Better Travel Tips (“we”, “us”) operates bettertraveltips.com. This policy explains what personal data we collect, why we collect it, and how we protect it. We are based in Norway and aim to comply with the EU General Data Protection Regulation (GDPR).
1. Data controller
The data controller is Better Travel Tips, contactable at str.media.no@gmail.com.
2. What we collect
We only collect personal data when you create an account to use the trip planner.
When you sign in with Google
- Your email address
- Your name (as provided by Google)
- Your Google profile picture URL
- Your Google account identifier (a stable opaque ID used to recognise you on return visits)
When you use the planner
- Places you save (saved-places list)
- Trips you create (name, dates, city, day-by-day items, your notes)
Automatically
- A session cookie named
btt_session(HttpOnly, Secure, SameSite=Lax, 30-day expiry) used to keep you signed in - Standard server access logs (IP address, user agent, request path) kept for up to 30 days for security and debugging
3. Why we collect it
- To operate the trip planner — so your saved places and trips are tied to your account and available on return visits (GDPR Art. 6(1)(b), contract)
- To keep you signed in — the session cookie (GDPR Art. 6(1)(b), contract)
- To keep the site secure — server logs to detect abuse (GDPR Art. 6(1)(f), legitimate interest)
We do not use your data for advertising, nor do we sell or share it with data brokers.
4. Third-party services we use
- Google — for sign-in (OAuth 2.0). Google receives the fact that you signed into our site. See Google’s privacy policy.
- Cloudflare — our hosting provider. Handles traffic and stores data on our behalf. See Cloudflare’s privacy policy.
- Affiliate partners — GetYourGuide, Viator, Tiqets, Booking.com. When you click an affiliate link, that partner may set their own cookies. We receive a small commission if you book, but we do not share personal data with them.
5. Where we store data
Account data, trips, saved places and session information are stored in a Cloudflare D1 database running on Cloudflare’s global edge network. Data may be replicated to regions outside the EU, but Cloudflare is subject to Standard Contractual Clauses for international transfers.
6. How long we keep it
- Your account, trips and saved places: until you delete them or ask us to delete your account
- Session cookie: 30 days from last use
- Server access logs: up to 30 days
7. Your rights
Under GDPR you have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data
- Delete your account and all associated data
- Object to or restrict processing
- Port your data in a machine-readable format
- Withdraw consent at any time (where consent is the basis)
- Lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet)
To exercise any of these rights, email str.media.no@gmail.com. We respond within 30 days.
8. Cookies
We use a minimal set of cookies:
btt_session— essential, keeps you signed in (30 days)btt_oauth_state— essential, CSRF protection during Google sign-in (10 minutes)
We do not use analytics or advertising cookies. Affiliate partners may set their own cookies when you click through to their sites.
9. Children
The service is not directed to children under 16. We do not knowingly collect data from children. If you believe we have, please email us and we will delete it.
10. Changes to this policy
We may update this policy. Material changes will be announced on the site. The “Last updated” date at the top of this page always reflects the current version.
11. Contact
Questions? Email str.media.no@gmail.com.
