Privacy Policy
Contact us
Frauengasse 7
8010 Graz
Privacy Policy
Last updated: 11 August 2026
The protection of personal data is important to us. In this Privacy Policy, we inform you about how we process personal data in connection with the use of our website, the Go-Yeah Portal, the Go-Yeah Studio and our other digital services.
This Privacy Policy applies to users of our website and platform, consumers, providers, prospective customers, business partners and other persons who contact us.
1. Controller
The controller responsible for the processing of personal data is:
Go-World OG i.G.
Frauengasse 7
8010 Graz
Austria
Email:
Website: go-yeah.com
Where this Privacy Policy refers to “Go-Yeah”, “we”, “us” or “our”, this means Go-World OG i.G. as the operator of the Go-Yeah platform.
No data protection officer has currently been appointed, as we currently assume that there is no statutory obligation to appoint a data protection officer.
2. General Information on Data Processing
We process personal data only in accordance with applicable data protection laws, in particular the General Data Protection Regulation, the Austrian Data Protection Act and the Austrian Telecommunications Act 2021.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, name, email address, telephone number, address, IP address, usage data, booking data, communication content or payment information.
We process personal data in particular for the following purposes:
providing and operating the website and platform
providing the Go-Yeah Portal
providing the Go-Yeah Studio for providers
creating, managing and displaying provider profiles
registering and managing user and provider accounts
processing contact, inquiry and support messages
forwarding booking or contact inquiries to providers
processing bookings, payments, vouchers and commissions
communicating with users, providers and prospective customers
newsletters, contact management, direct communication and customer support, where these functions are offered
analyzing and improving our website and platform
marketing, reach measurement and conversion tracking
protection against misuse, fraud and technical attacks
compliance with legal obligations
safeguarding and enforcing legal claims
3. Legal Bases for Processing
We process personal data on the following legal bases:
Performance of a contract and pre-contractual measures
Where processing is necessary for the performance of a contract with a data subject or to take pre-contractual measures, processing is based on Article 6(1)(b) GDPR. This applies in particular to provider accounts, SaaS services, booking inquiries, payments, support and contractual communication.
Legal obligation
Where we are legally required to process or retain data, processing is based on Article 6(1)(c) GDPR. This applies in particular to tax, corporate and accounting retention obligations.
Legitimate interest
Where processing is necessary for the purposes of our legitimate interests or the legitimate interests of third parties and the interests or fundamental rights and freedoms of the data subjects do not override those interests, processing is based on Article 6(1)(f) GDPR. This applies in particular to the secure operation of the platform, server logs, misuse prevention, direct communication with providers, the display of publicly available provider information, the processing of inquiries and the improvement of our services.
Consent
Where processing is based on consent, it is carried out on the basis of Article 6(1)(a) GDPR. This applies in particular to newsletters, non-essential cookies, tracking, marketing pixels, external media and certain analytics or marketing functions. Consent given may be withdrawn at any time with effect for the future.
4. Provision of the Website and Server Logs
When our website and platform are accessed, technically necessary data is processed in order to provide the website securely and reliably. This may include in particular:
IP address
date and time of access
page or file accessed
amount of data transferred
browser type and browser version
operating system
referrer URL
device information
error messages and technical log data
Processing is carried out for technical provision, system security, error analysis and misuse prevention. The legal basis is our legitimate interest pursuant to Article 6(1)(f) GDPR.
Server logs are currently planned to be stored for a maximum of up to one year, but generally for a shorter period, in particular where they are no longer required for security, error analysis or evidence purposes.
5. Hosting and Technical Infrastructure
According to the current technical setup, our platform uses in particular the following technical service providers:
Supabase
Supabase is used for backend functions, database, authentication, storage and technical platform functions. According to the current setup, the server location is Ireland. Backups are currently stored for up to 90 days.
Vercel
Vercel is used for the frontend, deployment, hosting and serverless functions. Vercel operates infrastructure worldwide. Technical access data may be processed in this context.
Processing is carried out for the provision, security and scalability of the platform. The legal bases are performance of a contract pursuant to Article 6(1)(b) GDPR, insofar as processing is required for registered users or providers, and our legitimate interest pursuant to Article 6(1)(f) GDPR in secure, stable and high-performance platform operation.
Where service providers process personal data on our behalf, we enter into data processing agreements pursuant to Article 28 GDPR where required.
6. User Accounts and Provider Accounts
User accounts and provider accounts may be created on the platform. Depending on the function and role, the following data may be processed:
name
email address
password or authentication data
telephone number
company name
address
VAT identification number
payment data
profile picture
interests and categories
provider and offer data
technical usage data
saved favorites or preferences
Processing is carried out for registration, login, account management, provision of platform functions, communication and contract processing. The legal basis is Article 6(1)(b) GDPR.
Where data is processed for security, misuse prevention or evidence purposes, processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR.
7. Provider Profiles and Go-Yeah Studio
Go-Yeah provides digital functions for providers to manage provider profiles, offers, content and marketing information. In this context, the following data may in particular be processed:
company name
legal form
contact persons
address and location data
email address
telephone number
website
VAT identification number
company register number
trade license
bank and payment information
offer data
images, logos and media
prices and availability
cancellation conditions
safety and participation information
communication and support data
performance and usage data
Processing is carried out for the provision of the Go-Yeah Studio, the display of provider profiles and offers, provider communication, billing, booking and payment processing, and the marketing of offers.
The legal basis is Article 6(1)(b) GDPR where processing is necessary for contract performance. In addition, we process data on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR in a functional, up-to-date and attractive platform.
8. Reverse Onboarding and Pre-Created Provider Profiles
Go-Yeah may pre-create, structure and display provider profiles on the platform based on publicly available information. The aim is to make regional leisure, experience and activity offers discoverable and to make it easier for providers to later claim, supplement or correct their profile.
Information may be processed from publicly available sources, including in particular:
provider websites
Google Business Profiles
publicly available social media profiles
tourism portals
booking platforms
other publicly available directories or sources of information
The following information may in particular be processed:
company name
names of sole proprietors or contact persons, where publicly visible
address
email address
telephone number
website
opening hours
descriptive texts
prices
images or placeholder images
social media links
categories
location data
publicly available offer information
Third-party descriptive texts may be summarized in substance, reformulated or structured in a suitable form. Images are used, where possible, only if a corresponding authorization exists or if license-free or otherwise suitable image sources are used.
Processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR. Our legitimate interest is to build a structured discovery platform for regional offers, make providers visible and make it easier for consumers to search for regional experiences.
Providers may request the correction, supplementation, claiming or deletion of their profile at any time. Corresponding inquiries may be sent to . We will review such inquiries and process justified requests within a reasonable period of time.
Once a provider profile has been claimed, the respective provider is responsible for the accuracy, currency and legality of the content provided.
9. Contact Forms, Inquiries and Communication
If users, providers or prospective customers contact us, we process the data provided in this context. This may apply in particular to the following functions:
general contact form
provider inquiry
demo request
booking inquiry
appointment coordination
newsletter registration
feedback or support inquiry
profile claiming
profile correction or profile deletion
The following data may in particular be processed:
name
email address
telephone number
message
preferred date
number of persons
provider or offer reference
payment status
technical metadata of the inquiry
Processing is carried out to process the respective inquiry and communication. The legal basis is Article 6(1)(b) GDPR where the inquiry relates to a contract or pre-contractual measures. In all other cases, processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in processing and documenting inquiries.
If an inquiry relates to a specific offer, the required contact details and inquiry information may be forwarded to the relevant provider. This is necessary so that the provider can process and respond to the inquiry or carry out a booking.
10. Booking Inquiries, Bookings and Forwarding to Providers
Through Go-Yeah, users may discover providers and offers, make contact, submit booking inquiries or, where available, make bookings.
Unless expressly stated otherwise, the contract for a specific leisure, experience or activity offer is concluded directly between the user and the respective provider. In this case, Go-Yeah provides the technical platform, mediation, communication and, where applicable, payment infrastructure.
In connection with booking inquiries and bookings, the following data may in particular be processed and forwarded to providers:
name
email address
telephone number
message
preferred date
number of persons
selected offer
booking status
payment status
special requests or relevant inquiry information
Processing is carried out for pre-contractual measures and booking processing pursuant to Article 6(1)(b) GDPR and for the purposes of legitimate interests pursuant to Article 6(1)(f) GDPR.
11. Payments, Vouchers and Payment Providers
Where paid services, provider packages, bookings, vouchers or other payments are processed via Go-Yeah, we process the payment and contract data required for this purpose.
At launch, the use of Stripe is planned in particular. Further payment methods such as Klarna, Amazon Pay, PayPal, Apple Pay or Google Pay may be added later.
The following data may in particular be processed in connection with payments:
name
email address
billing data
payment amount
payment status
transaction data
selected payment method
booking or order information
technical payment references
Complete credit card or payment data is generally not stored directly by Go-Yeah, but processed by the respective payment service provider.
Processing is carried out for contract processing and payment processing pursuant to Article 6(1)(b) GDPR, for compliance with statutory retention obligations pursuant to Article 6(1)(c) GDPR and for the purposes of legitimate interests pursuant to Article 6(1)(f) GDPR, in particular fraud prevention, payment documentation and enforcement of claims.
When using a payment service provider, the privacy information of the respective payment service provider also applies.
12. Newsletters, Contact Management and Communication
We may process personal data for contact management, processing inquiries, customer and provider communication and, where offered, sending newsletters.
The following data may in particular be processed:
name
email address
telephone number
company
role or user group
contact history
form content
newsletter registrations
interests and communication preferences
onboarding status
communication and interaction data
Processing may in particular take place for the following purposes:
managing contacts
processing inquiries
communicating with users, providers, prospective customers and partners
provider communication
support and customer care
demo and appointment coordination
profile claiming, profile correction or profile deletion
sending newsletters, where offered
documenting consents, unsubscribes and communication preferences
Newsletters are generally sent on the basis of consent pursuant to Article 6(1)(a) GDPR. You may unsubscribe at any time via the unsubscribe link in the newsletter or by email to .
Where communication is necessary for contract processing, provider support, processing inquiries or taking pre-contractual measures, processing is based on Article 6(1)(b) GDPR.
In all other cases, processing may be based on our legitimate interest pursuant to Article 6(1)(f) GDPR, in particular in efficiently processing and documenting inquiries, maintaining orderly contact management and ensuring professional communication with users, providers, prospective customers and partners.
If an external service provider for newsletters, contact management, CRM or marketing automation is used in the future, this Privacy Policy will be updated accordingly. Where required, we will enter into a data processing agreement with such service providers pursuant to Article 28 GDPR.
13. Cookies and Consent Management
Our website uses cookies and similar technologies. Cookies are small text files stored on the end device. Similar technologies may include local storage, pixels, tags, device identifiers or comparable methods.
We distinguish in particular between the following categories:
Necessary technologies
These are required to technically provide the website and platform, ensure security, enable logins, store settings or manage consent.
Analytics and statistics
These help us understand how our website and platform are used so that we can improve them.
Marketing
These are used to measure reach, campaigns, conversions and advertising, and to display interest-based content.
External media and third-party content
These enable the integration of services such as maps, videos, captcha services or other external content.
We use our own consent management solution. Users can use this solution to give, refuse or later change their consent. Consents are logged in order to be able to prove the selection made.
Technically necessary cookies and technologies are used on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR and to provide the platform. Non-essential cookies, analytics, marketing and external media functions are generally used only after consent pursuant to Article 6(1)(a) GDPR and Section 165 of the Austrian Telecommunications Act 2021.
14. Google Tag Manager
We may use Google Tag Manager to centrally manage tags and scripts. According to our understanding, Google Tag Manager itself does not create user profiles, but it may trigger other services if corresponding consent has been given.
Google Tag Manager is generally configured so that non-essential tracking or marketing services are loaded only after corresponding consent.
The legal basis, where technically required, is our legitimate interest pursuant to Article 6(1)(f) GDPR in efficient technical management of our website. Where consent-required services are triggered via Google Tag Manager, this is done on the basis of consent pursuant to Article 6(1)(a) GDPR.
15. Google Analytics 4
We may use Google Analytics 4 to statistically analyze the use of our website and platform. The following data may in particular be processed:
page views
clicks
duration of visit
interactions
form events
booking inquiries
purchases or payment events
technical device information
approximate location information
pseudonymous user identifiers
Google Analytics 4 is generally used only after consent. The legal basis is Article 6(1)(a) GDPR and Section 165 of the Austrian Telecommunications Act 2021.
Where possible, we use privacy-friendly settings, in particular IP anonymization or IP masking, Consent Mode and restrictions on data use. The specific configuration may be adapted depending on the technical setup.
16. Meta Pixel
We may use Meta Pixel to measure the effectiveness of advertising measures on Meta platforms such as Facebook and Instagram and to create audiences for advertising campaigns.
The following data may in particular be processed:
page views
clicks
form events
booking or purchase events
technical browser data
pseudonymous identifiers
where applicable, hashed contact data, if technically enabled and legally permissible
Meta Pixel is generally used only after consent. The legal basis is Article 6(1)(a) GDPR and Section 165 of the Austrian Telecommunications Act 2021.
17. TikTok Pixel
We may use TikTok Pixel to measure the effectiveness of advertising campaigns on TikTok and to optimize marketing measures.
In particular, page views, clicks, form events, booking events, purchase events and technical device information may be processed.
TikTok Pixel is generally used only after consent. The legal basis is Article 6(1)(a) GDPR and Section 165 of the Austrian Telecommunications Act 2021.
18. LinkedIn Insight Tag
We may use the LinkedIn Insight Tag to measure the effectiveness of LinkedIn campaigns and to analyze audiences for B2B communication.
In particular, page views, technical browser data, campaign interactions and pseudonymous identifiers may be processed.
The LinkedIn Insight Tag is generally used only after consent. The legal basis is Article 6(1)(a) GDPR and Section 165 of the Austrian Telecommunications Act 2021.
19. Google Maps
We may use Google Maps to display provider locations, experience locations or contact information on maps.
When Google Maps is used, data may be transferred to Google, in particular IP address, location data, device information and usage data.
Google Maps is loaded, where technically possible, only after consent. The legal basis is Article 6(1)(a) GDPR. Where a map is required for a function expressly requested by the user, processing may additionally be based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
20. YouTube and Vimeo
We may embed videos from YouTube or Vimeo in order to present content, providers, experiences or platform functions in a clear and illustrative way.
When embedded videos are played or loaded, data may be transferred to the respective provider, in particular IP address, device information, browser data, usage data and, where applicable, cookie information.
YouTube and Vimeo content is loaded, where technically possible, only after consent. The legal basis is Article 6(1)(a) GDPR.
21. Google Fonts
We use fonts for the consistent display of our website. Google Fonts should, where possible, be integrated locally so that no connection to Google servers is required when the website is loaded.
If fonts are technically loaded from Google servers, in particular the IP address and technical browser data may be transferred to Google. In this case, integration will be carried out only on an appropriate legal basis and, where required, after consent.
22. reCAPTCHA and Protection Against Misuse
We may use reCAPTCHA or comparable protection mechanisms to protect forms, registrations, logins or booking processes against spam, misuse and automated access.
In particular, IP address, device information, browser data, interaction data and technical verification values may be processed.
Processing is carried out to secure our website and platform. The legal basis is our legitimate interest pursuant to Article 6(1)(f) GDPR. Where consent is required, the service will be loaded only after corresponding consent.
23. AI-Supported Functions and Claude
We may use AI tools, in particular Claude, to support content creation, translation, categorization, SEO optimization, provider descriptions, data structuring and support processes.
The following data may in particular be processed:
offer data
company data
publicly available information
names of contact persons, where required
email addresses, where required
telephone numbers, where required
user messages, where required
other content necessary to process a function
We endeavor to limit personal data when using AI tools to what is necessary and, where possible, to avoid, remove or minimize such data.
AI-generated content may be reviewed before publication. Providers remain responsible for the accuracy, legality and currency of the content they approve or claim.
The legal basis is, depending on the processing activity, Article 6(1)(b) GDPR, Article 6(1)(f) GDPR or, where required, Article 6(1)(a) GDPR.
24. Reviews, Comments and User Content
The platform may provide review, comment or community functions. Users may publish content or submit reviews in this context.
The following data may in particular be processed:
name or username
review
comment
profile picture, if used
offer or booking reference
time of publication
technical metadata
Reviews and comments may be publicly visible. Content may be removed or restricted in the event of legal violations, misuse, insults, fake reviews or other violations of platform rules.
The legal basis is Article 6(1)(b) GDPR where the function is part of a user contract, and Article 6(1)(f) GDPR for providing a trustworthy platform and preventing misuse.
25. Minors
The platform is generally not directed at children. Persons under the age of 18 may use the platform only within the scope of statutory requirements and, where required, with the consent of their legal representatives.
Bookings by minors may be excluded or made subject to the consent of their legal guardians. Providers are responsible for correctly specifying age, health, safety and participation requirements.
If we become aware that personal data of minors has been processed unlawfully, we will take appropriate measures to delete or restrict the processing.
26. Recipients of Personal Data
Personal data may be disclosed, where required, to the following categories of recipients:
hosting and infrastructure service providers
technical service providers
newsletter, email, communication or contact management service providers, where used
payment service providers
providers in the case of contact or booking inquiries
tax advisors
accounting service providers
legal advisors
marketing and agency partners
support and communication service providers
authorities and courts, where legally required
other service providers used to provide our services
Disclosure takes place only where there is an appropriate legal basis, where it is required for contract performance, where there is a legal obligation, where consent has been given or where a legitimate interest exists.
27. International Data Transfers
Some of the service providers we use may be based outside the European Union or the European Economic Area or may process data outside the EU/EEA. This may in particular be the case with international technology, analytics, marketing, payment or AI service providers.
International data transfers take place only where the requirements of the GDPR are met. This may be based in particular on an adequacy decision by the European Commission, the EU-US Data Privacy Framework, standard contractual clauses or other appropriate safeguards.
Despite appropriate safeguards, a residual risk may exist in certain third-country transfers that authorities in the third country may access data and that data subjects may not have the same legal remedies there as within the EU.
28. Retention Period
We store personal data only for as long as required for the respective purposes or as long as statutory retention obligations apply.
According to the current planning, the following retention periods apply in particular:
server logs: generally shorter, maximum up to 1 year
backups: according to the current setup, up to 90 days
contact inquiries: for as long as required for processing, documentation and follow-up
contract and invoice data: generally 7 years pursuant to statutory retention obligations
newsletter data: until unsubscribe or withdrawal of consent
provider profiles: for as long as the profile exists or a legitimate interest in display, documentation or evidence exists
provider profiles after soft delete: up to 1 year
provider profiles after hard delete: according to current planning, up to 90 days in backups or technical systems
consent logs: up to 3 years
support inquiries: for as long as required for processing, documentation and enforcement of legal claims
booking data: depending on tax, contractual or legal relevance, up to 7 years or longer where legally required
Where data is no longer required and no statutory retention obligations or legitimate interests conflict with deletion, it will be deleted or anonymized.
29. Data Security
We implement appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.
These measures include in particular access restrictions, authentication, technical security measures, backups, logging, encryption, role-based permissions and organizational measures for handling personal data.
30. Rights of Data Subjects
Data subjects have the following rights in accordance with the statutory requirements:
right of access
right to rectification
right to erasure
right to restriction of processing
right to data portability
right to object
right to withdraw consent
right to lodge a complaint with a data protection supervisory authority
Requests to exercise these rights may be sent to .
Where processing is based on consent, this consent may be withdrawn at any time with effect for the future. The lawfulness of processing prior to withdrawal remains unaffected.
Where processing is based on legitimate interests, data subjects may object to the processing on grounds relating to their particular situation.
31. Right to Lodge a Complaint with the Data Protection Authority
Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection laws.
In Austria, the competent authority is:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
32. Changes to this Privacy Policy
We may update this Privacy Policy if our platform, our data processing activities, the service providers used or legal requirements change.
The current version is available on our website.
33. German Version Prevails
This Privacy Policy is provided in English for information purposes. The legally binding version is the German version. In the event of discrepancies between the German and English versions, the German version shall prevail.