Privacy
What we do with your data.
The short version: we store an email address if you ask for alerts, we count visits only if you say yes, Google advertising is controlled by your consent choice, and we never sell or rent your details. The long version is below.
- Required cookies
- 1
- Analytics
- Only with consent
- Ad consent
- Your choice
Who is responsible
Michael MüllerMaybachstraße 17
70469 Stuttgart
Germany
Email: hello@vollarie.com · Legal notice
Vollarie is a sole proprietorship. We are not required to appoint a data protection officer.
What we collect, why, and for how long
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Server logs — IP address, time, page requested, browser, referring page | Delivering the site; spotting overload and attacks | Legitimate interest, Art. 6(1)(f) GDPR | 30 days, then deleted or anonymised |
| Email address plus your chosen departure regions, display currency and which trip ranges you want | Sending the deal alerts you signed up for | Consent, Art. 6(1)(a) GDPR | Until you unsubscribe |
| Consent record after unsubscribing — email address, consent-text version, confirmation time and withdrawal time | Proving consent existed, if ever disputed | Legitimate interest, Art. 6(1)(f) GDPR | 3 years after you unsubscribe, then deleted |
| Suppression list — addresses that bounced or reported spam | Making sure we never email you again | Legitimate interest, Art. 6(1)(f) GDPR | Indefinitely, for that purpose only |
| Your emails to us | Answering you | Art. 6(1)(b), (c) and (f) GDPR, depending on the request | 6 months after the matter is closed. Correspondence that becomes a business or tax record is kept for the applicable statutory period. |
| Request counters — IP and email address, held in memory only | Blocking automated sign-up abuse | Legitimate interest, Art. 6(1)(f) GDPR | Not stored; lost on restart |
Providing any of this is voluntary. Without an email address we cannot send you alerts; nothing else on the site requires you to give us anything.
We do not profile you, and no decision affecting you is made automatically.
Deal alerts by email
Double opt-in
Enter your address and we ask Resend to send you a confirmation email. We do not create a subscription in our database until you click the signed, time-limited link. Before then, your address and choices are carried in that link, while Resend necessarily receives the address, message and delivery metadata in order to send it. This stops anyone signing up an address that isn't theirs.
No open or click tracking
Our emails contain no tracking pixels and no redirect links. We do not know whether you opened an email or what you clicked. They can contain destination photographs and airline logos loaded from the image providers in section 5. If your email app loads those images, it sends normal request data such as your IP address and device information to that image provider; the image URLs are not unique to you and do not tell Vollarie that you opened the message.
Delivery events
Resend processes the recipient address, email content and ordinary delivery metadata. It tells us when a message bounced, was marked as spam, or was blocked. We record the address, event type and event ID in our suppression list so we stop emailing you. Open and click tracking are disabled in our Resend configuration.
Unsubscribing
Every email has an unsubscribe link. Or write to hello@vollarie.com. Unsubscribing immediately removes your active subscriptions, preferences and sent-alert history. We retain only the consent record described in section 2 for three years, plus a suppression entry if one is needed to ensure no further mail is sent.
Third parties contacted by pages and emails
Loading a page — or allowing your email app to load remote images — can fetch content directly from other companies. The request normally includes your IP address, browser or mail-app information, and the referring page where supplied. We do not add a subscriber identifier to these image requests.
| Who | What for | Where | Basis |
|---|---|---|---|
| Unsplash Inc., Calgary, Canada | Destination photographs on deal pages and in deal emails | Canada — EU adequacy decision | Legitimate interest, Art. 6(1)(f) |
| Brandfetch SA, Savigny, Switzerland | Airline logos on deal pages and in deal emails | Switzerland — EU adequacy decision | Legitimate interest, Art. 6(1)(f) |
| Kiwi.com s.r.o., Brno, Czech Republic | Airline logos on deal pages and in deal emails, where Brandfetch has none | EU | Legitimate interest, Art. 6(1)(f) |
| Google Ireland Limited, Dublin, Ireland, and Google LLC, United States | Consent management and, when enabled, serving and measuring AdSense ads | EU, United States and Google's global infrastructure | Consent for optional storage and personalisation, Art. 6(1)(a) GDPR and § 25(1) TDDDG |
| Amplitude, Inc., San Francisco, United States | Counting visits, once you have agreed to it | EU data centre, under an Art. 28 GDPR processing agreement | Consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG |
Travelpayouts (eSIM widget, served from tpemd.com) | Prepaid eSIM offers for your destination, supplied by Airalo | See section 7 | Consent, Art. 6(1)(a) and § 25(1) TDDDG |
The eSIM widget does not load on its own. You first see only a notice and a button. Nothing reaches the provider until you press it, and your agreement applies to that page only: open a different destination and we ask again.
Fonts are served from our own servers. Opening our pages makes no connection to Google Fonts or any other font host.
Where your data is processed
| Provider | Role | Location |
|---|---|---|
| Railway Corporation, United States | Hosting the site and its API | Amsterdam, Netherlands; possible support access from the US |
| Supabase Pte. Ltd., Singapore | Database holding subscriber addresses | Ireland; possible support access from outside the EU |
| Plus Five Five, Inc. (trading as Resend), United States | Sending our emails | United States |
| IONOS SE, Germany | Receiving and storing messages sent to hello@vollarie.com, and domain services | European Union |
| Cloudflare, Inc., United States | DNS, network security and redirecting the bare domain to www.vollarie.com | Global network, including the EU and United States |
These providers process data for us under Art. 28 GDPR and the relevant data-processing terms. Railway and Supabase store the application data in the EU, although their staff may access it from elsewhere. Resend stores account and delivery data in the United States. Cloudflare operates a global network. Where the EU–US Data Privacy Framework applies, the relevant US provider relies on its certification under the EU–US Data Privacy Framework. Where it does not apply, the providers' agreements use the European Commission's standard contractual clauses or another legally recognised safeguard.
Apart from the providers and third parties described above, we disclose data only where the law requires it. We do not sell or rent address data.
Our price monitoring queries public sources and pricing APIs. No user data is involved: those requests happen on our servers and carry nothing about you.
Affiliate links
Vollarie is free and is funded by commission. When you follow a booking link or use the eSIM widget and then buy something, we may earn a commission. You pay no more because of it.
For that to work, the partner network — Travelpayouts, which also operates Aviasales — must recognise that you arrived from us. Our links therefore carry a partner ID, and following one passes your IP address, the page you came from and that ID to the partner, who may also store data in your browser.
Commission-bearing booking buttons are labelled next to the button and use the technical rel="sponsored" marker. Direct booking links that pay us nothing are not labelled as affiliate links. We never learn who booked what: partner networks report totals to us, never individuals. Once you follow the link, that company is responsible for your data under its own privacy policy — Travelpayouts.
Your rights
You can ask us to give you a copy of your data (Art. 15), correct it (Art. 16), delete it (Art. 17), restrict how we use it (Art. 18), or hand it over in a portable format (Art. 20). You can object to processing based on legitimate interests (Art. 21), and you can always object to direct marketing, with no reason needed. Where we rely on consent you can withdraw it at any time (Art. 7(3)), which does not affect what we did before.
Email hello@vollarie.com. We answer within one month.
You may also complain to a supervisory authority. Ours is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart — lfdi.baden-wuerttemberg.de.
Security
All connections use TLS. Database access is restricted, private links are signed and scoped to the action they encode, sign-up endpoints are rate-limited, and credentials are held outside the source code (Art. 32 GDPR).
Last updated 5 September 2026. Anything here unclear? Write to hello@vollarie.com and we will explain it properly, and probably rewrite the clause.