golocal

Privacy Policy

Last updated: 9 September 2026

This page explains which data we process when you use go_local, why we do it, and what rights you have. It describes only what our software actually does.

1. Who is responsible

Dimitrios Lazaridis · Megalopolis City Marketing, Paster 3, 54633 Thessaloniki, Greece · ΑΦΜ EL189615316 · megalopolisskg@gmail.com. Write to this address with any question about your data. We have not appointed a Data Protection Officer, as the conditions of Art. 37 GDPR do not apply to us.

2. In short

  • We use no web analytics, no advertising pixels and no tracking cookies.
  • We build no profiles and make no automated decisions about you.
  • We never sell or rent data to anyone.
  • The only cookies we set exist so partners can log in — nothing else.

3. Visiting the website

The site is hosted by Vercel. The server records technical data for each request: IP address, date and time, the page requested and the browser type. This is necessary to run and protect the site. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

4. Waiting list

If you join the waiting list we store your email address, optionally your city and whether you are interested as a partner, together with the date. You receive a confirmation email. Legal basis: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by emailing us.

5. Buying the pass

For a purchase we process your email address, your name if you provide one, and the payment identifiers. The payment itself runs entirely through Stripe — we never see or store card details. A unique token is created for your pass and encoded into your QR code. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and, for tax records, legal obligation (Art. 6(1)(c) GDPR).

6. Redeeming an offer

When a partner scans your QR code we record which pass redeemed which offer and when, so that each offer is used once. The partner only sees that the pass is valid — not your name or email address. Legal basis: performance of a contract.

7. Partner applications (businesses)

When a business applies we process: venue name and description, category, address and area, opening hours, photos and logo, the contact person's name and phone number, email address, legal form, VAT number (ΑΦΜ), tax office (ΔΟΥ) and legal representative, plus an optional website and public rating. The company details are required for the partner agreement. As evidence of the online acceptance of the terms we also store the date and time, the version of the terms, and the IP address from which the acceptance was made. Legal basis: performance of a contract, and legitimate interest in being able to prove consent.

8. Partner login

Partners log in with an identifier and a personal PIN. The PIN is stored only as a cryptographic hash (scrypt) and cannot be recovered — if it is lost, a new one is issued. Logging in sets a signed session cookie, which is required for the dashboard to work.

9. AI guide

If you use the AI guide, your messages are sent to Anthropic PBC (USA), which generates the answer. We do not store the conversations in our database. Please do not enter sensitive personal data into the chat. Legal basis: legitimate interest in providing the service; using it is entirely voluntary.

10. Maps and third-party images

Partner pages embed a Google map (Google Ireland Ltd. / Google LLC). When the page opens, the map is loaded from Google's servers; Google receives your IP address and may set its own cookies. Photos are stored partly at Vercel and partly loaded from the Pexels service, which also receives your IP address. Our fonts are self-hosted — no connection to Google is made for them.

11. Cookies and local storage

  • Partner session cookie — required for login, expires on logout or when the session ends.
  • Admin session cookie — internal administration only.
  • Local storage «language» — remembers the language you chose, on your device.
  • Local storage «popup seen» — so the waiting-list popup does not reappear.
  • The last two never leave your device. We set no tracking or advertising cookies.

12. Recipients

  • Vercel Inc. — website hosting and storage of partner photos.
  • Supabase — database, European Union region.
  • Stripe — payment processing.
  • Resend — transactional email (confirmations, your pass, partner login details), EU region.
  • Brevo — emails to businesses as part of partner acquisition.
  • Anthropic PBC — for the AI guide only.
  • Google — for the embedded map only.

13. Transfers outside the EU

Anthropic PBC and Google LLC are based in the USA. These transfers rely on the European Commission's standard contractual clauses. Vercel and Stripe may also process data outside the EU on the same basis.

14. How long we keep data

  • Waiting list: until you withdraw, at the latest 24 months after signing up.
  • Passes and redemptions: for the season, then for as long as tax law requires.
  • Partner data: for the duration of the partnership, then for as long as tax law requires.
  • Evidence of accepting the terms (time, version, IP): for the term of the contract and as long as a related claim can be brought.
  • Server logs: a short period, following Vercel's defaults.

15. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw any consent with effect for the future. An email to the address above is enough — no particular form is required.

16. Complaints

If you believe our processing breaches the GDPR, you can lodge a complaint with the Hellenic Data Protection Authority, 1-3 Kifissias Ave., 115 23 Athens, Greece, +30 210 6475600, contact@dpa.gr, www.dpa.gr. You may also complain to the supervisory authority where you live.

17. Security and changes

Data is always transferred encrypted (HTTPS). Partner PINs are stored only as hashes. We will update this text whenever our processing changes; the version published here always applies.