Data Protection Policy
Last updated: October 9, 2026
This text is a starting draft. Fields in brackets are placeholders the business must fill in (and have the content reviewed by a legal advisor) before publishing it.
This policy explains how Camino Backpack processes the personal data of people who use this website and book the backpack transport service.
1. Data controller
Camino Backpack, CaminoBackpack S.L., [TAX ID], registered address at [ADDRESS]. Website: caminobackpack.com. Contact for privacy questions: info@caminobackpack.com.
2. What data we process and where it comes from
You provide the data when you book and when you use the booking management portal. We process: identification and contact details (first name, last name, email and phone); booking details (Camino, dates, stages, pickup and drop-off accommodations, number of backpacks, amounts and booking code); billing details, only if you ask for a full invoice (name or company name, tax ID and address); payment details, which Stripe processes directly —Camino Backpack never sees or stores your full card details—; and technical data: the IP address you use the website from, used only to stop abuse and deleted within an hour, and the cookies described in section 9. If you arrive through a partner accommodation's link and book in that same visit, or come back another day having accepted its cookie, we also keep which accommodation recommended the service to you.
3. What we use it for and on what legal basis
Managing your booking, the payment, the transport with Correos, changes and cancellations, and sending you booking notices by email and WhatsApp (confirmation, changes, tracking and cancellation): necessary to perform the contract you enter into with us (art. 6.1.b GDPR). Issuing invoices and keeping accounting and tax records: compliance with legal obligations (art. 6.1.c). Handling your questions, incidents and complaints: performance of the contract and our legitimate interest in resolving them (art. 6.1.f). Protecting the website against abuse and fraud (attempt limits per IP address and access control for each booking): legitimate interest in the security of the service (art. 6.1.f). Paying a commission to the partner accommodation that recommended the service to you: if you book in the same visit in which you arrive through its link, our legitimate interest in rewarding accommodations for the bookings they bring us —the link only identifies the accommodation and nothing is stored in your browser— (art. 6.1.f); if you come back to book another day, your consent to the referral cookie (art. 6.1.a); if you book without that link, the commission is attributed to the pickup accommodation of your first stage using the booking's own data (legitimate interest, art. 6.1.f). We never share your personal data with the accommodations. The data requested in the booking form is required to contract: without it we can't manage the booking or the transport. We don't make automated decisions or build profiles with your data.
4. Who we share your data with
To provide the service we share your data with these third parties, only to the extent necessary: with Correos (Sociedad Estatal Correos y Telégrafos, S.A., S.M.E.), which carries out the physical transport through its Paq Mochila service, your name, phone and itinerary (dates and accommodations of each stage), which Correos processes as controller of its own transport service under its privacy policy —your name also appears on the backpack label, visible at the pickup and drop-off accommodations—; with Stripe (Stripe Payments Europe, Ltd.), which processes the payment, your email, the amount and the payment details you enter on its page, acting as processor and, to prevent fraud and meet its own legal obligations, as controller; with Twilio, which sends the WhatsApp messages, your phone and the content of the notices (name, booking code and management link), messages delivered through WhatsApp (Meta) under its terms; with our email delivery provider (Resend or Twilio SendGrid), your email and the content of the notices; and with the web hosting and database providers where the website runs and bookings are stored. Twilio, the email provider and the hosting and database providers are processors: they only process the data on our instructions and under a contract that guarantees it. We will also disclose data to the Tax Administration and other authorities, judges or courts when required by law. We don't sell or share data with third parties for commercial or advertising purposes.
5. International transfers
Stripe, Twilio, WhatsApp (Meta), the email provider and, where applicable, the hosting provider may process data outside the European Economic Area, mainly in the United States. Those transfers are covered by the adequacy decision for the EU-US Data Privacy Framework, where the provider is certified under it, or by the standard contractual clauses approved by the European Commission.
6. Retention period
Personal booking data (name, email, phone and tracking notes) is kept while the itinerary is active and deleted 5 years after the last day of the trip. Booking data required for tax and accounting obligations (code, dates, stages, amounts and payments) is kept for the periods required by applicable law, without any data that identifies you. If you exercise your right to erasure earlier, we delete your personal data as soon as the booking is no longer active. If you ask for a full invoice, the billing details on it (name or company name, tax ID and address) are kept with the invoice for 6 years from its issue (the period required by commercial and tax law), even after the rest of your data is deleted, and are then removed from the invoice too. IP addresses used to limit attempts are deleted within an hour.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to info@caminobackpack.com. If you gave your consent (referral cookie), you can withdraw it at any time from "Cookies" in the website footer, without affecting processing carried out before you withdraw it. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with the law.
8. Security
Reasonable technical and organisational measures are applied to protect data against unauthorised access, loss or alteration, proportionate to the risk of the processing.