AlpacaBag
Personal Data Processing Policy
Full text of the policy of Individual Entrepreneur Tatyana Aleksandrovna Ionova on the processing and protection of personal data when using the AlpacaBag service.
I. General Provisions
1.1. In order to ensure full compliance with the requirements of federal legislation in the field of personal data protection, Individual Entrepreneur Tatyana Aleksandrovna Ionova (hereinafter referred to as the “Operator”) considers it among its most important tasks to adhere to the principles of legality, fairness, and confidentiality when processing personal data, as well as ensuring the security of data processing operations.
1.2. This Policy on the Processing and Protection of Personal Data of Individual Entrepreneur Tatyana Aleksandrovna Ionova (hereinafter referred to as the “Policy”) is characterized by the following features:
1.2.1. It has been developed to ensure the implementation of the requirements of the legislation of the Russian Federation in the field of personal data processing of personal data subjects when using the service for generating individual tourist routes, “AlpacaBag”.
1.2.2. It discloses the main categories of personal data processed by the Operator, the purposes, methods and principles of personal data processing by the Operator, the rights and obligations of the Operator when processing personal data, the rights of personal data subjects, and also includes a list of measures applied by the Operator to ensure the security of personal data during their processing.
1.2.3. It is a public document declaring the conceptual framework of the Operator’s activities when processing personal data of users of the website-service alpacabag.app.
II. Information about the Operator
2.1. Name: Individual Entrepreneur Tatyana Aleksandrovna Ionova.
2.2. Email address for inquiries from personal data subjects: privacy@alpacabag.ru
III. Legal Basis for Processing Personal Data
3.1. The Operator’s Policy on the processing of personal data is determined by the following main regulatory legal acts of the Russian Federation:
3.1.1. The Constitution of the Russian Federation.
3.1.2. The Civil Code of the Russian Federation.
3.1.3. Federal Law No. 152-FZ of July 27, 2006 “On Personal Data”.
3.1.4. Federal Law No. 149-FZ of July 27, 2006 “On Information, Information Technologies and Information Protection”.
3.1.5. Decree of the Government of the Russian Federation No. 1119 of November 1, 2012 “On approval of requirements for the protection of personal data during their processing in personal data information systems”.
3.1.6. Other regulatory legal acts.
3.2. In implementation of this Policy, the Operator has approved the following local regulatory legal acts:
3.2.1. Regulation on the processing of personal data.
3.2.2. List of measures to ensure the security of personal data.
IV. Purposes of Personal Data Processing
4.1. The Operator processes personal data exclusively for the following purposes:
4.1.1. Registration and authentication of the User on the AlpacaBag service.
4.1.2. Personalized generation of individual tourist routes (selection of locations, activities, dates, budget).
4.1.3. Displaying the status of route generation (in progress, ready, error).
4.1.4. Providing the ability to reload previously created HTML routes.
4.1.5. Remembering the User’s selected interface language.
4.1.6. Ensuring security and preventing unauthorized access to accounts.
4.1.7. Improving the quality of the service (using anonymized data).
V. Categories of Processed Personal Data, Sources of Their Acquisition
5.1. The following categories of personal data are processed in the Operator’s personal data information systems:
5.1.1. Account Data: email address (login), password (hashed), name (at User’s discretion). Source: User during registration.
5.1.2. Tourist Route Parameters: country, region, travel dates, budget, preferences for type of vacation and activities, number of travelers. Source: User when creating a route.
5.1.3. Generation History: date and time of requests, unique identifiers of generated HTML routes. Source: automatic recording during service operation.
5.1.4. Authorization Technical Logs: IP address, device type, browser (User-Agent), date and time of account login. Source: automatic collection during authorization.
5.1.5. Selected Interface Language: language preference (ru/en). Source: User’s choice or browser settings.
5.2. The Operator does not process biometric personal data.
5.3. The Operator does not process special categories of personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, health status, or intimate life.
VI. Basic Principles of Processing, Transfer, and Storage of Personal Data
6.1. In its activities, the Operator ensures compliance with the principles of personal data processing specified in Article 5 of Federal Law No. 152-FZ “On Personal Data”.
6.2. Personal data is stored in the Supabase cloud database (data centers located on the territory of the Russian Federation).
6.3. Access to Users’ personal data is restricted using the Row Level Security (RLS) mechanism — each User has access only to their own data and generated routes.
6.4. Generated HTML route files are stored in the Supabase object storage and are linked to the User’s account ID.
6.5. The Operator does not perform cross-border transfer of personal data to territories of foreign states that do not provide adequate protection for the rights of personal data subjects.
6.6. The Operator does not transfer personal data to third parties, except as required by the legislation of the Russian Federation (upon request from a court, law enforcement agencies), as well as to technical subcontractors (hosting provider, Supabase) on the basis of contracts that include an obligation to ensure confidentiality.
VII. Cookies and Local Settings
7.1. The AlpacaBag service website uses cookies and the localStorage mechanism for the following purposes:
7.1.1. Remembering the User’s selected interface language.
7.1.2. Storing the User’s consent status for cookie processing.
7.1.3. Maintaining the user session (authorization).
7.2. Types of cookies used:
7.2.1. Session cookies — for technical operation of the session, deleted when the browser is closed.
7.2.2. Persistent cookies — for storing language and cookie consent status (storage period — up to 1 year or until cleared by the User).
7.2.3. Strictly necessary cookies — for authentication and security (deleted when the session ends).
7.3. The User has the right to disable cookies in their browser settings, but this may affect the correct operation of the service (language interface reset, need to log in again).
VIII. Measures to Ensure the Security of Personal Data During Their Processing
8.1. When processing personal data, the Operator takes all necessary legal, organizational, and technical measures to protect them from unlawful or accidental access, destruction, alteration, blocking, copying, provision, distribution, as well as from other unlawful actions. The security of personal data is achieved, in particular, by the following methods:
8.1.1. Appointing an official responsible for organizing the processing of personal data.
8.1.2. Conducting internal control of compliance of personal data processing with the requirements of No. 152-FZ and regulatory legal acts adopted in accordance with it.
8.1.3. Familiarizing the Operator’s employees directly involved in the processing of personal data with the provisions of the legislation of the Russian Federation on personal data.
8.1.4. Using a database management system with RLS support (Supabase) to differentiate access at the row level.
8.1.5. Hashing User passwords (bcrypt or similar algorithm).
8.1.6. Encrypting data transmission channels using the TLS protocol version 1.2 and higher.
8.1.7. Regularly backing up personal data with encryption.
8.1.8. Identifying facts of unauthorized access to personal data and taking appropriate measures.
8.1.9. Establishing rules for access to personal data processed in the information system.
8.1.10. Monitoring the measures taken to ensure the security of personal data.
IX. Rights of Personal Data Subjects
9.1. The personal data subject (User) has the right to receive information regarding the processing of their personal data by the Operator.
9.2. The personal data subject has the right to demand that the Operator clarify their personal data, block or destroy it if it is incomplete, outdated, inaccurate, illegally obtained, or cannot be considered necessary for the stated purpose of processing, as well as to take measures provided by law to protect their rights.
9.3. The personal data subject has the right to delete their account along with their entire generation history and saved routes (except for data required to be retained by law — authorization logs for the last year).
9.4. The personal data subject has the right to withdraw consent to the processing of personal data by sending a corresponding request to the Operator.
9.5. To exercise their rights and protect legitimate interests, the personal data subject has the right to contact the Operator via email: privacy@alpacabag.ru. The Operator reviews any requests and complaints from personal data subjects within 10 business days.
9.6. The personal data subject has the right to appeal the Operator’s actions or inaction by contacting the authorized body for the protection of the rights of personal data subjects (Roskomnadzor).
9.7. The personal data subject has the right to protect their rights and legitimate interests, including compensation for losses and/or compensation for moral damage in court.
X. Personal Data Retention Periods
10.1. Account data and route parameters are stored for the entire duration of the User’s account usage and for an additional 30 days after its deletion (to allow for restoration).
10.2. Generation history is stored for the entire lifetime of the account and is deleted along with it.
10.3. Authorization logs (IP address, login time) are stored for 1 year.
10.4. Data on the selected interface language in cookies/localStorage is stored until the User changes the settings or until it is cleared by the browser.
10.5. After the specified periods expire, personal data is subject to automatic destruction.
XI. Contact Information and Final Provisions
11.1. The responsibility for organizing the processing and ensuring the security of personal data of Individual Entrepreneur Tatyana Aleksandrovna Ionova is assumed by myself (the Operator).
11.2. The authorized body for the protection of the rights of personal data subjects is the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor).
Roskomnadzor Address:
7, Building 2, Kitaygorodskiy Proyezd, Moscow, 109074
Phone: +7 (495) 987-62-82
Website: https://rkn.gov.ru
11.3. This Policy is an internal document of Individual Entrepreneur Tatyana Aleksandrovna Ionova, is publicly available, and is subject to posting on the official website of the service at: https://alpacabag.app/privacy.
11.4. This Policy is subject to change and amendment in the event of new legislative acts and special regulatory documents on the processing and protection of personal data, but at least once every three years.
11.5. Control over the implementation of the requirements of this Policy is carried out by the person responsible for organizing the processing of personal data of Individual Entrepreneur Tatyana Aleksandrovna Ionova.
11.6. The liability of officials of Individual Entrepreneur Tatyana Aleksandrovna Ionova who have access to personal data for failure to comply with the requirements of the norms regulating the processing and protection of personal data is determined in accordance with the legislation of the Russian Federation and the Operator’s internal documents.