Last updated: 16 August 2026
We collect as little personal data as we can while still running the site well. A cookie-consent banner controls everything non-essential: strictly necessary cookies work without consent, and every tool that sets a cookie or could identify you – all the analytics and marketing platforms listed below – fires only after you opt in. You can change or withdraw your choices at any time via the cookie settings on the site. The one thing outside that banner is anonymous, cookie-free counting of page views, purchase starts and QR scans, described under “Anonymous usage statistics” below; it holds nothing that could identify you.
The data controller for testedroutes.com is MB „Tested routes“ (operating as TestedRoutes), a Lithuanian small partnership (mažoji bendrija), company code 308073804. Full entity details (company code, registered address, VAT) are on our Legal Notice page. Privacy and data-protection contact: hello@testedroutes.com.
When you subscribe to our newsletter we collect your email address and, optionally, your preferred language and the part of the site you subscribed from (e.g. footer, top banner). We use this to send you the newsletter and to confirm your subscription via double opt-in. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.
When you buy a guide, the transaction is processed by Polar Software Inc. as our Merchant of Record. At checkout Polar collects your email address, your payment details (card number, expiry, security code, cardholder name, or your Google Pay credentials), and your billing country. If you buy as a business, Polar additionally asks for your full billing address, business name, and (optionally) tax ID. Polar uses Stripe, Inc. as its payment processor for the card-handling step, and engages further sub-processors (hosting, email, invoicing, fraud monitoring) listed at polar.sh/legal/sub-processors. Details of Polar's processing are in Polar's Privacy Policy.
We (TestedRoutes) receive only the information needed to fulfil the order: typically the order ID, the product purchased, and your email address (so we can deliver the guide and respond to support questions). We do not receive your full payment-card data – Polar and Stripe handle that. Legal basis: performance of the contract for the digital guide (Art. 6(1)(b) GDPR).
We use PostHog for product analytics and session replay: which pages and guides are viewed, which buttons are clicked, and anonymised recordings of how visitors move through the site (keystrokes and form inputs are masked by default and are not recorded). PostHog sets analytics cookies only after you opt in via the consent banner; without consent it does not run. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time via the cookie settings. Payment details are entered on our payment processor's own checkout pages and are never captured in analytics or session recordings.
Separately from the above, we count a small number of events on our servers so we can tell how many people view a guide, how many go on to start a purchase, and which QR codes printed inside our guides get scanned. We record only the event itself, the guide it relates to, and your country – never your IP address, never a cookie, and never any identifier. Each event is stored with a random one-time value, so two events can never be connected to each other or to you, by us or by anyone else. Because the result is a count rather than information about a person, it is not personal data and it is not covered by the consent banner. Legal basis, to the extent any applies: our legitimate interest in knowing which guides are useful (Art. 6(1)(f) GDPR).
We also use Vercel Web Analytics for aggregate visitor counts. It is cookie-free and does not track visitors across sites or sessions.
We use Sentry to capture technical errors so we can fix bugs. Sentry is configured to not capture personal information, IP addresses, or cookies. Legal basis: legitimate interest in keeping the site secure and functional (Art. 6(1)(f) GDPR).
We use a small number of strictly necessary cookies. These keep the site working and do not require your consent under EU ePrivacy / GDPR rules.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
tr_currency | Remembers the currency you've selected to view prices in (3-letter currency code, e.g. EUR). | 365 days | Strictly necessary |
Once you opt in via the consent banner, additional cookies are set by the analytics and marketing tools listed below: PostHog analytics cookies (ph_*, up to 12 months), and marketing-pixel cookies such as Meta _fbp, Google _ga / _gcl_au, TikTok _ttp, Pinterest _pin_unauth, Reddit _rdt_uuid, and X muc_ads. The exact cookies per provider, with lifetimes, are listed in the consent banner settings.
Some of the links in our guides and on the “Get the links free” pages are affiliate links: when you click and complete a purchase on the destination site (for example, a hotel booking, a tour, or a piece of gear) we earn a commission, at no extra cost to you. Affiliate links are how we keep guide prices low and keep ourselves independent.
We use affiliate platforms including, where relevant, Amazon Associates, Booking.com, GetYourGuide, Viator (CJ), Tiqets, SafetyWing, Skyscanner, Awin, and Impact.com. When you click an affiliate link, the destination site may set its own cookies on your device per its own privacy policy; we do not control those cookies and they are subject to the destination site's disclosures, not ours. Where we add tracking pixels for these platforms on testedroutes.com itself (for example, Awin's MasterTag for conversion tracking), they are listed in the cookie table above and gated behind your consent.
We run paid marketing across Meta (Facebook, Instagram), Google Ads, YouTube, TikTok, Pinterest, Reddit, and X (Twitter). The corresponding tracking pixels on testedroutes.com set cookies on your device and share some browsing data (typically: pages viewed, products viewed, purchase events) with the relevant ad platform so we can measure campaign performance and show relevant ads on their platforms. None of these pixels fires before you opt in via the consent banner.
The platforms we use (each fires only after your consent):
| Platform | Status | Provider privacy policy |
|---|---|---|
| Meta Pixel (Facebook, Instagram) | Consent-gated | facebook.com/privacy |
| Google Ads + Google Analytics 4 | Consent-gated | policies.google.com/privacy |
| YouTube (via Google Ads) | Consent-gated | policies.google.com/privacy |
| TikTok Pixel | Consent-gated | tiktok.com/legal/privacy |
| Pinterest Tag | Consent-gated | policy.pinterest.com/privacy-policy |
| Reddit Pixel | Consent-gated | reddit.com/policies/privacy-policy |
| X (Twitter) Pixel | Consent-gated | twitter.com/en/privacy |
You can withdraw consent and disable any of these at any time via the cookie settings on the site; withdrawing stops the pixels immediately for future browsing.
The lawful basis for processing your data with these trackers is your consent (Art. 6(1)(a) GDPR for EU/EEA/UK visitors), given and withdrawable via the cookie settings.
We only share data with service providers who help us run the site. They process data on our behalf, under contracts that meet GDPR requirements:
Some of these providers are based in or transfer data to countries outside the European Economic Area (notably the United States). Where that's the case, transfers rely on the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework adequacy decision, as applicable.
Under the GDPR you have the right to: access the personal data we hold about you, ask us to correct it if it's wrong, ask us to delete it, restrict or object to certain processing, and ask for a portable copy. To exercise any of these rights, use our contact form (select Privacy / data request as the topic) or email hello@testedroutes.com. We aim to respond within one month. Before acting on a deletion or access request, we may ask you to verify your identity (for example, by writing from the email address used at purchase) so that we do not delete or disclose data at the wrong person's request.
You also have the right to lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at vdai.lrv.lt. If you live in another EU country you can also complain to your local data protection authority.
The site is not directed at children under 16, and we do not knowingly collect data from them.
If we change how we handle data – for example by adding a new analytics tool – we'll update this page and bump the “last updated” date. Material changes will be announced on the site or, where appropriate, by email.
Privacy questions: hello@testedroutes.com. See also our Terms of Service and Refund Policy.