Privacy
This page explains what happens to your data when you look around here, send me a message or sign up for a trip. No legal jargon: just what actually happens, part of the site by part of the site.
Last updated 1 August 2026
I am Evelyne Fontaine, content creator and travel guide, based in Belgium. This website is mine and I decide what happens to your personal data, which makes me what the law calls the controller. You can reach me at evelyne.fontaine@hotmail.com. An operation of this size is not required to appoint a data protection officer, so your privacy questions come straight to me.
You can look around here without leaving anything behind. There is no account, no newsletter, and you pay nothing here. There are exactly two places where you fill in data yourself: the contact form and the signup form on a trip. Everything else is technical: one language cookie, anonymous visitor counts, and the photos and videos the site loads from other companies. Each of those is covered below.
If you fill in the form on the contact page, you give me your name, your email address and your message. I ask for nothing more, and you decide what you put in it. This website does not keep your message in a database: it goes out as a single email to my own mailbox, and that is where I read it and reply. Resend, the service that sends the mail, and Microsoft, where my mailbox lives, both hold a copy of it. I use your message to answer your question and, if it is about a collaboration or a trip, to make arrangements about it. I use it for nothing else, and I do not add you to a mailing list.
The legal basis depends on what you write. If your message is about a possible collaboration or booking, those are steps taken at your request before an agreement (article 6(1)(b) of the GDPR). If you write to ask something or simply to say hi, I may reply on the basis of my legitimate interest: being reachable and being able to answer the people who write to me (article 6(1)(f) of the GDPR).
To keep spam robots out, the form has three silent checks, and the server counts per IP address how many messages come in. That counter expires after fifteen minutes. The address itself is never stored with your message and does not travel to my mailbox: it stays in the server's temporary working memory, which empties as soon as the site restarts.
Some trips have a signup form. Which questions it asks differs per trip, because I put them together per trip. Right now I ask for your name and your email address, on one trip also your date of birth and your Instagram handle, plus an open question about what you hope to get out of the trip. Every field says whether it is required. You can leave the optional ones empty; without your email address I simply cannot confirm your spot.
What happens next: your signup is stored in the system Nurani Studio runs for me, you get a confirmation email straight away, and I get a message that you signed up. Whether that confirmation email arrived is tracked, so I can see whether I actually reached you.
I use this to put the group together, to keep you posted about that one trip, and to tell you how to book. The legal basis is your own request: you sign up, and with that I take the steps that come before a trip agreement (article 6(1)(b) of the GDPR). The updates about that trip I send with your consent (article 6(1)(a) of the GDPR). If you would rather not get them, email me and I will take you off the list, at any moment and without giving a reason.
The trips themselves are not organised by me but by travel partners. For the trips currently on the site those are Mundero, Route du Soleil and Worldpackers. If you click through to book, you leave my website and their terms and their privacy statement apply. What you fill in there goes to them, not to me. Some of those links carry a code that tells the partner you came in through me, because that is how I am paid for those trips. The same kind of links appear in my travel guides, for example to GetYourGuide.
This site sets one cookie, and it is the only one: NEXT_LOCALE. It holds nothing but the language you are reading the site in, so you do not have to pick it again on every page. It disappears the moment you close your browser. A functional cookie like that is allowed without consent, which is why you see no cookie banner here. Nothing else is put on your device by this site. If you start a YouTube video or the Spotify player yourself, that player loads from YouTube or Spotify and they can then place their own cookies. That never happens on its own, only after your click.
I want to know which pages get read and which do not, so I can make the site better. For that a counter runs along: Umami, on a server of Nurani Studio's own in Europe. No Google Analytics, no ad network, no cookies.
What gets counted: which page you look at and what it is called, which site you came from, how far down you scroll, which parts of a page you get to see, and whether you sent the contact form or a trip signup. Along with that go the dimensions of your screen, the language your browser reports, and the line your browser identifies itself with, from which the browser, the operating system and the kind of device you use can be read. Your IP address goes along to that counter to work out roughly where a visit comes from, down to the city, and to tell visits apart. What I get to see afterwards are totals and overviews. Names and email addresses are not in there, because they are never sent along.
Separately, the site measures how fast pages load. That measurement goes to Nurani Studio's server rather than to the counter above, and it holds the path of the page, the measured values themselves, and what kind of device and internet connection you have. Your name, your email address and your IP address are not in it. On top of that, the server briefly counts per IP address how many requests come in on every request to the site, to hold off overload and abuse.
The legal basis is my legitimate interest in knowing how my site is used and making it better (article 6(1)(f) of the GDPR). No profile of you is built and your visit is not followed to other websites.
Part of what you see here comes from other companies, and they then see the IP address and the browser you request it with.
My photos and videos come from the Amazon Web Services content network, with the files stored in Sweden. On some trips the atmosphere photo comes from Unsplash.
The preview images of my YouTube videos are fetched by my own server and served to you from there, so YouTube does not see you pass by for those. Once you click play, the YouTube player itself loads, and from that moment YouTube sees your visit and can set cookies. The same goes for the Spotify player on the content page: it only loads at the moment you start it yourself.
The site's typeface sits on my own server, so nothing goes to Google for that. All traffic runs through Cloudflare, which keeps the site fast and reachable, blocks attacks, and makes my email address on the site unreadable to spam robots. Cloudflare sees every request pass by while doing so. Finally, if your browser notices that a page tries to load something it should not, it automatically sends a report about that to Nurani Studio's server. Your browser sends that report itself, so besides the page involved, your IP address and your browser details arrive there too.
I do not sell your data and I do not share it for advertising. These are the recipients involved in getting my work done. Nurani Studio, which builds and maintains this website and the trip system, has technical access for that, and receives the visitor counts and the speed measurements on its own servers. Resend, the service that sends my email, which the contact form messages and the trip confirmations pass through and stay in. Microsoft, because my mailbox is a Hotmail address, so your message arrives and stays there. Hetzner, the German hosting company this website runs on. Cloudflare and Amazon Web Services, for delivering and protecting the site and the imagery. Unsplash, which supplies the atmosphere photo on some trips. YouTube and Spotify, but only if you start their player yourself. And the travel partner of the trip you sign up for, if the booking happens with them. Beyond that I only share something when the law requires me to.
The website and the visitor counts run on servers in Europe. Several of the companies above are American: Resend, Microsoft, Cloudflare, Amazon Web Services and Google, of YouTube. Because of that, data may be processed outside the European Economic Area. That is allowed on the basis of the European Commission's standard contractual clauses and the EU-US Data Privacy Framework, the arrangements the European Commission has laid down for this.
Messages from the contact form stay in my mailbox as long as our conversation runs. If nothing comes of it, I throw them away at the latest two years after our last contact.
Trip signups I keep while that trip is being prepared and until twelve months after it has finished, so I can still reach you if there is something to say about that trip. After that I delete them.
Invoices and the rest of my bookkeeping I keep for seven years, because tax law prescribes that retention period.
The visitor counts hold nothing that can be traced back to you; I keep those as long as they are useful for improving the site. The IP address briefly used to stop spam and overload stays only in the server's temporary working memory and disappears from there as soon as the site restarts.
No decisions are taken about you by a computer on its own, without a person looking at it. I also build no profiles of visitors and I do not use your data to show you advertising elsewhere.
You may always ask me which data I hold about you (access), have something corrected that is wrong (rectification), have your data erased, have its use restricted, have it sent in a readable file to yourself or to someone else (portability), and object to the use that rests on my legitimate interest. If you have given consent for something, for example for the updates about a trip, you may withdraw it at any moment; what was already sent before that stays valid.
Email me at evelyne.fontaine@hotmail.com and I will sort it out. I respond within a month. If you ask me to erase something, it may be that I still have to keep part of it because tax law requires it of me; in that case I will tell you which part and why.
If you feel I am not handling your data carefully, tell me first and I will fix it. If we do not work it out together, you may file a complaint with the supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be, +32 (0)2 274 48 00. If you live in another country of the European Union, you can also go to the supervisory authority there.
If something changes on the site that means other data gets processed, I update this page to match. The date at the top says when that last happened.