How TourVigator collects, uses, and protects your personal information when you use our platform.
At TourVigator, protecting your personal information is something we take seriously. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we may share it with, and what rights you have in relation to it. It applies whenever you use the TourVigator platform, including our website and any mobile applications we operate (collectively, the "Platform").
TourVigator is registered and operates in Zanzibar, Tanzania. We process personal data in accordance with the laws of the United Republic of Tanzania, including the Electronic and Postal Communications Act and any applicable data protection regulations in force in Tanzania. Where you access our Platform from another country, we will also endeavour to respect the privacy rights applicable in your jurisdiction to the extent reasonably practicable.
If you are an Activity Provider or a business partner of TourVigator, separate privacy terms applicable to your business relationship with us may have been provided to you. This policy is directed at travelers and general Platform users.
This Privacy Policy has been written in English. Any translation is provided for convenience only. In the event of a conflict between the English version and a translation, the English version shall take precedence.
The following terms are used throughout this Privacy Policy:
TourVigator is the data controller responsible for the personal data collected through the Platform. Our contact details are:
TourVigator
Zanzibar, Tanzania
(Full registered address available in our Legal Notice)
To contact us about any privacy matter, please use our contact page.
Please note that when you book an Activity, the Supplier who delivers that Activity also receives your relevant personal data and acts as a separate, independent data controller for the purposes of fulfilling that Activity. Their handling of your data is governed by their own privacy practices. While we cannot fully control each Supplier's internal processes, we require Suppliers to meet baseline data-handling standards under our platform terms and review compliance signals where reasonably possible.
When you visit the Platform, we automatically collect certain technical data, including:
We collect this data to ensure the Platform operates correctly, to maintain security, and to detect and prevent fraudulent or abusive activity. This processing is necessary for our legitimate operational interests.
2.1 Creating an account. If you register for an account, we collect your full name, email address, and password. If you choose to sign in through a third-party service (such as Google or Apple), we receive your name, email address, and an authentication token from that service to create and manage your account. This data is processed in order to provide you with access to the Platform and manage your account.
2.2 Saved activities and wishlists. If you save or shortlist activities on the Platform, we may use this information to provide you with personalised suggestions and improve your experience. This is based on our legitimate interest in making the Platform more useful and relevant to you.
2.3 Reviews and ratings. If you submit a review following a booking, we collect the information you provide, which may include a rating, written comments, and any photos you upload. Reviews may be displayed publicly on the Platform and used in our marketing materials. You may request removal of a review by contacting us. We process reviews based on our legitimate interest in helping other travelers make informed decisions and in improving the quality of our Platform.
3.1 Booking data. When you book an Activity, we collect the personal data necessary to complete the booking, which may include your full name, email address, phone number, billing address, number of participants, preferred date, and any special requirements you submit. This data is used to process and confirm your booking and is shared with the relevant Supplier so they can deliver the Activity.
3.2 Booking communications. We will send you booking confirmations, reminders, and relevant updates by email or through the Platform. These communications are necessary to provide the service you have requested.
Payments on the Platform are processed through third-party payment service providers. Depending on the payment method you choose, we and our payment providers process transaction-related data such as billing details and partial card information to complete and verify your payment. We do not store full card numbers. Each payment provider acts as an independent data controller for the data they collect, and their own privacy policy applies to that processing.
When you contact us for support or with an enquiry, we process the information you provide β such as your name, email address, booking reference, and the content of your message β in order to respond to and resolve your request. We may use third-party support tools, and where we do, those providers process data on our behalf under confidentiality agreements.
If you subscribe to our newsletter or opt in to marketing communications, we use your email address to send you updates, promotions, and travel inspiration relevant to the Platform. You can unsubscribe at any time using the link in any marketing email or by updating your account preferences. We may also send you relevant post-booking communications about similar Activities based on your booking history, unless you have opted out. We will always respect your communication preferences.
We use automated and manual processes to detect, investigate, and prevent fraudulent transactions and abuse of the Platform. This may involve analysing transaction patterns, device data, and usage behaviour. This processing is carried out in the interests of protecting our users, Suppliers, and the integrity of the Platform.
We use cookies and similar technologies to operate the Platform, remember your preferences, and where you have given consent, to serve relevant advertising and measure the effectiveness of our marketing. Full details of how we use cookies, what choices you have, and how to manage your preferences are set out in our Cookies & Marketing page.
We work with third-party providers to operate the Platform. These providers may process personal data on our behalf and are required to do so under confidentiality and data-processing safeguards.
| Provider Type | Purpose | Current Services We Use |
|---|---|---|
| Cloud Hosting | Storing platform data and files securely | Infrastructure providers used by our web platform |
| Analytics | Understanding how users interact with the Platform | Google Analytics |
| Email Delivery | Sending booking confirmations and newsletters | Titan Email |
| Payment Processing | Handling transactions securely | Pesapal, Visa, Mastercard networks |
| Customer Support | Managing support enquiries | Internal support channels and service tooling |
| Mobile App Distribution | Delivering app updates and diagnostics | Google Play, Apple App Store |
Where data is transferred to providers located outside Tanzania, we take reasonable steps to ensure appropriate protections are in place, including contractual safeguards.
If you use our mobile app, we may collect additional technical data such as device model, operating system version, app version, and crash diagnostics to maintain performance and security. Where app features request permissions (for example location, camera, storage, or notifications), those permissions are requested by your device OS and can be managed in your device settings. We use such permissions only for the feature you enable and not for unrelated profiling.
We may disclose your personal data in the following circumstances: (a) to comply with a legal obligation, court order, or lawful request from a government authority; (b) to enforce our Terms and Conditions or protect the rights, property, or safety of TourVigator, our users, or third parties; (c) to professional advisers such as lawyers or auditors where necessary; (d) in connection with a merger, acquisition, or sale of all or part of our business, in which case the acquiring party would be bound by equivalent privacy obligations. We do not sell your personal data to third parties for their own marketing purposes.
We may use automated processes to assess the risk of certain transactions, for example to flag or block potentially fraudulent bookings. If your booking is declined as a result of an automated decision, you may contact us to request a manual review of that decision.
We retain your personal data only for as long as it is needed for the purposes described in this Privacy Policy, or as required by applicable law. When your data is no longer needed, we delete or anonymise it securely. If you close your account, your profile data will be removed, although we may retain certain records where required by law or for the purposes of resolving disputes or enforcing our agreements.
You have the following rights in relation to your personal data held by TourVigator. To exercise any of these rights, please contact us through our contact page. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
TourVigator is based in Zanzibar, Tanzania, and your personal data is processed and stored in Tanzania. If you access the Platform from another country, your data will be transferred to and processed in Tanzania, which may have different data protection standards from those in your home country.
European Union and United Kingdom users. If you are located in the EU or UK, you may have additional rights under the GDPR or UK GDPR, including the right to lodge a complaint with your local supervisory authority. The rights described in Section IV are intended to align with these frameworks. Where we rely on legitimate interests, you may request additional information about how we balance those interests against your rights.
California users. If you are a California resident, you may have rights under the CCPA, including the right to know what personal data we collect, the right to request deletion, and the right to opt out of sale. We do not sell personal data. You can exercise relevant rights via our Do Not Sell My Info page or by contacting us.
By using the Platform, you acknowledge that your data may be transferred internationally. If you have concerns about cross-border transfers, please contact us through our contact page.
The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe that a child under 18 has provided us with personal data without appropriate consent, please contact us and we will take steps to delete that information promptly.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include encrypted data transmission, access controls, and regular security reviews. However, no method of transmission over the internet or method of electronic storage is completely secure. While we do our best to protect your data, we cannot guarantee absolute security and encourage you to use strong passwords and to keep your account credentials confidential.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will notify you by posting a notice on the Platform or by sending you an email. The date of the most recent update is shown at the bottom of this page. We encourage you to review this policy periodically.
Last updated: April 30, 2026