Traveloop Single Member P.C. β GDPR Compliant Data Processing Notice
LAST UPDATED: JUNE 27, 2026 β VERSION 2.4
Traveloop Single Member P.C. ("Traveloop", "we", "our", "us") is strictly dedicated to maintaining transparent, highly compliant, and privacy-by-design data processing paradigms. This Privacy Policy ("Policy") constitutes the formal Data Processing Notice required under Article 13 and Article 14 of the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the Greek Data Protection Act (Law No. 4624/2019), the EU ePrivacy Directive (2002/58/EC as amended), and all related applicable European data protection legislation. This Policy informs you, as a Data Subject, of the categories of personal data we collect, the purposes and legal bases for their processing, the recipients to whom data is disclosed, your rights, and the security measures we implement to protect your personal data. By using the Platform, you acknowledge having read and understood this Policy. This Policy is incorporated by reference into our Terms of Service.
The legal Data Controller responsible for your personal data processed through the Platform is:
Entity Name: Traveloop Single Member P.C. (Greek: Traveloop ΞΞΏΞ½ΞΏΟΟΟΟΟΟΞ· Ξ.Ξ.Ξ.)
Legal Form: Single Member Private Capital Company (Ξ.Ξ.Ξ.) incorporated under Greek Law 4072/2012
Registered Office: Athens, Greece
Primary Data Protection Contact: privacy@traveloop.co
Support Contact: support@traveloop.co
Platform URL: https://traveloop.co
Where Traveloop processes personal data jointly with Stripe, Inc. and/or Stripe Payments Europe, Ltd. for purposes of AML/KYC compliance, each party acts as an independent Data Controller in respect of its own processing operations. Traveloop does not act as a Data Processor on behalf of Stripe, nor does Stripe act as a Data Processor on behalf of Traveloop, for the sensitive financial data described in Section 3.4 below.
Traveloop operates under a strict data minimization architecture: we collect, process, and retain only the personal data that is strictly necessary for the specific, explicit, and legitimate purposes described in this Policy. We do not collect personal data in anticipation of future needs that are not clearly defined at the time of collection.
Traveloop stores and processes the following categories of personal data within its own controlled infrastructure, hosted on Supabase Inc. servers located within the European Union (Frankfurt, Germany β EU-Central region):
Traveloop has implemented a strict architectural segregation β informally referred to as the "Stripe Wall" β to ensure that highly sensitive financial and governmental identity data is never collected, stored, processed, transmitted through, or accessible by Traveloop's own servers or databases. The following categories of data are processed exclusively by Stripe:
All such data is subject exclusively to Stripe's Privacy Policy, available at https://stripe.com/en-gr/privacy. Traveloop has no technical or administrative access to any data described in this Section 2.3.
The table below sets out, for each category of personal data processed by Traveloop, the specific processing purpose, the applicable legal basis under the GDPR, and any relevant retention information:
| Data Category | Processing Purpose | GDPR Legal Basis |
|---|---|---|
| Full Name & Email | Account creation, authentication, transactional notifications, support | Art. 6(1)(b) β Performance of a Contract |
| Phone Number (OTP) | MFA security, bot prevention, account integrity | Art. 6(1)(b) & Art. 6(1)(f) β Legitimate Interests (security) |
| Chat Messages & Metadata | Dispute resolution, law enforcement cooperation, platform safety | Art. 6(1)(c) β Legal Obligation & Art. 6(1)(f) β Legitimate Interests |
| Uploaded Documents (PDFs) | Listing verification, fraud detection, dispute evidence | Art. 6(1)(b) β Performance of a Contract & Art. 6(1)(f) |
| Transaction Metadata | Escrow management, audit trail, DAC7 reporting obligations | Art. 6(1)(b), Art. 6(1)(c) β Legal Obligation (DAC7) |
| IP Address & Device Data | Fraud prevention, rate-limiting, network security | Art. 6(1)(f) β Legitimate Interests (security) |
| Behavioral / Personalization Data (localStorage) | Homepage personalization (last 5 viewed listings/locations) | Art. 6(1)(a) β Consent (opt-in only via Cookie Banner) |
Traveloop employs a granular privacy-by-design framework for homepage personalization. The Platform records and structures your last five (5) viewed geographical listing locations using your device's native client-side localStorage array to render a personalized homepage experience. This data is stored exclusively on your device and is not transmitted to Traveloop's servers.
This client-side tracking logic is permanently blocked, sandboxed, and completely non-functional by default upon your first visit. It is dynamically activated only if and when you explicitly click the "Accept All" option on the Platform's GDPR-compliant Cookie Consent Banner.
Consent for behavioral tracking may be withdrawn at any time, with immediate effect, through the Cookie Consent settings. Upon withdrawal, all personalization data stored in your device's localStorage will be cleared immediately.
Traveloop uses strictly necessary session cookies and authentication tokens that are essential for the operation of the Platform and do not require consent under the ePrivacy Directive.
All messages transmitted through the Platform's Chat System, together with associated metadata, are securely retained on Traveloop's Supabase infrastructure for dispute resolution, platform safety, and legal compliance.
Chat transcripts and metadata are retained for a period of twenty-four (24) months from the date of the last message, or for the duration of any active or pending dispute or legal proceeding, whichever is longer.
Chat data is stored in encrypted form at rest using AES-256 encryption. Access is strictly limited on a need-to-know basis and all access is logged and auditable.
Council Directive (EU) 2021/514 (the "DAC7 Directive"), transposed into Greek law via Law 5057/2023, imposes mandatory reporting obligations on Platform Operators. Traveloop qualifies as a Platform Operator subject to DAC7 reporting obligations.
Traveloop and/or Stripe are legally mandated to collect, process, and report Seller identification data, transaction volume, number of transactions, platform fees, and taxes withheld to the Greek tax authority (ΞΞΞΞ) and other EU Member States where applicable.
Reporting is triggered for each Seller who completes thirty (30) or more relevant transactions or receives total consideration exceeding two thousand Euros (β¬2,000) in a calendar year.
The processing is conducted on the legal basis of compliance with a legal obligation (Article 6(1)(c) GDPR). This basis does not require additional consent and cannot be objected to under Article 21 GDPR.
| Processor | Purpose | Processing Location | Transfer Mechanism |
|---|---|---|---|
| Supabase Inc. | Relational database, file storage, authentication | EU-Central (Frankfurt, Germany) | EU/EEA β No transfer mechanism required |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Payment processing, escrow, KYC/AML, DAC7 | EEA (Ireland), with potential US parent access | Standard Contractual Clauses (SCCs) for US parent access |
| Upstash Inc. | Security rate-limiting, edge caching | EEA Edge Nodes | EU/EEA β No transfer mechanism required |
| Vercel Inc. | Platform hosting, serverless compute, CDN | EEA Edge Nodes; potential US origin | Standard Contractual Clauses (SCCs) for any US data transfers |
International transfers outside the EEA are safeguarded by Standard Contractual Clauses (SCCs). A copy may be requested at privacy@traveloop.co.
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| Account Profile Data | Duration of active account + 30 days after deletion request | Cryptographic erasure |
| Uploaded Booking Documents | 90 days after escrow close or account deletion | Secure permanent deletion |
| Chat Transcripts | 24 months from last message or duration of dispute | Cryptographic erasure |
| Transaction Metadata | 7 years (Greek commercial + DAC7 obligations) | Archival then deletion |