Legal

Privacy Policy

Last updated: 27 July 2026

This policy explains what personal information MV Abroad collects when you visit our website or purchase a digital guide, how we use it, and what rights you have over it. We keep this plain and readable — if anything is unclear, email us at contact.mvabroad@gmail.com.

1. Who we are

MV Abroad is a travel guiding brand operated by Evangelos-Marios Nikolados and Mantalena-Maria Vasileiou, based in Edinburgh, Scotland, United Kingdom. We are the data controllers for any personal information processed in connection with this website, our tours, and our digital products.

Contact: contact.mvabroad@gmail.com

2. Information we collect

We collect only what we need to deliver our services and support you:

  • Email address — provided by you at checkout, used to deliver your guide, to allow you to recover access later, and to send one follow-up email with tips after your purchase (every such email includes an unsubscribe link).
  • Payment information — processed directly by Stripe. We never see or store your card number. Stripe provides us with a transaction reference and the amount paid.
  • Purchase record — which guide you bought, when, and the amount paid. Stored securely to fulfil your order and for our accounting obligations.
  • Enquiry and booking details — if you use our contact or book-a-call forms, we receive what you enter there: your name, email, trip type, destinations, dates, and your message.
  • Review details — if you submit a review, we receive your name, surname, home city, country, tour date, star rating, and review text. Approved reviews are shown publicly with your first name, surname initial, and location. Review text and location may be machine-translated between Greek and English.
  • Chat messages — if you use the site's chat assistant, your messages are sent to Anthropic (the AI provider) to generate a reply. Don't include sensitive personal information in chat. We log an anonymised, hashed connection token to prevent abuse, not your identity.
  • Usage events — we record basic, non-identifying product events (e.g. that a guide page was viewed or a purchase completed) to understand what's useful. These are not tied to your name or profile and we use no advertising trackers.

3. How we use your information

  • To deliver your digital guide immediately after purchase.
  • To allow you to recover your download link later using the same email address.
  • To send one post-purchase follow-up email with practical tips (opt out any time via the unsubscribe link).
  • To respond to enquiries, booking requests, and support messages you send us.
  • To moderate and publish customer reviews you choose to submit.
  • To meet our legal accounting and record-keeping obligations.

We do not run advertising, do not profile you, and do not sell or rent your data to any third party.

4. Legal basis for processing (GDPR)

If you are in the European Union or United Kingdom, our processing of your personal data is based on the following legal grounds under the UK GDPR and EU GDPR:

  • Contract performance (Art. 6(1)(b)) — processing your email and purchase record is necessary to deliver the guide you purchased.
  • Legal obligation (Art. 6(1)(c)) — we are required to retain transaction records for tax and accounting purposes.
  • Consent (Art. 6(1)(a)) — when you submit a contact, booking, or review form, or use the chat assistant, you provide the information voluntarily for the purpose stated on the form.
  • Legitimate interests (Art. 6(1)(f)) — we retain minimal operational logs and anonymised usage events to diagnose issues and prevent abuse; these are not linked to individual identities.

5. Who we share your information with

We use trusted third-party services to operate our platform. These parties act as data processors and are contractually bound to protect your information:

  • Stripe — processes your payment. Stripe is PCI-DSS Level 1 certified and GDPR-compliant. Their privacy policy: stripe.com/privacy.
  • Supabase — stores your email and purchase record securely on servers in the European Union. Their privacy policy: supabase.com/privacy.
  • Netlify — hosts this website. Netlify may log request metadata (such as IP addresses) for security purposes. Their privacy policy: netlify.com/privacy.
  • Anthropic — powers the site's chat assistant and the automatic translation of reviews. Chat messages and review text are processed to generate replies/translations. Their privacy policy: anthropic.com/legal/privacy.
  • Google (Gmail) — we send guide-delivery and follow-up emails from a Gmail-hosted address, so your email address passes through Google's mail infrastructure. Their privacy policy: policies.google.com/privacy.

We do not share your data with any other party.

6. How long we keep your information

  • Purchase records — retained for 7 years to comply with UK and EU accounting regulations, after which they are permanently deleted.
  • Email address — retained for as long as your purchase record exists. If you request deletion before the 7-year period, we will remove your email from our records and replace it with an anonymised identifier, while retaining the transaction data required by law.
  • Form submissions (contact and call requests) — kept for as long as needed to handle your inquiry and for a reasonable reference period afterwards. You can request deletion at any time.
  • Reviews — kept for as long as they are displayed on the site. You can request removal of your review at any time.
  • Anonymous usage events — contain no direct identifiers (the IP address is stored only as an irreversible hash) and are retained for statistical purposes.

7. Your rights

Under the UK GDPR and EU GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the data we hold about you.
  • Right to rectification — ask us to correct inaccurate data.
  • Right to erasure — ask us to delete your data, subject to our legal retention obligations.
  • Right to restriction — ask us to limit how we process your data in certain circumstances.
  • Right to data portability — request your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.

To exercise any of these rights, email us at contact.mvabroad@gmail.com. We will respond within 30 days.

If you are in the UK, you may also lodge a complaint with the Information Commissioner's Office (ICO). If you are in the EU, you may contact your national data protection authority.

8. Cookies and local storage

This website does not use tracking or advertising cookies. We use localStorage in your browser to remember your language preference (English or Greek), and standard browser caching so pages and downloaded guides keep working offline. These stay on your device. Separately, the anonymous usage events described in section 2 are sent to our own server; they contain no advertising identifiers.

9. Changes to this policy

If we make material changes to this policy, we will update the "Last updated" date at the top of this page. Continued use of our website after changes are published constitutes acceptance of the revised policy.

10. Contact

For any questions about this policy or how we handle your data, contact us at contact.mvabroad@gmail.com.