Cookie Policy

Version v11 — 2026-09-24

Cookie Policy

The Greek Local (formerly “Greece Activity Guide”) is operated by TRAVEL ACTIVITY GUIDE LTD (HE 493917), a company registered in the Republic of Cyprus, with registered office at Vavyla 3, Block A, Flat/Office 204, Pera Chorio, 2572 Nicosia, Cyprus. This Cookie Policy explains what cookies and similar technologies we use on thegreeklocal.com, why we use them, and how you can control them. It should be read alongside our Privacy Policy. Version v11 — 24 September 2026. This Cookie Policy is published in English and Greek. The English version is definitive; the Greek version is provided for convenience and, if the two diverge, the English version prevails.

Clarity notice: Published and effective 21 September 2026. Microsoft Clarity recording requires your Analytics consent. This notice does not change the effective dates of our other policies or the operation of existing services.

Google Maps notice: Published and effective 24 September 2026. Maps on information pages load only after you allow functional cookies. This notice does not change the effective dates of our other policies or the operation of existing services.

1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the website to remember your actions and preferences (such as language, currency, or items you have started booking) over time, and they help us understand how the site is used so we can improve it.

Cookies can be:

  • Session cookies — deleted when you close your browser.

  • Persistent cookies — stored on your device until they expire or you delete them.

They can be set by us (first-party cookies) or by third-party services we use (third-party cookies), such as our payment processor.

We also use similar technologies — including localStorage, sessionStorage, tracking pixels (also called web beacons, such as the Meta Pixel described below) and (where strictly necessary for a feature you have asked us to provide) limited fingerprint-like signals such as your screen size or browser language. Throughout this policy we use the word “cookies” as a shorthand for all of these.

2. How We Use Cookies

We use cookies to:

  • Make the website function correctly (load the right page, keep you signed in, complete your booking).

  • Remember choices you have made (language, recently viewed tours).

  • With your consent, understand how visitors interact with our site so we can improve it.

  • With your consent, measure the performance of any advertising we run on third-party platforms.

We do not sell information collected from cookies, and we do not use cookies to build advertising profiles outside what is described below.

3. Categories of Cookies We Use

You can switch the optional categories on or off at any time using the Cookie Settings button in the footer of every page.

Necessary (always active)

These cookies are essential for the website to function and cannot be switched off. They are usually set in response to actions you take — signing in, adding a tour to checkout, saving your cookie preferences. Without them parts of the site will not work.

gag_consent
Set by
The Greek Local
Purpose
Stores the categories of cookies you have accepted so we do not ask again.
Duration
12 months
gag_consent_cid
Set by
The Greek Local
Purpose
An opaque random ID linking your accept / withdraw actions in our consent audit log. Not used for tracking.
Duration
12 months
tgl:sign-up-intent:v1 (session storage)
Set by
The Greek Local
Purpose
Stores a random tab-local nonce and fixed account context to authorise one post-sign-up handoff and prevent replay. It contains no identity data, is not sent to Google Analytics, and is consumed when you return from sign-up.
Duration
Current tab only; code rejects it after 2 hours
__session, __client_uat, __clerk_db_jwt (and similar)
Set by
Clerk (our authentication provider)
Purpose
Keep you signed in to your account. Only set after you sign in.
Duration
Session – 1 year
NEXT_LOCALE
Set by
The Greek Local
Purpose
Remembers your language preference (English / Greek).
Duration
1 year
__stripe_mid, __stripe_sid
Set by
Stripe
Purpose
Required to process card payments and to detect fraud during checkout. The Stripe script is only loaded on /checkout, so these cookies are not set anywhere else on the site.
Duration
Session – 1 year

Functional

Enable enhanced functionality and personalisation, and record which partner referred you. The affiliate referral cookie ref_code belongs in this category and is set only if you accept it.

Functional cookies enable improved functionality such as Google Maps on our pages. When a map loads, Google may set its own cookies. Pressing “Show map” on a page switches on functional cookies only; the other categories keep your banner choice, and the banner stays until you answer it.

ref_code
Set by
The Greek Local
Purpose
If you arrived through an affiliate link (?ref= parameter), records which partner referred you so they can be credited if you book. Belongs in the Functional category and is set only if you accept that category: it serves our commission arrangement with the partner rather than a service you asked us for, so it does not fall within the “strictly necessary” exemption in Article 5(3) of Directive 2002/58/EC.
Duration
90 days
Google’s own cookies on google.com domains, for example NID
Set by
Google Maps Platform, Google Ireland Limited
Purpose
Shows maps and place search on information pages and in the pickup-point list of the booking form. Google may set or read these cookies when a map loads.
Duration
Up to six months, set by Google

Analytics

Help us understand how visitors interact with the site so we can improve it. With your consent, GA4 records pseudonymous events such as page, Tour and list views; controlled search/filter choices and result counts; checkout progress; successful account creation; and genuinely paid or refunded booking value. Reports are aggregated, and we ask Google Analytics to anonymise IP addresses. We do not send names, email addresses, phone numbers, form contents, free-text search terms, or selected booking dates and times to GA4. Our application does not supply customer or form fields to GA4 as user-provided data.

With Analytics consent, we also use Microsoft Clarity to understand how visitors use our public pages through heatmaps and session recordings of clicks, scrolling and navigation. This helps us find confusing links and pages where visitors leave. Clarity receives technical and usage data, including public page addresses, referring-page information and pseudonymous browser/session identifiers. Input and dropdown contents are masked. We do not supply names, email addresses, account IDs or booking references to Clarity. We exclude account, administration, sign-in, booking and checkout pages, links containing private access tokens, and pages with sensitive query information. Clarity is used for analytics only: its advertising storage consent stays denied, even if you accept Advertisement cookies. Microsoft processes the data under its Privacy Statement.

_ga
Set by
Google Analytics (GA4)
Purpose
Distinguishes unique visitors.
Duration
13 months
ga*
Set by
Google Analytics (GA4)
Purpose
Persists session state.
Duration
13 months
_clck
Set by
Microsoft Clarity (first-party)
Purpose
Stores a pseudonymous browser identifier and Clarity preferences for this site.
Duration
1 year
_clsk
Set by
Microsoft Clarity (first-party)
Purpose
Links page views within a Clarity session recording.
Duration
1 day
_cltk (session storage)
Set by
Microsoft Clarity
Purpose
Distinguishes the browser tab during an analytics session.
Duration
Current tab only

Analytics cookies are only set if you accept the Analytics category. Until then we tell Google Consent Mode that analytics storage is denied, and neither the GA4 nor Clarity script is loaded. You can withdraw Analytics consent through Cookie Settings; this disables our analytics tracking and removes readable Clarity cookies and its tab identifier.

Where a paid, refunded or partner-lifecycle milestone happens on the server after your visit, we send it to GA4 only if you granted Analytics consent and supplied GA’s opaque browser identifier during the original journey. We re-check the consent audit record before delivery, omit stale session identifiers, and do not include contact details or form contents. These server events are explicitly marked as denied for advertising-data use; Google Ads conversion reporting follows the separate Advertisement consent described below.

Performance

We use Vercel Analytics, a cookieless measurement service provided by our hosting platform, to count page views in aggregate without setting a cookie or storing an identifier on your device. Because it does not store or read information on your device, it does not require consent under the ePrivacy rules. No Performance cookies are currently set.

Advertisement

Used to measure the effectiveness of any advertising campaigns we run on third-party platforms (such as Google Ads and Meta / Facebook / Instagram), to attribute bookings to the advertisement or source that brought you to the site, and to build audiences for retargeting.

gag_ad_click
Set by
The Greek Local
Purpose
If you arrived through one of our advertisements, stores the advertising click identifier (for example a Google Ads click ID) so that, if you later book, we can attribute the booking to that advertisement. First-party; set only after you accept this category and deleted if you later refuse or withdraw it.
Duration
90 days
gag_utm
Set by
The Greek Local
Purpose
Stores the campaign labels (utm parameters) of the advertisement or campaign link that brought you to the site, for the same measurement purpose.
Duration
90 days
gag_touch
Set by
The Greek Local
Purpose
Stores a one-time snapshot of how you first arrived at the site: the Meta (Facebook / Instagram) advertising click identifier where present, the address of the page you first landed on, and the external website that referred you. Recorded once, at the first visit that carries such information, for the same booking-attribution purpose. First-party; set only after you accept this category and deleted if you later refuse or withdraw it.
Duration
90 days
gag_touch_sent (local storage)
Set by
The Greek Local
Purpose
A small local-storage note (no personal data: a rank number and a date) that stops your browser re-sending the first-arrival snapshot it has already sent us. Written only after you accept this category and deleted if you later refuse or withdraw it.
Duration
90 days
_fbp, _fbc
Set by
Meta (Facebook)
Purpose
Identify the browser and, where you arrived through a Meta advertisement, the advertising click for campaign measurement and retargeting.
Duration
3 months
__oppref
Set by
OpenAI Pixel
Purpose
Stores the OpenAI click reference from a ChatGPT advertisement so later measurement events can be attributed to that click. First-party; set only after you accept this category.
Duration
30 days
__oaiq_consent
Set by
OpenAI Pixel
Purpose
Records whether the OpenAI Pixel is permitted to measure events on this site.
Duration
30 days
oaiq_consent (local storage)
Set by
OpenAI Pixel
Purpose
Stores the same OpenAI Pixel permission state in your browser.
Duration
Until you refuse or withdraw Advertisement consent, or clear this site's data

Advertisement cookies are only set if you accept the Advertisement category. The Meta Pixel and OpenAI Pixel scripts are not loaded before you opt in. We do not load a Google Ads browser tag; consent-checked Google Ads conversion reporting is server-to-server only. If you later switch this category off, we revoke Meta and OpenAI consent, block further advertising events from our application and delete readable advertising cookies and matching optional browser-storage identifiers. A vendor script already downloaded during the consented part of the page visit may remain in browser memory until you leave or reload the page, but our application does not use it to send further events after withdrawal.

With Advertisement consent, the OpenAI Pixel measures eligible public page and Tour views and checkout starts so OpenAI can attribute activity to our advertisements in ChatGPT. It captures the oppref click reference from the landing-page URL and stores it in the first-party __oppref cookie. The Pixel can also automatically detect supported customer information entered in recognisable forms and other sources on the Site. It normalises and securely hashes that information in your browser using SHA-256 before including the hashes with conversion events; raw customer information is not sent to OpenAI through this automatic advanced matching. We mark our OpenAI events so they are not used for future user-level personalisation. That setting does not disable automatic advanced matching.

When an Advertisement-consented booking is genuinely paid, we may also send OpenAI the click reference with a pseudonymous event identifier, the Tour identifier, booking value and currency, first-payment time and a public Tour-page URL over a server-to-server connection. We do not manually include your name, email address or phone number in this server report.

When we run Google Ads campaigns, if you accepted this category and a booking you make is completed, we also report the advertising click identifier together with the booking value and currency to Google Ads over a server-to-server connection, so that our advertising can be measured accurately. We do not send your name, email address or phone number with that report, and each report carries your recorded consent status. If your booking is later cancelled and fully refunded, we retract the report.

You can also opt out of interest-based advertising across many advertising networks through Your Online Choices (EU) and the Digital Advertising Alliance (US), and manage how Meta uses your data for advertising in your Meta ad preferences. These industry tools operate independently of our Cookie Settings — opting out there does not remove the cookies themselves, so we recommend using both.

Other

Any cookie that does not fit the above categories. Currently none are in use. If we add one we will update this page and re-prompt for consent.

4. Third-Party Services and International Data Transfers

The following third parties may set cookies through our site when you use a feature they provide:

  • Stripe — payment processing (Ireland, EU). Necessary for completing a booking. Stripe privacy policy.

  • Clerk — authentication. Necessary if you sign in to a customer or supplier account. Clerk privacy policy.

  • Google Analytics (GA4) — analytics, only with your consent. Google privacy policy.

  • Microsoft Clarity — public-page heatmaps and session recordings, only with Analytics consent and with advertising storage denied. Microsoft acts as a data controller for its processing. Microsoft Privacy Statement.

  • Google Ads — advertising measurement and conversion reporting, only with your consent. Google privacy policy.

  • Google Maps Platform (Google Ireland Limited, with transfers to Google LLC in the United States): maps and place search. On information pages, and for maps that only help you choose from a list of pickup points, it belongs in the Functional category and a map loads only after you accept that category; in the transfer booking form it counts as Necessary, because there you mark the exact pickup or drop-off point on the map. Google privacy policy.

  • Meta (Facebook) Pixel — advertising, only with your consent. Meta privacy policy.

  • OpenAI Ireland Limited — advertising measurement and matching through the OpenAI Pixel and Conversions API, only with your consent. We and OpenAI each act as independent controllers for this measurement unless Restricted Processing terms apply. The OpenAI Ad Tools Data Processing Addendum governs this processing and requires a valid transfer mechanism for onward transfers of EEA or Swiss personal data. OpenAI privacy policy.

  • Vercel — our hosting platform, which also provides the cookieless, aggregate page-view statistics described above. It sets no cookies and stores no identifiers on your device. Vercel privacy policy.

Google and Meta process data in the United States. Those transfers are covered by the EU–US Data Privacy Framework (European Commission Adequacy Decision 2023/1795 of 10 July 2023) — both companies have self-certified under the Framework, and you can confirm their status on the DPF participants list. For any other transfer outside the EEA, we rely on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) together with appropriate supplementary measures.

For Clarity, the EU contracting entity is Microsoft Ireland Operations Limited. Microsoft may process data in the United States and other countries where it operates; its Irish and US entities use Standard Contractual Clauses, and Microsoft also participates in the EU–US Data Privacy Framework. Its Privacy Statement explains these safeguards.

Each provider has its own privacy and cookie policy, which governs the data they collect through their cookies.

5. Legal Basis

Strictly-necessary cookies are placed on the basis of our legitimate interest in providing the website and the services you have requested (Article 6(1)(f) GDPR, and the “strictly necessary” exemption in Article 5(3) of the ePrivacy Directive (2002/58/EC) as transposed into Cyprus and Greek law).

All other categories are placed only on the basis of your explicit consent (Article 6(1)(a) GDPR), which you can grant or withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.

6. Managing and Withdrawing Consent

You can update or withdraw your consent at any time:

  • Click Cookie Settings at the bottom of any page.

  • Or clear cookies for this site in your browser, which will cause the banner to re-appear on your next visit.

We will also re-prompt you for consent at least every 12 months, even if nothing has changed, in line with the recommendation of the European Data Protection Board.

How we record your consent

We keep a record of every accept / reject / save / withdraw action so we can demonstrate, if asked by a supervisory authority, that consent was freely given and informed (Article 7(1) GDPR). Each record contains: an opaque browser identifier (gag_consent_cid), the categories you chose, the policy version, your language, a timestamp, a truncated IP prefix (/24 for IPv4, /48 for IPv6 — never your full address) and your browser’s user agent. The legal basis for this processing is Article 6(1)(c) GDPR (compliance with a legal obligation) read together with Article 7(1).

We keep a record of your cookie choices, including a map-only grant, with the date and the version of this policy you accepted.

We retain these records for 6 years after withdrawal or expiry — the longer of the limitation periods in Cyprus (Limitation of Actions Law 66(I)/2012, 6 years) and Greece (Civil Code Article 250, 5 years for commercial claims). They are deleted automatically at the end of that period.

Browser-level controls

You can also manage or delete cookies directly through your browser:

  • Google Chrome

  • Mozilla Firefox

  • Apple Safari

  • Microsoft Edge

Be aware that blocking strictly-necessary cookies will prevent parts of the site (signing in, checkout, language preference) from working.

7. Do Not Track

Most browsers offer a “Do Not Track” signal. Because there is no consensus on how it should be interpreted, we do not currently respond to it. We do, however, honour the Global Privacy Control (GPC) signal. Use the Cookie Settings panel to make your choice — those preferences are honoured.

8. Children

This site is not directed at children under 16, and we do not knowingly collect personal data from them. Where a booking’s pricing depends on age, the parent or guardian making the booking provides the age on the child’s behalf — the data does not come directly from the child. If you believe we have collected data from a minor without parental consent, please contact us so we can delete it.

9. Data Protection Officer

Based on the scale and nature of our processing, we have determined that we are not required to appoint a Data Protection Officer under Article 37 GDPR — our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special-category data. We review this assessment annually. For data-protection enquiries please use the contact details below.

10. Automated Decision-Making

In one specific case an automated decision can affect you: our payment processor, Stripe (including its fraud-screening tool, Stripe Radar), automatically screens card transactions for fraud, and a transaction assessed as high-risk may be automatically declined — which means a booking may not complete. If this happens to you, you can ask us to review the decision, give us your point of view, and contest the outcome using the contact details in section 12. Apart from this fraud screening, we do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. See also the corresponding section of our Privacy Policy.

11. Changes to This Policy

We may update this Cookie Policy from time to time. If we change the categories of cookies, add a new tracker, or make any other material change, we will bump the consent version, which automatically re-prompts every visitor for their preferences. The current version is shown at the top of this page.

12. Contact and Complaints

If you have questions about how we use cookies, or you would like to exercise any of your GDPR rights, please contact us:

  • Email: support@thegreeklocal.com

  • Postal address: TRAVEL ACTIVITY GUIDE LTD, Vavyla 3, Block A, Flat/Office 204, Pera Chorio, 2572 Nicosia, Cyprus.

You also have the right to lodge a complaint with a supervisory authority:

  • Cyprus: Office of the Commissioner for Personal Data Protection (www.dataprotection.gov.cy).

  • Greece: Hellenic Data Protection Authority (www.dpa.gr).

  • Or with the supervisory authority of the EU Member State where you reside.