1. Who we are
TourTour is operated by TourTour, a company registered in Estonia (European Union). "We", "us", and "our" refer to TourTour. For privacy questions: [email protected].
2. What data is collected and where it lives
| Data | Where it lives | We can read it? | Exposure |
|---|---|---|---|
| Apple ID (identity) | Apple's servers | No | Apple |
| Subscription & purchases | Apple (StoreKit) | No | Apple |
| Saved routes, playback progress, preferences | Your private iCloud (CloudKit) | No only your devices can access | Apple |
| Downloaded city packs (audio & images) | Your device only | No | Local only |
| Server access logs (IP, path, timestamp) | Our servers (Hetzner, EU) | Yes 90-day retention, then deleted | Operational |
| Error reports (if enabled) | Sentry PII-scrubbed | Yes anonymised crash data only | Operational |
3. Identity and payments
TourTour has no sign-in screen and no user account system. Your identity comes from the Apple ID on your device. Apple handles authentication entirely we never receive your email, name, or Apple ID.
Purchases are processed by Apple through StoreKit. Your device verifies purchase validity directly with Apple. Our backend never receives payment information or billing details.
Apple's privacy policy governs Apple-held data: apple.com/legal/privacy.
4. Your walking data
Routes you save, places you bookmark, playback progress, and preferences are stored in your private iCloud using Apple's CloudKit. TourTour has no access to this data it lives in your iCloud account and is only accessible by your own devices.
Deleting TourTour from your device removes all local data (downloads, cache) immediately. Your CloudKit data remains until you delete it through your Apple ID settings.
5. Server logs and sub-processors
Server access logs
Every API request (fetching city catalogue, downloading city packs) creates an access log entry: timestamp, IP address, URL path, HTTP response code. Retained 90 days for security and debugging, then automatically deleted.
Lawful basis under GDPR: legitimate interest (security and service operation). We do not log request bodies or link access logs to individual users.
Infrastructure
Our servers run on Hetzner (Germany/Finland), Neon (Frankfurt), Backblaze B2, and Bunny.net. All EU-friendly. None receive personal data beyond what is inherent in internet infrastructure.
6. Cookies and tracking
The TourTour iOS app uses no cookies and no tracking. There is no analytics SDK, no advertising framework, and no third-party data sharing. This marketing website uses no tracking cookies.
7. Account deletion
TourTour creates no accounts on our side there is nothing for us to delete. To remove data:
- Local data: Delete the app. All local files are removed immediately.
- CloudKit data: Managed through your Apple ID settings.
- Purchase history: Contact Apple Support for StoreKit records.
- Server logs: Email [email protected] with your IP address we can purge your entries on request.
8. Your rights (GDPR)
If you are in the EU or EEA, you have the right to access, correct, delete, or object to processing of personal data we hold. For TourTour, that means your entries in our 90-day server access logs. For data held by Apple, contact Apple directly. To exercise any rights, email [email protected]. We respond within 30 days.
9. Changes
We will update the date at the top of this page when this policy changes. Material changes will be communicated in-app before taking effect.