TourTask
FeaturesPricingDemo
Sign up
  1. Home
  2. Privacy policy

DocumentationContact

Privacy policy

Contents

  1. Who we are
  2. At a glance
  3. When we are controller and when we are processor
  4. Visitors to tourtask.com
  5. Tour operators and their staff
  6. Travelers booking with an operator
  7. Tour businesses we contact and referral partners
  8. Cookies and similar technologies
  9. Who receives data
  10. International transfers
  11. How long we keep data
  12. How we protect data
  13. Your rights
  14. European Economic Area and United Kingdom
  15. Chile
  16. Brazil
  17. Mobile apps
  18. Google user data
  19. Artificial intelligence
  20. How to delete your data
  21. Children
  22. Changes to this policy
  23. Contact us

Who we are

Last updated: September 26, 2026

Policy version: 1

TourTask makes booking and management software for tour and activity operators.

TourTask is run by TourTask SpA, Chilean tax ID (RUT) 77.381.727-8, Kai Tuoe s/n, 2770000 Hanga Roa, Easter Island, Chile. “TourTask”, “we” and “us” mean TourTask SpA.

An “operator” is a tour or activity business that uses TourTask. A “traveler” is a person who books with an operator or contacts one.

For any privacy question or request, email us at info@tourtask.com.

This policy covers tourtask.com and its subdomains, including operators’ booking pages and the backoffice; our booking, reviews and chat widgets and WordPress plugin; the TourTask Chat and TourTask Sales apps; the referral portal; and the emails, messages and notifications we send.

At a glance

  • We are the “controller” for operators’ accounts and staff users, website visitors, referral partners and tour businesses we contact.
  • For travelers’ booking data, the operator is the controller and we are its “processor”. Contact the operator first.
  • InMotion Hosting runs our servers in the United States, where many of our providers are. TourTask SpA is in Chile.
  • Our chat assistants are AI, running on Claude models from Anthropic.
  • In the European Economic Area (EEA) and the UK, and where we cannot tell your location, Google Analytics on tourtask.com runs only if you allow it. Elsewhere it is on by default, and you can turn it off.
  • We do not sell personal data.
  • You can ask for a copy of your data, or ask us to correct or delete it. See “Your rights” and “How to delete your data”.
  • You can object at any time to our marketing emails, and to uses based on our legitimate interests. See “Your rights”.

When we are controller and when we are processor

The controller decides why and how personal data is used. The processor handles it on the controller’s behalf.

Where TourTask is the controller

Visitors to tourtask.com; operators’ accounts and staff users; billing and support; messages to TourTask’s own WhatsApp, Messenger and Instagram accounts; our emails to tour businesses; the referral program; security, abuse prevention and technical logs; Google Calendar sync; and mobile app device and sign-in data and push tokens.

Where TourTask is a processor

When a traveler books with or contacts an operator through TourTask, the operator is the controller, and we process the data for it using the providers in “Who receives data”. This covers bookings, passenger details, payment status, reviews, messages, emails sent for the operator, its records about guides and other contacts, and booking details we write into staff members’ Google Calendars.

The operator’s own privacy policy applies. Apart from the uses below, we do not use this data for our own purposes.

Traveler-related data we use for our own purposes

  • Security and technical logs of requests to our systems, with the IP address and data sent, which can include booking and health details, used only to run, debug and secure the service.
  • Chat abuse prevention: a random visitor ID kept in your browser, used with your IP address to limit abuse. In our abuse records we store the ID and a hashed code of your IP address.
  • Our widgets and hosted pages: we decide which outside services they load, which details our chat form requires, how the advertising banner works and which bookings are reported to advertising accounts.
  • Messages kept after an operator leaves: our central copy of messages to a deleted operator’s channels, and its forwarded emails. We hold them as controller until you ask us to delete them.
  • Support chat for cruise travelers: travelers who log in to a shore excursion page can open a support chat with TourTask, which we handle as controller.

Visitors to tourtask.com

Our servers receive your IP address, browser type and the pages you request, to deliver the site, keep it secure and fix errors. Failing pages may send us an error report with the page address and browser type.

Contact form and support chat

The contact form requires your name, email address, a subject and your message, because we need them to answer you. It goes to our team mailbox, with a copy to you, and stays until no longer needed for your request.

The support chat requires your name, email address, phone number and first message, so that we have complete contact details for each conversation. If you prefer not to give a phone number, use the contact form.

An AI assistant may answer first, and our team can take over. If the assistant cannot answer, it may keep the question and your last message to improve our help content.

Chats are deleted from our live database 14 days after the last activity; copies stay in our API request log for 1 day and in backups for up to about 10 weeks.

Messaging TourTask on WhatsApp, Messenger or Instagram

We receive your messages, profile name and account ID (on WhatsApp, your phone number). An AI assistant may answer first. The conversation is deleted after 14 days of inactivity. We keep our central copy of your incoming messages until you ask us to delete it.

Tour operators and their staff

Signing up and signing in

To create an account, you must give your business name and subdomain, country, currency, time zone, tour languages, name, email address, a password and where you heard about us; without them we cannot create it. Phone numbers, a sales currency and a pickup area are optional. We record who referred you, if anyone.

Signing in on tourtask.com creates a one-time sign-in link, with your IP address, for each business where your email address and password match. We keep these links until your user or that business is deleted.

Your account and staff users

For each user we store the name, email address, phone numbers, language, role, permissions and last login. Operators create their users, so we received your details from the operator that added you.

For chat agents, we record availability and last activity, to show travelers that someone is online. We keep a history of who changed bookings and some settings.

Operators may also record other details about their team, such as dates of birth, start dates, fees or payout details. We handle those as the operator’s processor.

Authorized staff see your account, users, invoices, usage, support chats and error logs in our admin tool, for support and billing. A few senior staff can download backups and the API request log to recover from failures and investigate problems.

Billing

Our monthly fee depends on the value of the bookings you record and your use of paid features such as SMS, WhatsApp and AI.

We store tax details you give us, such as tax number, legal name, business activity and address, to identify your business on the electronic tax documents for our fees.

When you pay, the provider you choose, such as Getnet, Khipu, Mercado Pago, PayPal or Transbank Webpay, receives what it needs, which can include your name, email address, phone number, IP address, browser type and the amount. You enter card details on the provider’s own page; we do not store card numbers. Payment notifications are copied to our accounting mailbox.

If an invoice stays unpaid, the account is frozen 10 days after it expires, and the business and its data are deleted 6 months later, after warning emails.

Payment provider applications

Our documentation pages have application forms for the Chilean providers PVS and Getnet, collecting company and contact details and, for PVS, the legal representative’s identity document, company documents and premises photos. We email them to the provider and to you, and a staff member keeps a copy, with the attached documents, until no longer needed to check it was sent.

Support, emails and the WordPress plugin

Backoffice support chats and screenshots are deleted after 14 days of inactivity; an AI assistant may answer first. We keep records of AI use, and unanswered questions with your last message, user and business.

We send account, billing, security and service emails, such as invoices, password resets and booking alerts; you can turn off several of them in your settings or with the link in the email. We may also email administrators about TourTask, such as new features or reactivating a frozen account. To stop them, write to info@tourtask.com.

Our WordPress plugin keeps your Business ID, Business Token and display settings in WordPress until uninstalled. The plugin itself sends us no usage data.

On pages with its widgets, and on every page if you turn on the chat widget, visitors’ browsers connect to our API, which receives and logs their IP address, browser details and what they enter; the chat widget does so each time a page opens.

The plugin’s support form sends us your name, email address, message, site address and the name and version of its theme. We email it to our support team and send you a copy; it is also kept in our API request log for 1 day and in backups for up to about 10 weeks. For what the widgets load, see “Booking, reviews and chat widgets”.

Services you connect

You can connect services such as WhatsApp, Messenger, Instagram, Telegram, your email inbox, Google Calendar, Google Ads, Meta ads, payment providers and travel agencies. We store the access details needed and exchange data with them on your instructions.

To connect Meta, you log in to Facebook and allow TourTask to manage your Pages’ and Instagram messages and your WhatsApp Business accounts. We read your Pages, Instagram accounts, business portfolios and WhatsApp numbers only so that you can choose what to connect.

We store the account’s ID and name, the WhatsApp number and business account ID, who connected it, and an access token (your Page’s or, for WhatsApp via Facebook Login, your personal Facebook token). We encrypt the token with AES-256-GCM. We store nothing else from your Facebook profile.

If you forward your business email to TourTask, we store every email sent to the forwarding address, and the chat assistant reads them to answer travelers.

Reselling and referrals

Other operators can find your business and public tours, to ask to resell them. A referral partner who referred you sees your business name, subdomain and join date.

Travelers booking with an operator

What the operator can collect through TourTask

  • Contact and booking details: name, email address, phone numbers, country, language, tours, dates, number of people, prices and payment status.
  • Passenger details, such as names, ages, email addresses, phone numbers, nationality and spoken languages, and if the operator asks, passport number, gender, height, weight, shoe size, disability, pregnancy, allergies and diet. Some of these are health data.
  • Travel details, such as your hotel or pickup point, arrival and departure dates, flight or transport numbers and, for shore excursions, your cabin and group.
  • Notes, reviews, ratings and uploaded payment receipts.
  • Ad click IDs, campaign (UTM) details and affiliate codes from the link you arrived with.
  • Messages you send the operator by website chat, WhatsApp, Messenger, Instagram, Telegram or email.

Your name and email address are always required to book online; the operator decides what else is. Without them you cannot book online, but you can contact the operator directly.

The data comes from you, a seller using TourTask Sales, the operator’s staff (by entry, import or AI filling from an email), the operator’s chat assistant, or online travel agencies and resellers such as Viator and GetYourGuide.

How it is used

  • To manage your booking and run the tour with the operator’s guides, drivers and partners.
  • To email you for the operator, including confirmations, reminders, review requests and follow-ups that may promote its tours. Review requests and follow-ups include an unsubscribe link.
  • To take payment through the operator’s payment provider, which receives what it needs, such as your name, email address, phone number, the amount and the booking reference. Card details go directly to the payment provider’s page or secure form fields; we do not store card numbers.
  • To let the chat assistant answer you and, if you ask, look up or create a booking.
  • To show reviews the operator publishes: your first name, rating, comment and the tour name.
  • If the operator sets it up, to report bookings to its advertising accounts.

Your booking link

Booking emails and vouchers link to your booking page. Anyone with the link can see your booking, including contact and passenger details, and pay for it. Keep it private.

Advertising measurement set up by the operator

If an operator connects its Meta or Google Ads account, we report its confirmed bookings from the last 30 days, including phone, in-person and reseller bookings: the first email address and the first phone number recorded among the booking’s passengers, hashed; any ad click ID; and the booking number, time, value and currency.

Meta and Google compare the hashed codes with their own users’ details, so that they can link the booking to you.

We do not report your booking if you declined the advertising banner. We do if you accepted, did not answer or saw no banner, or booked another way, such as by phone.

The operator decides whether to connect its accounts and is responsible for having a legal basis. We are responsible for how the banner works and which bookings are reported. For operators’ own tags, see “Cookies and similar technologies”.

Tours run by another operator

The operator running a resold tour sees the name on the booking and the passenger details the seller collected, and can cancel the booking, which emails you.

Shore excursion groups

Shore excursion group members see each other’s names and cabin numbers on the group page and get group messages by email. If the operator turns it on, booking emails also list members’ names, email addresses and cabins.

Chat and messaging apps

TourTask, not the operator, requires your name, email address and phone number in the chat widget, so that the operator has complete contact details. If you prefer not to give them, contact the operator another way.

On messaging apps, we receive your messages, account ID (on WhatsApp, your phone number) and name or username. Staff can see your Messenger or Instagram profile picture, loaded from Meta, not stored. We do not download media you send. If you email an operator that forwards its inbox to us, we keep your whole email.

An AI assistant may reply for the operator, and staff get a push notification with your first name. Conversations stay while the operator’s account exists, and our central copy of incoming messages stays even after that account is deleted. We delete a conversation and our central copy on request (see “How to delete your data”).

Your requests

Send requests about your booking data to the operator. If you send them to us, we forward them and help the operator respond. For data we use for our own purposes, write to info@tourtask.com.

Tour businesses we contact and referral partners

Tour businesses we contact about TourTask

We collect tour businesses’ contact details from public sources (TripAdvisor listings, their websites and tourism directories such as Chile’s SERNATUR registry), and our team adds some by hand.

We collect the business or contact name, email address, phone number, website, location, language and TripAdvisor link, rating and review count, and email the business about TourTask through Twilio SendGrid, from no-reply@tourtaskupdates.com, based on our legitimate interest in offering TourTask to tour businesses.

Every email has an unsubscribe link. Unsubscribing, a bounce or a spam report stops our emails. Unsubscribing marks your record, which we keep until you ask us to delete your details.

After a deletion request, we keep your email address and choice so that we do not email you again. To object or ask for deletion, write to info@tourtask.com.

Referral partners

Partners earn a commission when businesses they refer pay TourTask. To join, you must give your name, email address and a password, and confirm your email. We pay through PayPal, so without a PayPal address we cannot pay you.

We store your account, payout settings, earnings, payouts and the businesses you referred. Your referral link stores your code in a cookie for 60 days, to credit you. An automatic self-referral check applies (see “Artificial intelligence”).

Cookies and similar technologies

Cookies are small files websites store in your browser. Similar technologies include local storage and session storage.

On tourtask.com

  • _ga and _ga_V0LBS4GCKX (Google Analytics): usage measurement, kept up to 2 years. Set for the tourtask.com domain, so they may also reach our subdomains.
  • tt_ref: a referral partner’s code, when you open our sign-up page through a referral link. Kept for 60 days.
  • tt:support-chat (local storage): continues your support chat across pages until you clear your browser data; its session expires after 30 days.
  • tourtask.public.cookie-consent.v1 (local storage): your analytics choice, until you clear your browser data.
  • Technical items, such as a language cookie we may set, deleted when you close the browser.

Apart from Google Analytics, these are set without asking for your consent, in every region. Every page also loads flag images from jsDelivr, which receives your IP address. In the sign-up form, Google Maps loads only if you limit your pickup area; connecting Meta loads Facebook’s login script.

Google Analytics and your choices

Google Analytics 4 measures how tourtask.com is used. Google receives your IP address, browser details and each page’s title and address, sent without query parameters except campaign tags (utm_…). We tell Google Analytics not to use advertising storage, ad personalization or ad user data.

  • In the EEA or the UK, or if we cannot tell where you are, it runs only after you choose “Allow analytics” in our banner.
  • Elsewhere it runs by default. Turn it off at any time with “Cookie preferences” at the bottom of our pages; passenger list pages have none, so use the link on any other page.
  • If your browser sends a Global Privacy Control or Do Not Track signal, it never loads.
  • When you turn it off, we stop it and delete its cookies.

We do not use marketing cookies on tourtask.com. Our widget demo can load the demo business’s advertising tags, if any, and the widget services below.

Learn more: How Google uses information from sites or apps that use its services.

To apply the right regional privacy settings on tourtask.com, we estimate your country from your IP address on our own servers, using a local copy of the DB-IP IP-to-Country Lite database (CC BY 4.0). Your address is not shared with anyone for this. IP Geolocation by DB-IP

In the TourTask backoffice and the referral portal

authToken and referralAuthToken keep you signed in for a limited time; NEXT_LOCALE (language) and, in the backoffice, bizSlug (subdomain) last 1 year. Technical items store display preferences and chat availability. No analytics or advertising tracking is used; flag images from jsDelivr and, on some pages, Google Maps load.

On booking pages we host for operators

On every page we host at an operator’s tourtask.com subdomain, including booking, review, unsubscribe and sign-in pages, we set NEXT_LOCALE and bizSlug (language and subdomain, 1 year) and technical items without asking for your consent, and authToken for shore excursion sign-in. The widget items, services and operator tags below apply too.

Booking, reviews and chat widgets

Our widgets, on operators’ websites or through our WordPress plugin, set no cookies of their own, but store in your browser:

  • tourtask.checkoutForm.v1 (local storage, no expiry): the booking form as you type it, with your cart and the contact and passenger details you enter, which can include health details.
  • tourtask.consent.v1 (local storage): your answer to the advertising banner.
  • tourtask.purchaseTracked.v1.… (local storage): stops a purchase being counted twice. Written only when tracking is allowed.
  • tt:chat: plus the operator’s subdomain, and tt:chat:visitor (local storage): your chat session, and a random anti-abuse visitor ID that stays until you clear your browser data.
  • tourtaskBookingAid and tourtaskBookingAttribution (session storage): affiliate code, ad click ID and campaign details from your link, cleared when you book or close the tab.
  • Technical items, such as payment QR codes.

Contact details and most passenger answers stay, even after booking, until you next open the checkout on that site; passengers’ ages and cabin numbers until you clear your browser data. On a shared computer, clear it after booking.

Except tourtask.purchaseTracked.v1.…, these are stored without asking for your consent, in every region. Ad click IDs and campaign details are saved with your booking even if you decline the banner, but it is then not reported to the operator’s advertising accounts.

TourTask chose these services, which load with the widgets without consent, in every region, and receive your IP address and browser details:

  • Cloudflare, which delivers the widget files.
  • Stripe’s script, wherever the booking widget runs, even if the operator does not use Stripe. Stripe may set cookies and collect device and browsing signals to prevent fraud.
  • Flag images from jsDelivr in the booking form, booking page and country or phone pickers; the image requested shows the country or language selected.
  • Google Maps, with our Google key, when you choose a hotel or pickup point with a location, or open a tour map.

Payment services the operator uses, such as PayPal or Amazon Pay, load their scripts when their payment form or button appears.

The operator’s own advertising tags

An operator may add its own Meta Pixel or Google Ads tag to the widget; on pages we host, our code decides when they load. They can set cookies such as _fbp, _fbc, _gcl_au and _gcl_aw. On tourtask.com subdomains, these may be set for the whole domain, where other operators’ tags can read them.

Their scripts download when the page opens, so Meta or Google receives your IP address and browser details even before you answer the banner.

When the operator has added these tags, the widget shows a banner, and the tags send tracking events only if you accept. Events include the page address and, for a booking, its number, value and currency.

If the operator’s website has its own IAB Transparency and Consent Framework tool, our banner is not shown and the tags send no tracking events from your browser.

To change your banner answer, clear that website’s data in your browser. The operator’s own policy covers its other cookies.

Who receives data

We share personal data only as described in this policy. We do not sell personal data.

Service providers and platforms we send data to

  • InMotion Hosting (United States): runs our servers, which hold our website, apps, API, databases, backups, files and mail.
  • Anthropic (United States): AI for the chat assistants and other AI features.
  • OpenAI (United States): AI for some features that are not chat, where we enable it.
  • Google (United States): Analytics, Maps and address search, Cloud Translation, Firebase Cloud Messaging, and Google Calendar and Google Ads when you connect them.
  • Cloudflare (United States, with servers worldwide): delivers our widget files.
  • jsDelivr (a public network with servers worldwide): delivers flag images.
  • Stripe (United States): its script loads with our booking widget and may collect fraud-prevention signals. Operators can also use Stripe for payments.
  • Twilio SendGrid (United States): sends our emails to tour businesses.
  • Twilio (United States) and ConnectUS (Chile): send operators’ SMS messages to their staff and guides.
  • Meta Platforms (United States): delivers WhatsApp, Messenger and Instagram messages.
  • Telegram: delivers messages on Telegram channels an operator connects.
  • Expo (United States) and Apple (United States): deliver push notifications.
  • Getnet, Khipu, Mercado Pago and Transbank (Chilean payment services) and PayPal (United States): process payments of TourTask invoices. PayPal also sends referral payouts.

Most of these providers process data only for us, or for the operator we work for. Some, such as messaging platforms, payment providers and Google Maps Platform, also use it under their own privacy policies.

Where a provider processes data for us, we require it to protect the data at least as well as this policy describes, and to use it only to provide its service to us.

Other recipients

  • The operator a traveler books with and, for resold tours, the operator that runs the tour.
  • Services an operator connects, such as payment providers, travel agencies, Meta and Google.
  • The public, when an operator publishes your review: your first name, rating, comment and the tour name.
  • Referral partners: the name, subdomain and join date of businesses they referred.
  • PVS and Getnet (Chile): merchant applications you send them through our website.
  • Authorities and courts, when the law requires it, or to establish, exercise or defend legal claims or protect our users’ safety.
  • A buyer or successor, if TourTask is sold or merged. We would require the buyer to keep protecting your data as this policy describes, and would transfer data received from Google only with your explicit prior consent.

International transfers

TourTask SpA is in Chile. Our servers and most providers are in the United States, and Cloudflare and jsDelivr serve files from many countries. Your data may therefore be processed outside your country.

Neither the European Commission nor the UK has found that Chile offers adequate data protection. For the United States, the EU and UK adequacy decisions cover only organizations certified under the EU-US Data Privacy Framework or its UK Extension. Where the law requires it, we rely on:

  • the European Commission’s Standard Contractual Clauses
  • the UK International Data Transfer Agreement, or the UK Addendum to those clauses
  • the recipient’s certification under the EU-US Data Privacy Framework and its UK Extension

Chile: the Agencia de Protección de Datos Personales will decide which countries offer adequate protection, and has published no such list. Where Chilean law requires it, we rely on contractual clauses with each recipient that give adequate safeguards.

Brazil: Brazil’s data protection agency (ANPD) has not recognized Chile or the United States as adequate. Where the LGPD treats our sharing as an international transfer, we rely on the ANPD’s standard contractual clauses or, where the transfer is needed to perform a contract with you, meet a legal obligation or exercise rights in legal proceedings, on Article 33(IX) of the LGPD.

You can ask for a copy of the safeguards at info@tourtask.com.

How long we keep data

  • Business data, including users, bookings, passenger details, reviews, chats, invoices, payment records, change history, sign-in links, chat abuse records, SMS and conversion records, import files and integration errors: until the business is deleted, either at the operator’s request or 6 months after the account is frozen for an unpaid invoice.
  • Invoices and payment records from our earlier billing system: kept after the business is deleted, until you ask us to delete them.
  • Payment receipts uploaded by travelers: as long as the booking.
  • Cancelled bookings are kept like other bookings. When an operator removes a user, the account is deleted, but bookings keep the names and passenger details on them. Some users can only be removed by us; see “How to delete your data”.
  • Conversations on an operator’s channels: while its account exists, or until we delete one on request.
  • Our central copy of incoming messaging and email messages (operators’ and our own) and forwarded emails: kept even after the business is deleted, until you ask us to delete them or we no longer need them to run the channel.
  • Channel connection details and tokens: until disconnected. If the business is deleted, its tokens are deleted with it; the connection details are deleted when you ask us to delete the business.
  • TourTask’s own support chats and conversations with our messaging accounts: 14 days after the last activity.
  • Unanswered assistant questions, with the message behind them, and AI use records: until no longer needed for support and our help content.
  • API request log, with the data sent and the IP address: 1 day, then up to about 10 weeks in backups. Exports from it, to investigate a problem: until newer exports replace them.
  • Central error log: 90 days.
  • Web server and application logs (which can include page addresses, email addresses in links, browser details and IP addresses) and emails that failed to send: as long as needed to run and fix the service.
  • Messages in our team mailboxes, such as contact messages, support requests, sign-up notices, payment notifications and payment provider applications with their attachments: until no longer needed for their purpose.
  • Mobile apps: sessions until 60 days after expiry; sign-in and action log, with installation ID and IP address, 90 days; push tokens while the user exists.
  • Tour businesses we contact: until you ask us to delete your details; we then keep your email address and your choice. Unsubscribing marks the record but does not delete it.
  • Referral partner data: while the partner account exists.
  • Google Calendar event records: 35 days after the event. Shared “TourTask” calendar record: until you ask us to delete it.
  • Google Analytics event data: kept by Google for up to 14 months, depending on our setting.
  • Cookies and browser storage: see “Cookies and similar technologies”.

Backups

We back up our business database hourly and our platform database daily, and keep hourly backups for 24 hours, daily for 7 days and weekly for 10 weeks. Deleted data, including the API request log, can stay in backups for up to about 10 weeks.

How we protect data

Our security measures include:

  • encrypted connections (TLS) to our website, apps and API
  • AES-256-GCM encryption for Google Calendar tokens, for the access tokens of connected WhatsApp, Messenger and Instagram channels, and for the signing keys of email channels
  • an IP address allowlist, with emailed approval, for TourTask’s internal admin tool
  • rate limits against automated abuse of our API
  • a firewall on our servers
  • regular database backups

Our internal admin tool can be used only by TourTask staff we have authorized, from approved IP addresses, and we grant access to its areas (such as businesses, chats and billing) person by person.

No system is completely secure. Where the law requires it, we will tell you, the operator concerned and the data protection authority about a personal data breach that affects your data.

Your rights

TourTask SpA is established in Chile, so Chilean data protection law applies wherever you live, and your local law may add rights. Depending on the law that applies, you have the right to:

  • Access: know whether we process your data, and get a copy.
  • Correction of inaccurate or incomplete data.
  • Deletion of your data.
  • Restriction: have us limit or block how we use your data.
  • Portability: get your data in a portable format, or sent to another company.
  • Withdraw consent at any time, without affecting what we did before.
  • Not be subject to solely automated decisions with legal or similarly significant effects, and have a person review an automated decision.
  • Complain to a data protection authority.

Your right to object

Where we use your data based on our legitimate interests, you can object at any time, for reasons related to your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.

You can always object to direct marketing, including our emails to tour businesses. We will then stop using your data for it.

To object to marketing emails, use their unsubscribe link or, for our emails to operators’ administrators about new features or reactivating a frozen account, write to info@tourtask.com.

How to make a request

Email info@tourtask.com saying what you want and which TourTask services you use. We may ask you to confirm your identity, for example by replying from the address we have for you.

Travelers: send requests about your booking data to the operator (see “Travelers booking with an operator”).

Operators’ staff can ask their administrator to correct their account details, and can change some settings, such as language, under Settings.

We respond within the legal deadline that applies to you, free of charge unless the law allows a fee. Complaints to the same address are acknowledged within 30 days, investigated and answered with the outcome.

European Economic Area and United Kingdom

This section applies in the EEA and the UK, under the GDPR and the UK GDPR.

Our legal bases

  • Contract: providing TourTask, including sign-up, billing, support and connected services, where you are the customer yourself, such as a sole trader. If you act for a company, we rely on our legitimate interests instead: see “Your team’s accounts”.
  • Contract: running the referral program with our partners.
  • Consent: Google Analytics in the EEA, the UK and where we cannot tell your location, app push notifications, and Google Calendar permissions. Withdraw it with “Cookie preferences”, in device settings, or by disconnecting Google Calendar.
  • Legal obligation: meeting obligations EU or UK law places on us, such as answering data protection requests.

We rely on our legitimate interests for these purposes (our interest follows each one):

  • Your team’s accounts: accounts, apps, sign-in security and notifications for the administrators, staff, sellers and guides an operator adds. Interest (ours and the operator’s): its team can use the service.
  • Signing in on tourtask.com: checking your password against each business that uses your email address. Interest: one place to sign in.
  • Security: preventing abuse, fixing errors, and keeping backups, logs and chat abuse records. Interest: a safe, working service.
  • Widgets and hosted pages: Cloudflare, jsDelivr and Google Maps, and estimating your country to apply consent rules. Interest: pages that work reliably.
  • Questions and help content: answering you and improving our help content. Interest: supporting users and prospects.
  • Marketing: emailing tour businesses and operators’ administrators about TourTask, and keeping a do-not-contact list. Interest: promoting TourTask and respecting your choice.
  • Referrals: crediting partners and checking for self-referrals. Interest: a fair referral program.
  • Payment provider applications: sending them and keeping a copy. Interest: helping operators start taking payments.
  • Tax and authorities: keeping invoices and payment records and answering lawful requests, as Chilean law requires. Interest: complying with the laws that apply to us.
  • Google Calendar: keeping your shared “TourTask” calendar record after you disconnect, to reuse it if you reconnect. Interest: avoiding duplicate calendars. You can ask us to delete it.
  • Legal claims: establishing, exercising or defending them. Interest: protecting our rights.
  • Business transfer: passing data to a buyer if TourTask is sold or merged. Interest: reorganizing while the service continues.

For travelers’ data, the operator decides the legal basis. If it requires health data, such as disability, pregnancy or allergies, it is responsible for a legal basis and an Article 9 GDPR condition, such as your explicit consent.

Where we need data to provide a service, the relevant section says so. Without it, we cannot provide that service.

Response time and complaints

We answer within one month. For complex or numerous requests we may take two more months, and will tell you why within the first month.

You can complain to the data protection authority in the EEA country where you live or work, or where you believe the problem happened (see the list of EEA data protection authorities), or in the UK to the Information Commissioner’s Office.

Chile

Chilean data protection law applies to our processing wherever you live, so this section applies to everyone.

Law 21.719 amends Law 19.628 on the protection of private life and takes effect on 1 December 2026. When we last updated this policy, a bill in Congress proposed moving this date to 1 December 2027.

Until Law 21.719 takes effect

You can ask, free of charge, for information about your data, its source and recipients, and have it modified, deleted or blocked. If we do not answer within two business days, or refuse, you can ask the civil court where TourTask SpA is based to order us to act.

Law 19.628 allows processing with your express consent or where a law authorizes it. Without consent, it allows processing of data from sources accessible to the public when that data is commercial in nature, or is needed for direct-response commercial communications or direct sales, such as our emails to tour businesses.

Once Law 21.719 takes effect

You will have the rights of access, rectification, erasure, objection, portability and blocking, and can object to, and not be subject to, automated decisions, including profiling, with legal or significant effects on you. You can always ask for an explanation, human intervention and a review, and give your point of view.

We will confirm receipt and answer within 30 calendar days, extendable once by up to 30 days. We will answer a request to block your data, while we handle a correction, deletion or objection, within two business days.

If we reject your request or do not answer in time, you can complain to the Agencia de Protección de Datos Personales within 30 business days of our answer or its due date.

Our bases of lawfulness will then match the EEA and UK section: contract, legitimate interests (to which you can object at any time), consent, legal obligations and, for legal claims, the exercise or defense of a right before courts or public bodies.

Google Analytics runs by default in Chile. Once Law 21.719 takes effect, we rely on our legitimate interest in understanding how visitors use tourtask.com, to improve it. You can object at any time with “Cookie preferences”.

Brazil

In Brazil, the General Data Protection Law (LGPD, Law 13.709/2018) gives you the right to:

  • confirmation that we process your data, and access to it
  • correction of incomplete, inaccurate or outdated data
  • anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the LGPD
  • portability to another provider
  • deletion of data processed with your consent, except where the LGPD allows us to keep it, such as for a legal obligation
  • information about who we share your data with, and whether you can refuse consent and what happens if you do
  • withdraw consent at any time
  • object to processing on a basis other than consent that does not comply with the LGPD
  • review of solely automated decisions affecting your interests, such as the self-referral check, and information about their criteria

You, or a legally appointed representative, can make these requests free at info@tourtask.com, or petition the National Data Protection Agency (ANPD) or a consumer protection body.

We confirm whether we process your data straight away where we can. If you ask for a full statement, including source, criteria and purpose, we send it within 15 days of your request.

Our legal bases match the EEA and UK section: contract, legitimate interest, consent, legal obligations and, for legal claims, the regular exercise of rights in legal proceedings.

Google Analytics runs by default in Brazil, based on our legitimate interest in understanding how visitors use tourtask.com, to improve it. You can object at any time with “Cookie preferences”.

Some details are a condition of using a service: the details marked as required to sign up; your name, email address and phone number to start a chat on tourtask.com or on an operator’s website; and your name, email address and a password to join our referral program. Without them, you cannot use that service. You can still exercise all the rights listed above.

Mobile apps

TourTask SpA offers two mobile apps: TourTask Chat, for an operator’s staff to answer travelers’ chats, and TourTask Sales, for sellers to book tours for travelers in person.

Both are for people with a TourTask login from an operator; you cannot create an account in the apps. The operator’s administrator creates accounts in the backoffice, and can remove most there.

What the apps send to us

  • your email address and password when you sign in
  • a device ID: the Android ID (unchanged on reinstall), Apple’s identifierForVendor, or a random ID
  • your IP address and the app’s user agent, when you sign in and act in the app
  • a push notification token, if you allow notifications
  • in TourTask Chat: your replies, chat availability and actions on conversations, such as assigning, closing or marking them as spam
  • in TourTask Sales: bookings and payments you record, with travelers’ contact, travel and passenger details, which can include passport numbers and health details, and your hotel or pickup searches

TourTask Chat also downloads the operator’s chats, with travelers’ names, contact details and messages. TourTask Sales downloads its tours and your bookings, with customers’ names and email addresses.

We use this to sign you in, secure accounts, send push notifications and run the apps. We keep sessions until 60 days after expiry, the sign-in and action log for 90 days, and push tokens while your user exists; they are switched off when you sign out.

Like every API request, app requests and our replies are also kept in our API request log for 1 day, then in backups for up to about 10 weeks.

Push notifications

We send them through Expo to Apple Push Notification service (iOS) and Google Firebase Cloud Messaging (Android); turn them off in your device settings. Chat notifications show “New message” and the traveler’s first name, sales notifications the booking number and business name, never message text.

Who receives app data

  • Expo, Apple and Google, as our service providers, to deliver push notifications: the push token, identifiers Firebase Cloud Messaging creates on Android, and the notification text, which can include a traveler’s first name.
  • Google Maps Platform (independent controller, own terms): TourTask Sales hotel and pickup searches, sent from our servers.
  • InMotion Hosting, our service provider, which runs our servers.
  • WhatsApp, Messenger, Instagram or Telegram, under their own terms: your replies to travelers who wrote to you there.
  • Anthropic, as our service provider, when the chat assistant answers in a conversation you also replied to: that conversation, including your replies.

Permissions, tracking and device storage

The apps ask only for permission to show notifications, do not use your location, camera, photos, contacts or microphone, and contain no advertising or analytics tracking. On Android, Google’s Firebase Cloud Messaging library is used only for push notifications.

  • Both apps keep your sign-in details, including a refresh token, in the device’s secure storage (Keychain on iOS, Keystore on Android). On iOS, sign-in details in the Keychain can remain after you delete the app.
  • TourTask Chat keeps recent conversations in an encrypted cache, deleted when you sign out or with “Wipe local data” in Settings.
  • TourTask Sales keeps your cart, the tour catalog, your settings and the details of your last checkout, including the traveler’s contact and passenger details, on the device.
  • Uninstalling the app removes these checkout details from the device, but your device’s own backups, such as Android’s automatic backup to your Google account, may keep a copy.

Deleting your app account

Ask your administrator to remove your user, or see “How to delete your data”. Some users can only be removed by us. Write to info@tourtask.com and we will remove them. Removal deletes your sessions and push tokens.

Google user data

TourTask connects to Google in two ways: Google Calendar sync, where staff connect their own Google account, and Google Ads conversion upload, where operators connect their Google Ads account.

Google Calendar sync: permissions

When you connect, Google asks you to grant:

  • openid and email: your Google account ID and email address.
  • https://www.googleapis.com/auth/calendar.app.created: to create TourTask’s own calendars and add, read back, change and delete TourTask’s events on them.
  • https://www.googleapis.com/auth/calendar.events.owned: Google describes it as seeing, creating, changing and deleting events on calendars you own. We ask for it each time you connect and use it only for TourTask’s own events on your main calendar, if you choose it.

What we access and write

Events go to a calendar per business named “TourTask — ” plus the business name (the default), one shared “TourTask” calendar for all businesses on the same Google account, or your main calendar. If you change this, we move the events.

We add your assigned activities or, if you choose and may see it, the business’s whole operations calendar. Events hold the tour name, booking number, name on the booking, number of people, tour parts, assigned guides or providers, pickup place, notes and a booking link. Group departures list the name of each booking that has a note, next to that note.

Our nightly check or “Sync now” restores TourTask’s events for today or later if you change or delete them. We do not change past events, and never change or delete events TourTask did not create.

We read your Google account ID and email address, and read back only the events TourTask created, which carry a hidden marker. We never list your calendars.

What we store

We store your Google account ID and email address, the calendar ID, the permissions granted, your access and refresh tokens (encrypted with AES-256-GCM), the sync status and time, and a code for the last sync problem, until you disconnect or your user or business is deleted. Our record of each event we created is deleted 35 days after the event.

With the shared “TourTask” calendar, we also keep your Google account ID and its calendar ID, so that all your businesses, and any reconnection, use the same calendar. Disconnecting or deleting your user or business does not remove this record; to delete it, write to info@tourtask.com.

How we use and share it

We use this data only to keep your calendar in sync, show which Google account is connected and fix sync problems. Your Google email address can appear in our 90-day error log, which staff read only to investigate errors.

We do not transfer data we receive from Google to anyone, except to our hosting provider, InMotion Hosting, which stores our databases; when needed for security; when the law requires it; or with your explicit prior consent, as part of a merger, acquisition or sale of TourTask.

We do not use data we receive from Google for advertising, we do not sell it, and we do not use it to assess creditworthiness.

TourTask staff do not read your Google data, except: when you ask us for help and agree that we look at specific data; when it is necessary for security purposes, such as investigating a bug or abuse; or when the law requires it.

We do not use Google user data, or data received through Google Workspace APIs, to develop, improve or train artificial intelligence or machine learning models, whether generalized or personalized. We do not send it to AI providers.

Disconnecting and deleting

You can disconnect Google Calendar in TourTask at any time. We then delete a per-business calendar with all its events. For your main or the shared calendar, we delete future events and those from about the last 35 days; older events and the shared calendar stay for you to delete in Google Calendar.

We then ask Google to revoke our access, and delete your tokens and connection settings. If Google cannot be reached, some events and our access may remain; remove them in Google Calendar and your Google Account permissions.

If you only remove our access at Google, sync stops; also disconnect in TourTask so that we delete your tokens. If your user or business is deleted first, we delete your tokens, but the calendar, its events and our access stay in Google for you to remove. Deleted data can stay in backups for up to about 10 weeks.

Google Ads conversion upload

An operator can give us a Google Ads customer ID, a conversion action ID and an OAuth refresh token issued to TourTask’s Google app with the Google Ads API permission (https://www.googleapis.com/auth/adwords), which can reach every Google Ads account the granting Google user can manage.

We use it only to upload that operator’s booking conversions to the customer ID it entered, and read no data from Google Ads, such as campaigns or reports. The uploaded data comes from TourTask; we never send data received from Google, including Calendar data, to Google Ads or any other advertising platform.

We do not know or store which Google user granted the token. We store the values as entered until the operator removes them or the business is deleted. If Google rejects an upload, we keep Google’s error message with our record of that upload until the business is deleted.

Removing them in TourTask stops the uploads but does not cancel the authorization at Google. The Google user who granted it can cancel it in their Google Account permissions.

Limited Use

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

TourTask’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

See also the Google Workspace API User Data and Developer Policy.

Artificial intelligence

Chat assistants

The chat assistants are AI, not people: the support chats on tourtask.com and in the backoffice, and the assistant on operators’ websites and messaging channels, including email. A person from TourTask or the operator can take over.

All run on Claude models from Anthropic (United States). We send Anthropic the conversation, what the assistant needs to answer, such as tours, prices and availability, and on operators’ channels the contact details you gave or the channel provides, such as name, username, phone number or email address. Bookings it looks up or creates are sent too.

On operators’ website chats, AI also checks whether each message is about the operator’s tours, and the assistant does not answer other topics.

Other AI features for operators

AI fills in a booking from a traveler’s email and attachments pasted by staff, who check and save it (the email is not kept); writes tour descriptions and captions; matches tour names in imports; and drafts the chat assistant’s instructions from the operator’s website. These use Anthropic and, where enabled, OpenAI (United States).

We translate tour content with Google Cloud Translation or one of these AI providers. TourTask itself does not use your personal data to train AI models.

Automated decisions

  • An account is frozen 10 days after an invoice expires unpaid, and deleted with its data 6 months later, after warning emails.
  • A referral earns no commission or discount if the partner’s email address belongs to a user of the referred business.
  • The chat assistant may stop replying to a conversation that goes in circles or, on website chats, to messages it classifies as off topic.
  • Above a daily message limit the operator can set, the assistant stops answering that visitor ID and IP address for the rest of the day; after several off-topic messages, the website chat blocks them for one hour.

When the assistant stops, a person can still answer you. You can ask a person at TourTask to explain and review any of these decisions, and give your view and contest it, at info@tourtask.com. Apart from these, we make no solely automated decisions with legal or similarly significant effects on you.

How to delete your data

This section explains how anyone can ask TourTask SpA to delete personal data in TourTask, what we delete and what we keep. It is the deletion guide for our Facebook, WhatsApp, Messenger, Instagram and Telegram integrations and the TourTask Chat and TourTask Sales apps.

How to ask

Email info@tourtask.com, in any language, with a subject such as “Delete my data”. Say who you are and which data you mean, for example your email address, phone number or the business you contacted.

We may ask you to confirm by replying from that address, or by sending a code we give you to the same business from the messaging account you used. We confirm by email when done, or explain what we could not do.

Tour operators: your business account

To delete a business account, the account owner or an administrator emails us at info@tourtask.com. We then disconnect its channels and delete the business and its data, including users, bookings, passenger details, chats, invoices, uploaded files, channel connections, message copies, forwarded and failed emails, and support usage records.

Accounts frozen for an unpaid invoice are deleted automatically 6 months later, after warning emails. Records we keep outside our main database, such as channel connection details, copies of incoming messages, forwarded and failed emails and support usage records, are then kept until you ask us to delete them.

If you connected Facebook, Instagram or WhatsApp to TourTask

Disconnect the channel in TourTask, under the website chat settings. This deletes the stored access token, including a personal Facebook access token, and the connection details.

Removing TourTask under Business integrations in your Facebook settings, or in your Meta business settings, stops our access but deletes nothing we stored, so also disconnect in TourTask or write to us. Neither step deletes conversations already received; ask us to delete them.

Staff users and mobile app users

First disconnect Google Calendar in TourTask; otherwise the TourTask calendar stays in your Google account and you need to remove our access in your Google Account permissions.

Ask your administrator to remove your user, or write to us from your sign-in address, naming the business. Some users can only be removed by us. Write to info@tourtask.com and we will remove them. We tell the administrator, then remove your user unless the operator must keep it for a legal reason, which we explain.

This deletes your login, phone numbers, app sessions, push tokens, app settings and Google Calendar connection. Bookings, payments and messages you entered stay with the operator, with their change history. Records of news you have seen, unanswered questions and your shared calendar record stay until we delete them; ask us.

To clear your device, sign out and then uninstall the app. In TourTask Chat, you can also use “Wipe local data” in Settings. Your device’s own backups, such as Android’s backup to Google, may keep copies until you delete them there.

Travelers and messaging app users

Travelers: ask the operator you booked with, which controls your booking data. If you write to us, we forward your request and help. We handle data we use for our own purposes ourselves.

If you messaged an operator on WhatsApp, Messenger, Instagram or Telegram, ask the operator, or send us your WhatsApp number, or the business name and your Messenger name, Instagram username or Telegram name.

After checking it is you, we tell the operator and, unless it must keep the data by law, delete your messages, name and platform ID from our chat records, including our central copy.

Conversations with TourTask’s own accounts are deleted 14 days after the last activity; we delete our copy of your incoming messages on request.

Website visitors, business contacts and referral partners

Support chats on tourtask.com are deleted after 14 days of inactivity. If our assistant could not answer a question, we keep it and your message until we delete them. Write to us to delete these, your business-contact details or a referral account.

To stop only marketing emails, see “Your right to object”.

What we keep after a deletion

  • Backups: up to about 10 weeks, until replaced. Only a few senior staff can open them, to recover from failures or investigate problems.
  • API request log: 1 day, then backups. Central error log and app sign-in and action log: 90 days.
  • Error records for an operator’s account, which can include a traveler’s email address, phone number or messaging ID: until the business is deleted, or on request.
  • If you asked us to stop emailing you: your email address and that choice, with no end date, so that we do not contact you again.
  • Bookings stay with the operator (and, for resold tours, the operator running the tour). Ask the operator to delete them.

For other logs, team mailboxes and Google Calendar, see “How long we keep data” and “Google user data”; you can ask us to delete team-mailbox messages sooner.

Children

TourTask is made for businesses and adults. It is not directed at children, and we do not knowingly collect personal data directly from children.

Operators may record the names and ages of children on a tour, given by a parent, guardian or adult booker. We process this as the operator’s processor, and it can appear in our logs and backups like other booking data.

If you believe a child has given us personal data directly, contact us at info@tourtask.com and we will delete it.

Changes to this policy

We update this policy when our services or the law change. The date and version at the top show the last change.

For important changes, we say at the top of this page what changed, and email operators’ administrators and referral partners before they take effect. Before using Google user data in a new way, we ask for your consent again.

If you notice a difference between language versions of this policy, tell us at info@tourtask.com.

Contact us

For questions or requests about this policy or your data, email info@tourtask.com.

TourTask SpA, Chilean tax ID (RUT) 77.381.727-8, Kai Tuoe s/n, 2770000 Hanga Roa, Easter Island, Chile.

TourTask

The all-in-one platform to run, automate, and grow your tour operation.

Product
FeaturesPricingBook a demo
Resources
DocumentationPayment gatewaysOnline travel agencies
Company
ContactPrivacy policy

© 2026 TourTask. All rights reserved.