Effective date: 4 October 2026
100 Places Bulgaria is a community project. This policy explains how the team identified below (“100 Places”, “we”, “us”) processes personal data through www.100places.bg (the “Website”) and the 100 Places Bulgaria mobile application (the “App”). The Website and App have different features and data flows; they are described separately below.
Responsible for personal-data processing in this community project: 100 Places BG Team. For privacy questions, rights requests, or account deletion, contact contact@100places.bg. If your request concerns an App account, write from the email address associated with that account where possible. We may ask for proportionate information to verify your identity before acting on a request. Do not send passwords or identity-document copies unless specifically requested.
When you request a page, our hosting and infrastructure providers necessarily receive technical data such as your IP address, date and time, requested URL, referrer, browser and device information, and diagnostic or security events. We use this information to deliver the Website, prevent abuse, diagnose faults, and maintain security. The legal basis is our legitimate interest in operating a reliable and secure service (Article 6(1)(f) GDPR).
If you contact us, we process the email address and message you provide, together with delivery metadata needed to send and receive the message. We use it only to handle your enquiry, take steps you request before entering into an agreement where applicable, and protect or establish legal claims. The legal bases are Article 6(1)(b) and, where applicable, our legitimate interests under Article 6(1)(f) GDPR. Do not include sensitive or unnecessary personal information in the message.
On place-detail pages the map may load automatically when its panel is near the visible area; a click or advertising consent is not required for map tiles. Images served through our Website's image optimisation are fetched by the hosting service; directly loaded third-party images may instead be requested by your browser.
Place photographs may be delivered from Google Firebase Storage, Wikimedia, or Flickr. Interactive maps use OpenStreetMap map tiles. When your browser requests an image or an activated map tile, that provider receives the technical information needed to return it, including your IP address, the requested file, and browser request data. Place pages may also contain ordinary links to Google Maps, app stores, social networks, and travel partners. Those linked third parties receive data when you follow a link, and their own privacy terms then apply.
We use Google Privacy & Messaging, a Google-certified consent management platform integrated with the IAB Europe Transparency and Consent Framework. It displays the European regulations message, records your choices, and makes the resulting consent signals available to participating vendors. Processing needed to remember and demonstrate your choice is necessary for compliance with our legal obligations and for managing your preferences (Articles 6(1)(c) and 6(1)(f) GDPR). The message offers equally accessible choices to consent, not consent, or manage individual options.
The Google Analytics 4 tag loads with analytics storage denied by default. Before you choose, or while analytics storage remains denied, Google may receive cookieless consent-status and measurement pings. Those pings may include the current page URL and technical request data such as the IP address and user agent, but they do not read or write Analytics cookies. If you consent to analytics storage, GA4 may use identifiers and process fuller information about visits and interactions, including pages viewed, approximate location derived from IP, device/browser information, referring source, and the limited event categories described by the Website. Automatic page-view measurement includes the current page URL; on a place page, that URL contains the public place slug and its catalogue identifier. Separately defined interaction and performance events are sent only after analytics consent, are restricted to fixed categories, and do not include contact-form contents, exact coordinates, or free text. We use aggregated and modelled reporting to understand use of the Website, measure the app-download and travel-link journeys, and monitor performance. The legal basis for optional Analytics storage and the Website's separately defined analytics events is consent (Article 6(1)(a) GDPR).
Third-party vendors, including Google, may use advertising cookies to serve ads based on your previous visits to this Website or other websites. Google's advertising cookies enable Google and its partners to personalise advertising where you have given the required consent. You can change this Website's consent choices using “Privacy and cookie settings” and manage Google's personalised advertising through My Ad Center. Google's ad preferences do not replace consent choices on this Website.
The account-specific Google AdSense bootstrap loads with advertising storage, user-data, and personalisation consent denied so that Google Privacy & Messaging can operate and Google can verify the publisher integration. The Website does not request an advertisement before the required advertising consent exists. The Travelpayouts link-enhancement script also remains blocked until advertising consent. Depending on your choices, these providers may use cookies or similar technologies and process device, browser, IP, page, interaction, consent, and advertising data to select, deliver, limit, secure, and measure advertising or attribute an eligible booking. AdSense may show personalised ads only where the required consent signals exist. The legal basis for optional advertising technologies is consent (Article 6(1)(a) GDPR).
Some place pages contain plain affiliate links which remain usable without consent. Following one takes you to the named third party, whose privacy policy applies. We may receive a commission if you make an eligible purchase, at no additional cost to you. Direct sponsorships are selected contextually by page, language, placement, and campaign date; their reviewed images are served from our own Website and do not use third-party tracking pixels.
The App may process account details you provide (such as email address and profile information), your saved visits or stamps, device and app information, and support communications. When you ask the App to verify a visit, it uses your device location for that feature. Location permission is controlled through your device settings. The App also uses Firebase services for operation, usage analytics, and crash diagnostics; those services may process device identifiers, interaction data, and technical diagnostics.
We process account and stamp information to provide the App under Article 6(1)(b) GDPR. Optional permissions and analytics rely on consent where required. Security, fault diagnosis, prevention of abuse, and improvement of the service rely on our legitimate interests under Article 6(1)(f), balanced against your rights. App-store providers also process data under their own terms when you download or update the App.
We disclose data only as needed to operate the relevant feature, comply with law, or protect legal rights. Recipients may include:
We do not sell contact-form or App account data. Advertising providers may act as independent controllers for their own advertising activities; consult their notices through the consent message and the links in our Cookie Policy.
Some providers operate in countries outside Bulgaria or the European Economic Area. Where GDPR applies and a destination is not covered by an adequacy decision, transfers must use an appropriate safeguard such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. Details of a provider’s transfer arrangements are available in its privacy notice.
We keep personal data only for as long as needed for the purpose described above:
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting processing that was lawful before withdrawal. When the European consent message applies to your visit, use the enabled “Privacy and cookie settings” button in the Website footer to change Website choices. You can also delete this Website’s data in your browser. Contact us for other requests.
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria. Current submission methods are published on the CPDP website. You may also complain to the supervisory authority where you live or work.
The Website is intended for a general audience and is not designed to collect personal data directly from children. A child who cannot lawfully provide consent on their own behalf should use consent-based features only with the involvement of a parent or guardian. Contact us if you believe a child provided personal data improperly.
We use proportionate technical and organisational measures to protect personal data, but no internet service can guarantee absolute security. We may update this policy when the service, providers, or law changes. We will publish the new effective date here and provide additional notice where a change materially affects your rights.