Privacy & cookies
Last updated: 24 August 2026
What we collect, and why. Reading this site requires no account. Three things are optional, and you choose each of them:
- An account, if you open one. Accounts are optional — a trip can be viewed from its private link without one. If you do open one we store your email address; your first and last name; your phone number if you choose to give one; your password as a PBKDF2-SHA256 hash with a random per-account salt and an iteration count, never the password itself; a record of each signed-in session; short-lived tokens for confirming your address (24 hours) and resetting a password (1 hour); and a count of failed sign-in attempts with any lockout time, which is what stops someone guessing their way in. We never see your password, and we cannot tell you what it is — only help you set a new one.
- The booking form. It is not switched on. The booking page exists, but the endpoint behind it refuses every submission until our travel agency registration completes, so nothing you type there is saved and no booking can be made today. When it does open you will have to be signed in to use it, and what it stores is the choices you make on the page: which package, your start date, how many are walking, how many single rooms, and any extras you tick — extra nights, a Porto airport pickup, the Santiago–Porto bus. Saved beside those choices are the price and deposit we work out here on the server, a booking reference and a private link to the trip. The form does not ask for your name, email address or phone number: those are taken from your account. When you tick the box accepting the booking conditions, we also record which version of them you accepted, the time on our server, and the language of the page, so either of us can show later what the contract said.
- Email you send us. If you write to [email protected] we keep the correspondence for as long as it’s relevant to answering you.
Processors. Cloudflare (hosting, the database behind your account, email routing and the form endpoints), Resend (sending confirmation and password-reset email) and Stripe (card payments, once bookings open). All three process data under GDPR-compliant terms. We do not use an email marketing platform.
How long we keep it. Your account stays until you ask us to delete it. Sessions expire after 30 days and the expired and signed-out records are cleared from the database a week later. The token that confirms your address lasts 24 hours and a password-reset token lasts one hour; both stop working when they expire. Email you send us is kept for as long as it is relevant to answering you — ask us sooner and we delete it sooner.
Sessions, and how to end them. Signing in stores a session on our server and puts a matching token in a cookie. Only a SHA-256 hash of that token is stored, so a copy of our database would not let anyone sign in as you. Sessions expire after 30 days, and signing out revokes the record immediately rather than just clearing the cookie — so it ends on every device using it. Alongside each session we keep a hashed fingerprint of the browser and IP it started from, to spot a stolen session; the raw values are not stored.
Deleting an account. Write to [email protected] and we delete the account, its sessions and its tokens. If you have a booking with us we have to keep the booking records themselves for as long as Portuguese tax and consumer law requires, but they stop being linked to a login. Accounts that are never confirmed are removed after 30 days.
Your rights. Under the GDPR you can ask for access, correction, erasure, restriction, portability, or object to processing — write to [email protected] and we will act within 30 days. You can also complain to the CNPD (Comissão Nacional de Proteção de Dados, cnpd.pt).
Data controller. Until the company is registered, José Carvas as operator of this site. Contact: [email protected]. This page will be updated with the company name, NIPC and RNAVT number once registration completes.[COMPANY NAME], Unipessoal Lda, NIPC [NUMBER], registered office [ADDRESS]. Contact: [email protected].
Payments
No payment can be taken yet — the agency registration is not complete, so nothing on this site charges a card. When bookings do open, cards are handled by Stripe, and this is what that means in practice: you leave this site for Stripe’s own checkout page, you type your card number there and not here, and we never see or store it. Bom Caminho holds only what Stripe hands back — a payment reference, the amount, the currency and whether it succeeded.
What we send Stripe to open a checkout is your email address, the amount, and a description of what you are paying for, plus our own booking reference so the payment can be matched to your trip. We also tell Stripe which version of the booking conditions you accepted, and in which language. Stripe is the data controller for the card details themselves and processes them under its own privacy policy.
Cookies & analytics
This site runs no analytics and no tracking scripts, and sets nothing for advertising. There is nothing to accept or decline, because nothing here follows you anywhere.
This site sets three cookies, none of them for advertising or analytics. bc_csrf is set the moment you LOAD a page carrying a form — the sign-in, registration, password and account pages — not when you sign in; it is a random value your browser mints and sends back with the form, which is how we know the submission came from our page and not somebody else’s. It expires after two hours. The other two arrive only when you actually sign in. __Host-sx is the session itself — it is marked HttpOnly so no script can read it, and Secure so it never leaves over plain HTTP. bc_csrf guards forms against being submitted from another site. bc_in holds the single character 1, so the page knows to show “Account” instead of “Log in”; it identifies nobody. Signing out clears all three.
External links
Guides may link to other websites for reference. Those sites have their own privacy policies; we have no control over, and receive nothing from, what happens there.