Privacy Policy

Last updated: 18 July 2026

Protecting your personal data is important to us. We process your data exclusively on the basis of the applicable legal provisions (GDPR, the Austrian Data Protection Act and the Telecommunications Act 2021). In this privacy policy we inform you about the key aspects of data processing within our website and services.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

FashionTouri e.U.
Owner: Mag. Ronja Svenja Scherzinger
Alserbachstraße 26/42
1090 Vienna, Austria
E-mail: office@fashiontouri.com
Phone: +43 660 7720150

If you have any questions about data protection, you can contact us directly at any time.

2. Your rights

With regard to the personal data concerning you, you generally have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw a given consent (Art. 7(3) GDPR) with effect for the future

If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you can lodge a complaint with the supervisory authority. In Austria this is the Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna
E-mail: dsb@dsb.gv.at · Web: www.dsb.gv.at

3. Visiting our website (server log files & hosting)

When you access our website, your browser automatically transmits information to our website's server and temporarily stores it in log files. This includes in particular: the IP address of the requesting device, the date and time of access, the page/file accessed, the browser and operating system used, and the referrer URL.

Purpose: ensuring a smooth connection, convenient use, evaluation of system security and stability, and administrative purposes.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation).
Retention period: server log files are stored for a maximum of 14 days and then automatically deleted; longer storage only occurs in the event of security-relevant incidents until they are resolved.

Hosting: Our website and services are operated at Hostinger International Ltd. (61 Lordou Vironos Street, 6023 Larnaca, Cyprus). The hosting provider processes the aforementioned data on our behalf as a processor (Art. 28 GDPR). The servers are located in a data centre in Frankfurt am Main, Germany (European Union).

4. Cookies and consent

We use cookies or comparable technologies (e.g. local storage) on our website. Cookies are small text files stored on your device. We distinguish between technically necessary and consent-based services.

4.1 Technically necessary cookies

These are strictly required for the operation of the website and are set without consent. They include in particular the session cookie (login), the CSRF token (protection against cross-site request forgery), the storage of your language selection, and the storage of your cookie decision itself (local storage entry ft_consent_v1).
Legal basis: Section 165(3) of the Austrian Telecommunications Act 2021 (technically necessary) in conjunction with Art. 6(1)(f) GDPR.
Retention period: session cookies are deleted at the end of the session; your cookie decision remains stored until you withdraw or delete it.

4.2 Consent-based external services

External services (in particular Google Maps, see section 7, and embedded content, see section 10) are only loaded after you have selected "Accept all" in the cookie banner. Without your consent, no data is transmitted to these providers.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 165(3) of the Telecommunications Act 2021.

Your consent is voluntary and can be withdrawn or changed at any time with effect for the future via the "Cookie settings" button (bottom left on every page). We do not use any cookies for third-party advertising, tracking or reach-measurement purposes (no Google Analytics, no Facebook/Meta pixel, no other tracking pixels).

5. Registration and user account

To use certain features you can create a user account. In doing so we process the data you provide (e.g. name, e-mail address, password in encrypted form, profile details).
Purpose: provision and management of your account, authentication, use of the platform's personalised features.
Legal basis: Art. 6(1)(b) GDPR (performance of the usage relationship).
Retention period: for the duration of your account. After deletion of the account, the data is erased unless statutory retention obligations apply.

6. Business registration and payment processing (Stripe)

If you register a business or store listing with a paid or booked plan, we process the payment via the payment service provider Stripe. The provider for users in the EEA is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

The payment data entered during the payment process (e.g. card details) is processed exclusively by Stripe; we ourselves do not receive or store complete payment data, only transaction and status information to assign your booking.
Purpose: processing of the paid service you have commissioned.
Legal basis: Art. 6(1)(b) GDPR (performance of contract); for the retention of invoice data Art. 6(1)(c) GDPR (legal obligation).
Retention period: invoice and booking data is retained in accordance with tax and fiscal retention periods (in Austria generally 7 years pursuant to Section 132 of the Federal Fiscal Code / BAO).
Third-country transfer: insofar as Stripe transfers data to Stripe, Inc. (USA), this is based on the EU standard contractual clauses or a valid adequacy decision (EU-US Data Privacy Framework). Details: https://stripe.com/at/privacy

7. Google Maps and address search (Places)

To display maps and for the address search (autocomplete) we use Google Maps including the Places function. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Maps is only loaded after your explicit consent ("Accept all" in the cookie banner). Without consent, no connection to Google is established; a notice is shown instead of the map. When the map is active, Google may in particular process your IP address and usage data.
Purpose: display of locations on an interactive map, address and location search.
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention period: processing by Google is governed by Google's specifications; the consent remains valid until withdrawn.
Third-country transfer: a transfer to Google LLC (USA) may occur; this is safeguarded by the EU standard contractual clauses or the EU-US Data Privacy Framework. Details: https://policies.google.com/privacy

8. AI concierge "Kiki" (Mistral AI)

On our platform we offer "Kiki", an AI-based concierge/chatbot that answers your questions and supports you in using the service. When you actively use Kiki and enter a message, the content of your request is processed to generate a response.

For language processing (generating the responses) we use the AI model of the provider Mistral AI SAS, 15 rue des Halles, 75001 Paris, France. Your inputs are transmitted to Mistral AI for this purpose. Mistral AI is a European provider with its registered office and data processing in the EU; no transfer to a third country outside the EEA takes place for this. In addition, "Zero Data Retention" is enabled for our organisation at Mistral: your inputs and the generated responses are processed by Mistral solely to generate the response and are not stored beyond that. This data is also not used to train the AI models.

Please do not enter any sensitive personal data (e.g. health, financial or ID data) in the chat, as this is not required to answer your query.
Purpose: provision of an interactive information and support service.
Legal basis: Art. 6(1)(b) GDPR (provision of the function you requested) or Art. 6(1)(f) GDPR (legitimate interest in a service-oriented information offering).
Retention period: at Mistral, due to the enabled Zero Data Retention, no storage takes place beyond generating the response. On our side, chat content is processed to answer your query and is not stored permanently; for operational and security purposes, technical usage data (e.g. time and scope of use) may be logged.
Further information: https://legal.mistral.ai/terms/privacy-policy

9. E-mail delivery (Brevo)

For sending transactional and process e-mails (e.g. registration, confirmation and status messages) we use the service Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France). The data required for delivery (in particular your e-mail address and the message content) is transmitted to Brevo.
Purpose: reliable dispatch of system- and process-related e-mails.
Legal basis: Art. 6(1)(b) GDPR (contractual or usage relationship) and Art. 6(1)(f) GDPR (legitimate interest in reliable mail delivery).
Retention period: dispatch and delivery information is stored only for as long as required for the operation and traceability of delivery. Brevo processes the data within the EU.

10. Embedded content / external media

On individual pages (e.g. in blog or place posts) external content may be embedded, such as videos from YouTube (Google Ireland Limited) or YouTube-nocookie, Vimeo (Vimeo Inc.) or content from Instagram (Meta Platforms Ireland Limited). This content is only loaded after your consent; without consent a placeholder appears in its place and no data is transmitted to the providers.
Purpose: display of embedded media content.
Legal basis: Art. 6(1)(a) GDPR (consent).
Third-country transfer: when embeds are activated, a transfer to providers in the USA may occur, safeguarded by the EU standard contractual clauses or the EU-US Data Privacy Framework.

11. Mobile app and push notifications

If you use our mobile app, the above information applies accordingly. If you wish to receive push notifications, your explicit consent on the device is required. For delivery, an anonymous device identifier (push token) is processed via the push service of the respective platform operator or via the Expo service (Expo/EAS).
Purpose: delivery of the notifications you have requested.
Legal basis: Art. 6(1)(a) GDPR (consent). You can deactivate receipt at any time in your device settings.

12. Contacting us

If you contact us by e-mail or contact form, your details are processed to handle the request.
Legal basis: Art. 6(1)(b) GDPR (for contract-related enquiries) or Art. 6(1)(f) GDPR (legitimate interest in responding).
Retention period: until your enquiry has been fully processed, unless statutory retention obligations exist.

13. Data security

We use appropriate technical and organisational measures to protect your data against manipulation, loss or unauthorised access. The transmission between your browser and our server is encrypted via TLS/SSL (recognisable by "https" and the padlock symbol in the address bar).

14. Changes to this privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The version in force at the time then applies to your next visit.