Privacy Policy
Last Updated: November 29, 2025
1. Introduction
TourWiseCo ("we," "us," "our," or "the Platform") is committed to protecting your privacy and ensuring transparency in how we collect, use, store, and share your personal data. This Privacy Policy explains our data practices in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the UK GDPR as incorporated into the Data Protection Act 2018, the ePrivacy Directive 2002/58/EC, and other applicable data protection laws.
This Privacy Policy applies to all users of the TourWiseCo Platform, including tourists seeking local guide services ("Tourists") and university students offering guide services ("Student Guides" or "Guides").
By using our Platform, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree with our practices, please do not use our Services.
2. Data Controller
For the purposes of the GDPR and UK GDPR, TourWiseCo is the data controller responsible for your personal data collected through the Platform.
Contact Information:
You may contact us regarding data protection matters through the contact form available on our Platform, or by contacting our Data Protection Officer (DPO) through the same channel.
EU Representative:
TourWiseCo operates in France. Our primary operating location is Paris, France.
UK Representative:
TourWiseCo operates in the United Kingdom through our London operations.
3. Personal Data We Collect
We collect different categories of personal data depending on how you interact with our Platform.
3.1 Data Collected from All Users
Account and Profile Information:
- Email address (required for account creation and authentication)
- Name (first name and last name)
- User type designation (Tourist or Student Guide)
- Account credentials (password stored in hashed format)
- Authentication tokens and session data
Communication Data:
- Messages exchanged through our Platform messaging system
- Contact form submissions and support inquiries
- Email communications (including magic link authentication emails)
Technical and Usage Data:
- IP address
- Browser type and version
- Device information (operating system, device type, unique device identifiers)
- Time zone setting and location data (country/city level)
- Pages visited, features used, and time spent on the Platform
- Referral source and clickstream data
- Log files and error reports
3.2 Additional Data from Tourists
- Phone number (optional)
- WhatsApp number (optional)
- Travel dates and destination cities
- Trip preferences (time of day, group size, group type)
- Service preferences (guided tours vs. itinerary assistance)
- Interests and activity preferences
- Budget information
- Preferred languages and guide characteristics
- Accessibility requirements
- Special requests and trip notes
3.3 Additional Data from Student Guides
- University name and enrollment status
- Student identification documents (student ID card for verification)
- Date of birth
- Nationality
- Languages spoken and proficiency levels
- Areas of expertise and local knowledge
- Service offerings and availability schedule
- Profile biography and cover letter
- Interests and hobbies
- Preferred service types and tourist preferences
- Safety compliance acknowledgments
3.4 Data We Do NOT Collect
We do NOT collect or process:
- Payment card information (PCI DSS data) – all payments occur directly between users
- Government-issued ID numbers (passports, national ID cards, social security numbers)
- Financial account information (bank accounts, IBAN)
- Sensitive personal data as defined under GDPR Article 9 (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, sex life, or sexual orientation) – except where voluntarily provided by users in free-text fields
4. Legal Basis for Processing Personal Data
Under the GDPR and UK GDPR, we must have a lawful basis to process your personal data. We process your personal data on the following legal grounds:
4.1 Performance of Contract (GDPR Article 6(1)(b))
Processing is necessary for the performance of our Terms of Service contract with you, including:
- Creating and managing your account
- Facilitating connections between Tourists and Student Guides
- Operating our matching algorithm based on preferences
- Providing our Platform messaging functionality
- Delivering authentication services (magic links, OAuth)
- Enforcing our Terms of Service
4.2 Legitimate Interests (GDPR Article 6(1)(f))
Processing is necessary for our legitimate business interests, where such interests are not overridden by your data protection rights:
- Platform security and fraud prevention: Monitoring for suspicious activity, preventing unauthorized access, detecting fraud
- Service improvement: Analyzing usage patterns, conducting user research, optimizing features and user experience
- Customer support: Responding to inquiries, resolving issues, providing technical assistance
- Business analytics: Generating aggregated statistics, understanding user demographics, evaluating Platform performance
- Legal compliance and safety: Investigating violations of Terms of Service, responding to legal requests, protecting user safety
4.3 Consent (GDPR Article 6(1)(a))
For certain processing activities, we obtain your explicit consent:
- Non-essential cookies and tracking technologies (managed through our cookie consent banner)
- Marketing communications (where required by law)
- Sharing profile information with matched users
You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
4.4 Legal Obligation (GDPR Article 6(1)(c))
Processing is necessary to comply with legal obligations, including:
- Responding to lawful requests from law enforcement and regulatory authorities
- Complying with tax and accounting regulations
- Retaining records as required by applicable laws
- Reporting illegal activity as mandated by law
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Core Platform Services
- Account creation, authentication, and management
- User verification (student ID validation for Student Guides)
- Matching Tourists with suitable Student Guides based on preferences and availability
- Facilitating communication between Tourists and Student Guides
- Displaying user profiles to matched parties
- Sending transactional emails (account verification, match notifications, system updates)
5.2 Platform Operation and Improvement
- Monitoring and analyzing Platform usage and trends
- Conducting user research and surveys
- Testing new features and improvements
- Optimizing matching algorithm performance
- Improving user interface and experience
- Generating aggregated, anonymized statistics
5.3 Security and Fraud Prevention
- Detecting and preventing fraudulent activity
- Monitoring for Terms of Service violations
- Protecting against spam, harassment, and malicious behavior
- Investigating security incidents
- Enforcing our Terms of Service
5.4 Customer Support
- Responding to support inquiries and requests
- Resolving technical issues
- Investigating and addressing user complaints
- Providing guidance on Platform features
5.5 Legal Compliance
- Complying with legal obligations and regulatory requirements
- Responding to lawful requests from authorities
- Establishing, exercising, or defending legal claims
- Enforcing our rights and agreements
6. How We Share Your Personal Data
We do not sell your personal data to third parties. We share your personal data only in the limited circumstances described below:
6.1 With Other Users
When our matching algorithm identifies a suitable match, we share relevant profile information:
- Tourist to Student Guide: Name, trip details, preferences, contact method preference, and any information you include in your booking request
- Student Guide to Tourist: Name, university affiliation, profile biography, languages, interests, and service offerings
- Contact Information: Email addresses and phone numbers (if provided) are shared only after both parties agree to connect
6.2 Service Providers and Data Processors
We engage trusted third-party service providers to assist with Platform operations. These processors have access to personal data only as necessary to perform their functions and are contractually obligated to protect your data in accordance with GDPR Article 28:
- Cloud Infrastructure: Vercel (hosting, CDN) – USA (Standard Contractual Clauses)
- Database Services: Vercel Postgres – USA (Standard Contractual Clauses)
- Email Delivery: Resend – USA (Standard Contractual Clauses)
- Authentication Services: NextAuth.js (self-hosted), Google OAuth, Microsoft OAuth – Various (Standard Contractual Clauses where applicable)
- Analytics: Google Analytics (if enabled with consent) – USA (Standard Contractual Clauses, anonymized IP addresses)
- Image CDN: Unsplash – USA (publicly available images, no personal data transmitted)
6.3 Legal Obligations and Safety
We may disclose personal data when required by law or when we believe in good faith that disclosure is necessary to:
- Comply with legal obligations, court orders, or lawful requests from government authorities
- Enforce our Terms of Service and other agreements
- Investigate potential violations of our policies
- Protect the rights, property, or safety of TourWiseCo, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Respond to emergencies involving danger of death or serious physical injury
6.4 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal data may be transferred to the successor entity. We will notify you via email and/or a prominent notice on our Platform before your personal data is transferred and becomes subject to a different privacy policy.
6.5 With Your Consent
We may share personal data for purposes not described in this Privacy Policy when we obtain your explicit consent to do so.
6.6 Aggregated and Anonymized Data
We may share aggregated or anonymized data that cannot reasonably be used to identify you, such as statistical trends, platform metrics, or research findings. This data is not considered personal data under GDPR.
7. International Data Transfers
TourWiseCo operates in the European Union and United Kingdom. However, some of our service providers are located in countries outside the European Economic Area (EEA) and the United Kingdom, including the United States.
7.1 Safeguards for International Transfers
When we transfer personal data to countries that do not provide an adequate level of data protection as determined by the European Commission or UK authorities, we implement appropriate safeguards in accordance with GDPR Chapter V:
- Standard Contractual Clauses (SCCs): We use the European Commission's approved Standard Contractual Clauses (also known as Model Clauses) for transfers to third countries. These clauses are legally binding commitments between data controllers and processors to protect your personal data.
- Adequacy Decisions: Where applicable, we rely on adequacy decisions issued by the European Commission recognizing that certain countries provide adequate data protection (e.g., under the EU-U.S. Data Privacy Framework, if applicable).
- Supplementary Measures: In addition to SCCs, we conduct transfer impact assessments and implement supplementary technical and organizational measures, such as encryption in transit and at rest, pseudonymization, and access controls.
7.2 Your Rights Regarding International Transfers
You have the right to obtain information about the safeguards we have in place for international transfers. You may request a copy of the relevant safeguard mechanisms by contacting us using the details in Section 14.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
8.1 Retention Periods
| Data Category | Retention Period | Reason |
|---|---|---|
| Active account data | Duration of account + 30 days | Contract performance, service provision |
| Inactive accounts (no login) | 3 years | User convenience (account recovery) |
| Deleted account data | 30 days (soft delete), then permanent deletion | Recovery period, then data minimization |
| Booking/match history | 6 years after last activity | Legal compliance, dispute resolution |
| Communication logs | 2 years | Customer support, dispute resolution |
| Technical logs (IP addresses, etc.) | 90 days | Security, fraud prevention |
| Analytics data (anonymized) | 26 months | GDPR compliance, business insights |
| Legal/compliance records | As required by law (typically 6-10 years) | Legal obligations |
8.2 Retention Criteria
We determine retention periods based on:
- The purpose for which the data was collected
- Legal, regulatory, tax, accounting, or reporting requirements
- Statute of limitations for legal claims
- Pending or potential litigation
- Our legitimate business interests (security, fraud prevention, user safety)
8.3 Secure Deletion
When personal data is no longer required, we securely delete or anonymize it using industry-standard methods to prevent recovery or reconstruction. Backups containing deleted data are retained for disaster recovery purposes but are securely overwritten according to our backup rotation schedule (maximum 90 days).
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies in accordance with the ePrivacy Directive 2002/58/EC and GDPR.
9.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our Platform. They help us recognize you, remember your preferences, and improve your experience.
9.2 Types of Cookies We Use
Strictly Necessary Cookies (No consent required)
These cookies are essential for the Platform to function and cannot be disabled:
- Authentication cookies: Keep you logged in and manage your session
- Security cookies: Detect and prevent fraudulent activity
- CSRF tokens: Protect against cross-site request forgery attacks
- Load balancing cookies: Ensure Platform stability and performance
Functional Cookies (Consent required)
These cookies enhance functionality and personalization:
- Preference cookies: Remember your language, location, and display settings
- UI state cookies: Preserve your navigation and form input state
Analytics Cookies (Consent required)
These cookies help us understand how users interact with the Platform:
- Google Analytics: Tracks page views, user journeys, and engagement metrics
- Performance monitoring: Identifies technical issues and slow-loading pages
Analytics cookies are only placed with your explicit consent. IP addresses are anonymized. You can withdraw consent at any time through our cookie preference center.
Marketing Cookies (Consent required)
We do NOT currently use marketing or advertising cookies. Should this change in the future, we will obtain your explicit consent before placing such cookies.
9.3 Third-Party Cookies
When you use OAuth authentication (Google, Microsoft), these providers may set their own cookies subject to their privacy policies:
- Google OAuth: https://policies.google.com/privacy
- Microsoft OAuth: https://privacy.microsoft.com/
9.4 Managing Cookies
You can control cookies through:
- Cookie Preference Center: Accessible through the banner displayed on your first visit or through Platform settings
- Browser Settings: Most browsers allow you to refuse or delete cookies. Instructions vary by browser:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Options → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Privacy, search, and services → Cookies
Blocking strictly necessary cookies will prevent you from using certain essential features of the Platform.
9.5 Other Tracking Technologies
In addition to cookies, we may use:
- Local storage: Stores data locally on your device to improve performance
- Session storage: Temporary storage that expires when you close your browser
- Pixels and web beacons: May be used in emails to track delivery and open rates (with consent)
10. Your Data Protection Rights
Under the GDPR and UK GDPR, you have the following data protection rights. To exercise any of these rights, please contact us using the information in Section 14.
10.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you. We will provide:
- Confirmation of whether we process your personal data
- A copy of your personal data in a commonly used electronic format
- Information about the purposes of processing, categories of data, recipients, retention periods, and your rights
We will respond within one month of your request. The first copy is provided free of charge; additional copies may incur a reasonable administrative fee.
10.2 Right to Rectification (Article 16)
You have the right to request correction of inaccurate or incomplete personal data. You can update most information directly through your account settings. For data you cannot modify yourself, contact us, and we will update it promptly.
10.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data in certain circumstances:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where processing is based on consent)
- You object to processing and there are no overriding legitimate grounds
- The data was unlawfully processed
- Deletion is required to comply with a legal obligation
This right is not absolute. We may retain data where necessary to:
- Comply with legal obligations
- Establish, exercise, or defend legal claims
- Protect the rights of other Users or third parties
10.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict processing of your personal data in certain situations:
- You contest the accuracy of the data (restriction applies during verification)
- Processing is unlawful, but you prefer restriction over deletion
- We no longer need the data, but you require it for legal claims
- You have objected to processing pending verification of our legitimate grounds
10.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and to transmit it to another controller. This right applies where:
- Processing is based on consent or performance of a contract
- Processing is carried out by automated means
10.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes:
- Legitimate interests: You may object to processing based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims.
- Direct marketing: You have an absolute right to object to processing for direct marketing purposes. We will cease such processing immediately upon objection.
10.7 Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
Our matching algorithm uses automated processing to suggest suitable Student Guides based on preferences. However:
- The algorithm provides suggestions only; final decisions are made by human Users
- You are not obligated to accept suggested matches
- The algorithm does not make legally binding decisions
If you have concerns about our matching algorithm, you may contact us to request human review and explanation of matching logic.
10.8 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. You can withdraw consent through account settings or by contacting us.
10.9 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates data protection law.
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) – www.cnil.fr
- United Kingdom: Information Commissioner's Office (ICO) – ico.org.uk
- Other EU Member States: Contact your local data protection authority
We encourage you to contact us first so we can address your concerns directly.
11. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
11.1 Technical Measures
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS)
- Encryption at rest: Database and file storage use AES-256 encryption
- Password security: Passwords are hashed using bcrypt with salt before storage; plain-text passwords are never stored
- Access controls: Role-based access control (RBAC) restricts employee access to personal data on a need-to-know basis
- Network security: Firewalls, intrusion detection systems, and DDoS protection
- Secure authentication: Multi-factor authentication (MFA) for administrative access
- Regular security testing: Vulnerability scanning, penetration testing, and security audits
11.2 Organizational Measures
- Data protection policies and procedures
- Employee confidentiality agreements
- Privacy and security training for staff
- Data breach response plan and incident management procedures
- Regular review and update of security measures
- Vendor security assessments and due diligence
11.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33)
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
- Provide clear information about the nature of the breach, likely consequences, and measures taken to address it
11.4 Limitations
While we implement robust security measures, no system is completely secure. You are responsible for:
- Keeping your account credentials confidential
- Using strong, unique passwords
- Logging out of shared or public devices
- Promptly notifying us of any unauthorized access
12. Children's Privacy
Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children under 18. Users must be at least 18 years old to create an account or use our Services.
If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete such data from our systems.
If you believe we have collected data from a child under 18, please contact us immediately using the contact information in Section 14.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.
When we make material changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email (to the email address associated with your account)
- Display a prominent notice on the Platform
- Where required by law, obtain your consent to the updated Privacy Policy
We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes are posted constitutes your acceptance of the updated Privacy Policy, unless additional consent is required by law.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- By contact form: Available on our Platform (preferred method)
- Data Protection Officer: You may contact our Data Protection Officer through the Platform contact form, marking your message "Attn: Data Protection Officer"
TourWiseCo
Operating in Paris, France and London, United Kingdom
We will respond to all legitimate requests within one month, as required by GDPR Article 12(3). In complex cases, we may extend this period by an additional two months and will inform you of such extension.
15. Additional Information for EEA and UK Users
15.1 Legal Basis Summary
This section summarizes the legal bases under which we process different categories of personal data:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of contract (Art. 6(1)(b)) |
| Matching algorithm | Performance of contract (Art. 6(1)(b)) |
| Student verification | Performance of contract (Art. 6(1)(b)) |
| Platform messaging | Performance of contract (Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Platform improvement and analytics | Legitimate interests (Art. 6(1)(f)) / Consent (Art. 6(1)(a)) |
| Customer support | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
| Non-essential cookies | Consent (Art. 6(1)(a)) |
15.2 Representative for UK GDPR
TourWiseCo operates in the United Kingdom and is directly subject to UK GDPR. Our London operations serve as the point of contact for UK data protection matters.
15.3 Cross-Border Data Sharing Within EEA/UK
Data may be transferred between our operations in France and the United Kingdom. Such transfers within the EEA and between the EEA and UK benefit from adequacy protections and do not require additional safeguards.
Acknowledgment
BY USING THE TOURWISECO PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. WHERE CONSENT IS REQUIRED (SUCH AS FOR NON-ESSENTIAL COOKIES OR OPTIONAL PROCESSING), WE WILL ASK FOR YOUR EXPLICIT CONSENT SEPARATELY.
