TestedRoutes
GuidesDestinationsInspireAbout me

TestedRoutes Newsletter

Field-tested travel routes, in your inbox when they drop.

© 2026 TestedRoutes. All rights reserved.

ContactFAQLegalTermsPrivacyRefundsSecurityAffiliate disclosureSitemap

We independently review everything we recommend. When you buy through our links, we may earn a small commission at no extra cost to you. More on how this works.

ExploreGuidesDestinationsInspireAbout

Privacy Policy

Last updated: 16 August 2026

We collect as little personal data as we can while still running the site well. A cookie-consent banner controls everything non-essential: strictly necessary cookies work without consent, and every tool that sets a cookie or could identify you – all the analytics and marketing platforms listed below – fires only after you opt in. You can change or withdraw your choices at any time via the cookie settings on the site. The one thing outside that banner is anonymous, cookie-free counting of page views, purchase starts and QR scans, described under “Anonymous usage statistics” below; it holds nothing that could identify you.

1. Who is responsible for your data

The data controller for testedroutes.com is MB „Tested routes“ (operating as TestedRoutes), a Lithuanian small partnership (mažoji bendrija), company code 308073804. Full entity details (company code, registered address, VAT) are on our Legal Notice page. Privacy and data-protection contact: hello@testedroutes.com.

2. What we collect, and why

Newsletter signup

When you subscribe to our newsletter we collect your email address and, optionally, your preferred language and the part of the site you subscribed from (e.g. footer, top banner). We use this to send you the newsletter and to confirm your subscription via double opt-in. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.

Purchases

When you buy a guide, the transaction is processed by Polar Software Inc. as our Merchant of Record. At checkout Polar collects your email address, your payment details (card number, expiry, security code, cardholder name, or your Google Pay credentials), and your billing country. If you buy as a business, Polar additionally asks for your full billing address, business name, and (optionally) tax ID. Polar uses Stripe, Inc. as its payment processor for the card-handling step, and engages further sub-processors (hosting, email, invoicing, fraud monitoring) listed at polar.sh/legal/sub-processors. Details of Polar's processing are in Polar's Privacy Policy.

We (TestedRoutes) receive only the information needed to fulfil the order: typically the order ID, the product purchased, and your email address (so we can deliver the guide and respond to support questions). We do not receive your full payment-card data – Polar and Stripe handle that. Legal basis: performance of the contract for the digital guide (Art. 6(1)(b) GDPR).

Analytics

We use PostHog for product analytics and session replay: which pages and guides are viewed, which buttons are clicked, and anonymised recordings of how visitors move through the site (keystrokes and form inputs are masked by default and are not recorded). PostHog sets analytics cookies only after you opt in via the consent banner; without consent it does not run. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time via the cookie settings. Payment details are entered on our payment processor's own checkout pages and are never captured in analytics or session recordings.

Anonymous usage statistics

Separately from the above, we count a small number of events on our servers so we can tell how many people view a guide, how many go on to start a purchase, and which QR codes printed inside our guides get scanned. We record only the event itself, the guide it relates to, and your country – never your IP address, never a cookie, and never any identifier. Each event is stored with a random one-time value, so two events can never be connected to each other or to you, by us or by anyone else. Because the result is a count rather than information about a person, it is not personal data and it is not covered by the consent banner. Legal basis, to the extent any applies: our legitimate interest in knowing which guides are useful (Art. 6(1)(f) GDPR).

We also use Vercel Web Analytics for aggregate visitor counts. It is cookie-free and does not track visitors across sites or sessions.

Error tracking

We use Sentry to capture technical errors so we can fix bugs. Sentry is configured to not capture personal information, IP addresses, or cookies. Legal basis: legitimate interest in keeping the site secure and functional (Art. 6(1)(f) GDPR).

Strictly necessary cookies

We use a small number of strictly necessary cookies. These keep the site working and do not require your consent under EU ePrivacy / GDPR rules.

NamePurposeLifetimeType
tr_currencyRemembers the currency you've selected to view prices in (3-letter currency code, e.g. EUR).365 daysStrictly necessary

Once you opt in via the consent banner, additional cookies are set by the analytics and marketing tools listed below: PostHog analytics cookies (ph_*, up to 12 months), and marketing-pixel cookies such as Meta _fbp, Google _ga / _gcl_au, TikTok _ttp, Pinterest _pin_unauth, Reddit _rdt_uuid, and X muc_ads. The exact cookies per provider, with lifetimes, are listed in the consent banner settings.

Affiliate links

Some of the links in our guides and on the “Get the links free” pages are affiliate links: when you click and complete a purchase on the destination site (for example, a hotel booking, a tour, or a piece of gear) we earn a commission, at no extra cost to you. Affiliate links are how we keep guide prices low and keep ourselves independent.

We use affiliate platforms including, where relevant, Amazon Associates, Booking.com, GetYourGuide, Viator (CJ), Tiqets, SafetyWing, Skyscanner, Awin, and Impact.com. When you click an affiliate link, the destination site may set its own cookies on your device per its own privacy policy; we do not control those cookies and they are subject to the destination site's disclosures, not ours. Where we add tracking pixels for these platforms on testedroutes.com itself (for example, Awin's MasterTag for conversion tracking), they are listed in the cookie table above and gated behind your consent.

Marketing and advertising

We run paid marketing across Meta (Facebook, Instagram), Google Ads, YouTube, TikTok, Pinterest, Reddit, and X (Twitter). The corresponding tracking pixels on testedroutes.com set cookies on your device and share some browsing data (typically: pages viewed, products viewed, purchase events) with the relevant ad platform so we can measure campaign performance and show relevant ads on their platforms. None of these pixels fires before you opt in via the consent banner.

The platforms we use (each fires only after your consent):

PlatformStatusProvider privacy policy
Meta Pixel (Facebook, Instagram)Consent-gatedfacebook.com/privacy
Google Ads + Google Analytics 4Consent-gatedpolicies.google.com/privacy
YouTube (via Google Ads)Consent-gatedpolicies.google.com/privacy
TikTok PixelConsent-gatedtiktok.com/legal/privacy
Pinterest TagConsent-gatedpolicy.pinterest.com/privacy-policy
Reddit PixelConsent-gatedreddit.com/policies/privacy-policy
X (Twitter) PixelConsent-gatedtwitter.com/en/privacy

You can withdraw consent and disable any of these at any time via the cookie settings on the site; withdrawing stops the pixels immediately for future browsing.

The lawful basis for processing your data with these trackers is your consent (Art. 6(1)(a) GDPR for EU/EEA/UK visitors), given and withdrawable via the cookie settings.

3. Who we share your data with

We only share data with service providers who help us run the site. They process data on our behalf, under contracts that meet GDPR requirements:

  • •Vercel – hosting and content delivery for testedroutes.com, plus cookie-free aggregate visitor counts (Vercel Web Analytics).
  • •Sanity – content management for our guides and stories.
  • •Beehiiv – newsletter delivery.
  • •Polar Software Inc. – payment processing and merchant of record for purchases. Polar in turn engages Stripe, Inc. (US / Ireland) as their payment processor and additional sub-processors (hosting, invoicing, fraud monitoring) listed at polar.sh/legal/sub-processors.
  • •PostHog – product analytics and session replay (consent-gated), and the anonymous usage statistics described above.
  • •Sentry – technical error tracking with no personal data.
  • •Google Search Console – aggregate statistics on the Google searches our pages appear in. Google reports these to us already grouped and anonymised; we never see who searched.

Some of these providers are based in or transfer data to countries outside the European Economic Area (notably the United States). Where that's the case, transfers rely on the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework adequacy decision, as applicable.

4. How long we keep your data

  • •Newsletter subscribers: until you unsubscribe. You can unsubscribe at any time using the link in any newsletter email.
  • •Order records: kept for as long as required for accounting and tax purposes under Lithuanian law (typically 10 years).
  • •Analytics and session recordings: session recordings are retained for up to 90 days; analytics event data is retained for product-analytics purposes and deleted on request.
  • •Error logs: 90 days, our Sentry retention default.

5. Your rights

Under the GDPR you have the right to: access the personal data we hold about you, ask us to correct it if it's wrong, ask us to delete it, restrict or object to certain processing, and ask for a portable copy. To exercise any of these rights, use our contact form (select Privacy / data request as the topic) or email hello@testedroutes.com. We aim to respond within one month. Before acting on a deletion or access request, we may ask you to verify your identity (for example, by writing from the email address used at purchase) so that we do not delete or disclose data at the wrong person's request.

You also have the right to lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at vdai.lrv.lt. If you live in another EU country you can also complain to your local data protection authority.

6. Children

The site is not directed at children under 16, and we do not knowingly collect data from them.

7. Changes to this policy

If we change how we handle data – for example by adding a new analytics tool – we'll update this page and bump the “last updated” date. Material changes will be announced on the site or, where appropriate, by email.

8. Contact

Privacy questions: hello@testedroutes.com. See also our Terms of Service and Refund Policy.