Privacy Policy
Last updated: July 28, 2026
This policy describes what data TourBrain collects from subscribed providers and from travelers using the platform, and how it is used.
1. Data we collect
- ·From the Provider: business name, contact person, email, phone/WhatsApp, branch locations and addresses, billing information.
- ·Payment data: processed directly by Stripe. TourBrain does not store card numbers.
- ·From the traveler who books: booking date, number of people, and the contact detail provided (WhatsApp or email), which is shared with the booked business.
- ·Platform usage: plan change history and subscription status, needed to run billing.
When a Provider shares the short link to their own listing (tourbrain.online/r/…), TourBrain counts how many visits that link receives, so the business can tell whether sharing it is working. For each visit we store only the date, the browser type and an irreversible fingerprint (hash) of the IP address: the IP address is NOT stored in clear text and cannot be reconstructed from that fingerprint. It is used solely to avoid counting the same person twice.
These visits are not linked to any account, do not identify the visitor, and are not used for advertising or shared with third parties. Beyond that count, TourBrain does not generate per-listing metrics for clicks or conversations.
2. Use of data
- ·Operate and bill the Provider subscription.
- ·Deliver bookings from interested travelers to the Provider.
- ·Answer traveler questions through the conversational assistant.
- ·Communicate service changes, charges and support.
3. Sharing with third parties
TourBrain shares data only with providers necessary to operate the service: Stripe (payments), Supabase (storage), messaging and email providers for notifications, and the language model provider powering the conversational assistant. Data is not sold to third parties for advertising.
4. Security
Data is stored with Row Level Security access controls, and service credentials are managed through environment variables, never exposed in public code.
5. Provider rights
The Provider may request access, correction or deletion of its data by writing to soporte@creativabalam.com.mx. Deleting data means removing the listing from the catalog.