the partner may set cookies to attribute the referral to us and pay our commission. The partner's own privacy policy applies to this, and to everything you enter at checkout. We never see your name, your card details or your booking, and the attribution does not make you identifiable to us. How the commission works is explained in our affiliate disclosure.
You can set your browser to refuse all or some cookies. We do not sell your personal data.
Fonts, images and links
Fonts and images. All fonts and images are served from our own server. Your browser does not contact Google Fonts or any other font or image service.
Links. The website links to third-party websites, such as Headout, whose privacy practices we do not control. Please read the privacy notice of every website you visit.
Sharing your data
We may share personal data with the service providers named above who host and deliver the website, and with authorities or professional advisers where the law requires it. We require all third parties to keep your data secure and to process it only for specified purposes and in line with our instructions.
International transfers
Some of our service providers, Cloudflare in particular, may process data outside the European Economic Area. In that case we rely on the safeguards provided for in the GDPR, such as an adequacy decision of the European Commission (including the EU-US Data Privacy Framework) or standard contractual clauses, to ensure a comparable level of protection for your data.
Data security and retention
We take measures to prevent your personal data from being lost, misused, altered or accessed without authorisation, and we limit access to those who need it. We keep personal data only for as long as needed for the purpose concerned, including legal retention obligations. We keep an email for as long as we need it to reply, and for a reasonable period afterwards in case of follow-up questions; after that it is deleted.
Your rights under the GDPR
You have the right to access, rectify, erase and restrict the processing of your personal data, the right to data portability, and the right to withdraw any consent you have given. Where we rely on legitimate interests, you can object to the processing on grounds relating to your particular situation (Art. 21 GDPR). To exercise any of these rights, write to .
You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
Children
The website is a general travel information service for adults and is not aimed at children. We do not knowingly collect personal data from children.
Changes
We update this privacy policy when needed, for example when we add or replace one of the services named above; the date at the top shows the current version.