Legal

Privacy Policy.

Last updated: June 30, 2026

TourismIntel ("we", "us", "our") respects your privacy. This Privacy Policy describes how we collect, use, and disclose your personal data when you use the TourismIntel website (tourismintel.ai), the TourismIntel iOS and Android mobile applications, and related services (collectively, the "Service").

1. Data Controller

The data controller is:

2. What Data We Collect

We collect the following categories of personal data:

a) Account data

b) Usage data

c) Push notification data

d) Subscription data

e) Communication data

We do NOT collect

3. Why We Collect Data (Legal Basis under GDPR)

PurposeLegal basis (GDPR Art. 6)
Provide the Service (account, content)Contract (Art. 6(1)(b))
Send transactional emails (magic link)Contract (Art. 6(1)(b))
Send marketing emails (with opt-out)Consent (Art. 6(1)(a))
Send push notificationsConsent (Art. 6(1)(a))
Process subscription paymentsContract (Art. 6(1)(b))
Analytics and product improvementLegitimate interest (Art. 6(1)(f))
Comply with legal obligationsLegal obligation (Art. 6(1)(c))

4. Third-Party Processors

We share data with the following service providers under data-processing agreements (GDPR Art. 28):

For US-based processors, we rely on Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures to ensure GDPR-equivalent protection.

5. Data Retention

6. Your Rights (GDPR)

You have the right to:

To exercise these rights, email privacy@tourismintel.ai. We respond within 30 days.

7. Account Deletion

You can delete your TourismIntel account at any time:

Deletion removes all your personal data within 30 days, except where retention is required by law (e.g., subscription receipts for tax compliance).

8. Cookies and Tracking

The website tourismintel.ai uses minimal first-party cookies for session management. We do not use third-party advertising cookies and we do not share data with ad networks. The mobile app does not use cookies but uses secure on-device storage (Keychain on iOS, EncryptedSharedPreferences on Android) for authentication tokens.

For product analytics on the website, we use two GDPR-conscious tools:

No advertising, cross-site or fingerprinting technologies are used on the website or in the mobile apps.

9. Security

We use industry-standard security measures: HTTPS/TLS encryption in transit, encryption at rest for sensitive data, JWT-based authentication, hashed magic-link tokens, and role-based access control. No method of transmission over the Internet is 100% secure, however, and we cannot guarantee absolute security.

10. International Transfers

Some of our processors are located outside the European Economic Area (EEA). When we transfer data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

11. Children

The Service is not intended for users under 16. We do not knowingly collect data from children. If you become aware that a child has provided data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app banner at least 30 days before they take effect.

13. Contact

For privacy-related questions or to exercise your rights: