Privacy Policy

Last Updated: August 12, 2026

A policy explaining what personal data Turs processes, for what purposes and on what legal bases, which categories of recipients it is disclosed to, how long it is retained, and how to exercise your rights.

This Privacy Policy (hereinafter, the "Policy") describes in detail the processing that Turs Technologies LLC (doing business as "Turs"; hereinafter "Turs", "we", "us" or "the Platform") carries out on the personal data of the people who access, register on or in any way use the website turslatam.com, the portal portal.turslatam.com, the Turs mobile app and our messaging channels (WhatsApp, Instagram and Facebook Messenger): what data we process, for what purposes and on what legal bases, which categories of recipients it is disclosed to, how long it is retained, and how you can exercise your rights.

This Policy forms an integral part of the Turs Terms and Conditions, published at turslatam.com/terms, and must be read together with them. Capitalized terms not defined here (Platform, User, Tour, Listing, Booking, Traveler, Host, Guest, Account, User Content, among others) have the meaning given to them in that document. In this Policy, "AI Assistant" refers to Turs's conversational assistant, presented on the Platform under the commercial name "Súper Agente" (and in some materials as "Concierge").

Turs is an intermediary marketplace that connects Travelers with independent Hosts who offer Tours and experiences in El Salvador. Tours are provided by the Hosts, not by Turs, and Turs does not take part in their material performance. This Policy applies exclusively to the data processing carried out by Turs as operator of the Platform; Hosts are independently responsible for their own use of the data they receive in order to provide the service, in accordance with the terms they accept when using the Platform, and for complying with the obligations that fall on them with respect to that data.

This Policy is governed by the laws of the Republic of El Salvador on personal data protection and electronic commerce. Platform transactions are conducted in United States dollars (USD) and times are expressed in the America/El_Salvador time zone.

We recommend that you read this Policy carefully before providing us with any personal data. If you have any questions about its content or about how we process your information, you can write to us at any time at info@turslatam.com.

1. Data Controller and General Information

1.1. Controller. The controller of the personal data described in this Policy is Turs Technologies LLC, a limited liability company (LLC) organized under the laws of the State of Delaware, United States, with operations in the Republic of El Salvador (commercial brand "Turs").

1.2. Registered address. 1007 N. Orange St., 4th Floor, Suite 1382, Wilmington, Delaware, United States.

1.3. Privacy contact channel. For any matter relating to the processing of your personal data or the exercise of your rights, you can contact info@turslatam.com, indicating the nature of your request in the subject line, which will allow us to handle it more quickly. For operational matters (bookings, payments, support) you can use the help center available inside the app and turslatam.com/contact; if an operational inquiry includes a privacy request, we will route it internally to the appropriate channel without you having to repeat it.

1.4. Scope of application. This Policy applies to all processing carried out through Turs's channels. It does not apply to the processing that unrelated third parties — including Hosts, with respect to the data they receive to provide their Tours — carry out on your data through their own services, platforms or websites, even where you access them from a link published on the Platform, for which you should consult their respective policies (see Section 17). Turs does not control such third-party services and assumes no responsibility for their privacy practices.

2. Guiding Principles of Processing

Turs processes personal data in accordance with the following principles, which guide all of its processing operations and are reflected in the specific practices described in this Policy:

  • Lawfulness, fairness and transparency: we process your data lawfully, fairly and transparently, informing you in a clear and accessible manner. This Policy describes the categories of recipients with which your data is shared (Section 7) and explains in detail how the AI Assistant works (Section 6), including its limits, its safeguards and your rights regarding it.
  • Purpose limitation: we collect your data for specified, explicit and legitimate purposes (Section 5), and we do not further process it in a manner incompatible with those purposes.
  • Data minimization: we process only data that is adequate, relevant and limited to what is necessary for each feature. Real examples of this principle: your device's location is used only in the moment and is not stored in our database (Section 3.8); your card details are processed directly by the payment provider and never reach our systems (Section 3.5); Travelers are not subject to any identity verification process, which is reserved for Hosts (Section 3.2).
  • Accuracy: we take reasonable steps to ensure that inaccurate data is rectified or erased without delay; you can correct much of your profile data directly from your Account.
  • Storage limitation: we retain data only for as long as necessary for the purposes of the processing and to comply with applicable legal obligations (Section 9), after which we proceed to delete or anonymize it.
  • Integrity and confidentiality: we apply appropriate technical and organizational measures, described by their effect in Section 12, including encryption of communications in transit, role- and owner-based access controls in the database, private storage with verified temporary access, and reinforced encryption of bank data with access logging.
  • Accountability: we take responsibility for complying with these principles and maintain mechanisms that allow us to demonstrate it, such as the audit log that records every staff access to Hosts' bank data and the periodic review of our internal procedures.

3. Categories of Personal Data We Process

We process the categories of data described below, depending on your relationship with the Platform and the features you use. Not all categories apply to all Users: the actual scope of the processing depends on your role (Traveler, Host, Guest), on the channels through which you interact with us and on the permissions you grant on your device. Where a feature requires data beyond that described here, we will inform you at the time of collection.

3.1. Identification and Account data

  • Registration data: full name, email address and password — stored exclusively using cryptographic techniques that prevent it from being read —; or the data provided by your sign-in provider if you register with Google or Apple (name and email and, with Google, also your profile photo). If you use Sign in with Apple, the email we receive may be a private relay address if you choose Apple's "Hide My Email" option.
  • Profile data: profile photo (avatar), phone number, bio, languages and role on the Platform (Traveler, Host, co-host).
  • Travel preferences declared during onboarding: categories of interest, traveler type (solo, couple, friends, family), budget level and activity level. These are used to personalize recommendations and the AI Assistant.
  • Guest profiles: if you make a Booking through a messaging channel (WhatsApp, Instagram or Messenger) without having created an Account, we create a Guest profile linked to that channel's identifier (your phone number or your Meta identifier) with the contact details you provide to manage the Booking.
  • If you subscribe to our waitlist, newsletter or contact forms, we store your email, name and the source of the subscription, together with the data you provide in the form.
  • Contacts database: we maintain a contacts record (email, name, signup source — waitlist, newsletter or Host application — and related metadata) to manage communications, and we may link the identifiers of your different channels (email, WhatsApp phone number, Meta identifiers) when they correspond to the same person. It is accessible only to our systems and authorized staff.

3.2. Host verification and onboarding data

Identity verification applies only to Hosts; Travelers are not subject to any identity verification process.

  • Host application: first name, last name, email, phone, city, experience, social media handles and a description of your proposal.
  • During verification: identity documents and bank statements, which are stored in private, access-restricted repositories, served only through verified temporary access after confirming that the person accessing them is the owner or authorized staff.
  • Bank details for payouts: those captured on the platform are stored with reinforced encryption at the application level; only the last 4 digits are shown in the interface, and every staff access to this data is recorded in an audit log.
  • The result and status of bank verification, a requirement for receiving payouts (Section 3.5).

3.3. Data relating to Tours, Listings and the shop

  • If you are a Host: the information of the Tours you publish (descriptions, conditions, prices, capacity, schedule and meeting point), the photos of your Tours and your shop items with their photos and prices. This information constitutes the content of your public listing and is visible to any visitor of the Platform.
  • Profile, Tour, review and shop item photographs are hosted in publicly accessible repositories (they are visible on the Platform); you should keep this visibility in mind before publishing them.
  • The content of published Tours is additionally converted into numerical representations (embeddings) for semantic search (see Section 6.1), without this altering their content or visibility.

3.4. Data relating to Bookings and their performance

  • For each Booking we store: the Traveler's (or Guest's) contact name, email and phone, the Tour booked, date, number of guests, amounts, currency (USD), Booking status and originating channel (web, app — recorded as "app" or "in-app" —, WhatsApp, Instagram, Messenger). These data are necessary to manage the full life cycle of the Booking, from the request through to its performance, cancellation or refund.
  • If you add items from a Host's shop to a confirmed Booking, we record the item, its price at the time and the quantity.
  • Tour attendance records, when the Host marks attendance through their management tools.

3.5. Payment and payout data

  • Card data: payments are processed by an authorized payment service provider; the provider currently used for card processing is Stripe, whose involvement is visible in the payment process itself. Your card details are entered directly into the provider's payment components and Turs never stores card numbers or security codes; we keep only tokenized references to the payment method, the card brand and its last 4 digits, plus a customer identifier from the payment provider associated with your profile. Apple Pay and Google Pay are processed through the same channel.
  • We keep the financial breakdown of each transaction (amounts, fees, total and Host payout, as itemized before payment confirmation) and the refund history.
  • Refunds, where applicable under the Cancellation Policy, are processed through the payment provider to the original payment method.
  • If you are a Host: your wallet balance, your withdrawal requests and the payout history; Turs issues payouts by bank transfer to your verified account.
  • If you participate in the referral program: your application (with your contact details), its approval status, the codes or coupons assigned to you and their usage, and the commissions credited to your referral wallet, linked to the third-party Bookings that originate them.

3.6. Communications and content

  • Traveler–Host chat: messages you exchange with a Host (or Traveler) inside the Platform are stored linked to the Booking. You may request automatic translation of these messages; the text to be translated is processed with AI (see Section 6).
  • Conversations with the AI Assistant: messages you exchange with the AI Assistant in the web chat, the mobile app, the Host business assistant, and the WhatsApp, Instagram and Messenger channels are stored in our database, together with the sender identifier (your phone number on WhatsApp, your Meta identifier on Instagram/Messenger, or your user ID/IP address on web and app). Conversations with the tour widget and the Host profile assistant are processed in the moment and we do not store their content: for those we only record technical telemetry, without the text of the messages (see 3.7), and their history is kept only on your device. Two clarifications: if you escalate a question to the Host from the tour widget, that specific question is stored so we can deliver it to the Host and record their reply; and on all AI Assistant surfaces, the preferences you share may be saved to its memory (see 6.4), even where the conversation itself is not stored.
  • Voice notes and images on WhatsApp: voice notes you send via WhatsApp are transcribed with AI, and images are processed with AI in order to respond to you (see Section 6).
  • Messages on Meta channels (WhatsApp, Instagram, Messenger) are also processed by Meta Platforms under its own policies, since they travel through Meta's infrastructure.
  • Reviews: the content of the reviews you publish about a Tour, their rating (1 to 5) and up to 4 photos per review — reviews and photographs that constitute User Content and are publicly visible on the Platform — linked to the Booking that originates them. Reviews may be subject to moderation in accordance with the Terms and Conditions.
  • Support requests: support tickets you create (or that are opened on your behalf) and their history: the content of the request, category, priority, status and the messages exchanged with our team, which are retained for the handling of the case and as a service history.

3.7. Usage, device and security data

  • Crash reports (mobile app): the app sends error and performance reports to a specialized diagnostics provider when a failure occurs (crash data, device model, operating system and app version), for the sole purpose of detecting and fixing errors. This tool is configured not to send personally identifiable data by default.
  • AI Assistant telemetry: for each interaction with the AI Assistant we record technical traces: channel, sender identifier, latency, model used, processing volume, tools invoked and error messages, for operation, security and service improvement purposes.
  • AI Assistant security logs: in conversations with the AI Assistant started from the web or the mobile app we additionally record technical data about the request — such as your IP address and your device's user agent — as security audit data, to detect abusive uses or attempts to manipulate the AI Assistant. Where there are signs of an attack, the system may automatically suspend the conversation — the suspension may extend to the other channels of the same Account — and generate an alert to our team with that data for subsequent human review (see 6.9).
  • Web analytics: the website uses third-party usage analytics tools to measure use of the service in aggregate form (events such as booking started, booking completed, searches). The mobile app does not include third-party behavioral analytics tools; the only third-party tool it incorporates is the crash-diagnostics tool described in the first item of this section, which does not constitute usage analytics.
  • Security and anti-abuse: we use your IP address or your user ID as a key to apply rate limits at sensitive points of the Platform, in order to prevent abuse and protect the availability of the service.
  • Push notifications: if you enable notifications in the app, we store your push notification token together with your user ID and platform (iOS/Android), and your per-category notification preferences. Delivery is carried out through a specialized notifications provider and the token is deleted when you sign out.

3.8. Location data

  • Mobile app: with your permission, we use your location (approximate or precise, depending on what you authorize on your device) only in the foreground and in the moment, to show you nearby Tours. We do not track your location in the background and we do not store your location in our database. You can revoke the location permission at any time from your device settings without this preventing the use of the rest of the features.
  • Web and mobile app: address autocomplete relies on a specialized provider of mapping and geocoding services; your browser or device connects to its servers and sends it only the address queries needed to run the search. On the web, maps are also loaded from that provider; in the mobile app, maps are displayed with the operating system's map service (Apple Maps on iOS, Google Maps on Android), and your device connects to Apple's or Google's servers to load them.
  • AI Assistant: if you voluntarily share a pin or coordinates in a conversation with the AI Assistant, those coordinates form part of the message: they are stored with the conversation history and processed as described in Section 6.

3.9. Third-party data provided by the User

If you provide us with personal data of third parties — for example, if you mention another person's data in a message to the AI Assistant or in the chat with a Host, or if you make a Booking that includes other participants — you warrant that you have the necessary authority to disclose it to us and that you have previously informed them of the contents of this Policy. Turs is not liable for any breach of this duty to inform, which rests exclusively with you as the person providing the data.

4. Sources of the Data

The personal data we process comes, as the case may be, from the following sources. As a general rule, we do not obtain data about you from sources other than those listed here, and where a piece of data may come from several sources we process it with the safeguards corresponding to all of them:

  • Directly from you, when you register, complete your profile or onboarding, make a Booking, publish a review, apply as a Host or referrer, or communicate with us or with the AI Assistant. You are responsible for the truthfulness and currency of the data you provide to us.
  • Generated by your use of the Platform, such as the technical records, the AI Assistant telemetry and the security logs described in Section 3.7, which are produced automatically as a result of your interaction with the service.
  • From sign-in providers (Google, Apple), limited to the minimum identification data you authorize in that process (name, email and, with Google, profile photo; with Apple, the email may be a private relay address).
  • From Meta channels (WhatsApp, Instagram, Messenger), which deliver to us the messages you send us together with the identifier of the channel you write from.
  • From Hosts, in the course of managing their Tours and Bookings: for example, when answering a question escalated by the AI Assistant or when recording the attendance of a Tour's participants.

5. Purposes of Processing and Legal Bases

We process your personal data for the following purposes, relying on the processing bases indicated in each case. We do not process your data for purposes incompatible with those described here; if in the future we intended to carry out further processing for a different purpose, we would first provide you with the corresponding information and, where required, obtain your consent:

  • Creating and managing your Account; authenticating you (including Google/Apple sign-in) — Performance of the contract (Terms and Conditions).
  • Processing Bookings, payments, refunds and Host payouts — Performance of the contract and legal/accounting obligations.
  • Connecting you with Hosts and enabling communication between the parties — Performance of the contract.
  • Operating the AI Assistant and personalizing its responses (see Section 6) — Performance of the contract and consent, as applicable.
  • Sending transactional communications (confirmations, reminders, payment links) — Performance of the contract.
  • Sending promotional communications and the newsletter — Consent (with opt-out at any time).
  • Verifying Host identity and bank details — Performance of the contract and fraud prevention.
  • Operating the referral program (applications, coupons, commissions) and the shop for items added to Bookings — Performance of the contract and legal/accounting obligations.
  • Platform security, fraud and abuse prevention, rate limiting — Legitimate interest.
  • Analytics and service improvement — Legitimate interest.
  • Complying with requests from competent authorities — Legal obligation.

We do not sell or rent your personal data to third parties for marketing purposes.

5.1. Performance of the contractual relationship

  • Creating, maintaining, authenticating and managing your Account and your profile, including Guest profiles created from messaging channels.
  • Putting Travelers and Hosts in contact and making it possible for them to contract with each other, disclosing to each party the data strictly needed for the performance of the Booking.
  • Managing Booking requests, confirmations, expirations, modifications and cancellations, in accordance with the Terms and the Cancellation Policy.
  • Processing payments and refunds through the payment provider, and issuing payouts and withdrawals to Hosts and referrers.
  • Verifying Host identity and bank details, a purpose based on the performance of the contract and on fraud prevention.
  • Operating the AI Assistant in its service functions (Section 6) and the translation of chat messages.
  • Enabling communication between the parties and with our support channels, including tickets.
  • Sending operational communications relating to your Bookings, your Account and the service.

5.2. Compliance with legal obligations

  • Retaining accounting, tax and transaction records for the legally required periods.
  • Responding to valid requests from administrative, judicial or law enforcement authorities.
  • Preventing and detecting fraud and other unlawful conduct, to the extent required by applicable law.
  • Complying with any other obligations imposed on Turs by applicable law as operator of the Platform.

5.3. Legitimate interest

  • Ensuring the security of the Platform and its Users: rate limiting at sensitive points, anti-bot verification at sign-up, cryptographic validation of provider integrations, and detection of abusive uses of the AI Assistant (Section 3.7).
  • Preventing, detecting and investigating fraudulent or abusive uses, or uses contrary to the Terms.
  • Handling claims and incidents and defending Turs's rights against legal actions.
  • Analyzing Platform usage in aggregate form (third-party usage analytics tools on the website; technical telemetry of the AI Assistant) in order to maintain, debug and improve it.
  • Moderating published content (Tours, items, reviews) to preserve the quality and trust of the community.

5.4. Consent

  • Sending commercial communications, promotions and the newsletter when you have authorized it (Section 14).
  • Accessing the device's approximate or precise location (Section 3.8), a permission you manage directly from your device settings.
  • Sending push notifications to the device (Section 3.7).
  • Any other processing for which your consent is expressly requested, which you may withdraw at any time without retroactive effect and without the withdrawal conditioning access to features that do not depend on that processing.

6. Automated Decisions and Artificial Intelligence

Turs uses artificial intelligence as a core part of the Platform. In order to provide these features, Turs relies on artificial intelligence systems operated by specialized providers acting on behalf of Turs as data processors, to which only the information strictly necessary for the relevant purpose is sent. This section transparently explains what the AI does, what data it processes, what its limits and safeguards are, and what rights you have regarding it.

6.1. Features that use AI

  • Traveler AI Assistant: available in the web chat, the mobile app, the per-tour assistant, the profile of each Host, and via WhatsApp, Instagram and Facebook Messenger. It answers questions, recommends Tours based on your preferences and can manage Bookings with the safeguards described in 6.5.
  • Host business assistant: available on the web, in the mobile app and on WhatsApp, so the Host can manage their Bookings, schedule, capacity and earnings using natural language.
  • Message translation: on-demand translation of Traveler–Host chat messages.
  • Voice transcription: voice notes sent via WhatsApp are transcribed to text.
  • Image analysis: images sent via WhatsApp are analyzed to understand your request and suggest Tours.
  • Semantic search: published Tour content and your search queries are converted into vector representations (embeddings) to deliver better results.
  • Internal uses: an automated auditor classifies conversations with the AI Assistant to detect when a human should step in; a triage system classifies technical errors; and the Turs magazine includes AI-generated articles and covers that are published only after approval by a member of our team.

6.2. External AI provider and models

The features described in 6.1 are provided through specialized AI model providers acting on behalf of Turs as data processors: the messages and data described in 6.3 are sent to those providers solely to generate the corresponding responses and features, and only to the extent strictly necessary for each of them. Depending on the feature, language models are used for conversational chat and translation, transcription models for voice notes, semantic representation models for search, and image generation models for the magazine's editorial content; the specific model versions may be updated to equivalent versions without diminishing the safeguards described in this Policy.

These providers are contractually required to process the data in accordance with our instructions, maintain its confidentiality and apply appropriate security measures (see 7.1). If onboarding a new AI provider were to entail a material change in the processing described in this section, we will update this Policy before sending it any personal data.

6.3. What data is sent to the AI provider

When you use the AI Assistant, the following is sent to the specialized AI providers acting on behalf of Turs, depending on the context and always limited to what is necessary to generate the requested response or feature:

  • Your messages and the recent conversation history (up to the last 20 messages).
  • Your name and the channel identifier (phone number on WhatsApp; Meta identifier on Instagram/Messenger; user ID or IP address on web/app).
  • The AI Assistant's memory about you (see 6.4) and your onboarding taste profile.
  • Images and voice notes you send via WhatsApp.
  • If you are a Host: your name and email, and the operational data you query (schedule, your customers' Bookings — name, date, party size, amounts — and your earnings).
  • Platform business information (frequently asked questions, policies, seasonal information) that gives context to the responses.

6.4. AI Assistant memory

The AI Assistant keeps a persistent memory per user to personalize its responses: your name, interests, group type and size, whether you travel with children or elderly companions, budget, Tours you have booked and Tours you have viewed. This memory is stored in our database, is updated with what you share in the conversation, and is injected as context in future interactions, for the sole purpose of improving the relevance of the responses you receive. If you started conversations anonymously and later sign in, the anonymous memory is linked to your Account. This memory is not used for advertising purposes and is not disclosed to third parties other than the AI providers described in 6.2, and you can request access to, correction of, or deletion of it at any time (see 6.8).

6.5. Actions the AI Assistant can take

The AI Assistant can perform real actions on your Account, always with safeguards designed so that no action with economic or irreversible effects takes place without your intervention:

  • Create Bookings and generate payment links; the payment is always completed by you at checkout: the AI never executes charges.
  • Cancel your own Bookings, applying the current Cancellation Policy (if a refund applies, it is processed through the payment provider to your original payment method). Before canceling, the AI Assistant identifies the Booking, tells you whether or not a refund applies, and waits for your explicit confirmation.
  • For Hosts: confirm or reject Booking requests, manage capacity, mark attendance, create draft Tours and perform other operational tasks, with prior confirmation for non-reversible actions.
  • Create Accounts through a one-time code (OTP) verification sent to your email, record reviews for Bookings whose Tour has already taken place, and open support tickets.

In addition to your confirmation in the conversation, sensitive actions require server-side identity and ownership verification: the AI Assistant can only operate on the data of the authenticated user or verified channel, never on third parties' data, and these verifications do not depend on what is claimed in the conversation itself. Bookings, cancellations and payments managed through the AI Assistant are in all cases governed by the Platform's Terms and Conditions and Cancellation Policy, which prevail over any conversational formulation.

The AI Assistant can make mistakes. Its responses are generated automatically by language models, may contain inaccuracies or omissions and do not constitute professional advice of any kind. The binding information about your Booking is the information recorded on the Platform and in the contractual documents, not what the AI Assistant states in a conversation. If you have any doubt about a Booking, a payment or a policy, you can ask to speak with a person (see 6.6) or contact support.

6.6. Human review and escalation

  • Our team can view complete AI Assistant conversation threads in an internal supervision inbox and take over the conversation; while a human agent is handling the thread, the AI is paused on all channels. This access is restricted to authorized staff and is carried out for support, quality, security and fraud-prevention purposes.
  • An automated auditor and keyword detection (for example, requests to speak with an agent, complaints or refund topics) escalate the conversation for human attention.
  • Tour-specific questions the AI Assistant cannot answer are escalated to the Host, who replies from their own app.
  • Payment-related cases are always routed to human review: the AI Assistant does not process refunds through the support path.

6.7. Use of your data for model training

Turs does not use your conversations to train its own models and contractually requires its providers not to use them to train theirs. Data is sent to the AI providers solely to generate the requested response or feature, and not for training, advertising profiling or any other purpose unrelated to the provision of the service.

6.8. Your rights regarding the AI Assistant

  • You can ask to be attended by a person at any time, without needing to give a reason and at no cost or reduction in service.
  • You can request access to, correction of, or deletion of your conversation history stored by Turs and the memory the AI Assistant keeps about you, through the channels in Section 10. The history of the tour widget and the Host profile assistant is kept only on your device (not on our servers, see 3.6), so its deletion is under your control.
  • You can choose not to use the AI Assistant: all essential Platform features (searching, booking, contacting support) are available without interacting with the AI.

6.9. Automated decisions with significant effects

The AI features described in this section do not make decisions that produce legal effects on you without the possibility of human intervention. In particular, the automatic suspension of conversations for security reasons (Section 3.7) is subject to review by our team, and you can request its review at any time by writing to info@turslatam.com, obtain human intervention, express your point of view and contest the measure taken.

7. Categories of Recipients and Data Processors

Turs does not sell, rent or trade your personal data. We disclose your data exclusively to the categories of recipients indicated below, always to the extent strictly necessary for the corresponding purpose and, in the case of service providers, under the data processing rules described in 7.1. Whether a given piece of data falls into one category or another depends on the feature you use:

  • The counterparty to your Booking (Host or Traveler): your name, your contact details and the Booking details strictly needed for the provision of the Tour are disclosed to the other party, as well as questions escalated by the AI Assistant and their replies.
  • Payment service providers: authorized entities that process card, Apple Pay and Google Pay payments, and refunds to the original payment method; they receive the transaction and payment method data. The provider currently used for card processing is Stripe, whose involvement is visible in the payment process itself. Turs does not see or store card numbers. Host payouts are issued by Turs via bank transfer to the verified account.
  • Technology infrastructure providers: providers of hosting, database, authentication, file storage, app distribution and backup services that technically sustain the Platform.
  • Artificial intelligence system providers: specialized providers that carry out, on behalf of Turs, the processing described in Section 6; they receive the data described in 6.3.
  • Communications providers: providers of transactional email services (Booking confirmations, payment links, Host notifications) and push notifications; they receive your email address or your notification token and the message content.
  • Mapping and geocoding service providers: they display maps and autocomplete addresses; your browser or device connects to their servers and sends them the address queries (see 3.8).
  • Federated authentication providers: Apple and Google, only when you choose to sign in through their sign-in services; additionally, the mobile app's maps are displayed with the operating system's map service (Apple Maps on iOS, Google Maps on Android).
  • Meta Platforms: WhatsApp, Instagram and Facebook Messenger: messages you exchange with Turs on these channels pass through Meta's infrastructure, subject to its own policies.
  • Security, diagnostics and abuse-prevention providers: providers of crash-diagnostics tools, website usage analytics, anti-bot verification at sign-up and rate-limiting controls; they receive the technical signals strictly necessary for their function (see 3.7).
  • Advisors and auditors: legal, accounting and tax advisors and auditors bound by confidentiality obligations, where necessary for the defense of rights or compliance with legal obligations.
  • Competent authorities: administrative, judicial, tax or law enforcement authorities, where there is a legal obligation or a validly issued order.
  • Third parties in corporate reorganizations: in the event of a merger, spin-off, acquisition or total or partial transfer of the business, with prior notice to the affected Users.

We do not share your data with recipients other than the above.

7.1. Rules applicable to processors

The technology providers in the above categories access personal data on behalf of Turs, as data processors or sub-processors, and only to the extent necessary to provide their service. We require adequate data protections from them through their terms of service and data processing agreements, which oblige them to process data in accordance with documented instructions, maintain confidentiality, apply appropriate security measures and not use the data for their own purposes.

An up-to-date, named list of the data processors involved in providing the service is available to any interested party upon reasoned request addressed to info@turslatam.com. This information is provided upon request, rather than through permanent publication, for information security and trade secret protection reasons, without this limiting in any way your right to know it.

Hosts are not processors of Turs: they are independent providers who receive Booking data in order to perform the Tour and are responsible for their own use of that data, in accordance with the Terms they accept when using the Platform.

8. International Data Transfers

8.1. Location of processing. Turs is operated by Turs Technologies LLC, a United States company, and our technology infrastructure providers (Section 7) host the data primarily in the United States of America, so the processing of your data takes place primarily in that jurisdiction. Given the international nature of our operation, if you use the Platform from El Salvador or another country, your data is transferred to and stored in the jurisdictions where these providers operate.

8.2. Safeguards. Where an international transfer takes place, we adopt contractual safeguards with each provider — such as contractual clauses or equivalent contractual commitments — so that the level of protection of your data is not undermined and, with respect to users in El Salvador, we comply with applicable Salvadoran regulations.

8.3. Additional information. You can request additional information about the safeguards applicable to a specific transfer by writing to info@turslatam.com, indicating the feature or processing you would like the information about.

9. Retention Periods

We retain your personal data only for as long as necessary for the purposes for which it was collected and to comply with applicable legal obligations, in accordance with the criteria indicated below; once the corresponding periods have elapsed, we proceed to delete or anonymize it. Where the same data serves several purposes, it is retained for the longest applicable period, and during the residual period its use is limited to the purpose that justifies its retention:

  • Account and profile data: while your Account exists and you do not request its deletion, and for as long as necessary after its deletion to comply with legal obligations.
  • Bookings and financial records: Booking, transaction, refund and payout records are retained after Account deletion for the period required by applicable accounting, tax and fraud-prevention obligations, and in any event for as long as liability may arise from the transaction.
  • Referral program and shop: referral program records (applications, coupons and commissions) and shop items added to Bookings are retained together with the financial records they are linked to, for the same periods.
  • AI Assistant conversations and AI memory: retained while your Account is active and for as long as necessary to operate the service; you can request their deletion at any time (see 6.8 and Section 10).
  • Messages with Hosts: linked to the Booking, retained with it.
  • Support requests and contacts database: retained while your Account or your relationship with the Platform is active, and thereafter for as long as necessary to keep the support history and comply with legal obligations.
  • Technical traces and diagnostic and security logs: retained for as long as strictly necessary for operation, security, error debugging and fraud-prevention purposes.
  • Data processed on the basis of your consent: until you withdraw it, without prejudice to the lawfulness of prior processing.

10. Your Rights

As the data subject, and to the extent recognized by applicable Salvadoran law, you may exercise the following rights. Exercising any of them does not require justification — except where the law itself requires it —, is not conditional on keeping your Account, and cannot give rise to any unfavorable treatment by us:

  • Access: obtain confirmation as to whether we process personal data about you and, if so, know what that data is, access it and obtain a copy.
  • Rectification: correct inaccurate data or complete incomplete data (you can edit part of your data directly in your profile, without needing to file a request).
  • Deletion: request deletion of your data and your Account (see Section 11), subject to the legal exceptions indicated.
  • Objection: object to processing based on legitimate interest on grounds relating to your particular situation and, in any event and without needing to give a reason, to commercial communications.
  • Withdrawal of consent: withdraw at any time any consent you have given (for example, for marketing communications), without affecting the lawfulness of prior processing.
  • Any other rights recognized by applicable Salvadoran data protection law — such as restriction of processing or data portability, to the extent they are recognized — which we will honor in accordance with that law.

10.1. How to exercise them

To exercise these rights, write to info@turslatam.com from the email address associated with your Account, indicating the right you wish to exercise and providing the information needed to handle your request. In order to protect your information against fraudulent requests, we may ask you for additional information to verify your identity before acting on the request. Exercising these rights is free of charge, except for manifestly unfounded or excessive requests, particularly repetitive ones. We will handle your request without undue delay.

We will respond within the time limits established by applicable Salvadoran regulations. If you believe we have not addressed your request or that the response was unsatisfactory, you may turn to the competent data protection authority of El Salvador, without prejudice to any other actions available to you under the law.

11. Deletion of the Account and the Data

11.1. Available channel. You can request deletion of your Account by writing to info@turslatam.com from the email address associated with your Account, indicating that you wish to delete it. No justification will be required, without prejudice to reasonable identity checks aimed at protecting your Account against fraudulent requests.

11.2. Timeframe. We will process the deletion within a maximum of thirty (30) days. Deletion is irreversible and does not allow later recovery of your Account history.

11.3. Scope. Deletion covers your profile data, favorites, messages, AI Assistant conversations, AI memory, notification tokens and other personal data and, in the case of Hosts, the identity documents and bank details provided for verification and withdrawals, except for those linked to payouts already executed or to legal obligations, which are retained in accordance with the retention periods in Section 9; all of the above subject to the exceptions in clause 11.4.

11.4. Data that is retained. After deletion, the following is retained, dissociated from your identity to the extent possible:

  • Accounting and transaction records of Bookings and payments, which are kept linked to the transaction due to legal, accounting and tax obligations and for fraud prevention, as well as for the establishment, exercise or defense of claims.
  • Published reviews, which may be retained in anonymized form, as they form part of the public history of the Tours they refer to.
  • Data whose retention is required by a legal obligation or a valid order from a competent authority.

11.5. Grounds for postponement or refusal. We may postpone or refuse the deletion of your Account while there are: (a) active Bookings or Bookings pending settlement, which must first be completed or canceled in accordance with the Cancellation Policy; (b) open support cases; and, (c) if you are a Host, balances pending withdrawal or ongoing penalty appeals.

11.6. Messaging users without an Account. If you have interacted with Turs only through WhatsApp, Instagram or Messenger, without creating an Account, you can request the deletion of your conversations and of the data linked to your channel identifier in two ways: by asking in the channel itself, where a human agent will take over the conversation to process the request, or by writing to info@turslatam.com, indicating that identifier so we can locate them. We may confirm the request through a message to that channel before deleting them, as a safeguard against requests made by unauthorized third parties.

12. Security Measures

12.1. Measures applied. We apply appropriate technical and organizational measures to protect personal data against destruction, loss, alteration and unauthorized disclosure or access, described below by their effect:

  • Encryption of communications in transit: all communication with the Platform travels encrypted using industry-standard protocols.
  • Role- and owner-based access controls in the database: access controls are enforced in the database itself, so that each user can only access the data that corresponds to them according to their role and their status as data owner, following the principle of least privilege.
  • Private storage with verified temporary access: sensitive documents (identity, bank documents) are stored in private, access-restricted repositories and are served only through short-lived temporary access, after validating the identity and authorization of the person accessing them.
  • Reinforced encryption of bank data with access logging: Host bank account numbers captured on the web are stored with reinforced application-level encryption, and every staff access to this data is recorded in an audit log.
  • Rate limiting at sensitive points: sensitive operations (authentication, payments, documents) apply rate limits with a restrictive policy on repeated failures, to hinder unauthorized access attempts and abuse.
  • Cryptographic validation of integrations: communications we receive from our providers are cryptographically validated before being processed, and internal automated processes are protected with access-restricted secrets.
  • Web application hardening: we apply policies that restrict the origin of the content the browser may load and that protect against embedding the Platform in external sites, among other hardening measures.
  • AI Assistant supervision: automatic detection of abusive uses or manipulation attempts in conversations, with thread suspension, alerts to the team and subsequent human review (see 3.7 and 6.9).

12.2. User's duty of care. Security is a shared responsibility: you must safeguard your credentials, not share them with third parties, use strong passwords, keep your device up to date and notify us immediately of any unauthorized use or suspected compromise of your Account. Turs will never ask you for your password by email, phone or messaging channels; be wary of any communication that does.

12.3. No infallibility and incident notification. No information system is completely invulnerable, so Turs cannot absolutely guarantee the security of data transmitted over open networks, although it undertakes to diligently apply the measures described and to review them periodically. If we detect a security incident affecting your personal data that entails a risk to your rights, we will notify you in accordance with applicable regulations.

13. Cookies and Similar Technologies

13.1. Cookies we use. On the web we use:

  • First-party session cookies, set for the .turslatam.com domain, strictly necessary to keep you signed in across turslatam.com and portal.turslatam.com and for browsing security.
  • First-party access cookies: if restricted-access phases are enabled (for example, a pre-launch), we may use our own access cookies to control them.
  • Third-party analytics tool cookies, used exclusively for the website usage analytics described in Section 3.7.

13.2. Control. You can configure your browser to block or delete cookies, although this may affect how your session and certain features work.

13.3. Mobile app. The mobile app does not use browser cookies; it keeps your session and your preferences through the device's secure local storage, under your control and removable by signing out or uninstalling the app.

14. Commercial Communications

14.1. Transactional communications. As part of the service we send you operational communications that do not require additional consent, as they are essential for the performance of the contractual relationship: Booking confirmations and receipts, payment links, notices of request approval or rejection, cancellation and refund notices, and reminders of your Tour (by push notification and, if you agree to it in the conversation, through the messaging channel you booked through — WhatsApp, Instagram or Messenger — 24 hours before the Tour). These communications are limited to what is necessary to manage your Bookings and your Account and do not include promotional content.

14.2. Marketing communications. Promotional communications (promotions and newsletter) are optional and require your express authorization. You can turn them off at any time, free of charge and without giving a reason, from the app's notification preferences (promotions and newsletter categories) or by requesting to unsubscribe through the contact channels; withdrawal will have no retroactive effect on communications already sent.

14.3. Effects of opting out. Opting out of marketing does not affect operational, contractual, security or legally required communications relating to your Bookings and your Account, which are essential for the provision of the service. You can also disable push notifications entirely in your device settings without this preventing the use of the rest of the features.

15. Minors

The Platform is intended for people aged 18 or older. You must be at least 18 years old to create an Account and make Bookings (a requirement also established in the Terms and Conditions). We do not knowingly collect personal data from minors; if we become aware that we have processed data of a minor without the corresponding legal authority — for example, because a minor created an Account — we will delete it without delay, together with the associated data. Minors may only take part in Tours as companions, under the sole responsibility of the adult who makes the Booking, who is responsible for the truthfulness of the information provided. If you are a parent or guardian and believe that a minor in your care has provided us with personal data, write to us at info@turslatam.com so we can verify it and act accordingly.

16. Advertising and Absence of Cross-App Tracking

The Turs mobile app does not incorporate third-party behavioral analytics components or cross-app or cross-site advertising tracking mechanisms; the only third-party tool it includes is the crash-diagnostics tool, limited to that purpose (Section 3.7). The website uses third-party usage analytics tools exclusively to measure use of the service in aggregate form: we do not use these tools for advertising purposes and we do not have their advertising features enabled. We do not display personalized third-party advertising, we do not build advertising profiles of our Users, and we do not disclose data to advertising networks for any purpose.

17. Third-Party Links and Services

The Platform may contain links to third-party websites, social networks or services — including those of Hosts — that are not controlled by Turs or covered by this Policy; you access those resources at your own risk and subject to the privacy policies of their respective owners, which we recommend you read before providing them with any data. Likewise, when you communicate with Turs through WhatsApp, Instagram or Facebook Messenger, those channels are operated by Meta Platforms, and Meta's processing of your messages and data is additionally governed by its own policies, over which Turs has no control. Turs is not responsible for the processing of your data by such third parties or for any damages that may arise from it.

18. Changes to This Policy

We may update this Policy to adapt it to regulatory, technical or operational changes in the Platform. We will publish the current version at turslatam.com/privacy with its last-updated date and, when changes are significant, we will notify you through the Platform's channels reasonably in advance of their entry into force. We recommend that you review this Policy periodically to stay informed of its current content. Continued use of the Platform after the changes take effect implies acceptance of the updated Policy, without prejudice to your rights and to any processing that requires specific consent, which shall in no case be deemed given by mere continued use.

19. Contact and Complaints

  • Controller: Turs Technologies LLC (brand "Turs").
  • Email for privacy matters and exercising your rights: info@turslatam.com.
  • Operational support: help center inside the app and turslatam.com/contact.
  • Address: 1007 N. Orange St., 4th Floor, Suite 1382, Wilmington, Delaware, United States.

We will endeavor to resolve any inquiry, request or complaint satisfactorily and as quickly as possible. Using our contact channels does not limit or replace any of the rights described in Section 10. In any event, you have the right to lodge a complaint with the competent data protection authority of El Salvador.

This Policy is interpreted in accordance with the laws of the Republic of El Salvador.

Turs Technologies LLC

1007 N. Orange St., 4th Floor, Suite 1382, Wilmington, Delaware, USA. Operations: Republic of El Salvador.