Privacy Policy
Last updated: April 2026
1. Who we are
gemci is operated by Treasure Card VOF, registered in the Netherlands. Our website is gemci.nl. For questions about this privacy policy, contact us at contact@gemci.nl.
2. What data we collect
Data you provide
- Contact form: name, email, and your message
- Newsletter: email address
- Reservation/lead form: name, email, phone, date, number of guests, and optional message
Data collected automatically
- Analytics: we track page views and clicks using anonymized IP hashes. We do not use third-party analytics.
- Cookies: we use functional session cookies and request consent before loading Google Maps.
3. Why we collect this data
- To respond to your contact requests
- To send you our newsletter (only if you subscribe)
- To forward reservation requests to businesses via WhatsApp
- To improve our website and understand which places are popular
- To show maps and location-based features (with your consent)
4. Third-party services
- Google Maps: loaded only after cookie consent. Google's privacy policy applies.
- WhatsApp: reservation messages are sent via WhatsApp. WhatsApp's privacy policy applies.
- DeepL: used for translations. No personal data is sent.
- CloudFront (AWS): images are served via Amazon CloudFront CDN.
- Tiqets: for ticket purchases, you are redirected to Tiqets. Their terms and privacy policy apply to your purchase.
- Booking.com: for hotel reservations, you are redirected to Booking.com. Their terms and privacy policy apply to your booking.
5. Data retention
- Contact form submissions: 1 year
- Newsletter subscriptions: until you unsubscribe
- Analytics data: anonymized, kept indefinitely
- Lead/reservation data: 1 year
6. Your rights
Under the GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Withdraw consent at any time
- File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
7. Cookies
- laravel-session: functional cookie, required. Expires after 2 hours.
- XSRF-TOKEN: security cookie. Expires after 2 hours.
- gemci-cookies: stores your cookie consent choice (localStorage).
- gemci-locale: stores your language preference (localStorage).
- Google Maps cookies: only loaded after consent.
8. Changes to this policy
We may update this privacy policy from time to time. The latest version is always available on this page.