Privacy Policy
Last updated: 16 July 2026
We collect as little personal data as we can while still running the site well. A cookie-consent banner controls everything non-essential: strictly necessary cookies work without consent, and every analytics or marketing tool listed below fires only after you opt in. You can change or withdraw your choices at any time via the cookie settings on the site.
1. Who is responsible for your data
The data controller for testedroutes.com is MB „Tested routes“ (operating as TestedRoutes), a Lithuanian small partnership (mažoji bendrija), company code 308073804. Full entity details (company code, registered address, VAT) are on our Legal Notice page. Privacy and data-protection contact: hello@testedroutes.com.
2. What we collect, and why
Newsletter signup
When you subscribe to our newsletter we collect your email address and, optionally, your preferred language and the part of the site you subscribed from (e.g. footer, top banner). We use this to send you the newsletter and to confirm your subscription via double opt-in. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.
Purchases
When you buy a guide, the transaction is processed by Polar Software Inc. as our Merchant of Record. At checkout Polar collects your email address, your payment details (card number, expiry, security code, cardholder name, or your Google Pay credentials), and your billing country. If you buy as a business, Polar additionally asks for your full billing address, business name, and (optionally) tax ID. Polar uses Stripe, Inc. as its payment processor for the card-handling step, and engages further sub-processors (hosting, email, invoicing, fraud monitoring) listed at polar.sh/legal/sub-processors. Details of Polar's processing are in Polar's Privacy Policy.
We (TestedRoutes) receive only the information needed to fulfil the order: typically the order ID, the product purchased, and your email address (so we can deliver the guide and respond to support questions). We do not receive your full payment-card data – Polar and Stripe handle that. Legal basis: performance of the contract for the digital guide (Art. 6(1)(b) GDPR).
Analytics
We use PostHog for product analytics and session replay: which pages and guides are viewed, which buttons are clicked, and anonymised recordings of how visitors move through the site (keystrokes and form inputs are masked by default and are not recorded). PostHog sets analytics cookies only after you opt in via the consent banner; without consent it does not run. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time via the cookie settings. Payment details are entered on our payment processor's own checkout pages and are never captured in analytics or session recordings.
Error tracking
We use Sentry to capture technical errors so we can fix bugs. Sentry is configured to not capture personal information, IP addresses, or cookies. Legal basis: legitimate interest in keeping the site secure and functional (Art. 6(1)(f) GDPR).
Strictly necessary cookies
We use a small number of strictly necessary cookies. These keep the site working and do not require your consent under EU ePrivacy / GDPR rules.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
tr_currency | Remembers the currency you've selected to view prices in (3-letter currency code, e.g. EUR). | 365 days | Strictly necessary |
Once you opt in via the consent banner, additional cookies are set by the analytics and marketing tools listed below: PostHog analytics cookies (ph_*, up to 12 months), and marketing-pixel cookies such as Meta _fbp, Google _ga / _gcl_au, TikTok _ttp, Pinterest _pin_unauth, Reddit _rdt_uuid, and X muc_ads. The exact cookies per provider, with lifetimes, are listed in the consent banner settings.
Affiliate links
Some of the links in our guides and on the “Get the links free” pages are affiliate links: when you click and complete a purchase on the destination site (for example, a hotel booking, a tour, or a piece of gear) we earn a commission, at no extra cost to you. Affiliate links are how we keep guide prices low and keep ourselves independent.
We use affiliate platforms including, where relevant, Amazon Associates, Booking.com, GetYourGuide, Viator (CJ), Tiqets, SafetyWing, Skyscanner, Awin, and Impact.com. When you click an affiliate link, the destination site may set its own cookies on your device per its own privacy policy; we do not control those cookies and they are subject to the destination site's disclosures, not ours. Where we add tracking pixels for these platforms on testedroutes.com itself (for example, Awin's MasterTag for conversion tracking), they are listed in the cookie table above and gated behind your consent.
Marketing and advertising
We run paid marketing across Meta (Facebook, Instagram), Google Ads, YouTube, TikTok, Pinterest, Reddit, and X (Twitter). The corresponding tracking pixels on testedroutes.com set cookies on your device and share some browsing data (typically: pages viewed, products viewed, purchase events) with the relevant ad platform so we can measure campaign performance and show relevant ads on their platforms. None of these pixels fires before you opt in via the consent banner.
The platforms we use (each fires only after your consent):
| Platform | Status | Provider privacy policy |
|---|---|---|
| Meta Pixel (Facebook, Instagram) | Consent-gated | facebook.com/privacy |
| Google Ads + Google Analytics 4 | Consent-gated | policies.google.com/privacy |
| YouTube (via Google Ads) | Consent-gated | policies.google.com/privacy |
| TikTok Pixel | Consent-gated | tiktok.com/legal/privacy |
| Pinterest Tag | Consent-gated | policy.pinterest.com/privacy-policy |
| Reddit Pixel | Consent-gated | reddit.com/policies/privacy-policy |
| X (Twitter) Pixel | Consent-gated | twitter.com/en/privacy |
You can withdraw consent and disable any of these at any time via the cookie settings on the site; withdrawing stops the pixels immediately for future browsing.
The lawful basis for processing your data with these trackers is your consent (Art. 6(1)(a) GDPR for EU/EEA/UK visitors), given and withdrawable via the cookie settings.
3. Who we share your data with
We only share data with service providers who help us run the site. They process data on our behalf, under contracts that meet GDPR requirements:
- •Vercel – hosting and content delivery for testedroutes.com.
- •Sanity – content management for our guides and stories.
- •Beehiiv – newsletter delivery.
- •Polar Software Inc. – payment processing and merchant of record for purchases. Polar in turn engages Stripe, Inc. (US / Ireland) as their payment processor and additional sub-processors (hosting, invoicing, fraud monitoring) listed at polar.sh/legal/sub-processors.
- •PostHog – product analytics and session replay (consent-gated).
- •Sentry – technical error tracking with no personal data.
Some of these providers are based in or transfer data to countries outside the European Economic Area (notably the United States). Where that's the case, transfers rely on the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework adequacy decision, as applicable.
4. How long we keep your data
- •Newsletter subscribers: until you unsubscribe. You can unsubscribe at any time using the link in any newsletter email.
- •Order records: kept for as long as required for accounting and tax purposes under Lithuanian law (typically 10 years).
- •Analytics and session recordings: session recordings are retained for up to 90 days; analytics event data is retained for product-analytics purposes and deleted on request.
- •Error logs: 90 days, our Sentry retention default.
5. Your rights
Under the GDPR you have the right to: access the personal data we hold about you, ask us to correct it if it's wrong, ask us to delete it, restrict or object to certain processing, and ask for a portable copy. To exercise any of these rights, use our contact form (select Privacy / data request as the topic) or email hello@testedroutes.com. We aim to respond within one month. Before acting on a deletion or access request, we may ask you to verify your identity (for example, by writing from the email address used at purchase) so that we do not delete or disclose data at the wrong person's request.
You also have the right to lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at vdai.lrv.lt. If you live in another EU country you can also complain to your local data protection authority.
6. Children
The site is not directed at children under 16, and we do not knowingly collect data from them.
7. Changes to this policy
If we change how we handle data – for example by adding a new analytics tool – we'll update this page and bump the “last updated” date. Material changes will be announced on the site or, where appropriate, by email.
8. Contact
Privacy questions: hello@testedroutes.com. See also our Terms of Service and Refund Policy.