Privacy Policy

Last updated: 9 September 2026 Effective: 9 September 2026

This Privacy Policy explains how Hell’s Highway (“we”, “us”, “G3 Ops”) collects, uses, and protects personal data in connection with the G3 Operations tour-planning and tour-execution service (the “Service”), available at g3ops.com and as a web/mobile application.

We are established in the Netherlands and process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Dutch data-protection law.


1. Who we are

The data controller for the personal data described in Section 3.1 is:

We are not required to appoint a Data Protection Officer, but the contact above handles all data-protection requests.

2. Controller and processor — an important distinction

The Service handles two kinds of personal data with two different roles:

Where we act as your processor, our handling is governed by our Data Processing Agreement (see Section 12), and you are responsible for having a lawful basis to enter that data and for informing the people it concerns.

3. What data we collect and why

3.1 Data we collect as controller

Account data (guides / account owners). When you sign in with Google, we receive your name, email address, and Google account identifier. We use this to create and secure your account and to identify you within the Service.

Tour manager data. When invited to a tour, a tour manager provides an email address, which is used to send the invitation and to authenticate them via a one-time code.

Billing data. Payments are processed by Stripe. We do not receive or store your full card number. We store your Stripe customer identifier, subscription tier, subscription status, billing interval, and related subscription details (such as subscription and billing-period identifiers) so we can manage your plan and entitlements.

Technical and log data. Our infrastructure providers automatically process technical data such as IP address, device and browser information, and access logs, for security, abuse prevention, and reliability.

3.2 Data we handle as processor

Tour content. Anything you enter into a tour — including any personal data about tour managers, drivers, clients, or others — is stored and processed on your behalf to provide the Service. We do not use it for our own purposes.

3.3 Drivers

Drivers view a tour through a temporary read-only shared link, which may be protected by a PIN, and are not required to create an account. We do not collect a driver’s account data. Any personal data about a driver that appears in a tour is tour content you control (Section 3.2).

We rely on the following GDPR Article 6 legal bases for the data we control:

5. How we use personal data

We use personal data to provide, secure, and support the Service; to authenticate users; to process subscriptions and send service and billing communications; to comply with legal obligations; and to detect and prevent abuse or misuse. We do not sell personal data and do not use it for advertising.

6. Service providers (subprocessors) and sharing

We share personal data only with the providers we need to run the Service. Each is bound by a data-processing agreement and appropriate safeguards.

Provider Purpose Location / safeguard
Google Ireland Ltd / Google LLC (Firebase) Database, authentication, hosting Primary data stored in the EU (europe-west1, Belgium); EU-US Data Privacy Framework and SCCs for any transfer
Stripe Payments Europe Ltd / Stripe, Inc. Subscription billing and payment processing EU/US; DPF and SCCs
Sendinblue SAS (Brevo) Transactional and invitation emails France (EU)
Geoapify GmbH Route and travel-time calculation, when you use the automatic drive-time feature Germany (EU)
Cloudflare, Inc. Sales website and edge services EU/US; DPF and SCCs

The app also loads its typefaces from Google’s font service, which means your browser’s IP address reaches Google when a page loads. We intend to serve these fonts from our own domain to remove that request.

We may also disclose data where legally required, or to protect our rights, safety, or property.

7. International transfers

Our core application data (accounts and tour content) is stored in the EU. Some providers are US-based; where personal data is transferred outside the EEA, we rely on the EU-US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.

8. Retention

We keep personal data only as long as we need it for the purposes in this Policy, then delete or anonymise it. Our retention periods are:

9. Your rights

Under the GDPR you have the right to access, rectify, erase, or restrict processing of your personal data; to data portability; to object to processing based on legitimate interests; and to withdraw consent. To exercise any of these, contact privacy@g3ops.com.

If your request concerns tour content where we act as a processor, we will refer you to the relevant account owner (controller) or act on their instructions.

Deleting your account. You can delete your account yourself at any time from your account settings — no request or support ticket needed. Deletion immediately cuts off all access to your tours (including any tour managers’ and drivers’ access to them) and cancels your subscription, then permanently erases your account and Content after a 30-day recovery period. You can cancel the deletion during that period simply by signing back in. A restored account keeps its tours, but previously issued driver and tour-manager share links are not restored and must be created again. Billing records are retained as described in Section 8.

You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

10. Security

We use industry-standard measures including encryption in transit, authenticated and role-based access, tenant isolation, and access controls on our infrastructure. No system is completely secure, but we work to protect your data and to notify you and the authorities of any breach where legally required.

11. Cookies and local storage

The Service uses only strictly necessary cookies and local storage — to keep you signed in, maintain your session, and enable the app to work offline as a progressive web app. We do not use advertising or third-party tracking cookies. If we introduce analytics in future, we will update this Policy and request consent where required.

12. Data Processing Agreement

Where we process tour content on your behalf, we do so under our Data Processing Agreement (DPA), which forms part of our Terms and sets out the Article 28 GDPR terms, our security measures, and our sub-processors. Business and institutional customers may request a countersigned copy at privacy@g3ops.com.

13. Children

The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal data from children.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated through the Service or by email. The “Last updated” date above reflects the current version.

15. Contact

Questions or requests: privacy@g3ops.com.

Note: The retention periods in Section 8 and the self-service erasure process in Section 9 reflect the data-deletion and retention controls implemented for the Service. Retention on infrastructure surfaces (backups and logs) is enforced through our cloud provider’s configuration and our documented internal retention policy.