The detail, section by section.
Who we are
Tallest Tourguide is a small guiding business based in Sarajevo. When you book a tour, send an enquiry or simply read this site, we are the "data controller" for the information involved — meaning we decide what is collected and why, and we are the ones answerable for it.
- Tallest Tourguide, Hamdije Kreševljakovića 61, 71000 Sarajevo, Bosnia and Herzegovina
- Email: hello@tallesttourguide.com
- Phone: +387 62 664 244
We are a two-person operation, not a company with a privacy department. Everything below describes what actually happens to your information — not a template we copied.
Bosnia and Herzegovina is outside the European Union, but most of our guests are not. Where we offer tours to people in the EU and UK, we treat their information according to the GDPR, which is what this policy is written to.
What we collect
Only what a given interaction actually needs. There is no account to create and no profile building in the background.
When you book a tour
- Your name, email address and phone number
- The tour, date, number of guests, and any promotional code
- Anything you choose to write in the notes field — dietary needs, mobility requirements, who you're travelling with
- A booking reference we generate
Payment card details are not collected, not stored, and never reach us. The online card gateway is not live: you pay by bank transfer against an invoice we email you, or in cash on the day. If you write card numbers into a message to us, we will ask you to stop and will delete the message.
When you send an enquiry or request a personalised trip
- Your name, email, and whatever you tell us about the trip you have in mind
- Your phone number, if you give one
When you leave a review
- The name you choose to publish under, your rating, and your words
- Reviews left on Google or Tripadvisor are governed by those platforms' own policies, not this one
When you simply read the site
Our host records standard server logs — IP address, browser, and which page was requested — for security and to keep the site running. If, and only if, you accept analytics cookies, we also learn which pages you read and roughly where in the world you are. Details are in section 04.
We do not ask for, and have no use for, special category data — health, religion, politics. Some of our tours cover the siege of Sarajevo and the war; if you tell a guide something personal about your own connection to it, that stays a conversation, not a record.
Why we use it, and our legal basis
Under the GDPR every use of your information needs a stated justification. Ours:
| What we do | Why we're allowed to |
|---|---|
| Take and confirm your booking, hold your seat, email you the details | Performance of our contract with you |
| Answer an enquiry or quote a personalised trip | Steps taken at your request before a contract |
| Email you an invoice and keep the payment record | Contract, and our legal obligations for tax and accounting |
| Keep records required by Bosnian tax and accounting law | Legal obligation |
| Publish a review you submitted | Your consent, which you can withdraw |
| Analytics and advertising cookies | Your consent, which you can withdraw |
| Keep the site secure and working; defend a legal claim if one arises | Our legitimate interests |
| Use tour photographs in marketing | Our legitimate interests — tell a guide and we won't use yours |
We do not send marketing emails to people who have not asked for them, and we do not add booking guests to a mailing list as a side effect of booking.
Sending data outside the EU
We are in Bosnia and Herzegovina, and some of our providers are in the United States. If you are in the EU or UK, that means your information leaves the area your law protects it in. We would rather say this plainly than bury it.
Bosnia and Herzegovina does not have an EU adequacy decision — the EU has not formally ruled that our data protection law matches its own. For your booking, the transfer is permitted because it is necessary to perform the contract you asked us to enter into: we cannot guide you around Sarajevo without knowing who is arriving and when.
For our US providers, transfers rely on the European Commission's Standard Contractual Clauses, and — for Google — its certification under the EU–US Data Privacy Framework.
For anything not necessary to your booking, such as analytics and advertising, the transfer happens only because you consented, and stops if you withdraw.
How long we keep it
| What | How long |
|---|---|
| Booking and payment records | For the period Bosnian tax and accounting law requires us to keep financial records |
| Enquiries that never became bookings | 24 months, then deleted |
| Calendar entries for completed tours | 24 months, then deleted |
| Published reviews | Until you ask us to remove them |
| Your cookie choice | 12 months, then the banner asks again |
| Analytics data | Held by Google on its own retention schedule, no longer than 14 months |
When a retention period ends we delete the record rather than archiving it indefinitely. If you ask us to delete something sooner, see section 08.
Your rights
If you are in the EU or UK these are rights in law; if you are elsewhere, we extend the same ones to you anyway, because running two standards would be worse for everybody.
- See what we hold about you, and get a copy
- Have anything wrong corrected
- Have it deleted, where we have no obligation to keep it
- Ask us to pause using it while a dispute is sorted out
- Receive it in a portable, machine-readable form
- Object to any use we justify by our own legitimate interests — including tour photography
- Withdraw consent at any time, without it affecting anything done before you withdrew
To exercise any of these, write to hello@tallesttourguide.com. There is no form. We will reply within 30 days, and there is no charge. We may ask you to confirm your identity first — only so that we don't hand your booking history to someone who isn't you.
If you are unhappy with how we have handled it, you can complain to the data protection authority where you live, or to Bosnia's Personal Data Protection Agency (Agencija za zaštitu ličnih podataka u BiH). We would much rather you told us first and gave us the chance to fix it.
Keeping it safe
The site is served entirely over HTTPS. Booking data goes to accounts protected by two-factor authentication, accessible only to the two of us. We keep the number of places your information lives deliberately small — the strongest protection available to an operation our size is simply not spreading data around.
No system is perfect. If a breach ever affected your information and put you at real risk, we would tell you and the relevant authority, without waiting to be asked.
Children
Our tours are open to families, and children are welcome on them. This website, though, is aimed at the adult making the booking: we don't knowingly collect information directly from children, and a child's details reach us only through the parent or guardian booking for them. If you believe we hold information a child gave us directly, tell us and we will delete it.
Changes to this policy
This policy was last updated in August 2026. When we change it we update that date. If a change materially affects what you agreed to — a new category of tracking, a new provider handling your booking — we will ask for your consent again rather than relying on you to re-read this page.
Want to know what we hold about you?
Ask, and we'll tell you — no form, no charge.