Privacy Policy

Last updated October 7, 2026

This Policy covers the personal data TourMan collects and controls itself — organization users' accounts, and marketing-site visitors. It does not cover the personal data of an organization's own guests (booking details, WhatsApp messages) — that's governed by the Data Processing Agreement, where TourMan is a Processor acting on the organization's instructions, not this Policy.

This Privacy Policy explains how Maksym Chernysh, an individual established in Italy ("TourMan", "we", "us"), of 15A Via dei Licheni, Roma, Lazio 00172, Italy, collects and uses personal data when an organization's Admin, Manager, or Guide creates or uses a TourMan account; someone visits our sites or submits the "get started" or contact forms; or TourMan bills an organization for its subscription.

1. What we collect, and why

DataCollected whenWhy (legal basis)
Name, email, hashed password, roleAn organization creates a user account (itself, or an Admin inviting a teammate)To provide the Service — performance of TourMan's contract with the organization
Phone number (optional)A user adds it to their own account, or an Admin adds it for themEntered voluntarily (consent), so the organization's team can reach the user — and, only if the organization turns it on, shared with its guests (§2). Can be removed at any time
Full name, email, company name, plan/add-on choicesSomeone submits the "get started" trial request formTo respond to the request and, if it proceeds, set up an organization
Name, email, company, messageSomeone submits the contact formTo respond to the enquiry — legitimate interest
Organization's own business details (address, city, country, tax ID), if providedAn organization fills in its own settingsTo issue accurate invoices and comply with Italian accounting/tax law (§4)
Payment method and billing historyAn organization subscribesProcessed by Stripe, not stored on TourMan’s own servers — contract performance

2. Who we share it with

The same sub-processors disclosed on our Sub-processors page — Google Workspace, Stripe, Resend, and Hetzner — are also used for this layer of data. We do not sell personal data, and we do not share it with anyone for their own independent marketing purposes.

Guide details shown to guests. If an organization's Admin turns on Share guide details with guests for the optional AI Concierge (it is off by default), then when a guest asks about their own tour's guide, the concierge may tell them the guide's first name and — only if the guide added one — their phone number. Only guides confirmed for that guest's own booking are included, and nothing else about them (no surname, email, or other detail) is shared. The phone number is optional and can be removed at any time from Account, or by an Admin. The AI Concierge runs on the organization's own Anthropic account — Anthropic is that organization's own vendor, not a TourMan sub-processor (see the Sub-processors page) — so this information is processed by Anthropic under the organization's own agreement with it.

3. International transfers

Google Workspace (EU), Stripe and Resend (US, via the EU-U.S. Data Privacy Framework with Standard Contractual Clauses as fallback), and Hetzner (Germany, no transfer at all).

4. How long we keep it

  • Organization user accounts: for as long as the organization's account is active, plus a 30-day deletion grace period.
  • Trial requests that don't lead to an organization: deleted automatically 1 year after the request.
  • Contact-form submissions: not stored in our database at all — the form only sends an email.
  • Billing and invoice records: 10 years, per Art. 2220 of the Italian Codice Civile.

5. Your rights

Under the GDPR, you can ask to access, correct, delete, or export your personal data, object to or restrict our processing of it, and withdraw consent where processing is based on it. Contact info@tourman.app to exercise any of these. If an organization's Admin is the one who added your account, some requests may need to go through that organization first.

You can also lodge a complaint with the Garante per la protezione dei dati personali (Italy's supervisory authority), or with the supervisory authority in your own EU/EEA/UK country of residence.

6. Cookies

The marketing site uses cookies as described in our Cookie Policy.

7. Children's privacy

The Service is a business tool for tour operators — it isn't directed at children, and TourMan doesn't knowingly collect personal data about children through it.

8. Security

bcrypt password hashing, role-based access control, administrative action logging, HTTPS, firewall and DDoS protection at the infrastructure level. No disk-level encryption at rest is configured yet on our hosting.

9. Changes to this Policy

We'll update the effective date when this Policy changes. For a material change to how organization users' data is handled, every organization Admin will be notified.

10. Contact

info@tourman.app, or by post to Maksym Chernysh, 15A Via dei Licheni, Roma, Lazio 00172, Italy.

Privacy Policy — TourMan