FairFareFinder GmbH Legal & Privacy

Privacy Policy

Last updated: 19 August 2026  |  Applies to: FairFareFinder.com, HotWeekends.com, MeetOnArrival.com

Short version: We run server-side request logging with no raw IP addresses stored, no advertising cookies, and no user accounts. Google Analytics is available opt-in only. The full details follow.

1. Controller

The data controller responsible for all processing described in this policy is:

FairFareFinder GmbH
Kolonnenstraße 8, 10827 Berlin, Germany
HRB 283854 B, Amtsgericht Charlottenburg
Email: [email protected]

We operate three websites — FairFareFinder.com, HotWeekends.com, and MeetOnArrival.com — from a shared technical platform. This policy covers all three.

2. What we collect and why

2.1 Server-side request analytics Art. 6(1)(f) GDPR

When you visit any of our sites, our servers automatically record certain technical information about each request. Our legitimate interest in this processing is operating and improving a free travel discovery service, detecting abusive automated traffic, and measuring affiliate performance (GDPR Art. 6(1)(f)).

We do not store your IP address. We derive a pseudonymous session identifier from the first three octets of your IP (the /24 network prefix), your browser family, and the current one-hour time window. This identifier is used to group requests into browsing sessions. It is not directly linked to you as an individual, changes every hour, and is deleted after 14 days. It remains pseudonymous personal data and is treated as such under GDPR.

Data element What it contains Retained for
Session identifier Pseudonymous identifier derived from partial IP prefix + browser family + hour. No raw IP stored. 14 days
Timestamp Time of the request (unix seconds) 14 days
URL path The page or endpoint visited 14 days
Query fingerprint A pseudonymous fingerprint of filter parameters used — not the values themselves 14 days
Origin city Departure city selected by you in the search form (e.g. "Berlin") 14 days
HTTP status code Whether the request succeeded, returned an error, etc. 14 days
Response time How long the server took to respond 14 days
Browser family Broad category only: Chrome, Firefox, Safari, Bot, etc. Not the full User-Agent string. 14 days
Device type Mobile or desktop (derived from User-Agent) 14 days
Interaction flags Boolean flags: did this request involve a modal, an affiliate link click, or a filter change? 14 days

After 14 days, individual session records are aggregated into statistical summaries and permanently deleted. Cells with fewer than five sessions are suppressed and never written to the aggregate, to avoid singling out individuals in sparse time windows. The aggregate data that remains contains no session identifier, no origin city sequence, and no path sequence — it is aggregated statistics intended to be anonymous.

Legitimate interest assessment summary: The privacy impact of this processing is minimal: no raw IP is stored, the session identifier is pseudonymous and not designed to reveal the original inputs, data is automatically deleted after 14 days, and no profiling of individuals takes place. We consider this processing proportionate and unlikely to override the interests or fundamental rights of visitors.

2.2 First-party cookies TDDDG §25(2)

We set four first-party cookies. All contain only values you have actively configured or that are necessary to record your own decisions. None contain tracking identifiers and none are shared with any third party for marketing purposes. Where a cookie offers a user-controlled retention period, the duration defaults to session-only unless you choose otherwise in Settings.

Cookie name Purpose Duration
fff-consent Records your cookie preference choices (analytics: yes/no) and the timestamp of your last decision. Necessary to honour your preferences across page loads. 6 months
fff-user-preferences Stores display preferences you have configured: currency, language, and temperature unit (Celsius / Fahrenheit). Session to 1 year — your choice
fff-origins Stores your selected departure city or cities (up to two for MeetOnArrival dual-origin searches) and associated country codes. Session to 1 year — your choice
fff-acknowledgements Records which informational notices you have dismissed (e.g. the price-accuracy disclaimer banner) and the version seen, so the same notice is not shown again after explicit dismissal. 1 year

2.3 Google Analytics 4 Art. 6(1)(a) GDPR / TDDDG §25(1)

We use Google Analytics 4 (GA4) to understand how the Sites are used in aggregate. GA4 is loaded only if you accept analytics cookies via the cookie preference panel. If you decline or have not yet made a choice, the GA4 script is not loaded at all.

The legal basis for this processing is your consent (GDPR Art. 6(1)(a); TDDDG §25(1)). You can withdraw consent at any time via the Cookie Preferences option in the site footer or settings menu. Withdrawal takes effect immediately for the current session and prevents GA4 from loading on future visits. It does not affect data already collected.

We use GA4 Consent Mode: analytics_storage is set to denied by default and updated to granted only after you accept. IP anonymisation is enabled. Each of our three Sites has its own separate GA4 property; data is not combined across brands. Google acts as our data processor under a data processing agreement.

GA4 data may be transferred to and processed in the United States. Google relies on Standard Contractual Clauses as the transfer safeguard under GDPR Art. 46(2)(c). For details of what Google collects and how they process it, see policies.google.com/privacy.

Cookie name Purpose Duration
_ga Distinguishes unique visitors via a randomly generated client ID. Set by Google on the google.com domain. 2 years
_ga_<ID> Maintains GA4 session state for a specific property. Contains an expiry timestamp and session counter; no personal identifiers. Set by Google on the google.com domain. 2 years

2.5 Affiliate link tracking and partner widgets Art. 6(1)(f) GDPR / TDDDG §25(2)

When you click a link to a partner site (currently GetYourGuide), we record the click as a boolean flag in our server-side logs only. We do not place any cookie of our own for this purpose. When you follow an affiliate link, the destination site will receive standard HTTP request data including your IP address, browser information, and the referring URL. The partner may also receive an affiliate identifier in the URL that attributes the referral to us. Affiliate partners act as independent data controllers once you arrive on their site.

Destination share pages also embed a GetYourGuide widget that displays activities available at the specific destination you are viewing. We load this widget without requiring marketing consent because you have explicitly arrived at a specific destination page, and showing relevant activities there is a functional part of that page's service. The legal basis is TDDDG §25(2) no. 2 — strictly necessary to deliver a service you have explicitly requested. As part of delivering the widget, GetYourGuide may set a visitor_id cookie on the .getyourguide.com domain. We do not set, read, or control this cookie. What GetYourGuide does with it is governed by their own privacy policy at getyourguide.com/privacy-policy.

2.6 Automated traffic classification Art. 6(1)(f) GDPR

Our servers assign a bot-likelihood score to each browsing session based on request patterns (request rate, path diversity, timing gaps, known probe paths). This score is used solely for rate-limiting abusive automated traffic and for internal traffic analysis. It is stored as part of the session record and deleted after 14 days along with all other session data.

Automated traffic-security rules may temporarily limit requests classified as abusive. They do not produce legal or similarly significant effects within the meaning of Art. 22 GDPR. If you believe you have been incorrectly rate-limited, contact us at [email protected].

3. Data we do not collect

4. Data storage and security

Server-side analytics are stored on our web servers (DigitalOcean, EU region, acting as our data processor) and transferred to our internal analysis system in Berlin via encrypted SSH. Apart from our contracted hosting provider DigitalOcean and, where consented to, Google Analytics, we do not store analytics data with other cloud providers.

We implement technical and organisational measures appropriate to the sensitivity of the data, including SSH key authentication, network-level access restrictions, and automatic data expiry.

5. Retention periods

Data Retention What happens after
Session-level analytics 14 days Aggregated into statistics intended to be anonymous; session rows permanently deleted
Aggregated statistics Indefinite Retained; intended to be anonymous, with cell suppression applied
First-party cookies (fff-consent, fff-user-preferences, fff-origins, fff-acknowledgements) Session to 1 year depending on cookie and user choice Deleted by the browser at expiry, or immediately if you clear cookies via browser settings or reset via Settings
Google Analytics data (if consented) 2 years (GA4 cookies); Google's own retention applies Governed by Google's data retention settings and policies

6. Your rights under GDPR

Under GDPR you have the following rights in relation to personal data we hold about you. Some rights depend on the legal basis for processing and may not apply in every circumstance.

Because our server-side analytics do not store a full IP address or any directly identifying information, we may not be able to locate data relating to a specific individual without additional context from you (e.g. the approximate time and departure city of your visit).

To exercise any of these rights, contact us at [email protected]. We will respond within one month (GDPR Art. 12(3)).

7. Third-party services and recipients

Service Role Purpose / legal basis Data transfer Privacy policy
Google Analytics 4 Processor Usage analytics — consent (Art. 6(1)(a) GDPR / TDDDG §25(1)). Loaded only when you accept analytics cookies. IP anonymisation enabled. Separate GA4 property per brand. United States. Standard Contractual Clauses (Art. 46(2)(c) GDPR). policies.google.com/privacy
GetYourGuide Processor (widget delivery); independent controller (after affiliate navigation) (1) Activities widget embedded on destination pages — TDDDG §25(2) no. 2, strictly necessary to deliver the destination page service. (2) Affiliate link click-through — Art. 6(1)(f) GDPR, user-requested navigation to partner site. Widget: data processed by GetYourGuide per their policy. Link click: standard HTTP data transmitted on navigation. getyourguide.com/privacy-policy
DigitalOcean Processor Web hosting and server infrastructure — legitimate interest (Art. 6(1)(f) GDPR) Primary location: Frankfurt, Germany. Any transfers or remote access outside the EEA are protected by applicable safeguards including Standard Contractual Clauses. digitalocean.com/legal/privacy-policy
Cloudflare Processor (and potentially independent controller for security operations) DNS, CDN, and DDoS protection — legitimate interest (Art. 6(1)(f) GDPR). Cloudflare processes request metadata including IP addresses for network security. Transfers outside the EEA are covered by Cloudflare's Standard Contractual Clauses and EU-US Data Privacy Framework participation. Global edge network (SCCs / EU-US DPF) cloudflare.com/privacypolicy

8. Additional information (Art. 13 GDPR)

9. Children's privacy

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

10. Changes to this policy

We may update this policy when our processing activities change. We will update the "Last updated" date at the top. Continued use of the sites does not constitute consent to processing that requires consent — that remains governed by your explicit cookie choices.

11. Contact and complaints

Email: [email protected]
Post: FairFareFinder GmbH, Kolonnenstraße 8, 10827 Berlin, Germany

If you are not satisfied with our response, you have the right to complain to the Berliner Beauftragte für Datenschutz und Informationsfreiheit: www.datenschutz-berlin.de