Laster Artic Safari…
Laster Artic Safari…
Legal
This explains what we collect when you book a tour or a transfer with us, why we need it, who else sees it, and how to get it deleted. It describes what our booking system actually does — not a generic template.
Last updated
Artic Safari operates articsafaritour.com and the Artic Safari mobile app, running private Northern Lights tours and VIP transfers in Tromsø, Norway. We are the data controller for the information described here.
We only ask for what a trip actually requires. There is no advertising profile, no data broker, and nothing is sold.
To identify your booking, confirm it with you, and reach you if the pickup or the weather changes.
So the driver can find you and the fare can be calculated by distance.
To place your pickup pin exactly, so a driver is not searching a street for you at night.
So you can sign in and see your own bookings, reward points and trip photos.
To calculate the balance you can spend on a booking.
So we can share them with you afterwards.
To show prospective guests real feedback.
So you can see the car approaching.
Sharing your live location is always optional. Nothing on this site or in the app asks your device for a position unless you press the “Use my location” button, and your browser or phone will ask your permission on top of that. Typing an address instead works exactly as well.
If you do share it, we use it once — to place your pickup pin so a driver is not circling a street looking for you. You can clear the field before submitting, and the pickup point can be corrected afterwards.
During a trip, the driver’s position may be shown to you so you can see the car approaching. That is the driver’s location, not yours, and only one current position is stored per booking — it is not a movement history.
We use a small number of established services to run the site. Two of them are worth distinguishing: some are contacted directly by your browser, which means they see your IP address, while others are only ever contacted by our server on your behalf, which means they do not.
Database, sign-in, and file storage. Holds everything in the table above.
Their privacy policyHosts the website, and provides its visitor statistics. The statistics are cookieless and do not identify you or follow you to other sites.
Their privacy policySupplies the map images shown once you select an address. Loading a map image reveals your IP address to them.
Their privacy policyTurns the address you type into coordinates. Our server asks on your behalf, so they receive the search text but not your IP address.
Their privacy policyCalculates the driving distance between two addresses for the fare estimate. Our server sends the two addresses only. Used only when that feature is switched on.
Their privacy policyDelivers booking messages when you contact us or we confirm a trip. Used only when that feature is switched on.
Their privacy policySends transactional email such as booking confirmations. Used only when that feature is switched on.
Their privacy policyOur drivers see the name, phone number and pickup address for the trips they are assigned — nothing more, and it is the database that enforces that limit, not just the app screen.
Under the GDPR you have the following rights, and exercising them is free. Email privacy@articsafaritour.com or message us on WhatsApp, and we will respond within one month.
One thing worth being straight about: when you ask us to delete your data, we cannot erase the financial record of a trip you already took. Norwegian bookkeeping law requires us to keep transaction documentation for five years. What we do instead is strip your name, email, phone and address from that record, leaving an anonymous entry that satisfies the accountant without identifying you.
Access rules are enforced inside the database itself rather than by the app hiding buttons. Signed in as a guest, you can only ever read rows that match your own email address; a driver can only read the jobs assigned to them or still unclaimed. If somebody bypassed our website entirely and queried the database directly, those limits would still hold.
Passwords are never stored — our authentication provider keeps only a one-way hash that we cannot read or reverse. All traffic is encrypted in transit.
We do not process card payments on this site. Bookings are recorded as requests and confirmed with you directly, so no card details are ever entered here.
Our booking system is intended for adults. We do not knowingly collect data from anyone under 16. Children are welcome on our tours as part of a family booking made by a parent or guardian, whose details are the ones we hold.
Contact us first — most things are a misunderstanding we can fix quickly. If you are still dissatisfied, you have the right to lodge a complaint with Datatilsynet (Norwegian Data Protection Authority).
If we add a feature that changes what we collect, we update this page and the date at the top. Material changes affecting existing bookings will be emailed to the address on the booking.