Last updated: April 2026
Avamundo, Patrick Kieber, Heiligwies 6, 9486 Schaanwald, Liechtenstein
Email: legal@avamundo.com
When you create an account we collect your email address and a hashed password. Optionally you may provide a first and last name. The legal basis is the performance of a contract (Art. 6 para. 1 lit. b GDPR).
After login we issue short-lived JWT access tokens and a refresh token, stored in your browser's localStorage. These are used solely to authenticate subsequent requests and are never shared with third parties.
When you generate an AI trip itinerary we store your preferences (duration, difficulty, interests, region, start date) and the resulting itinerary text. This data is linked to your account and visible only to you. You can delete individual trips at any time from your account page, or delete all data by deleting your account.
We log which guides you download and when, to enforce monthly download quotas. This data is linked to your account.
If you explicitly consent, we use your usage patterns to personalise recommendations via Mistral AI (EU-based). This consent is optional, can be withdrawn at any time from your account settings, and has no effect on core functionality.
Pass purchases are handled entirely by Stripe. We do not store your card number, CVV, or full payment details. Stripe shares only the pass type and payment status with us via webhook. See Stripe's Privacy Policy.
If you joined our earlier waitlist, we stored only your email address. Waitlist addresses are not linked to user accounts. You may remove yourself via the unsubscribe page.
Our hosting provider automatically records standard access logs (IP address, browser type, pages visited, date/time). These logs are retained for a maximum of 7 days for security purposes and are not linked to your identity.
Your data is processed by the following third-party services:
We do not use advertising networks, social media tracking pixels, or Google Analytics.
Under GDPR (applicable in Liechtenstein as an EEA member state), you have the right to:
For requests that cannot be fulfilled self-service, contact legal@avamundo.com. We respond within 30 days.
AlpineSpot does not use tracking or advertising cookies. We use browser localStorage for:
This data is stored only on your device and is never transmitted to analytics services.
All data is transmitted over HTTPS (TLS 1.2+). Passwords are hashed using Django's PBKDF2-SHA256 algorithm. JWT tokens are short-lived (access: 15 minutes; refresh: 7 days). The backend runs on an isolated Hetzner VPS with no public SSH access.
We may update this policy as the service evolves. We will note the date of the last update at the top of this page. Continued use of the service after a material change constitutes acceptance of the updated policy.