Last updated 8 September 2026

Privacy Policy

Indy Guide connects travellers with local hosts and guides. To do that we handle personal data. This page explains what we collect, why, who else sees it, and what you can ask us to do about it. It is written to satisfy the Swiss Federal Act on Data Protection (revDSG) and, for visitors in the European Union, the GDPR.

Who is responsible

Indy Guide GmbH
Humbelrain 9, 8824 Schönenberg ZH, Switzerland
Contact for data protection matters: Alexandra Tosun, [email protected]

What we collect

Everyone with an account: first and last name, email address, password (stored only as a cryptographic hash, never in readable form), anything you add to your profile, and the time you last signed in. If you sign in with Google, we receive your name, email address and profile picture from your Google account.

Travellers: trip requests including destination, dates and party size; bookings; reviews and any photos you upload with them.

Hosts: in addition, date of birth, mobile number, town and country, company details, portrait photo and links to your social profiles. To verify your identity we ask you to upload an official identity document. We do not keep it: the file is deleted automatically at the latest 30 days after upload.

From using the site: the messages you exchange with other users, your booking history, and technical log data such as timestamps and error reports.

Why we use it

To run your account, connect travellers with hosts, deliver messages, take payments and verify that hosts are who they say they are — all of which is necessary to provide the service you asked for.

Beyond that, we send occasional emails with suggestions and reminders, measure how the site is used, and take steps against fraud and abuse. These rest on our legitimate interest in running and improving a safe marketplace. Newsletters are sent only if you asked for them. You can stop any non-essential email at any time using the unsubscribe link or by writing to us.

Who else sees your data

We do not sell personal data. Other users see what you choose to show them: your public profile, your reviews, and the messages you send them. Beyond that, we use service providers who process data on our behalf and under contract:

ProviderPurposeLocation
HetznerServers and databaseUSA
Amazon Web ServicesImage and file storageUSA
CloudflareDelivering the websiteUSA
StripePaymentsUSA / Ireland
Twilio SendGridSending emailUSA
PusherReal-time messagingUSA
GoogleSign-in, push notifications, spam protection, analyticsUSA
Google Gemini, AnthropicAutomated text analysis (see below)USA
SentryError reportsUSA
MetaWhatsApp reminders to hosts about waiting travellers (host phone number, both first names); publishing review photos on InstagramUSA

All of these process data in the United States, which means your data leaves Switzerland and the European Economic Area. We rely on the contractual safeguards these providers offer, including the standard contractual clauses, and on their certification under the applicable data privacy frameworks where they hold one.

Automated analysis

We use automated systems on some content, and we would rather say so plainly than bury it:

  • Messages between travellers and hosts are analysed to detect fraud attempts and to draft suggested replies. For this, message content is sent to Google Gemini and to Anthropic.
  • Review texts and photos are analysed to prepare posts for our social media channels.

Under the terms we have with these providers, your content is not used to train their models. No decision with legal effect for you is made automatically.

Reviews and social media

Reviews appear publicly on our website with your first name and any photos you uploaded. We also publish selected review photos on our Instagram account, @indy.guide, usually with the host's first name in the caption. Some of these photos show people, and a photograph of a recognisable person is personal data, so we want to be clear that this happens.

If you would rather we did not, write to us. We will take the post down and leave your photos out in future.

How long we keep it

  • Identity documents: deleted automatically at the latest 30 days after upload.
  • Account data, profile and messages: as long as your account exists. If you close it, we delete them, apart from what we must keep by law.
  • Bookings, invoices and payment records: ten years, as Swiss accounting law requires.
  • Sessions and device identifiers for push notifications: cleared automatically once they expire.

Cookies and analytics

Necessary cookies. laravel_session keeps you signed in and XSRF-TOKEN protects forms against misuse. The site does not work without them.

Analytics. Google Analytics sets _ga and _ga_… so we can count visits and see which pages are used. You can refuse this at any time by blocking these cookies in your browser or by installing Google's opt-out add-on.

Signing in with Google. If you use the Google sign-in button, Google sets its own cookies.

Your rights

You can ask us for a copy of the data we hold about you, have it corrected, have it deleted, have its use restricted, object to uses that rest on our legitimate interest, receive it in a portable form, and withdraw any consent you gave.

An informal email to [email protected] is enough. We answer within 30 days. If you are not satisfied, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB) or, in the EU, to the data protection authority where you live.

Security

Traffic to and from this site is encrypted. Passwords are stored only as hashes and cannot be read by us. Access to our systems is limited to a small number of people and protected by cryptographic keys rather than passwords. We keep this under review and improve it when we find a weakness.

Changes

We update this policy when what we do with data changes. The version published on this page is the one that applies. If a change matters to you, we will say so rather than let you find it here.