Privacy Notice – Booking & Voucher
Last updated: 6 August 2026
Last updated: 2026-07-12 · Version: 1.1
1. What is this notice about?
This notice supplements our general privacy policy and applies in addition and specifically when you book an experience via mallorca.com (e.g. a guided tour, a boat trip, a tasting or a ticket) and in doing so purchase a voucher that you later redeem on site with the respective supplier.
Here you will learn which of your data we process in the course of such a booking, which data we pass on to the supplier of the experience, on which legal basis this takes place, what role our payment service provider plays and how long we retain the data. General information (e.g. on website usage, cookies, your user account and your rights as a data subject) can be found in the general privacy policy; it is not repeated here. This supplement does not make any statements that deviate from the general privacy policy; in case of doubt, the general privacy policy applies in addition.
2. Who is responsible for the processing? (Allocation of roles)
mallorca.com is an intermediary marketplace. We act as a disclosed intermediary (commercial agent) of the respective supplier; the contract for the performance of the experience is concluded directly and exclusively between you and the supplier. We disclose this role to you consistently in our General Terms and Conditions, in the booking flow and in the legal notice (Impressum). This results in the following allocation of roles under data protection law:
- mallorca.com / operator: MenzeMedia.de GmbH, Am Wunderhügel 27, 58644 Iserlohn, Germany, represented by its managing director Frank Menze, registered in the commercial register of the Local Court (Amtsgericht) of Iserlohn under HRB 6785, VAT ID No. DE265536437. Email / data protection contact: support@mallorca.com. We are the controller within the meaning of the GDPR for the arranging (brokering) of the booking, the issuance and administration of the voucher and the collection of payment in the name and for the account of the supplier via our payment service provider.
- The supplier of the experience: The experience itself is provided not by mallorca.com, but by a legally independent supplier, generally established in Mallorca/Spain. The supplier is a separate, independent controller for the processing of your data for the performance of the experience and the redemption of the voucher. The supplier's specific company name will be displayed to you with its full name and address for service as well as its contact details at the latest in the booking confirmation or on the voucher.
- Payment service provider: Payment is processed via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (see Section 5). Stripe processes payment data under its own responsibility (as a controller under data protection law).
3. Which data we process in the booking and voucher process
Depending on the booking, we process the following categories of personal data:
- Identification and contact data: your name (booking name) and your email address; a telephone number only insofar as the specific booking process requests it (e.g. if the supplier needs to be able to reach you for short-notice scheduling or weather-related coordination).
- Booking and voucher data: booked experience/offer, number of persons/tickets, price, booking and order date, voucher code or QR token, validity period, redemption status and — for dated experiences — the booked date/period.
- Payment data: the information required for payment processing. Complete payment instrument data (e.g. the full credit card number) is processed exclusively by our payment service provider and is not stored by us (see Section 5).
- Any additional information you provide voluntarily with the booking (e.g. notes or special requests regarding the experience), to the extent you provide it.
Note on the technical implementation: In the ordering process, in particular your email address and — for logged-in users — the assignment of the order to your profile are stored; the voucher is identified via a code/QR token and verified by the supplier against this token upon redemption. Name, telephone number and special requests are only collected and stored insofar as the respective booking process requests them (data minimisation pursuant to Art. 5(1)(c) GDPR).
4. Which data we pass on to the supplier — and why
So that the supplier can perform your experience and redeem your voucher, we pass on the data necessary for this purpose to the respective supplier. This typically comprises:
- Name (booking name),
- Booking details (booked experience, number of persons/tickets, and for dated experiences the date/period),
- Voucher code / redemption status,
- insofar as necessary for performance: contact details (email and/or telephone number) as well as any special requests/notes you have provided.
Why (purpose): The transfer serves exclusively to prepare and carry out the experience you booked, to contact you about the experience if necessary (e.g. in the event of weather or schedule changes) and to check the validity/redemption of the voucher.
Legal basis: The processing and transfer of this data is carried out for the performance of the contract or in order to take steps prior to entering into a contract — both of our intermediary and voucher contract with you and of the service contract between you and the supplier arranged by us — pursuant to Art. 6(1)(b) GDPR. Insofar as we additionally process data to prevent misuse (e.g. to prevent double redemption of vouchers) and to establish, exercise or defend legal claims, we additionally base this on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Note on the obligation to provide data: The provision of the data mentioned above is required for the booking. Without this data, we cannot arrange the booking, cannot issue a voucher, and the supplier cannot provide the experience.
5. Payment processing via Stripe
We process the payment for your booking via the payment service provider Stripe Payments Europe, Ltd., Dublin, Ireland (hereinafter "Stripe").
- Your payment data (the information associated with the chosen payment method) as well as your email address and the data required for issuing the receipt/invoice are transmitted to Stripe and processed by Stripe as part of the payment process.
- Due to our intermediary model, the respective supplier is the merchant in the legal sense (Merchant of Record) for the payment and the issuer of the payment receipt/invoice. The payment is technically routed via the supplier's Stripe account (booking "in the name and for the account of the supplier"); the payment receipt/invoice is issued via the supplier's account. As a result, the payment- and receipt-related data becomes accessible to the supplier via its Stripe account. Upon your successful payment to Stripe, you have discharged your payment obligation towards the supplier with debt-discharging effect; however, the payout to the supplier only takes place once you redeem the voucher on site (QR code scan = performance of the service), but at the earliest after expiry of the statutory 14-day withdrawal period. We deliberately do not make an immediate payout within the running withdrawal period (for instance based on consent to early commencement of performance pursuant to § 356 Abs. 4 BGB (German Civil Code)); the payout amount is withheld until the end of the period.
- Stripe processes this data as an independent controller in accordance with the Stripe privacy policy. We ourselves store no complete payment instrument data (e.g. no full credit card number).
- Legal basis: The processing of your payment data is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR and for compliance with legal obligations (in particular obligations under commercial and tax law) pursuant to Art. 6(1)(c) GDPR.
- Third-country transfer: For payment processing, Stripe may also transfer personal data to Stripe, Inc. in the USA. Insofar as such a transfer takes place, it is safeguarded by an adequacy decision of the EU Commission (EU-US Data Privacy Framework; Stripe, Inc. is certified under the Data Privacy Framework) and/or by the standard contractual clauses adopted by the EU Commission (Art. 46(2)(c) GDPR). Details and the currently applicable safeguards can be found in the Stripe privacy policy.
6. Recipients or categories of recipients
In connection with your booking, data is received by:
- the supplier of the booked experience (see Section 4),
- our payment service provider Stripe (see Section 5),
- technical service providers engaged by us, who act on our behalf subject to our instructions and whom we bind on the basis of data processing agreements (Art. 28 GDPR) — specifically our hosting/infrastructure provider Vercel (Vercel Inc., USA; any US transfers are safeguarded by standard contractual clauses and/or the EU-US Data Privacy Framework), our database/storage provider Supabase (Supabase, Inc.; storage region used: Frankfurt am Main/EU) and our email dispatch provider Brevo (Brevo GmbH, Germany) for the booking/voucher confirmation,
- and, where applicable, tax advisors, authorities or courts, insofar as we are legally obliged to do so.
7. International data transfers
The suppliers of the experiences are generally established in Spain and thus within the European Union / European Economic Area (EU/EEA). When your booking data is passed on to a supplier established in Spain, there is therefore no transfer to a third country outside the EU/EEA; the uniform European level of data protection under the GDPR applies.
Should, in an individual case, a booked supplier be established outside the EU/EEA, we will transfer your data only in compliance with the requirements of Art. 44 et seq. GDPR (e.g. on the basis of EU standard contractual clauses). Insofar as our technical service providers process data in third countries, this likewise takes place only on the basis of an adequacy decision and/or standard contractual clauses. Any data transfer by our payment service provider is described in Section 5.
8. Retention period
- Booking and voucher data is stored, as a rule, for as long as this is necessary for the handling of your booking and the redemption of the voucher — i.e. until the voucher has been redeemed or its validity has expired — and beyond that for the duration of any warranty, cancellation or reversal periods.
- Validity of the voucher: Under our voucher terms, vouchers are valid for three years, calculated from the end of the calendar year of purchase (in line with the standard limitation period under § 195, § 199 BGB (German Civil Code)). An unredeemed voucher lapses upon expiry of this period. After expiry of the validity, we process the voucher data only within the scope of statutory retention obligations and for the establishment or defence of legal claims.
- Dated vs. undated bookings: For dated experiences (with a fixed date/period), storage is based on the booked date plus the warranty and limitation periods. For undated vouchers (experience voucher without a fixed date), we store the data until redemption, but at the longest until expiry of the three-year validity, and — insofar as you have a right of withdrawal — additionally for the duration of the withdrawal period and any reversal of the transaction. At present, the platform offers undated vouchers exclusively; for these, the 14-day right of withdrawal regularly applies. The statutory exclusion of the right of withdrawal for dated leisure services (§ 312g Abs. 2 Nr. 9 BGB) only concerns any future dated experience offers. Whether and to what extent you have a right of withdrawal is set out in our withdrawal notice (Widerrufsbelehrung) and our General Terms and Conditions.
- Invoices and accounting-relevant records are retained by us on the basis of retention obligations under commercial and tax law. For booking records and invoices, the retention period has been 8 years since 1 January 2025 (§ 147 Abs. 3 i. V. m. Abs. 1 Nr. 4 AO (German Fiscal Code), § 257 Abs. 4 i. V. m. Abs. 1 Nr. 4 HGB (German Commercial Code), § 14b Abs. 1 UStG (German VAT Act), as amended by the Fourth Bureaucracy Relief Act); for other commercial letters, 6 years apply. The legal basis for this is Art. 6(1)(c) GDPR. During this time, the processing is restricted to storage.
- Data that we need for the establishment or defence of legal claims is stored until expiry of the applicable limitation periods.
9. Your rights and further information
You are entitled to the data subject rights described in more detail in our general privacy policy (in particular access, rectification, erasure, restriction of processing, data portability, objection and the right to lodge a complaint with a supervisory authority). For matters concerning the performance of the experience, the respective supplier, as a separate controller, is responsible; for the arranging of the booking, the voucher and the collection of payment, we are the right point of contact. You can reach us at support@mallorca.com.