Privacy statement

Last updated: 5 October 2026

The short version: we ask you for nothing. There is no account, no login, no newsletter and no form to fill in. You can read this entire site without telling us a single thing about yourself.

Even so, every visit to a website moves some data around, and now and then you click through to a partner from here. Below is exactly what happens then, who sees it, and what you can do about it.

Who we are

Rebels on the Road, established in the Netherlands and registered with the Dutch Chamber of Commerce under number 42009740, is the controller for the personal data described in this statement. You can reach us at info@rebelsontheroad.com.

Because we are based in the Netherlands, the European GDPR applies to everything on this page, wherever in the world you are reading from.

If you email us

Send us a message and we have your email address, your name and whatever you wrote. We use that to answer you and for nothing else. You do not go on a list, we do not sell your address and we do not email you again out of the blue. We keep messages for as long as they are useful to the conversation, and then we delete them.

What the website itself records

Server logs. The site runs at a hosting company. Like every web server, it records as standard which page was requested when, from which IP address and with which browser. That is needed to make the site work and to spot abuse. We do not read those logs to follow visitors around.

Photos and video. Everything you see here is served from our own domain. No image CDN, no video platform, nothing that loads a picture from someone else’s server while you read. That was not always true: until September 2026 the images came from an external media platform, and moving them onto our own site took a third party out of the loop for good.

Fonts come from our own site too, not from Google Fonts. So no request goes out to a font service either.

No social feeds. The Instagram photos at the bottom of the homepage are copies stored on our own domain, and the links to our accounts are ordinary links: nothing loads from Instagram or Facebook until you actually click one.

What stays in your own browser

Some pages have tools: checklists for your prep, a calculator, a trip planner. Anything you tick or type into one of those stays in your own browser so it is still there next time. Nothing is sent anywhere, we never see it, and it sits on no server. Clear your browser data and it is gone.

Visitor numbers

We count how often our pages are read, using Cloudflare Web Analytics. There is no Google Analytics on this site, no advertising pixel and no ad network.

That is a deliberate choice. This counter sets no cookies, stores nothing in your browser and does not recognise your device, so it cannot find you again tomorrow and it builds no profile of you. What it does record: which page was opened, which site you arrived from, roughly which country, and whether you are on a phone or a computer. That is all, and none of it leads back to you.

Clicks on booking buttons

We also count that a booking button was pressed. We write down three things: which page of ours it happened on, which partner the button pointed to, and whether it sat in a hostel card, a tour card or in the running text. That is it. No IP address goes with it, no cookie, no browser fingerprint and no number that could tie two clicks together, so there is never a trail of what you did.

What we see is a daily total, along the lines of: twelve people clicked a hostel from the Bangkok page.

Why we want to know: this site runs on bookings made through our links, and without that count we cannot tell which pages genuinely help someone and which are only read. Block it and the button still works, we just do not count it.

So there is nothing here for you to allow or refuse. If you would rather not be counted, block the script with an ad blocker or with the built in tracker blocking in Firefox, Safari, Brave or Edge. The site works fine without it.

This site earns its keep from bookings made through our links. How that works is explained in our affiliate disclosure; what matters here is your data.

When you press a booking button you leave our site. The link carries a code that tells the partner you came from us. Almost every partner sets a cookie at that moment, in your browser, on their own domain, so that a booking you make within a certain window is still credited to us. That window differs per partner and usually runs from a day to a month or more.

Three things worth knowing:

  • That cookie is not ours. The partner sets it, on their site, after your click. We cannot set it, read it or switch it off.
  • We see no personal data. What a partner sends back is a table of numbers: how many people clicked through and how many bookings came out of it. Not your name, not your email address, not your travel dates and not where you are sleeping.
  • From that click on, their policy applies. What the partner does with your data is in their own privacy statement and cookie notice. We have no say over it, so read it if it matters to you.

If you would rather not have that cookie, you can refuse it or remove it: through the cookie notice on the partner’s own site, or in your browser settings (under privacy, cookies or site data in Chrome, Safari, Firefox and Edge). Your booking goes through either way. We simply see nothing of it, and the commission is gone.

Because there is nothing to ask. We set no cookies to follow you, we have no ad network and we build no profiles. The checklists are purely functional and stay on your own device, and our visitor counter works without cookies and without device recognition. The only tracking in play is a partner’s, and that starts on their site, where they ask you themselves.

If that ever changes, a real choice comes with it and you make it yourself. Nothing gets switched on here quietly.

What we never do

We do not sell your data, we do not trade it and we do not hand it to advertisers. We do not try to work out who you are. And we do not use this site to chase you with ads somewhere else.

Your rights

You have the right to ask which data we hold about you, to have it corrected or deleted, to object to its use and to receive it in a readable file. In practice that almost always comes down to emails you sent us, because there is not much else.

Email us at info@rebelsontheroad.com and we will sort it out. If we cannot work it out together, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. If you live elsewhere in the EU you can go to your own national supervisory authority instead.

Children

This site is not aimed at children under sixteen and we do not knowingly collect data about them.

Security and changes

The site is reachable only over a secure connection (https) and we keep no file of visitor data ourselves. If anything in this statement changes, we update the date at the top. The current version is always here.