BookTourX Logo
Anytime

Privacy Policy

Last updated: 12 August 2026

BOOK TOUR X PRIVATE LIMITED (UEN: 202514301E), 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987

BOOK TOUR X PRIVATE LIMITED ("we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website, mobile app, and marketplace services, including booking, listing, and payment services (collectively, the "Platform"), whether you are a Customer, Supplier, or other user of the Platform.

By accessing or using the Platform, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Platform.

1. Introduction

BOOK TOUR X PRIVATE LIMITED ("we," "us," "our," or the "Company") operates BookTourX (the "Platform"), an online marketplace that connects customers ("Customers," "you") with independent third-party tour operators, activity providers, guides, and experience hosts ("Suppliers") for the purpose of booking tours, activities, and travel experiences.

This Privacy Policy ("Policy") explains what personal data we collect, how we use and disclose it, the legal bases on which we rely, how long we retain it, and the rights available to you. It applies to our website, mobile applications, supplier portal, and related services (together, the "Platform").

This Policy is directed principally at Customers using the Platform as consumers. Personal data we collect about Suppliers and their personnel in a business-to-business capacity is addressed separately in Section 4.3 and, in greater detail, in our Supplier Terms & Conditions, which takes precedence for that relationship.

By accessing or using the Platform, you acknowledge that you have read and understood this Policy. Where consent is the legal basis for a specific processing activity, we will seek that consent separately (e.g., via a cookie banner or marketing opt-in) rather than relying on continued use of the Platform alone.

2. Who We Are — Data Controller

The Platform is operated by:

  • Legal entity: BOOK TOUR X PRIVATE LIMITED
  • Registration number: 202514301E
  • Registered address: 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987
  • Data Protection Officer / Privacy contact: Lye Hoe Yip, reachable at [email protected]

BOOK TOUR X PRIVATE LIMITED acts as the data controller (or, in UK/EU terminology, "controller"; in Singapore PDPA terminology, the "organisation") for personal data processed through the Platform, except where explicitly stated that a Supplier acts as an independent controller for data it collects directly from you (for example, at the point of service delivery).

3. Scope and Key Definitions

3.1 Personal Data

"Personal data" means any information relating to an identified or identifiable natural person, consistent with the Singapore Personal Data Protection Act 2012 ("PDPA"), the EU/UK General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), as applicable to you based on your location.

3.2 Sensitive / Special Category Data

Certain data we process — including passport and national ID details, and in limited cases health or dietary information relevant to an activity (e.g., allergies, mobility requirements, medical fitness for diving or high-altitude trekking) — is treated as sensitive personal data and is subject to the heightened safeguards described in Section 5.

3.3 Jurisdictional Scope

Where you are located in the European Economic Area, the United Kingdom, or California, the jurisdiction-specific provisions in Sections 9.2, 9.3, and 9.4 supplement and, in the event of conflict, prevail over the general provisions of this Policy for your data.

4. Personal Data We Collect

4.1 Information You Provide Directly

When you register, browse, book, or communicate with us, we may collect:

  • Full name, date of birth, and gender (where relevant to an activity, e.g., age-restricted tours)
  • Contact details: email address, phone number, mailing address
  • Country of residence and nationality
  • Account credentials (username, password, or social-login identifiers)
  • Payment card or bank details, processed by our third-party payment processor(s) (see Section 6)
  • Passport, national ID, or visa details, where required by a Supplier, destination, or activity operator (see Section 4.4)
  • Health, dietary, accessibility, or fitness information voluntarily provided to enable safe participation in an activity
  • Travel preferences, wishlists, reviews, ratings, and booking/participation history
  • Correspondence with us or with Suppliers through the Platform (e.g., messages, support tickets)
  • Content you submit, such as reviews, photos, or forum posts

4.2 Information Collected Automatically

When you use the Platform, we and our service providers automatically collect:

  • IP address, device identifiers, browser type and version, and operating system
  • Precise or approximate location data, where you have granted permission
  • Log data: pages viewed, search queries, referring/exit pages, session duration, timestamps
  • Cookies, SDKs, pixels, and similar tracking technologies (Section 10)
  • Booking-funnel and transaction behavior used for fraud prevention and analytics

4.3 Supplier and Partner Information (Business-to-Business Data)

Where you act on behalf of a Supplier, business partner, or corporate client, we collect business contact details, company registration and tax information, bank/payment details for payout purposes, and licenses, permits, or insurance documentation required to list activities on the Platform. This information is governed primarily by our Supplier Terms & Conditions and any applicable data processing agreement between the parties; this Policy applies to it only to the extent such terms are silent.

4.4 Sensitive Data — Passport, National ID, and Health-Related Information

Certain activities (e.g., international tours, activities in regulated or protected areas, adventure sports, or destinations with visa/border requirements) may require us or a Supplier to collect passport numbers, national ID numbers, visa details, or health/fitness declarations. We apply the following additional safeguards to this category of data:

  • Collected only where strictly necessary for the specific booking, and flagged as optional wherever the activity or destination does not legally require it
  • Access restricted to personnel and systems directly involved in fulfilling the relevant booking, on a need-to-know basis
  • Encrypted at rest and in transit using industry-standard protocols
  • Retained only for the period specified in Section 8.2, and deleted or irreversibly anonymized thereafter unless a longer retention period is legally mandated (e.g., immigration or customs recordkeeping)
  • Never used for marketing, profiling, or any purpose unrelated to the booking, compliance, or safety of the activity

5. Legal Bases for Processing

Where GDPR/UK GDPR applies, we rely on the following legal bases (Article 6, and Article 9 for special category data):

  • Performance of a contract — to create your account, process bookings, and deliver the Platform's core functionality
  • Legitimate interests — for fraud prevention, Platform security, product analytics, and service improvement, balanced against your rights and expectations
  • Consent — for marketing communications, non-essential cookies, and processing of sensitive data such as health/dietary information, where consent is withdrawable at any time
  • Legal obligation — for tax, accounting, anti-money-laundering, and regulatory recordkeeping requirements
  • Vital interests — in rare cases, to protect the life or physical safety of a Customer or third party during an activity

Where the Singapore PDPA applies, we process personal data on the basis of your consent, or where processing falls within a permitted exception under the PDPA (e.g., necessary for the conclusion or performance of a contract with you, business improvement purposes, or legal/regulatory compliance).

6. How We Use Your Personal Data

We use personal data for the following specific purposes:

  • Account creation, authentication, and management
  • Processing, confirming, modifying, and cancelling bookings, including transmitting necessary details to the relevant Supplier
  • Processing payments and payouts via our payment processor(s) and, for Suppliers, payout providers
  • Customer support and transactional communications (booking confirmations, itinerary changes, safety alerts)
  • Verifying identity and eligibility where required by a Supplier, destination, or applicable law (e.g., age, passport validity)
  • Fraud detection, dispute resolution, chargeback handling, and Platform security
  • Aggregated and de-identified analytics to understand usage trends and improve search, recommendations, and Platform performance
  • Marketing communications about offers, new destinations, or activities — only where you have opted in or as otherwise permitted by law, and always with an opt-out (Section 11)
  • Complying with legal, tax, immigration, customs, and regulatory obligations
  • Enforcing our Terms & Conditions and protecting the rights, safety, and property of Customers, Suppliers, and the Company

We do not use passport/ID or health-related data for any purpose beyond those described in Section 4.4, and we do not use such data to make automated decisions that produce legal or similarly significant effects about you without human review.

7. Who We Share Your Data With

We disclose personal data only as necessary for the purposes described in this Policy, to the following categories of recipients:

  • Suppliers — to the extent necessary to fulfil, deliver, or provide safety/insurance coverage for your booking
  • Payment processors and financial institutions — to process payments, refunds, and (for Suppliers) payouts
  • Sub-processors and service providers — cloud hosting, analytics, customer support tooling, email/SMS delivery, identity verification, and fraud-prevention vendors, each bound by contractual confidentiality and data-protection obligations
  • Insurance providers — where you have purchased optional booking protection or where required for activity liability coverage
  • Professional advisers and auditors — where necessary for legal, accounting, or audit purposes
  • Regulators, law enforcement, or courts — where required by law, legal process, or to protect the rights, property, or safety of the Company, our users, or the public
  • Successors — in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of personal data under equivalent terms

We do not sell personal data, as "sell" is defined under the CCPA/CPRA, and we do not share personal data with third parties for their own independent marketing purposes without your consent.

8. Data Retention and Cross-Border Transfers

8.1 Retention Principles

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, after which it is securely deleted or anonymized, unless a longer period is required or permitted by law.

  • Account data: retained for the life of your account plus 3 years after closure, for dispute-resolution and legal purposes
  • Booking and transaction records: retained for up to 7 years to satisfy tax, accounting, and audit obligations
  • Marketing consent records: retained until consent is withdrawn, plus a reasonable evidentiary period thereafter
  • Customer support communications: retained for 5 years to support quality assurance and dispute resolution

8.2 Cross-Border Data Transfers

As a marketplace connecting Customers and Suppliers across multiple countries, personal data will routinely be transferred to, and processed in, jurisdictions other than your own — including the country where the activity takes place, where the Supplier is located, and where our service providers host infrastructure.

Where we transfer personal data out of the European Economic Area, the United Kingdom, or Singapore, we rely on one or more of the following safeguards, as applicable:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, together with a transfer impact assessment where required
  • The UK International Data Transfer Addendum to the SCCs
  • PDPA-compliant contractual clauses modeled on the ASEAN Model Contractual Clauses, for transfers out of Singapore
  • Adequacy decisions issued by the relevant regulator, where the destination jurisdiction has been recognized as providing adequate protection
  • Your explicit consent to the specific transfer, where no other mechanism is available and the transfer is necessary to perform your booking

A list of the countries to which personal data is routinely transferred, and copies of the relevant safeguards, are available on request from [email protected].

9. Your Privacy Rights

9.1 General Rights (All Users)

Subject to applicable law and exceptions, you may:

  • Request access to, and a copy of, the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your data, subject to legal retention obligations
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
  • Object to, or request restriction of, certain processing, including direct marketing

To exercise these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (e.g., 30 days under the PDPA; one month, extendable, under GDPR/UK GDPR; 45 days under CCPA/CPRA) and may need to verify your identity before actioning a request.

9.2 Additional Rights for EEA / UK Residents (GDPR / UK GDPR)

  • Right to data portability, for data processed by automated means on the basis of consent or contract
  • Right to lodge a complaint with your local supervisory authority without prejudice to any other administrative or judicial remedy
  • Right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects

9.3 Additional Rights for California Residents (CCPA/CPRA)

  • Right to know the categories and specific pieces of personal information collected, used, disclosed, or sold/shared
  • Right to delete personal information, subject to statutory exceptions
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information to purposes necessary to provide the Platform
  • Right to non-discrimination for exercising any CCPA/CPRA right

9.4 Singapore (PDPA)

  • Right to access and correct personal data held by us, subject to PDPA exceptions
  • Right to withdraw consent to any collection, use, or disclosure of personal data, on reasonable notice
  • Right to be informed of the ways personal data collected has been or may have been used or disclosed, on request

10. Cookies and Tracking Technologies

We and our service providers use cookies, SDKs, and similar technologies to operate the Platform, remember preferences, measure performance, and — where you consent — personalize content and advertising. Categories used include:

  • Strictly necessary cookies — required for core Platform functionality (e.g., login sessions, booking cart); cannot be disabled
  • Performance/analytics cookies — used to understand usage patterns and improve the Platform
  • Functional cookies — remember preferences such as language or currency
  • Advertising/targeting cookies — used to deliver relevant marketing, deployed only with your consent where required by law

On your first visit from a jurisdiction requiring opt-in consent (including the EEA and UK), we present a cookie banner allowing you to accept, reject, or customize non-essential cookies before they are set. Further detail is available in our separate Cookie Policy at Cookie Policy.

11. Marketing Communications

We will only send you marketing communications (email, SMS, or push notification) where you have opted in, or where permitted under applicable law based on an existing customer relationship, subject to your right to object at any time.

  • Every marketing email includes a one-click unsubscribe link, processed promptly and in any event within the timeframe required by applicable law (e.g., 10 business days under CAN-SPAM)
  • SMS marketing, where used, complies with applicable consent and opt-out requirements (e.g., reply "STOP" to unsubscribe)
  • Where phone numbers are used for marketing calls, we honor applicable do-not-call registries, including Singapore's Do Not Call Registry
  • Opting out of marketing does not affect transactional communications necessary to service an existing booking

12. Data Security

We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including encryption in transit and at rest for sensitive categories of data, role-based access controls, and regular security testing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Data Breach Notification

We maintain an incident response process to detect, contain, and assess data security incidents. Where a breach of personal data is likely to result in significant harm to affected individuals, or is otherwise required to be notified under applicable law (including the PDPA's mandatory data breach notification regime and GDPR Articles 33–34), we will:

  • Notify the relevant supervisory authority (e.g., Singapore's Personal Data Protection Commission, or the applicable EU/UK supervisory authority) within the timeframe required by law
  • Notify affected individuals without undue delay where the breach poses a real risk of significant harm, describing the nature of the breach and steps taken or recommended
  • Document the incident and remedial actions taken, consistent with our accountability obligations

14. Children's Privacy

The Platform is not directed to, and is not intended for use by, children under the age of 16 (or the higher age of digital consent applicable in your jurisdiction). We do not knowingly collect personal data from children below this threshold. Where a booking involves a minor (e.g., a family tour), the personal data of the minor is provided and consented to by their parent or legal guardian, who is responsible for its accuracy.

If we become aware that we have inadvertently collected personal data from a child in violation of this Policy, we will take reasonable steps to delete such data promptly. Parents or guardians who believe their child has provided personal data to us may contact [email protected] to request deletion.

15. Third-Party Links, Integrations, and Supplier Websites

The Platform may link to, or integrate with, third-party websites, payment gateways, mapping services, or Supplier-operated booking pages. This Policy does not apply to those third-party services, and we encourage you to review their respective privacy policies. Where a Supplier collects personal data directly from you (e.g., at check-in for an activity), that Supplier acts as an independent controller for that data.

16. Automated Decision-Making and Profiling

We may use automated tools to detect fraudulent bookings, generate personalized activity recommendations, or price dynamically based on demand. These processes may involve profiling but do not, on their own, produce legal or similarly significant effects about you without the opportunity for human review. Where required by law, you may request human review of, or object to, an automated decision by contacting [email protected].

17. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy with a revised "Last Updated" date and, for material changes, provide additional notice (e.g., email notification or an in-Platform banner) and, where required by law, obtain renewed consent before the changes take effect.

18. Contact Us

For questions, concerns, or to exercise your privacy rights, please contact:

BOOK TOUR X PRIVATE LIMITED
7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987
Attn: Data Protection Officer
Email: [email protected]