Tour operators and their staff
Signing up and signing in
To create an account, you must give your business name and subdomain, country, currency, time zone, tour languages, name, email address, a password and where you heard about us; without them we cannot create it. Phone numbers, a sales currency and a pickup area are optional. We record who referred you, if anyone.
Signing in on tourtask.com creates a one-time sign-in link, with your IP address, for each business where your email address and password match. We keep these links until your user or that business is deleted.
Your account and staff users
For each user we store the name, email address, phone numbers, language, role, permissions and last login. Operators create their users, so we received your details from the operator that added you.
For chat agents, we record availability and last activity, to show travelers that someone is online. We keep a history of who changed bookings and some settings.
Operators may also record other details about their team, such as dates of birth, start dates, fees or payout details. We handle those as the operator’s processor.
Authorized staff see your account, users, invoices, usage, support chats and error logs in our admin tool, for support and billing. A few senior staff can download backups and the API request log to recover from failures and investigate problems.
Billing
Our monthly fee depends on the value of the bookings you record and your use of paid features such as SMS, WhatsApp and AI.
We store tax details you give us, such as tax number, legal name, business activity and address, to identify your business on the electronic tax documents for our fees.
When you pay, the provider you choose, such as Getnet, Khipu, Mercado Pago, PayPal or Transbank Webpay, receives what it needs, which can include your name, email address, phone number, IP address, browser type and the amount. You enter card details on the provider’s own page; we do not store card numbers. Payment notifications are copied to our accounting mailbox.
If an invoice stays unpaid, the account is frozen 10 days after it expires, and the business and its data are deleted 6 months later, after warning emails.
Payment provider applications
Our documentation pages have application forms for the Chilean providers PVS and Getnet, collecting company and contact details and, for PVS, the legal representative’s identity document, company documents and premises photos. We email them to the provider and to you, and a staff member keeps a copy, with the attached documents, until no longer needed to check it was sent.
Support, emails and the WordPress plugin
Backoffice support chats and screenshots are deleted after 14 days of inactivity; an AI assistant may answer first. We keep records of AI use, and unanswered questions with your last message, user and business.
We send account, billing, security and service emails, such as invoices, password resets and booking alerts; you can turn off several of them in your settings or with the link in the email. We may also email administrators about TourTask, such as new features or reactivating a frozen account. To stop them, write to info@tourtask.com.
Our WordPress plugin keeps your Business ID, Business Token and display settings in WordPress until uninstalled. The plugin itself sends us no usage data.
On pages with its widgets, and on every page if you turn on the chat widget, visitors’ browsers connect to our API, which receives and logs their IP address, browser details and what they enter; the chat widget does so each time a page opens.
The plugin’s support form sends us your name, email address, message, site address and the name and version of its theme. We email it to our support team and send you a copy; it is also kept in our API request log for 1 day and in backups for up to about 10 weeks. For what the widgets load, see “Booking, reviews and chat widgets”.
Services you connect
You can connect services such as WhatsApp, Messenger, Instagram, Telegram, your email inbox, Google Calendar, Google Ads, Meta ads, payment providers and travel agencies. We store the access details needed and exchange data with them on your instructions.
To connect Meta, you log in to Facebook and allow TourTask to manage your Pages’ and Instagram messages and your WhatsApp Business accounts. We read your Pages, Instagram accounts, business portfolios and WhatsApp numbers only so that you can choose what to connect.
We store the account’s ID and name, the WhatsApp number and business account ID, who connected it, and an access token (your Page’s or, for WhatsApp via Facebook Login, your personal Facebook token). We encrypt the token with AES-256-GCM. We store nothing else from your Facebook profile.
If you forward your business email to TourTask, we store every email sent to the forwarding address, and the chat assistant reads them to answer travelers.
Reselling and referrals
Other operators can find your business and public tours, to ask to resell them. A referral partner who referred you sees your business name, subdomain and join date.