LEGAL

Privacy Policy

Effective Date: 1 June 2024  ·  Last Updated: 1 May 2025

Spotinga ("we", "us", or "our") operates a global marketplace that connects independent experience providers — guides, operators, event creators, and activity businesses — with customers seeking to discover and book tours, events, activities, and experiences worldwide. The platform is available at spotinga.com and related domains ("Platform"). We are committed to protecting the privacy and personal data of everyone who uses our Platform, regardless of where in the world they are located.

This Privacy Policy explains what personal data we collect, how we use and protect it, with whom we share it, and what rights you have. By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Platform.

1. Data Controller

The data controller responsible for personal data collected through the Platform is Spotinga, a product operated by Kenoli Systems. All data collected through the Platform is stored and processed on servers located in the United States of America. For all data privacy matters, please contact us.

2. Information We Collect

We collect the following categories of personal data from customers, providers, and visitors:

a) Identity & Contact Data

First name, last name, email address, and phone number provided during registration or profile setup. Providers may also submit business name, government-issued identity, and banking details for verification and payouts.

b) Account Data

Username, hashed password, account type (customer or provider), profile settings, saved listings, and account preferences.

c) Booking & Transaction Data

Booking references, selected dates, participant counts, amounts paid, payment status, special requests, and related correspondence between customers and providers through the Platform.

d) Payment & Billing Data

Billing address and payment method details for transactions processed through the Platform. We do not store full card numbers — payment processing is handled entirely by third-party PCI-DSS compliant providers (Stripe, Razorpay, or equivalent).

e) Technical & Usage Data

IP address, browser type and version, device information, operating system, pages visited, session duration, referral source, and diagnostic data collected automatically when you access the Platform.

f) User-Generated Content

Reviews, ratings, photos, and other content you submit to the Platform. Providers are responsible for the accuracy and appropriateness of their listing content. Content you post publicly is visible to other users.

g) Communications Data

Records of your communications with our support team, and your marketing communication preferences.

h) Third-Party Sign-In Data

If you sign in using Google, Facebook, or Microsoft, we receive basic profile information (name, email) from those providers, subject to your consent and their own privacy policies.

3. How We Use Your Information

We use personal data for the following purposes:

  • Account creation and management — to register your account, authenticate your identity, and provide access to Platform features.
  • Booking and transaction processing — to facilitate bookings between customers and providers, including passing necessary booking details to the relevant provider.
  • Payments and payouts — to process customer payments, issue receipts, and transfer provider earnings after applicable fees.
  • Customer support — to respond to enquiries, mediate disputes, and provide technical assistance.
  • Security and fraud prevention — to detect, investigate, and prevent unauthorised access, fake bookings, and fraudulent activity.
  • Platform improvement — to analyse usage patterns and feedback in order to improve the Platform and personalise your experience.
  • Communications — to send transactional messages (booking confirmations, receipts, account alerts) and, where you have opted in, marketing communications.
  • Legal compliance — to comply with applicable laws, regulations, and lawful governmental orders.
4. Lawful Basis for Processing

We process personal data on the following lawful bases, aligned with internationally recognised privacy standards including the EU General Data Protection Regulation (GDPR) and equivalent frameworks:

  • Consent — where you have given clear, affirmative consent (e.g., opting into marketing communications). You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Performance of a contract — where processing is necessary to deliver the services you have requested, including account management, processing bookings, and facilitating payments.
  • Legal obligation — where we are required to process data to comply with applicable law.
  • Legitimate interests — where processing serves our legitimate business interests (e.g., platform security, fraud prevention, usage analytics) and does not override your fundamental rights and freedoms.

Where you are located in the EEA, United Kingdom, or another jurisdiction with equivalent data protection law, these bases apply as required by the applicable framework. For California residents, we comply with the CCPA / CPRA as set out in Section 10 below.

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

  • Providers — when you make a booking, we share the information necessary to fulfil it with the relevant provider (name, contact details, booking specifics). Providers are independent controllers of data you share with them directly.
  • Payment processors (Stripe, Razorpay, or equivalent) to process transactions. These providers are PCI-DSS compliant and operate under their own privacy policies.
  • Cloud infrastructure — we use Amazon Web Services (AWS) for hosting, storage, and email delivery (SES, S3). AWS operates under its own compliance certifications including ISO 27001 and SOC 2.
  • Analytics providers for aggregated, anonymised platform usage analytics (e.g., Google Analytics).
  • Legal and regulatory authorities where required by applicable law, court order, or lawful governmental request.
  • Business successors — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will provide reasonable notice where practicable.

All third-party service providers are contractually required to process personal data only for the specified purposes and in accordance with appropriate data protection standards.

6. Data Hosting — United States

The Platform is hosted on cloud infrastructure located in the United States of America. All personal data collected through the Platform — including account information, booking records, payment data, and usage data — is stored and processed on US-based servers, regardless of your country of residence or where a provider operates.

By creating an account or using the Platform, you acknowledge and consent to the transfer and processing of your personal data in the United States. We apply technical and organisational safeguards to protect your data consistent with internationally recognised standards.

EEA, UK, and Switzerland: Transfers of personal data to the United States are made on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission, or equivalent transfer mechanisms where applicable.

Australia and New Zealand: We handle personal data in a manner consistent with the Australian Privacy Act 1988 and the New Zealand Privacy Act 2020 to the extent applicable.

Middle East, Southeast Asia, and other regions: We apply the same security and data protection standards to your data regardless of origin, and do not transfer or disclose personal data beyond what is described in this Policy.

7. Cookies and Tracking

The Platform uses cookies and similar technologies to maintain sessions, authenticate users, remember preferences, and collect usage analytics. Cookie categories:

  • Essential cookies — required for core Platform functions (authentication tokens, session management). Cannot be disabled without impairing Platform use.
  • Analytics cookies — collect aggregated usage data to help us understand how the Platform is used and improve it. You may opt out via your browser settings.
  • Preference cookies — remember your configuration and settings across visits.

Most browsers allow you to manage cookie settings. For EEA and UK users, we obtain consent for non-essential cookies where required by applicable law.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy:

  • Account data — retained for the duration of your account and for thirty (30) days after deletion, then permanently removed unless a longer period is required by law.
  • Booking and transaction records — retained for seven (7) years for financial record-keeping and audit purposes.
  • Usage data — retained in aggregated, anonymised form for Platform performance analysis.
  • Support communications — retained for two (2) years after the issue is resolved.
9. Data Security

We implement industry-standard technical and organisational security measures, including:

  • TLS/HTTPS encryption for all data in transit.
  • Encryption of sensitive data at rest on AWS infrastructure.
  • Password hashing using industry-standard algorithms.
  • JWT-based authentication with token invalidation on logout.
  • Rate limiting and security headers to mitigate common web vulnerabilities.
  • Access controls restricting production system access to authorised personnel only.

No system is completely secure. If you become aware of a security vulnerability in the Platform, please notify us immediately. In the event of a data breach affecting personal data, we will notify impacted users as required by applicable law.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact us. We will respond within thirty (30) days and may require identity verification. Requests are free of charge unless manifestly unfounded or excessive.

All users — general rights
  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Deletion — request deletion of your personal data, subject to legal retention obligations.
  • Portability — request a machine-readable export of your data.
  • Withdrawal of consent — withdraw consent at any time where consent is the lawful basis for processing.
EEA, UK, and Switzerland (GDPR / UK GDPR)

In addition to the above, you have the right to object to processing based on legitimate interests, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or the relevant EU data protection authority in your member state).

California residents (CCPA / CPRA)

California residents have the right to know what personal information is collected and how it is used, the right to delete personal information, the right to opt out of the sale of personal information (Spotinga does not sell personal data), and the right not to be discriminated against for exercising these rights. To make a verifiable consumer request, contact us.

Australia and New Zealand

Users in Australia may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Users in New Zealand may contact the Office of the Privacy Commissioner. We will cooperate with any investigation or enquiry from these authorities.

11. Children's Privacy

The Platform is not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will promptly delete that data.

12. Marketing Communications

We send marketing communications only where you have opted in, or where permitted by applicable law. You may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us. Transactional messages (booking confirmations, payment receipts, account alerts) cannot be opted out of while your account is active, as they are necessary for service delivery.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on the Platform and, where required by applicable law, by email, at least fourteen (14) days before changes take effect. Continued use of the Platform after that date constitutes acceptance of the updated Policy.

14. Contact

For any privacy questions, data subject rights requests, or complaints relating to this Policy, please reach out to us via our contact page.

Spotinga — Privacy

Contact Us

We will acknowledge your request within 48 hours and respond in full within thirty (30) days.

Statutory disclosure: The Platform is operated by Kenoli System, a company incorporated under the laws of India (registered office: Bangalore, India). All data processing occurs on infrastructure in the United States and is governed accordingly.

Loading...