Privacy Policy
Version 1.0. | Last updated 14 September 2026 | See previous version
MYMCO is an app that connects hikers, climbers, mountaineers and ski tourers with each other, and with independent mountain guides and guiding agencies for paid trips. This notice explains what personal data we collect, why we use it, who receives it and what you can do about it. If anything is unclear, write to help@mymcoapp.com.
Contents
- About this notice
- How to contact us
- What personal data we collect
- Why we use it and our legal basis
- Matching, ranking and moderation
- Who we share it with
- Sending data outside Europe
- How long we keep it
- Your rights
- How we protect your data
- Your choices
- Cookies
- Changes to this notice
- Contact us
1. About this notice
MYMCO OÜ (“MYMCO”, “we”, “us”), Õie tn 6-13, 93818 Kuressaare linn, Estonia, is the controller of the personal data described here. We follow the General Data Protection Regulation (Regulation (EU) 2016/679) and the Estonian Personal Data Protection Act.
The notice covers our App for iOS and Android, our website mymcoapp.com, the guide and agency dashboard and the services connected to them (the “Services”). It applies to people who plan or book trips (“Users” or “guests”), to mountain guides and guiding agencies and their staff (“Guides” and “Agencies”), and to people who visit the Website or contact support. Agencies must give this notice to any staff whose data they provide to us. Read it together with our Terms and our Community Guidelines in the App.
We are a marketplace, not a tour operator. A Guide who receives your details for a trip you booked decides for itself how it uses them and is responsible for that use (see section 6). The Services are for people aged 18 or over, and we do not knowingly collect data about children.
2. How to contact us
| Controller | MYMCO OÜ, Õie tn 6-13, 93818 Kuressaare linn, Estonia |
| Privacy questions and requests | help@mymcoapp.com – write “Privacy” in the subject line, or use Settings → Support in the App |
| Supervisory authority | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee |
3. What personal data we collect
The data below comes from you, from your use of the Services, and from others: other Users, our payment service provider, public registers, and the app stores and our technical providers. From the App Store and Google Play we receive install, purchase and crash information, and from the analytics and crash-reporting tools built into the App we receive device identifiers, the advertising identifier where you allow it, and diagnostic reports. We do not use your data for advertising or tracking across other companies’ apps and websites. We never sell your location data, and we do not request or use your location for advertising or analytics purposes.
| Category | What it includes |
| Account and profile | Your name, email address, telephone number, password, date of birth and photo; your activities and disciplines, experience and skill level, goals, the areas where you travel or work, and the languages you speak. |
| Trips and bookings | The trips you create, join, list or book, with dates, meeting points and prices; and your payments, payouts, refunds, cancellations and payment disputes. |
| Payment details | The payout account you register with us and the payment method you use at checkout. Full card numbers stay with our payment service provider, not with us. |
| Guide and Agency verification | Qualifications, certifications and memberships, evidence of liability insurance, trade register and VAT details, and the tax data we need for payouts and tax reporting. |
| Messages, ratings and content | Your messages in the App, photos, ratings and reviews, reports about other people, and your emails to support. |
| Health and emergency data | Health, dietary or emergency-contact information you choose to share for a trip. Sharing it is voluntary. |
| Usage and device data | Listings you view, searches, logins and times; device model, operating system, app version, IP address, device identifiers and crash reports. |
| Location | The approximate or precise location of your device, its latitude and longitude, when you give permission. If you decline, features that rely on precise location may not be available to you. |
| Safety and moderation records | Reports about content or behaviour, what we reviewed, and any warning, removal, restriction or suspension, with its reason. |
When you take part in a survey, focus group or market study, we collect your insights into our Services, your responses to our questions and any testimonial you give us. When you choose to take part in a promotion, event or contest, we collect the information you use to register or enter.
If you join our waitlist, we collect your first name, last name, email address and country of residence, and use them to tell you when the App is available to you. If you apply to become an ambassador, you may give us your social media handles, your favourite mountain activities, your motivation for joining and your experience in the mountains, and we use these to assess and administer your application.
You may choose to register or log in to the App using third-party accounts such as Apple, Google or Facebook. When you use social logins, we receive certain information from these providers, such as your name, email address and profile picture, as permitted by your privacy settings with the provider. We use this information only to create or authenticate your MYMCO account and provide you with access to the Services. Where you use Sign in with Apple and choose to hide your email address, we receive a relay address and can reach you only through it.
Please note that your use of these third-party services is subject to the privacy policies and terms of the respective providers. We encourage you to review their policies for more information: Apple, www.apple.com/legal/privacy; Google, policies.google.com/privacy; Facebook, www.facebook.com/privacy/policy.
Account, profile, trip, payment and verification data are needed to provide the Services and meet our legal duties; without them we cannot give you an account or let you book, list or be paid for a trip. Location, health and emergency data, marketing and non-essential cookies are voluntary.
4. Why we use it and our legal basis
We use your personal data only where we have a legal basis for it.
| Purpose | Legal basis |
| To create and manage your account, show you trips and members, let you message, apply, book, pay and be paid, and to give you support and service messages about a booking or payment. | Our contract with you |
| To check the qualifications, insurance and registration of Guides and Agencies, before we approve them and when documents expire. | Our legal obligation to identify the traders on our platform under the Digital Services Act, where it applies to us, and our legitimate interest in a safe marketplace |
| To prevent, detect and investigate fraud, fake accounts, harassment, misuse, and payments arranged outside the App. | Our legitimate interest in protecting Users, Guides and MYMCO |
| To review reports and content, and to remove content or suspend an account or a booking when our Terms or Community Guidelines are broken. | Our legitimate interest in a safe community, and our duties as an online platform |
| To keep records of trips, bookings, payments and incidents so that we can handle a complaint, a dispute or a claim. | Our legitimate interest in defending legal claims |
| To keep the Services secure, fix errors, and improve and develop features. | Our legitimate interest in secure and working Services |
| To keep accounting and tax records, and to report each year to the Estonian Tax and Customs Board what we paid Guides and Agencies, with a copy to them. | Our legal obligations, including the EU platform tax reporting rules (DAC7) |
| To run sanctions screening, and to give our payment service provider the data it needs for its anti-money-laundering checks. | Our legal obligation for sanctions screening; for the anti-money-laundering checks, our provider’s legal obligation and our legitimate interest in preventing misuse |
| To answer authorities, supervisory bodies and courts where we must. | Our legal obligations |
| To use your device location, to send you marketing, to use health or emergency data you share for a trip, to set non-essential cookies, to keep you on our waitlist or assess your ambassador application, to run a survey, focus group or market study you take part in, and to run a promotion, event or contest you enter. | Your consent and your explicit consent for health data |
You can withdraw your consent at any time, in your device settings, in the App, through the unsubscribe link in a marketing email, or by writing to help@mymcoapp.com. That does not affect what we did before. Where we rely on a legitimate interest, we use only the data we need for that purpose.
5. Matching, ranking and moderation
The App suggests trips and members and orders listings automatically. The main parameters are the activities and disciplines chosen, the experience and skill level stated, the goals stated, the dates available, and the location and area of the trip, and how closely these match. For Guides and Agencies, complete listings, fast replies and good ratings also improve visibility. We do not sell placement, and no payment to us changes the order of listings.
These suggestions are not decisions about you. We also run automatic checks for fraud and misuse, but a person at MYMCO decides whether to remove content or suspend an account or a booking; an automated flag can only lead to a short hold while that person looks at it. We tell you the reason for any such decision, and you can challenge it free of charge for at least six months by writing to help@mymcoapp.com.
6. Who we share it with
We do not sell your personal data. We share it only as set out below. We do not share your device location with anyone outside MYMCO.
| Who receives it | Why |
| Other Users, Guides and Agencies | Whatever is meant to be visible in the App – your profile, listings, trips and ratings. After a booking is confirmed, the Guide and the guest each get the contact and trip details they need. Do not put data in a listing or public profile that you would not want others to see. |
| Our payment service provider | To take payments, hold the trip price, make payouts, and handle refunds, disputes and fraud, sanctions and anti-money-laundering checks. |
| Our service providers | Hosting and storage, crash reporting, analytics, communication and support tools. They act on our instructions under a written contract, may not use your data for anything else, and are required to protect it to the same standard as this notice describes. |
| Our advisers | Accountants, auditors, insurers and lawyers who need it for their work for us. |
| Authorities, tax authorities and courts | Where the law requires it, including the yearly report on Guides and Agencies to the Estonian Tax and Customs Board or where we need it for a legal claim. |
| A new owner | If MYMCO is sold, merged or reorganised. The new owner must protect your data as described here. |
Guides and Agencies are separate controllers
When a Guide or an Agency receives a guest’s details for a trip – name, contact details, stated experience, and any health, dietary or emergency-contact information the guest shares – it decides for itself how it uses them. It is then a separate controller, not our processor, and it answers for its own use of the data. Its duties are in our Guide and Agency Terms. To ask a Guide what it holds about you, contact the Guide; we will help you find the details.
7. Sending data outside Europe
We keep your personal data in the European Economic Area where we can. Some providers — for example hosting, analytics or support tools — are outside it, mainly in the United States. We transfer data only where the European Commission has decided the country protects it adequately, including the EU–US Data Privacy Framework for providers certified under it, or under the Commission’s Standard Contractual Clauses with additional safeguards where they are needed. Write to help@mymcoapp.com for details.
8. How long we keep it
| Personal data | How long |
| Account and profile | While your account is open, plus 3 years. |
| Bookings, payments and accounting records | 7 years from the end of the financial year, as the Estonian Accounting Act requires. Data reported under the platform tax rules: at least 5 years. |
| Guide and Agency verification data | While the professional account is approved, plus 3 years. |
| Messages about a trip | 3 years after the trip, longer if there is a dispute or claim. |
| Ratings and reviews | While the account they concern is open; after that only in a form that does not identify you. |
| Reports, incidents and moderation records | 5 years after the case closes. |
| Support messages | 3 years after the case closes. Until you ask us to remove you, or 2 years after you join the waitlist or we decide on your application. |
| Device, usage and location data | Up to 14 months. We do not build a history of your movements. |
We may keep data longer where the law requires it, or for a legal claim we face or can reasonably expect. After that we delete it or make it anonymous.
9. Your rights
| Your right | What it means |
| Access | Ask what data we hold about you and get a copy. |
| Correction | Ask us to correct data that is wrong. You can change most of it yourself in the App. |
| Deletion | Ask us to delete your data, or delete your account and its data yourself in the App under Settings → Account → Delete account. Deactivating your account is not the same as deleting it. Where we must keep some data, for example accounting and tax records, we tell you what we keep and for how long. |
| Restriction | Ask us to pause our use of your data: while we check whether it is accurate, while we consider an objection, if our use was unlawful but you prefer a pause to deletion, or if you need the data for a claim. |
| Objection | Object where we rely on a legitimate interest. We then stop, unless we can show compelling grounds to continue and explain them. You can always object to marketing, and we stop. |
| Portability | Ask us to send the data you gave us to you or to another provider, in a format a computer can read. |
| Withdrawing consent | Withdraw any consent you gave, at any time. |
| Human review | Ask a person to review a decision about your account, content or booking, give your view, and contest it. |
| Complaint | Complain to a supervisory authority – see section 14. |
You can also ask us to delete your account and its data at mymcoapp.com/delete-account, without installing the App. To use a right, write to help@mymcoapp.com. Writing from your account email helps us find your data, but you can reach us another way if you no longer have access to it. We answer within one month, or tell you if we need up to two months more. It is free. We may ask you to confirm who you are.
10. How we protect your data
We use encryption of data in transit, access limited to staff who need the data, logging, backups and written contracts with our providers. No system is completely secure, so keep your password secret and tell us at help@mymcoapp.com if you think somebody else has used your account. If a breach is likely to put you at high risk, we notify the Estonian Data Protection Inspectorate within 72 hours and inform you without undue delay.
11. Your choices
| Your choice | How to use it |
| Location | Switch it on or off for the App in your device settings. The App still works without it, but location features are limited. |
| Push notifications | Switch them on or off in your device settings. We may still email you service messages, such as a booking confirmation. |
| Marketing | Change your settings in the App, use the unsubscribe link, or write to help@mymcoapp.com. |
| Health and emergency data | You choose whether to share it for a trip, and you can ask us to delete it afterwards. |
| What others see | You choose what you write in your profile and listings, and you can edit or remove most of it at any time. |
Before the App first uses your location, camera or photos, or the health, dietary or emergency-contact information you choose to share, it shows you a disclosure in the App explaining what is used and why, and asks for your permission. You can refuse, and you can withdraw any permission later in your device settings or in the App. Refusing does not stop you using the rest of the Services or anything you have paid for. MYMCO does not follow you during a trip and does not provide emergency, search or rescue services. In an emergency, call the local emergency number.
12. Cookies
Our Website uses the cookies it needs to work, and analytics cookies only if you agree in the cookie banner. A list of the cookies we use, what each one does and how long it lasts is at mymcoapp.com. Cookies are small text files stored on your device. Some are necessary for the Website to function, while others help us improve performance and provide analytics. Our Website uses them to recognise you, improve your experience and analyse use of our Services. You can manage or disable cookies through your browser settings, but disabling certain cookies may affect how the Website works.
The App uses similar identifiers for crash reporting and analytics. We use PostHog, an analytics platform hosted in the EU, to help us understand how visitors use our App so we can improve our Services. This may include masked session replay, which reconstructs a de-identified version of on-screen activity while hiding sensitive inputs from view. Session replay will only ever record users aged 18 or older. You can change your choice at any time in your browser, device or App settings.
13. Changes to this notice
We may update this notice. The new version applies when we publish it in the App and on the Website, and we keep the previous version available on request. We update our App Store privacy disclosures and our Google Play Data safety information at the same time so that they match this notice. Before an important change takes effect, we also tell you by email or by a notification in the App.
14. Contact us
Please contact us first at help@mymcoapp.com so that we can try to put things right. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee, or, if you live elsewhere in the European Economic Area, to the supervisory authority of your own country. You can also go to court.