Privacy policy

Some company details on this page, such as name and address, will be added shortly.

We want to know as little about you as possible. This privacy policy explains what data we do process, why, how long we keep it and what your rights are.

The short version

  • We don't use tracking, analytics or advertising cookies, and we don't track you across other websites.
  • We only count visits as totals. We don't store your IP address when we do.
  • Your location stays on your own device, unless you choose to check in when you rate a place.
  • Your favourites are stored only in your own browser.
  • If you send us a message, we keep it for no more than 12 months.
  • We don't sell data and we don't work with ad networks that track you.

Who is responsible?

ibizamap.nl is published by (to be added shortly), (to be added shortly), registered with the Netherlands Chamber of Commerce (KvK) under number (to be added shortly). We are the controller under the General Data Protection Regulation (GDPR). For any privacy question, email (to be added shortly).

What we process and why

1. When you visit the site

To show you our pages, our hosting and security provider Cloudflare receives technical data about your connection, such as your IP address and details about your browser. Cloudflare uses this on our behalf to deliver the site and protect it against attacks and abuse.

  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR): a site that works and is secure.
  • What we store ourselves: no IP addresses. Only when you rate a place do we turn it into an unrecognisable code (see point 4).

2. Anonymous statistics

We want to know which pages are useful without following you around. We use three things for that:

  • Cloudflare Web Analytics. A small script measures which page is viewed and how fast it loads. In the totals we see, among other things, the country, the referring website, the device type, the browser and the operating system. According to Cloudflare, this service doesn't use cookies or localStorage and doesn't "fingerprint" visitors.
  • Counters on our own server. When a page is viewed, or an ad or partner link is clicked, we count the page or link, the date, the language and the country. We derive the country from the connection. We don't store the IP address itself, nor any browser details or cookie ID.
  • "Most saved". When you save a place as a favourite, we add +1 for that place. Nothing is sent along that would let us recognise you or your device.

So all we see are totals, such as "this page was viewed 120 times from Germany".

  • Legal basis: legitimate interests: improving the site and giving advertisers total audience figures.

3. Your location

On the map you can show your own position and look for places nearby. Your browser asks for your permission first. If you allow it, we use your location only on your own device, for example to calculate distances. Your location is not sent to us.

Exception: checking in when you rate a place. If you choose "check in on site" when rating a place, we send your location once. Our server works out whether you are close enough to the place (about 150 metres) and then discards the coordinates straight away. We keep only whether you were on site (yes or no) and the date.

  • Legal basis: legitimate interests: reliable ratings. Checking in is always optional.

4. When you rate a place

You can rate places from 1 to 5 stars without an account. We don't ask for your name or email address. To fight fake ratings and bots, we process:

  • the number of stars, the place, the date and, if you check in, whether you were on site;
  • a hashed code of your IP address: a code calculated with a secret key that cannot be turned back into your IP address. We replace that key every 30 days and destroy the old one. After that, nobody, including us, can link the code to an IP address;
  • a second code per place, also derived from your IP address and the place, which we keep for no more than 24 months. It tells us whether the same connection has rated that place before;
  • the network (internet provider) and country of the connection, so we can spot traffic from data centres, where many bots come from;
  • the result of an automatic bot check in your browser.

As long as we keep these codes, they count as pseudonymised personal data. Because we don't know your name, we usually can't link a rating to you if you ask to see or delete it (Art. 11 GDPR). Read more in our ratings policy.

  • Legal basis: legitimate interests: preventing fraud and abuse (see Recital 47 GDPR) and showing fair ratings.

5. When you send us a message

This covers the contact form, the form to advertise or claim your listing, and emails to (to be added shortly).

  • Data: your name, your business name (optional), your email address, your message and the time it was sent. If you claim a listing, also what you send us about your business, such as opening hours or photos.
  • Purpose: answering your question, discussing an ad or listing with you, and checking details about a place.
  • Legal basis: if it is about advertising or managing your listing, these are steps prior to entering into a contract (Art. 6(1)(b) GDPR). For other questions: legitimate interests, namely being able to reply to you.
  • Is it required? No. But without an email address we can't reply to you, and without your details we can't arrange an ad or listing with you.
  • Spam check: when you send the form, Cloudflare Turnstile checks that you are not a bot. To do so, Turnstile processes your IP address, a technical fingerprint of the secure connection (TLS) and your browser's identifier (User-Agent), among other things. Cloudflare also uses these signals as an independent controller to improve its bot detection. See the Turnstile privacy addendum.
  • Retention: no more than 12 months after we receive it. If you become an advertiser, we keep contract and invoice data for 7 years because Dutch tax law requires it (Art. 6(1)(c) GDPR).

6. When you report content or a rating

If you report illegal content or suspicious ratings through our reporting page, we process your report and, if you provide them, your name and email address. That lets us confirm receipt and tell you what we did with your report.

  • Legal basis: legal obligation (Art. 6(1)(c) GDPR, together with Art. 16 of the Digital Services Act).
  • Retention: 24 months after the report is closed, so we can check what was decided if questions or repeat reports come in.

7. Your favourites

Favourites are stored only in your own browser's storage (localStorage). They are not sent to us, apart from the anonymous count (see point 2). You can delete them at any time. More in our cookie policy.

8. If your business is listed on ibizamap

For places, we show business details such as the name, address, phone number, website and opening hours. We take them from open sources (see our imprint) or receive them from the business itself. For a sole trader, these can be personal data.

  • Purpose: giving visitors correct, up-to-date information about places.
  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
  • Corrections or objections: if something is wrong, or you don't want to be listed on ibizamap, email (to be added shortly).

Who else processes your data

We work with the following processors. We have a data processing agreement with each of them.

  • Processor: Cloudflare, Inc. · What for: hosting, security, statistics, bot checks, image storage, form notification emails, backups · Where: worldwide network; stored files in the EU
  • Processor: Neon (Neon, LLC, part of Databricks, Inc.) · What for: database, including form messages and ratings · Where: servers in Frankfurt (Germany)
  • Processor: Backblaze, Inc. · What for: encrypted backups · Where: data centre in Amsterdam

Our email provider (for emails you send us) and our accountant (advertiser data only) also receive data. If the law requires it, we pass data to the competent authorities. We never sell data.

Data outside the European Economic Area

Cloudflare, Neon and Backblaze are US companies. Our database is in Frankfurt and our backups are in Amsterdam, but these companies may also manage data from the United States, and Cloudflare's network is worldwide. All three are certified under the EU-U.S. Data Privacy Framework. Where needed, the European Commission's standard contractual clauses also apply.

How long we keep data

  • Data: Statistics · Retention: totals only, no personal data
  • Data: Hashed IP code for a rating · Retention: no longer traceable once the key is destroyed after 30 days
  • Data: Per-place code against duplicate ratings · Retention: no more than 24 months
  • Data: Location when checking in · Retention: not stored; only "on site yes/no" and the date
  • Data: Form messages and emails · Retention: no more than 12 months
  • Data: Advertiser contract and invoice data · Retention: 7 years (tax retention obligation)
  • Data: Reports · Retention: 24 months after closing

Backups. We make encrypted backups so we can restore the site after an outage or mistake. Data we have deleted may remain in them for up to 12 months, after which the backups expire. We use them only to restore the site. If deleted data comes back during a restore, we delete it again.

Security

All connections to the site are encrypted (HTTPS). Only people who need it for their work can access the admin area and messages, and that access is protected with a physical security key. Backups are encrypted. If something does go wrong, we follow the GDPR rules on data breaches, including notifying the Dutch Data Protection Authority where required.

AI and your data

We write and translate texts with the help of AI; see our editorial policy. We do not enter visitors' personal data, such as form messages, into AI tools.

Automated decisions

We don't make decisions based solely on automated processing that have legal effects for you or affect you in a similarly significant way. Our bot check can, however, automatically block a rating or put it on hold for a while. If you think that was a mistake, email us.

Your rights

You have the right to:

  • access your data (Art. 15 GDPR);
  • have incorrect data corrected (Art. 16 GDPR);
  • have your data erased (Art. 17 GDPR);
  • have processing restricted (Art. 18 GDPR);
  • receive data you provided yourself in a common format (Art. 20 GDPR);
  • object to processing based on legitimate interests (Art. 21 GDPR).

Send your request to (to be added shortly). We will reply within one month. If your request is complex or we receive many at once, we may extend this by two months; we'll tell you so within the first month, with the reason. Sometimes we may ask you to confirm your identity, so we don't give data to the wrong person.

Making a complaint

If you are unhappy with how we handle your data, please tell us and we'll look for a solution together. You can also complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in the country where you live or work. You can find it in the list of EU data protection authorities. The Dutch authority usually asks you to raise your complaint with us first.

Changes

If the way we work changes, we will update this policy. The date of the latest change is shown on this page.

This text was written with AI assistance and has not yet been reviewed by our editors. Editorial policy