Privacy Policy

Effective date: 4 August 2026

This policy explains how AmsterTram B.V. processes personal data through amstertram.nl, booking.amstertram.nl and our related services.

1. Controller and contact details

AmsterTram B.V. is the controller. Our postal address is Kerkweg 54, 2985 AV Ridderkerk, the Netherlands. Our visiting address is Kromme Mijdrechtstraat 25, 1079 KN Amsterdam, the Netherlands. We are registered with the Dutch Chamber of Commerce under number 83728171 and our VAT number is NL862970714B01.

For privacy questions or to exercise your rights, email [email protected].

2. Personal data we process

  • Identity and contact data, such as name, email address, telephone number and the contents of a message.
  • Booking data, such as booking date, party size, selected experience, dietary or accessibility information you provide, and booking correspondence.
  • Transaction and administration data, such as payment status, amount, Stripe transaction reference, invoices and legally required financial records. We do not receive or store full payment-card details.
  • Newsletter data, such as name, email address, consent and subscription status.
  • Technical and usage data, such as IP address, device/browser information, cookie identifiers, visited pages, interactions, security logs and approximate location derived from an IP address.

3. Purposes and GDPR legal bases

  • Contact: to answer questions and follow up messages. The basis is our legitimate interest in communicating with you (Article 6(1)(f) GDPR), or steps at your request before a contract (Article 6(1)(b)).
  • Bookings: to take, administer and fulfil reservations, communicate service information and handle changes or complaints. The basis is performance of a contract and pre-contractual steps (Article 6(1)(b)).
  • Payments: to process payment through Stripe and prevent payment fraud. The bases are performance of a contract (Article 6(1)(b)) and our legitimate interest in secure payments and fraud prevention (Article 6(1)(f)).
  • Newsletter: to send marketing email through Kit only after consent (Article 6(1)(a)). Consent can be withdrawn at any time using the unsubscribe link.
  • Analytics: to understand and improve our websites using Google Analytics 4 and Cloudflare analytics. Non-essential analytics are based on consent (Article 6(1)(a)); strictly necessary, privacy-preserving security and traffic measurements are based on our legitimate interest in a reliable website (Article 6(1)(f)).
  • Advertising: we do not currently use personal data for personalised advertising or advertising pixels. If this changes, we will update this policy and request consent before placing non-essential advertising cookies.
  • Security: to protect accounts, websites, bookings and systems, investigate misuse and maintain logs. The basis is our legitimate interest in securing our services (Article 6(1)(f)) and, where applicable, a legal obligation (Article 6(1)(c)).
  • Legal administration: to keep tax and accounting records, establish or defend legal claims, and comply with lawful requests. The bases are legal obligations (Article 6(1)(c)) and our legitimate interest in protecting our legal position (Article 6(1)(f)).

4. Processors and recipients

We disclose only the data needed for each service. We use the following processors and recipients:

  • ChemiCloud, for hosting the WordPress/WooCommerce booking website.
  • WordPress and WooCommerce, as the booking and order-management platform.
  • Stripe, for payment processing, payment fraud controls and transaction records. Stripe may also act as an independent controller where required by financial law.
  • Vercel, for hosting and delivering the main website.
  • Supabase, for database, storage and application services still used by the main website; it is not used for newsletter subscriptions.
  • Resend, for transmitting contact-form email.
  • Google Gmail/Google Workspace, for receiving and storing business email and contact messages.
  • Kit (formerly ConvertKit), for newsletter subscriptions and delivery.
  • Google, for Google Tag Manager and Google Analytics 4.
  • Cloudflare, for content delivery, website security and traffic analytics.
  • Professional advisers, courts, regulators, tax authorities or law-enforcement bodies only where necessary or legally required. We do not use an external accounting provider or bookkeeper.

5. International transfers

Some providers may process data outside the European Economic Area, including in the United States. Where no adequacy decision applies, we rely on the provider’s European Commission Standard Contractual Clauses and supplementary safeguards where required. Where applicable, a provider may instead rely on an adequacy mechanism such as the EU–US Data Privacy Framework. Provider locations and safeguards can change; current details are available from the providers and can be requested from us.

6. Retention

  • Booking and ordinary customer-service data are retained for two years after the booking or last relevant contact.
  • Contact-form messages and related mailbox correspondence are retained for two years after the last contact.
  • Financial records are retained in Stripe for seven years to meet tax and administration duties.
  • Kit retains newsletter data while you are subscribed. When you unsubscribe, the subscriber record is removed directly.
  • Analytics information is retained according to the configured Google Analytics 4 and Cloudflare retention settings and is deleted or aggregated when no longer necessary.
  • Security logs are retained only as long as reasonably necessary to protect and investigate the service. Data may be kept longer where required by law, a dispute, fraud investigation or the establishment, exercise or defence of legal claims.

7. Your rights

Subject to the GDPR conditions, you may request access, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. Email [email protected]. We may ask for information needed to verify your identity and normally respond within one month.

8. Complaints

You may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. We welcome the opportunity to address your concern first, but contacting us is not a condition for filing a complaint.

9. Changes to this policy

We may update this policy when our processing, providers or legal obligations change. We will publish the revised policy on this page, change the effective date and, where a change materially affects you, provide an appropriate additional notice. We will request fresh consent where required.

10. Cookies and similar technologies

Our Cookie Policy explains the cookies and analytics technologies we use and how to manage consent. Read our Cookie Policy.

Book Here – From €84.95 All-in