Draft — pending legal review. This document is a working draft written for product development. It is not legal advice and has not been reviewed by counsel or checked against GDPR, CCPA or any other regime. Do not publish it in a live commercial deployment until a qualified lawyer has signed it off.
Privacy policy
Last updated: 22 August 2026 · Tourlies, Austin, Texas, USA
This policy explains what we do with personal data when you use Tourlies. Tourlies is the controller of that data. Questions or requests: privacy@tourlies.com.
1. What we collect
- Account data — name, email, password (hashed, never stored in plain text).
- Booking data — lead traveller name, email, phone, guest counts, dates, special requests, booking reference and voucher status.
- Payment data — handled by our payment provider. We receive the outcome, the last four digits, card brand and provider reference; we never see or store the full card number.
- Content you post — reviews, ratings and any photos you attach.
- Technical data — IP address, device and browser type, pages viewed, and cookies described below.
- Support correspondence — emails and call notes, so we can pick up where we left off.
2. Why we use it, and on what basis
- To perform your booking contract — taking payment, issuing vouchers, sending confirmations and reminders, passing the details the operator needs.
- Legitimate interests — fraud prevention, platform security, service analytics, and improving what we show you.
- Legal obligation — tax, accounting and anti-fraud record keeping.
- Consent — marketing email and non-essential cookies. You can withdraw consent at any time.
3. Who we share it with
- The operator you booked — lead traveller name, contact details, guest count and any special requests. They need it to run your experience and are independent controllers of what they receive.
- Payment processing — our payment provider, to take payment and issue refunds.
- Email delivery — our transactional email provider, to send confirmations and vouchers.
- Hosting and infrastructure — providers who store and serve the platform under contract.
- Authorities — where the law requires it, or to protect people from harm.
We do not sell personal data, and we do not share it with advertisers.
4. International transfers
Our infrastructure is primarily in the United States. Where data moves out of your region we rely on appropriate safeguards, such as standard contractual clauses with our processors.
5. How long we keep it
- Booking and payment records: 7 years, for tax and accounting.
- Account data: while your account is open, then 12 months.
- Reviews: published indefinitely, and anonymised if you close your account.
- Server and security logs: 90 days.
6. Your rights
Depending on where you live, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or port it elsewhere. Email privacy@tourlies.com from your account address and we'll respond within 30 days. You can also complain to your local data protection authority. We will not treat you differently for exercising these rights.
7. Cookies
We use strictly necessary cookies for sign-in sessions, checkout state and security — these can't be turned off without breaking the site. Anything analytical is aggregate and privacy-preserving. We do not run third-party advertising cookies.
8. Security
Passwords are hashed, traffic is encrypted in transit, access to production data is limited to staff who need it, and voucher codes are cryptographically signed. No system is perfect: if a breach affects you, we will tell you and the relevant authority as the law requires.
9. Children
Tourlies is not intended for under-18s. Children may of course join an experience — we ask for the details of the adult who books it, not theirs beyond a guest count.
10. Changes
We'll post updates here and change the date above. Material changes will also be emailed to account holders.
11. Contact
Tourlies, Austin, Texas, USA · privacy@tourlies.com. See also our terms of use and cancellation policy.