Legal
Privacy policy
What we collect when you book a museum ticket, why we need it, how long we keep it, and how to make us stop.
Last updated 1 August 2026 · Version 3.1
Note. This site is a demonstration build. The text below is a working template written to reflect how a real museum booking service should behave — have a lawyer review and adapt it before you publish it anywhere real.
1. Who we are
Museums of Egypt is an independent visitor guide and ticketing front end. We are the data controller for the personal data described here. We are not part of the Ministry of Tourism and Antiquities and we do not act on its behalf.
Write to [email protected] for anything on this page.
2. What we collect
You give us this
- The name that goes on the ticket, your email address, and your phone number if you add one.
- Your country of residence, which some museums use for their own visitor statistics.
- The booking itself: museum, date, entry window, ticket types and any extras.
- Anything you type into the access-needs field. Treat that field as optional — only tell us what you want the museum to act on.
Your browser gives us this
- IP address, browser and device type, and the pages you looked at.
- Whether you accepted optional cookies. See the cookie policy.
What we never collect
- Card numbers. Payment is handled by our payment provider on their own systems; we receive a confirmation and the last four digits, nothing more.
- Passport or national ID numbers. Museum staff check ID at the gate against the name on the booking; we never hold a copy.
- Location tracking of any kind.
3. Why we collect it
- To perform the contract. We cannot issue a ticket without a name, an email address and a slot.
- Legitimate interest. Keeping the service working, preventing fraudulent bookings and resale, and understanding which pages are read.
- Consent. Optional analytics cookies and the occasional email about new museum openings. You can withdraw either at any time without affecting your booking.
- Legal obligation. Retaining transaction records for tax and accounting purposes.
Where we rely on consent, we ask for it separately and we do not treat silence as a yes.
4. Who else sees it
We share the minimum needed to get you through the turnstile:
- The museum you booked receives your name, entry window, ticket types and any access needs you told us about.
- Our payment provider processes the transaction under its own privacy terms.
- Our email provider delivers the confirmation and the ticket.
- Our hosting provider stores the booking record.
We do not sell personal data, we do not trade it, and we do not hand it to advertisers. If a public authority makes a lawful demand for data, we comply only to the extent the law requires and tell you where we are permitted to.
Some of these providers operate outside the European Economic Area. Where that happens, transfers are covered by standard contractual clauses or an adequacy decision.
5. How long we keep it
- Booking records: 24 months after the visit date, for refunds, disputes and re-issuing lost tickets.
- Accounting records: as long as tax law requires, then deleted.
- Access-needs notes: deleted 30 days after the visit.
- Analytics data: 14 months, in aggregate form.
- Mailing list: until you unsubscribe, and every email carries the link.
6. Your rights
Wherever you live, we will honour all of the following:
- Access — ask for a copy of what we hold about you.
- Rectification — have anything wrong corrected.
- Erasure — have it deleted, unless we are legally required to keep it.
- Restriction and objection — tell us to stop a particular use.
- Portability — receive your data in a machine-readable file.
- Withdraw consent — at any moment, for anything based on consent.
Email [email protected]. We answer within 30 days and we do not charge. If you are unhappy with the answer, you can complain to your national data protection authority — in Germany, that is the supervisory authority for the federal state where you live.
7. Security
Traffic runs over HTTPS. Booking records are encrypted at rest, access is limited to staff who need it for support, and we review those permissions quarterly. No system is perfect; if a breach occurs that puts you at risk, we will tell you and the relevant authority within 72 hours of becoming aware of it.
8. Children
The booking service is for adults. Children are welcome in every museum on this site, but a booking must be made by someone aged 18 or over. We do not knowingly collect data directly from children, and we delete it if we find we have.
9. Changes and contact
When this policy changes materially we will update the version line at the top and, for anything that affects an active booking, email the address on that booking. Older versions are available on request.
Data protection contact:
[email protected]
General enquiries:
[email protected]