Privacy Policy
Last updated: 14 July 2026. This page explains, in plain language, what personal data Tourlio collects, why, who we share it with, and the rights you have over it — including under the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK, Law No. 6698).
Draft — pending legal review. This is a plain-English summary, not yet a binding legal document.
Who is responsible for your data
Tourlio ("Tourlio", "we", "us") operates the gettourlio.com website and the Tourlio mobile app, and is the data controller for the personal data described here. Company registration is being finalized; once complete, the registered legal entity and address will be published on this page. Until then, direct any privacy question to support@tourlio.com and we will respond as the data controller.
What we collect
Account data: name, email address, password (stored hashed by our authentication provider, never in plain text), profile photo, preferred language and currency, and whether you use Tourlio as a traveler or an operator. Booking data: the experience booked, date/time, number and type of guests, any note you add for the operator, and — only if you choose a pickup — your pickup address or a pinned map location. Communications: messages you send to operators or other travelers in a trip group chat, and support tickets you open with our team. Reviews: ratings, written reviews and any photos you attach. Operator data (operators only): business/legal name, country, tax ID, business type, contact phone, languages spoken, bio, and identity/business verification documents you upload for review. Technical data: IP address (used briefly for abuse/rate-limit protection, not stored long-term), device type and app version, and — only with your permission — your device's precise location (to drop a pickup pin) and a push-notification token (to deliver booking/message alerts).
Why we use it
To create and secure your account; to process bookings and let you and the operator communicate about them; to send booking confirmations, reminders and receipts; to show you relevant experiences and let operators manage their listings; to verify operator identity/business documents before they can publish or accept bookings; to provide the in-app AI assistant and trip-planning features you choose to use; to prevent fraud and abuse; and to comply with tax, accounting and consumer-protection obligations.
Who we share data with
We do not sell personal data. We use a small number of specialist service providers ("processors") who handle data on our behalf, each only for the purpose described: Supabase (database, authentication and file storage — hosts almost all the data listed above); Mapbox (maps and address/location lookups for pickup points); Resend (delivery of transactional emails such as booking confirmations and this policy's deletion-confirmation link); Anthropic (the Claude AI models that power the in-app assistant and operator-verification document analysis — see the AI section below); Upstash (short-lived IP-based rate limiting to stop abuse; no profile is built from it); DeepL (machine translation of listing content and app text into your language); and Vercel (web hosting and content delivery). Stripe is integrated for future card payments and operator payouts; as of this writing Tourlio bookings are reserve-first with no card charge, so no card data is processed by Stripe through Tourlio yet — this will be updated here before card payments go live. Operators, as the party fulfilling your booking, receive the booking details (name, party size, date, any note or pickup address) needed to run the experience. We disclose data to public authorities only when legally required.
AI features
Tourlio's in-app assistant, AI trip planner, and operator-document verification are powered by Anthropic's Claude models. When you use these features, the text you type (or, for operator verification, the document image you upload) is sent to Anthropic's API to generate a response or analysis. This content is processed under Anthropic's commercial API terms, which — unlike Anthropic's free consumer products — do not use your data to train their models. We retain AI conversation content only as long as needed to provide the feature and for the retention periods described below.
Payments
Tourlio does not currently charge cards for bookings — reservations are confirmed without payment, and you check in with a QR code. When card payments launch, they will be processed by Stripe; Tourlio will never see or store your full card number, and operators (as merchant of record) will receive only the transaction details needed to fulfill your booking.
Cookies and similar technology
We use a small number of first-party cookies: an authentication cookie that keeps you signed in (essential — the site cannot function without it), and functional cookies that remember your preferred display currency and, if you arrived via a referral link, which link you used. We do not use third-party advertising or cross-site tracking cookies.
How long we keep data
We keep account and booking data for as long as your account is active, and afterwards for as long as required by tax, accounting and consumer-protection law (typically several years for financial records). If you delete your account, we anonymize your personal details immediately (see "Deleting your account" below) but keep anonymized booking/payment/review records where retention is legally required.
International transfers
Our service providers (Supabase, Anthropic, Resend, Mapbox, Vercel, Upstash, DeepL) may process data outside your country, including in the United States. Where that involves transferring personal data out of the EU/EEA or Türkiye, we rely on the safeguards each provider offers (such as the EU Standard Contractual Clauses) to keep your data protected to an equivalent standard.
How we protect your data
Access to your data is enforced at the database level with row-level security, so other users can only ever see what the product intentionally shows them (e.g. your name on a booking an operator is fulfilling). Data is encrypted in transit (HTTPS/TLS). Identity/business verification documents are stored in a private, access-controlled location and only ever reviewed by authorized staff. Administrative access is protected with multi-factor authentication.
Your rights
Wherever you are, you can ask us to: access a copy of your personal data; correct inaccurate data; delete your data (see below); restrict or object to certain processing; and receive your data in a portable format. If you are in the EU/EEA, these are your GDPR rights and you may also lodge a complaint with your local data protection authority. If you are in Türkiye, these are your rights under KVKK Article 11, and you may apply to the Turkish Personal Data Protection Authority (Kişisel Verilerin Korunması Kurumu) if your request is not resolved. To exercise any of these rights, email support@tourlio.com.
Deleting your account
You can permanently delete your account and personal data at any time, from inside the app (Account → Delete account) or without signing in at gettourlio.com/delete-account.
Children
Tourlio is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact support@tourlio.com and we will delete it.
Changes to this policy
We may update this policy as Tourlio's features change (for example, when card payments launch). We will post the revised version here with an updated date, and, for material changes, notify account holders by email or in-app notice.
Questions
For anything not covered above, or to exercise any privacy right, contact us at support@tourlio.com.