top of page

Privacy Policy

Designing a thoughtful travel experience sometimes requires personal information. We may need to know how to contact you, what has been booked, who is traveling, and whether there are practical requirements that will help us look after you properly.

We aim to collect only what is reasonably useful, explain why we need it and share it only with the people and providers who need it for a legitimate purpose. The Zurich Insider™ does not operate as a data broker and does not sell guest lists or personal data for advertising revenue.

No digital system can promise perfect security. We nevertheless take privacy seriously and use reasonable organizational and technical measures appropriate to the nature of our business and the information involved.

This Privacy Policy explains how The Zurich Insider™ collects, uses, discloses, stores and protects personal data, and the choices and rights available to you. It is a transparency notice; it does not treat a visit to our website as consent to every form of data processing. Where consent is legally required, we request it separately or provide an appropriate choice.

Last updated: 26 July 2026

 

In This Policy

  1. Who Is Responsible for Your Data

  2. Scope and Applicable Law

  3. Personal Data We May Collect

  4. Where Personal Data Comes From

  5. How We Use Personal Data

  6. Legal Grounds for Processing

  7. Sensitive Data, Travel Documents and Children

  8. When We Share Personal Data

  9. Payments and Financial Information

  10. Service Providers and International Transfers

  11. Website Data, Cookies, Analytics and Social Media

  12. Communications and Direct Marketing

  13. Photographs, Reviews and Guest Content

  14. Digital and AI-Assisted Tools

  15. Retention

  16. Data Security

  17. Your Rights and Choices

  18. Questions and Complaints

  19. Changes to This Policy

1. Who Is Responsible for Your Data

The controller responsible for the processing described in this Policy is:

The Zurich Insider™ by Samantha Aeschbach
c/o WOW Zurich Tours by Matasaru
Baumgasse 10
8005 Zurich, Switzerland

 

For most activities described here, TZI determines why and how personal data is processed. Some recipients, such as banks, payment providers, travel agencies, public authorities, social-media platforms or independently contracted travel suppliers, may process data as separate controllers under their own privacy information.

2. Scope and Applicable Law

This Policy applies to personal data processed by TZI in connection with:

  • Our website, blog, inquiry forms and other online features;

  • Requests, proposals, bookings, gift cards and travel Services;

  • Communications by email, telephone, WhatsApp or other agreed channels;

  • Newsletters, social media, reviews, photographs and promotional activities;

  • Relationships with travel advisors, agencies, DMCs, corporate clients, suppliers and other business partners; and

  • Applications or inquiries from prospective guides, contractors and other candidates.

Personal data” means information relating to an identified or identifiable natural person. “Processing” includes collecting, recording, organizing, using, storing, disclosing, correcting, restricting, deleting or otherwise handling personal data.

TZI is established in Switzerland and processes personal data principally under the Swiss Federal Act on Data Protection (“FADP”) and its implementing ordinance. The EU General Data Protection Regulation or the UK General Data Protection Regulation, and other mandatory privacy laws, may also apply to specific processing depending on the circumstances.

Nothing in this Policy removes a right or protection that cannot lawfully be limited.

3. Personal Data We May Collect

The data involved depends on how you interact with us and which Service is requested. We may process the following categories where relevant:

3.1 Identity and Contact Data

  • Name, title, preferred form of address and language;

  • Postal or billing address, country of residence or nationality where relevant;

  • Email address and telephone or messaging details; and

  • Names and contact details of a lead guest, travel advisor, organizer or emergency contact.

3.2 Inquiry, Booking and Travel Data

  • Requested or confirmed dates, times, destinations, routes and Services;

  • Number and composition of guests, including children’s ages where relevant;

  • Hotel, meeting-point, arrival, departure, flight, train or transfer information;

  • Booking references, vouchers, gift-card details and supplier confirmations;

  • Travel preferences, interests, language, pace, celebration or special-request information; and

  • Communications, itinerary notes and feedback relating to the Service.

3.3 Accessibility, Health and Dietary Information

Where voluntarily provided and reasonably relevant, this may include:

  • Mobility, accessibility, sensory or communication needs;

  • Allergies, dietary requirements or food restrictions;

  • Health or safety information relevant to participation or emergency planning; and

  • Other practical information needed to assess or arrange a suitable Service.

Some dietary, accessibility or health information may constitute sensitive personal data or indirectly reveal information such as health or religious beliefs.

3.4 Identity and Travel Documents

For certain transfers, ticketing arrangements, regulated services or third-party bookings, we may need limited passport, identity-document or similar details. We do not request copies merely as a matter of routine and encourage you not to send more information than is required.

3.5 Payment and Transaction Data

This may include:

  • Amount, currency, payment status and transaction date;

  • Invoice, billing and accounting information;

  • Bank-transfer details visible to us as recipient; and

  • Payment-provider references and limited card-related information, such as card type or the last digits, where supplied by the payment provider.

TZI does not ordinarily receive or store the complete payment-card number or card security code when payment is made through an external payment page.

3.6 Website and Device Data

Depending on the website functions and settings in use, this may include:

  • IP address and approximate location derived from it;

  • Browser, device, operating system, language and screen information;

  • Date, time, referring page, pages viewed, links used and session activity;

  • Cookie identifiers, consent choices and security or diagnostic data; and

  • Information submitted through forms, comments, subscriptions or website accounts, where available.

3.7 Media, Reviews and Marketing Data

  • Photographs, video or audio recordings;

  • Reviews, testimonials, survey answers and correspondence;

  • Newsletter subscriptions, marketing preferences and engagement; and

  • Public interactions with TZI’s social-media accounts.

3.8 Business and Candidate Data

For business contacts, suppliers, guides and applicants, we may process professional contact details, company information, roles, qualifications, language skills, availability, correspondence, contractual records, invoices and application materials.

4. Where Personal Data Comes From

We may obtain personal data:

  • Directly from you through an inquiry, booking, email, call, message, form, payment or participation in a Service;

  • From a lead guest, family member or other person arranging travel for a group;

  • From a travel advisor, travel agency, DMC, concierge, hotel, employer, corporate organizer or event planner;

  • From a guide, driver, transportation provider, venue, ticketing partner or other service provider;

  • From payment providers, banks and fraud-prevention or transaction partners;

  • Automatically through the website and its technical services; and

  • From public or professional sources, review platforms or social media where you interact with TZI or make information public.

Where another person or organization provides your data, the information received may be limited to what is needed to answer an inquiry or provide the Service. We make this Policy publicly available and may also provide or link to it in booking communications.

If you give us another person’s data, please ensure that you are entitled to do so, share only what is reasonably necessary and direct that person to this Policy where appropriate.

5. How We Use Personal Data

Depending on the relationship and information involved, we may use personal data to:

  • Receive, assess and respond to inquiries;

  • Prepare proposals, quotations, routes, itineraries and booking documents;

  • Confirm, administer, personalize and provide Services;

  • Coordinate guides, drivers, transportation, tickets, restaurants, hotels, attractions and other arrangements;

  • Communicate before, during and after a Service;

  • Adapt a route, pace, meeting point or arrangement to practical guest needs;

  • Process payments, refunds, invoices, commissions and accounting records;

  • Provide support and respond to changes, complaints, emergencies or safety concerns;

  • Manage relationships with agencies, advisors, suppliers and corporate clients;

  • Operate, maintain, secure and improve the website and business systems;

  • Understand website use and the effectiveness of communications or marketing;

  • Send newsletters or other marketing where permitted;

  • Request or publish reviews, testimonials or media with an appropriate basis;

  • Prevent misuse, fraud, security incidents or unlawful conduct;

  • Establish, exercise or defend legal rights and insurance claims;

  • Comply with accounting, tax, regulatory, court or public-authority obligations; and

  • Evaluate applications and manage relationships with guides, contractors, or suppliers.

We may also create aggregated or anonymized information for business analysis or service improvement. Information that can no longer reasonably identify a person is not personal data.

6. Legal Grounds for Processing

Swiss data protection law requires that personal data be processed lawfully, in good faith, transparently, proportionately, and for a recognizable purpose. It does not structure every processing activity around the same legal-basis terminology used by the GDPR.

Where the GDPR or similar legislation applies, the relevant grounds may include:

  • Contract and pre-contractual steps: answering a requested inquiry, preparing an offer, administering a booking and providing a confirmed Service;

  • Legal obligations: accounting, tax, regulatory, court or authority requirements;

  • Legitimate interests: operating and protecting our business, communicating with guests and partners, improving Services, maintaining records, preventing fraud, securing systems and pursuing or defending legal claims, provided those interests are not overridden by applicable individual rights;

  • Consent: optional cookies, certain marketing, identifiable promotional photographs and sensitive data where consent is required;

  • Vital interests: using necessary information in a genuine emergency where a person cannot provide consent; and

  • Other grounds permitted by applicable law.

Where processing is based on consent, you may withdraw that consent for the future. Withdrawal does not make earlier lawful processing unlawful. If information is essential to a requested Service, withdrawing or withholding it may mean that we cannot provide a particular arrangement safely or as requested.

7. Sensitive Data, Travel Documents and Children

7.1 Sensitive Information

We ask guests to share only the practical information reasonably needed for the Service. We aim to:

  • Limit sensitive data to what is relevant;

  • Restrict access to people who need it;

  • Share only the necessary portion with a guide or provider;

  • Avoid using health, accessibility or dietary data for unrelated marketing or profiling; and

  • Delete, minimize or separate it when it is no longer reasonably needed, subject to legal or claims-related requirements.

Where explicit consent is required, we will request it through an appropriate communication or booking process. In an emergency, information may be used or disclosed where reasonably necessary to protect a person’s vital interests or as otherwise permitted by law.

Please avoid sending unnecessary medical records or unredacted identity documents by ordinary email or messaging. If a document is genuinely required, ask us about the available transfer method.

7.2 Children

Our Services may include children, but the website and booking process are intended for adults arranging travel. Information about a child should normally be provided by a parent, guardian or authorized organizer and should be limited to what is relevant—for example, name where needed, age, ticket category, dietary requirement or safety information.

7.3 Information About Travel Companions

A lead booker, agency or organizer should not share more information about a companion than is reasonably necessary. Particularly sensitive information should, where practical, be provided by the person concerned or with their knowledge and permission.

8. When We Share Personal Data

We do not disclose personal data merely because it may be commercially interesting. We may share relevant data with the following recipients where reasonably necessary:

  • TZI personnel and contracted professionals: guides, driver-guides, drivers, coordinators and administrative support involved in the inquiry or Service;

  • Travel and hospitality providers: transportation companies, ticketing providers, museums, attractions, restaurants, hotels, activity providers and local partners;

  • Booking participants and organizers: the lead guest, travel advisor, agency, DMC, concierge, employer or corporate organizer involved in arranging or paying for the Service, subject to appropriate discretion regarding sensitive information;

  • Technology and business providers: website hosting, email, communications, cloud storage, customer or booking administration, accounting, document, translation, automation, analytics and IT-security providers;

  • Payment and financial providers: Payrexx, card networks, payment acquirers, banks and transaction or fraud-prevention providers;

  • Professional advisers and insurers: accountants, tax advisers, lawyers, auditors and insurers where relevant;

  • Authorities and emergency services: where required by law, a binding request, legal proceedings or a genuine safety need; and

  • A business successor: if all or part of the business is reorganized, transferred or sold, subject to appropriate confidentiality and legal requirements.

Recipients receive only the information that is reasonably relevant to their role where we can control the disclosure. Some recipients act on TZI’s instructions, while others determine their own processing and are responsible for their own privacy information.

9. Payments and Financial Information

Credit-card and other electronic payments are processed through Payrexx AG and the financial institutions or payment methods selected during checkout. The payment provider may collect information needed to authenticate, authorize, prevent fraud, process and document the transaction.

Payment data entered directly on a provider’s secure payment page is processed under that provider’s terms and privacy information. TZI normally receives confirmation, transaction references, amount, status and limited payment details rather than the complete card credentials.

For bank transfers, the participating banks process the transaction, and TZI may receive the payer’s name, account or bank information shown on the payment record, payment reference, amount and date.

Payment providers and banks may be legally required to retain transaction information or conduct compliance and fraud checks independently of TZI.

Further information is available in the Payrexx Privacy Policy.

10. Service Providers and International Transfers

TZI uses service providers to operate a modern website and travel business. As of the date of this Policy, these include or may include:

  • Wix.com Ltd. and its affiliates for website hosting, forms, site functions, security, cookies and related business tools;

  • Payrexx AG and participating financial institutions for electronic payments;

  • Google services, where enabled or used, for functions such as analytics, maps, email or business tools;

  • Meta, Instagram and LinkedIn, when users interact with TZI through those platforms or when related content or features are displayed;

  • Providers of email, communications, cloud storage, booking or customer administration, accounting, document management, translation, automation and IT support; and

  • Travel suppliers and professional partners needed for a particular inquiry or Service.

These providers and recipients may process data in Switzerland, countries of the European Economic Area, the United Kingdom, Israel, the United States and, depending on the booking or business relationship, another country where a guest, agency, organizer, supplier or other intended recipient is located.

The laws of a recipient country may not provide the same level of protection as Swiss law. Where required, TZI seeks to rely on an adequate level of protection recognized by the competent authority, recognized contractual safeguards such as standard data-protection clauses, an approved certification or framework, supplementary organizational or technical measures, or a statutory exception—for example, where disclosure is necessary for a contract requested by the data subject, based on valid consent or required for legal claims.

Because providers, infrastructure and individual travel arrangements can change, the exact countries and sub-processors may vary. You may contact us for more specific information relevant to your data or booking.

Provider information includes the Wix Privacy Policy, Payrexx Privacy Policy, Google Privacy Policy, Meta Privacy Policy and LinkedIn Privacy Policy.

11. Website Data, Cookies, Analytics and Social Media

11.1 Technical Website Data

When you access the website, Wix and other technical providers may process device, browser, IP address, request, security, diagnostic and usage information needed to deliver and protect the site. Some of this processing is technically necessary even if optional cookies are declined.

11.2 Cookies and Similar Technologies

Cookies and related technologies may be used for:

  • Essential functions: security, network management, session continuity, forms, consent choices and other functions needed to operate the website;

  • Preferences and functionality: remembering settings or improving convenience;

  • Analytics: understanding visits, pages, interactions and website performance; and

  • Advertising or social media: measuring campaigns, displaying embedded content or supporting platform functions where enabled.

Where consent is required, optional categories should be activated based on the choice made via the website’s cookie controls. Essential technologies may operate without consent where permitted because the requested site function cannot reasonably be provided without them.

You can use the website’s available cookie controls and your browser settings to manage cookies. Withdrawing a choice applies prospectively. Blocking some technologies may affect particular website features.

Cookie names, providers and durations can change when the website platform or connected tools are updated. The applicable duration is determined by the purpose, provider settings and whether the cookie is session-based or persistent.

11.3 Analytics and Maps

Google Analytics or another analytics function may be used where enabled. Analytics tools can process identifiers, device and usage information to help us understand website performance. We configure optional analytics and consent controls with the aim of respecting applicable requirements, but we do not claim that analytics providers cannot process information for purposes described in their own policies.

Google Maps or another map service may be embedded or linked to help visitors locate meeting points or understand routes. Loading or using an embedded map may allow the provider to receive device, IP-address and interaction information and, depending on your device permissions, location information.

11.4 Social Media

Our website links to or may display content from Instagram, Facebook, LinkedIn or other platforms. A simple external link generally directs you to the platform when you choose it. An embedded feed, video, sharing tool or plug-in may transmit technical and interaction data when it loads or when you use it, depending on its configuration and your consent choices.

If you interact with TZI directly through a social-media account, the platform processes information under its own terms and privacy policy. Public comments, likes, tags and messages may also be visible to the platform and other users according to your settings.

12. Communications and Direct Marketing

We use contact details to answer inquiries, administer bookings and provide service-related information. These operational communications are not the same as a newsletter or general marketing.

We may send newsletters, travel inspiration, service updates or promotional communications where you have requested them or where another lawful basis permits. You can unsubscribe through the link in a marketing email or contact us at any time. We may retain a minimal suppression record so that we can respect the opt-out.

If you communicate through WhatsApp or another messaging service, the platform may process message metadata and other information in accordance with its own privacy practices. You may ask to continue by email or telephone if you prefer another channel.

13. Photographs, Reviews and Guest Content

Participation in a TZI Service does not by itself give TZI unrestricted permission to use an identifiable guest’s image for marketing.

Where we wish to publish or reuse identifiable guest photographs, recordings or submitted content for promotional purposes, we will seek appropriate permission or rely on another clearly disclosed lawful basis. Permission can generally be withdrawn for future use, although it may not always be possible to retrieve printed material or copies already lawfully published or shared outside our reasonable control.

Reviews posted on independent platforms may be linked, embedded or reproduced in accordance with the platform’s functions, applicable law and any relevant permission. Our Website Disclaimer contains further information about testimonials, and our Copyright & Content Use Policy explains ownership of guest-created material.

14. Digital and AI-Assisted Tools

TZI may use digital automation, translation, transcription, or artificial-intelligence-assisted tools to support administrative work, organize information, summarize or translate communications, develop draft itinerary content, or improve the clarity and quality of written material.

When using such tools, we aim to:

  • Limit personal data to what is reasonably needed for the task;

  • Avoid including sensitive or identity-document information where it is unnecessary;

  • Use business services and settings appropriate to the intended purpose where available; and

  • Apply human review before relying on material for a guest-facing decision or confirmed Service.

TZI does not ordinarily make a decision that produces legal or similarly significant effects for a guest solely through automated processing. Payment, security, or fraud-prevention providers may use automated checks under their own responsibility and in accordance with privacy information.

If TZI were to introduce automated decision-making of the kind that requires a specific legal notice, we would provide the information and the review opportunity required by applicable law.

15. Retention

We retain personal data for as long as reasonably necessary for the relevant purpose and then delete, anonymize or restrict it where appropriate. The period depends on factors such as:

  • Whether an inquiry is active or a Service is booked;

  • The nature and sensitivity of the information;

  • Follow-up, customer-service and business relationship needs;

  • Contractual, accounting, tax, insurance and legal-claim requirements;

  • Applicable limitation and statutory retention periods;

  • Security, fraud-prevention and dispute considerations; and

  • The settings and retention cycles of service providers and backups.

In practice:

  • Inquiry and booking correspondence may be retained while the relationship remains active and for an appropriate period afterward;

  • Contracts, invoices, payment and accounting records may need to be retained for statutory periods that can extend to ten years under Swiss accounting or tax rules;

  • Passport, health, accessibility and detailed dietary information should generally be kept for a shorter period and minimized after the Service, unless continued retention is reasonably justified;

  • Marketing data may be retained until consent is withdrawn, an objection is received, or the data is no longer reasonably useful, with a minimal suppression entry retained where needed;

  • Website logs and cookies are retained according to security needs, provider settings and cookie duration; and

  • Backup copies may remain for a limited time until they are overwritten through the ordinary backup cycle.

Legal holds, disputes, authority requirements or a valid request may require a different period.

16. Data Security

We take measures intended to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. Depending on the system and risk, these may include:

  • Limiting access according to role and practical need;

  • Using reputable hosting, payment and business-service providers;

  • Password protection and stronger authentication where supported;

  • Secure website connections and provider encryption in transit where available;

  • Device, software, backup and account-security practices;

  • Data minimization and separation of particularly sensitive information; and

  • Confidentiality and data-protection expectations for relevant contractors and providers.

Security measures reduce risk but cannot eliminate it. Email, messaging, mobile devices and internet services can be affected by interception, account compromise, delivery errors, malware, provider outages or human error. Please avoid sending unnecessary sensitive data and contact us if you believe information has been sent to the wrong recipient or an account may be compromised.

If a personal-data breach occurs, we assess it and notify the competent authority or affected individuals where required by applicable law.

17. Your Rights and Choices

Depending on the applicable law and circumstances, you may have the right to:

  • Ask whether we process personal data about you and receive relevant information or a copy;

  • Correct inaccurate or incomplete data;

  • Request deletion or destruction where continued processing is not justified;

  • Object to or request restriction of particular processing;

  • Withdraw consent for future processing;

  • Object to direct marketing;

  • Receive or transfer certain data in a commonly used electronic format where the legal conditions for portability are met;

  • Express your view and request human review of a qualifying automated individual decision; and

  • Raise a concern with a competent data-protection authority.

These rights are not absolute. A request may be limited, delayed or refused where permitted—for example, to protect another person, preserve legal privilege, comply with retention duties, prevent abuse or establish or defend legal claims.

To exercise a right, email hello@thezurichinsider.com and describe your request. We may ask for information reasonably necessary to verify your identity and protect the data from unauthorized disclosure. Please do not send an unredacted identity document unless we specifically request it and explain an appropriate method.

We aim to respond within the period required by applicable law. Under Swiss law, access information is generally provided without charge and within 30 days. A lawful extension, restriction or fee may apply in exceptional cases, including where a request requires disproportionate effort. We will explain this where required.

18. Questions and Complaints

Please contact us first if you have a privacy question or concern. We would like the opportunity to understand the issue and find an appropriate solution.

Privacy contact: Samantha Aeschbach
Email: hello@thezurichinsider.com
Telephone: +41 76 464 54 88

You may also contact the Swiss supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern, Switzerland

If another data-protection law applies, you may also have the right to contact the competent supervisory authority in your country or region.

19. Changes to This Policy

We may update this Policy when our practices, providers, Services or legal obligations change. The latest version will be published on this page with the date of the update.

For a material change, we will take any additional transparency or consent step required by applicable law. A revised Policy does not retroactively turn an earlier unlawful use into a lawful one or withdraw rights that cannot be limited.

© Copyright by The Zurich Insider
bottom of page