Version 1.0 · Last updated August 25, 2026

Privacy Policy

How Alpii Europe GmbH processes personal data on the triploc platform

1. Who is responsible

The controller for the processing described here is:

Alpii Europe GmbH
Franz-Joseph-Straße 11, 80801 Munich, Germany
Amtsgericht München, HRB 308896
Managing Directors: Winitiro Ramadhani, Michael Eheleben, Edho Amarendra Saptiono

Email: [email protected]
Data protection contact: Head of Legal & Compliance, Alpii Europe GmbH

2. Principles we work to

  • We collect what a purpose requires and nothing beyond it.
  • We say what the purpose is at the point of collection, not only here.
  • We do not sell personal data, ever, to anyone.
  • We do not use traveller or partner data for marketing that the person has not asked for.
  • We delete on a schedule, not when someone remembers.

3. What we process, why, and on what basis

3.1 Booking an experience

DataPurposeLegal basisRetained
Name, email, phone, country, participant names and party sizePerforming your booking; sending confirmation, meeting details and changesArt. 6(1)(b) — performance of a contract8 years from the end of the calendar year of booking for booking receipts and invoices (§ 147(3) AO, § 257(4) HGB, § 14b UStG, as shortened by the Fourth Bureaucracy Relief Act 2024); 10 years where the record forms part of the books or annual accounts
Payment reference, amount, currency, payment method type, last four digitsTaking payment, issuing refunds, reconciling, handling chargebacksArt. 6(1)(b) and Art. 6(1)(c) — legal obligationAs above
Pick-up address where applicablePerforming the bookingArt. 6(1)(b)Deleted 90 days after the experience
Booking history in your accountLetting you see and manage bookingsArt. 6(1)(b)Until you delete your account, then the retention above applies to the booking records only

We do not store your full card number. Card data is processed directly by our payment service providers (clause 5).

3.2 Participation requirements and health information

Some experiences require information about health, fitness, pregnancy, mobility, allergies or medical conditions — because the activity is physically demanding, because an operator must plan for it, or because the law requires it.

  • Legal basis: Art. 9(2)(a) GDPR — your explicit consent. We ask for it separately and specifically, at the point of booking, for that booking.
  • We pass only what the operator needs to perform the experience safely.
  • Deleted 30 days after the experience. Not retained in your profile, not used for anything else.
  • You can refuse. If the information is genuinely necessary for safety, we will tell you honestly that we cannot confirm the booking, and refund you in full.

3.3 Your account

DataPurposeLegal basisRetained
Email, password (hashed), name, preferences, languageOperating your accountArt. 6(1)(b)Until you delete the account
Login timestamps, IP at login, deviceAccount security, fraud preventionArt. 6(1)(f) — our legitimate interest in securing accounts12 months

3.4 Customer support

Correspondence, call notes, complaint files and refund requests, including any evidence you send in support of an emergency refund request. Basis: Art. 6(1)(b) where it concerns your booking, otherwise Art. 6(1)(f). Retained 3 years from the end of the year in which the matter is closed, aligned to the statutory limitation period. Medical certificates submitted for refund requests are deleted 90 days after the decision.

3.4a Affiliate and promotional codes

Where you use a discount code, we record the code, the booking it was applied to, the discount, and the affiliate it is attributed to. Basis: Art. 6(1)(b) — applying the discount you asked for — and Art. 6(1)(f) for paying the affiliate their commission. The affiliate is shown that a booking was made against their code and the commission due. The affiliate is not shown your name, contact details or booking details. Retained for the statutory accounting period applicable to the commission record.

3.5 Reviews

Your review, rating, first name, first letter of your surname, country, and the experience booked. Published on the platform. Basis: Art. 6(1)(b) and Art. 6(1)(f) — our and other travellers' interest in verified reviews. Retained while published; you may withdraw a review at any time.

3.6 Partners and their personnel

DataPurposeLegal basisRetained
Contact details, business address, register numberContracting and operating the relationshipArt. 6(1)(b)Duration of the relationship + 10 years for accounting records
Identity document copyVerifying whom we contract with and payArt. 6(1)(c) / Art. 6(1)(f)6 months after the relationship ends
Licence, permit, insurance certificateVerifying the right to operateArt. 6(1)(c) / Art. 6(1)(f)Duration + 3 years
Bank account and holder namePayouts, mandatory payee name verificationArt. 6(1)(b) / Art. 6(1)(c)Duration + statutory accounting period
Tax number, VAT ID, date of birthTax reporting where an obligation appliesArt. 6(1)(c)As the relevant tax law requires

3.7 Website and app use

DataPurposeLegal basis
Server log data: IP address, date and time, page requested, referrer, browser and OSDelivering the site, security, fault diagnosisArt. 6(1)(f) — legitimate interest in a secure, working service. Retained 7 days, then deleted or anonymised
Strictly necessary cookies: session, security, load balancing, cookie choiceMaking the site workArt. 6(1)(f); no consent required under § 25(2) TDDDG
Analytics, advertising and personalisation cookies and similar technologiesUnderstanding use, measuring campaignsConsent only — Art. 6(1)(a) and § 25(1) TDDDG

Nothing that is not strictly necessary is set before you consent. Consent is asked through our cookie banner, refusing is as easy as accepting, and you can change your choice at any time through the Cookie Settings link in the footer of every page.

3.8 Marketing

We send marketing email only where you have subscribed (Art. 6(1)(a)), or, for existing customers, on the narrow basis permitted by § 7(3) UWG for our own similar services, with an opt-out in every message and at the point of collection. Every message carries a one-click unsubscribe. Unsubscribing is immediate and does not affect your bookings.

3.9 Fraud prevention and legal claims

Booking patterns, payment anomalies and chargeback records, on Art. 6(1)(f). Retained 3 years. No automated decision producing legal effects on you is made under Article 22 GDPR. Where a booking is flagged, a person decides.

4. Where the data comes from

Almost all of it comes from you. We also receive booking outcome data from our partners (attendance, no-show, incident reports) and payment outcome data from our payment providers.

5. Who we share it with

We share personal data only where it is needed for a purpose stated above.

Recipient categoryExamplesRole
Local operators performing your experienceThe guide, school or operator named on the experience pageIndependent controller. Receives name, party size, contact details, pick-up point, and any participation requirements you have declared. Bound by contract to use it only to perform your booking, never for their own marketing, and to delete it — health information within 30 days of the experience, everything else within 90 days, except where their own tax or limitation law requires longer
Payment service providerStripe Payments Europe, Ltd.Independent controller for payment processing
Hosting and infrastructureCloudflare, Inc. (object storage and CDN), and our cloud hosting provider in the EEAProcessor
Email and messagingResendProcessor
AnalyticsOur analytics provider — set only where you have consentedProcessor
Customer support toolingOur support desk providerProcessor
Software development and technical supportPT Alpii Global Hub, IndonesiaProcessor
Professional advisers, auditors, insurersControllers or processors as applicable
AuthoritiesTax authorities, courts, law enforcementWhere legally required

Every processor is engaged under a data processing agreement meeting Article 28 GDPR.

6. Transfers outside the EEA

Personal data is stored in the EEA.

Some recipients are outside the EEA:

  • Switzerland — covered by an EU adequacy decision. No additional safeguard needed.
  • United Kingdom — covered by an adequacy decision.
  • Indonesianot covered by an adequacy decision. Transfers to, or access from, Indonesia are made under the European Commission's Standard Contractual Clauses together with a transfer impact assessment and supplementary technical measures.
  • Partners outside the EEA performing an experience receive only what clause 5 lists, under appropriate safeguards.

You may request a copy of the safeguards in place at [email protected].

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure, where the conditions are met (Art. 17);
  • restriction of processing (Art. 18);
  • data portability for data you provided, in a machine-readable format (Art. 20);
  • object to processing based on legitimate interest, on grounds relating to your situation (Art. 21) — and an unconditional right to object to direct marketing at any time;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).

Write to [email protected]. We answer within one month. No charge. We may ask you to confirm your identity where we cannot otherwise be confident.

Where we cannot comply — usually because a retention period is set by tax law — we will tell you which obligation prevents it, rather than declining without explanation.

8. Complaints

You may complain to a supervisory authority, in particular in the Member State of your residence or workplace. Ours is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de

Complaining to us first is welcome but not required.

9. Is providing data mandatory?

Providing the data needed to make a booking is necessary for the contract; without it we cannot confirm the booking. Everything else — marketing, optional profile details, non-essential cookies — is voluntary and refusing has no consequence for your booking.

10. Children

The Platform is not directed at children and we do not knowingly collect data from a person under 16 through their own account. Children participate in experiences through a booking made by a responsible adult, who provides their details.

11. Security

We use encryption in transit and at rest, access control on a need-to-know basis, access logging for identity documents, and regular review of who holds which permission. No system is perfectly secure; we will notify you and the supervisory authority where a breach is likely to result in a risk to your rights, within the deadlines Articles 33 and 34 set.

12. Changes

We will publish any change here with a new version number and date, and notify registered users of a material change by email before it takes effect.


Switzerland — additional information

Where Swiss law applies, the Swiss Federal Act on Data Protection (revDSG) applies alongside this policy. Your rights are broadly equivalent. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. Our Swiss group company is Alpii Switzerland GmbH, Jupiterstrasse 3, 3015 Bern (CHE-489.859.612).

We use cookies to keep Triploc working, remember your preferences, measure how the site is used, and show offers that fit your trip. You decide which ones we may set. Privacy and Cookies Statement