Skip to main content

Website Security

Your security is our priority.

We protect your connection with HTTPS encryption (SSL/TLS). Modern protections include HSTS, Content Security Policy (CSP), Permissions Policy, X-Frame-Options, X-Content-Type-Options, and Referrer Policy. Our site has achieved an A Security Rating in an independent HTTP Security Headers assessment. We regularly review and improve security to follow current best practices.

Secure Website
HTTPS Encrypted
A Security Rating

HTTPS Encryption (SSL/TLS)

Every page, form, and API call is protected by TLS encryption. Your booking details, messages, and payment information travel securely between your browser and our servers.

HTTP Strict Transport Security (HSTS)

We instruct browsers to always connect to us over HTTPS, preventing downgrade attacks and ensuring encrypted connections on every visit.

Content Security Policy (CSP)

A strict CSP helps block malicious scripts, inline code injection, and unauthorized data loading. Only trusted sources such as Google Fonts, Google Maps, and our own infrastructure are allowed.

Permissions Policy

We explicitly disable access to device features like camera, microphone, and geolocation. Your device stays under your control.

X-Frame-Options

Our pages cannot be embedded in hidden frames on other sites, protecting you against clickjacking attempts.

X-Content-Type-Options

Browsers are told not to guess the type of files we serve, reducing the risk of malicious content being disguised as something safe.

Referrer Policy

We send only the origin when you follow an external link, limiting how much browsing context is shared with third parties.

For details on browser storage, see our Cookie Notice.

Legal

Privacy Policy

Last updated 8 August 2026

Who we are

Navigate Dubrovnik is a private transfer, tour and concierge service based in Dubrovnik, Croatia. You can reach us on WhatsApp at +385 97 792 2181 or by email at dalijadevic@gmail.com.

What we collect

When you request a quote or booking we collect the details you enter in the form: name, phone number, email (if given), travel dates and times, pick-up and drop-off points, passenger and luggage numbers, flight or ship details, and any notes you add. If you post on the traveller community board we store your display name and message. We also keep basic, anonymous usage counts (for example, how often the WhatsApp button is clicked).

Why we use it

Solely to quote, confirm and deliver your transfer or tour, to answer your questions, and to keep the site working. We do not sell your data and we do not use it for advertising profiles.

Who we share it with

Only the service providers needed to run the site and your trip: our hosting and database provider, our email delivery provider, WhatsApp (Meta) when you choose to message us, our payment provider when you pay online, and any partner driver assigned to your journey. Each receives only what is necessary.

How long we keep it

Booking and quote records are kept for up to 5 years for accounting and dispute purposes. Community posts stay until you ask us to remove them. Anonymous usage counts are retained indefinitely as aggregates.

Your rights

Under the GDPR you can ask us to access, correct, export or delete your personal data, or object to its use. Message us on WhatsApp or email dalijadevic@gmail.com and we will respond within 30 days. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

Security

Data is stored on encrypted, access-controlled infrastructure. Payment card details never touch our servers — they are handled by our payment provider.

Cookies

See our Cookie Notice for what is stored in your browser and how to control it.