Privacy Policy
Effective Date: July 21, 2026
Pragmatic Tours ("Company," "we," "us," or "our") is committed to protecting the privacy and security of personal data collected through our tour dispatch and logistics SaaS platform ("Platform").
This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when tour agencies ("Agencies" or "Customers"), their staff, drivers, and passengers interact with our Platform.
1. Roles of the Parties (Data Controller vs. Data Processor)
Agency as Data Controller: When a tour agency inputs passenger manifests, customer names, contact details, driver profiles, or itinerary details into our Platform, the Agency acts as the Data Controller (or Business under US state privacy laws).
Pragmatic Tours as Data Processor: Pragmatic Tours processes this data solely on behalf of, and pursuant to the legal instructions of, the Agency as a Data Processor (or Service Provider).
If you are a passenger or driver on a tour operated by an Agency using Pragmatic Tours, please contact your tour agency directly regarding your personal privacy rights.
2. Information We Collect
2.1 Information Collected Directly from Agencies & Staff
- Account Credentials: Name, business email address, phone number, password, job title, and company details.
- Billing Information: Credit card details, billing address, tax identifiers (processed securely via third-party PCI-compliant payment processors).
2.2 Operational Data Provided by Agencies (Manifests & Drivers)
- Driver & Guide Information: Names, phone numbers, license category classifications, duty logs, shift schedules, and assigned vehicles.
- Passenger & Booking Information: Names, pickup locations, drop-off points, contact details, tour dates, and special requirements (e.g., luggage or seating accessibility notes).
2.3 Automatically Collected Telemetry & Technical Data
- Device & Usage Information: IP addresses, browser types, operating systems, session logs, performance metrics, and feature interactions.
- Location & Telemetry Data: If a driver or dispatcher uses mobile views or integrated telematics, coarse or precise location data necessary to render dispatch timelines, ETA estimates, or routing maps.
3. How We Use Personal Information
We use personal information strictly for legitimate business purposes:
- To Provide the Service: Operating the Dispatch Engine, building itineraries, rendering calendar views, calculating segment constraints, and notifying drivers.
- Platform Security & Maintenance: Detecting security incidents, preventing fraudulent activity, debugging, and maintaining system integrity.
- Customer Communication: Sending administrative updates, security alerts, service notices, and billing invoices.
- Product Optimization: Analyzing aggregated, non-identifiable usage patterns to improve performance and user interface design.
4. Disclosure & Sharing of Information
We do not sell, rent, or trade personal information or passenger manifests to advertisers or third parties. We share data only in the following circumstances:
- Sub-processors & Service Providers: Trusted vendor partners who perform technical services on our behalf (e.g., cloud hosting providers, database infrastructure, SMS/communication gateways, payment gateways). All sub-processors are bound by strict contractual data protection agreements.
- Legal Compliance: When required by law, subpoena, court order, or governmental regulation, or to protect the rights, property, and safety of Pragmatic Tours, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of company assets, provided the receiving party agrees to honor the commitments made in this Privacy Policy.
5. International Data Transfers
If data is transferred across international borders (including transfers outside the European Economic Area (EEA), UK, or Switzerland), Pragmatic Tours implements appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure personal data receives an adequate level of protection.
6. Data Security Measures
We enforce industry-standard administrative, technical, and physical security controls to safeguard personal data, including:
- Encryption in Transit: All network traffic to and from the Platform is encrypted using TLS 1.3 / SSL protocols.
- Encryption at Rest: Sensitive database records and credentials are stored using AES-256 bit encryption.
- Access Controls: Strict role-based access control (RBAC) preventing unauthorized access across tenancy boundaries.
- Container & Infrastructure Hardening: Continuous security patching and isolated container environments.
However, no web-based application is 100% immune to security threats. Agencies are responsible for maintaining strong account passwords and access hygiene.
7. Data Retention & Deletion
Retention Period: We retain Agency Data for as long as the Customer's account remains active, or as required to fulfill legal, accounting, or contractual obligations.
Account Deletion: Upon contract termination, the Agency may request full export of its manifests and database records. Following thirty (30) days from account termination, all identifying Agency Data is permanently purged or anonymized in our primary production databases.
8. Data Subject Rights (GDPR / CCPA)
Depending on your geographical jurisdiction (e.g., EU/UK GDPR, California CCPA/CPRA), individuals may possess statutory rights regarding their personal data, including the right to:
- Access, correct, or update personal information.
- Request deletion ("Right to be Forgotten").
- Restrict or object to certain processing activities.
- Request data portability in a structured, machine-readable format.
Because Pragmatic Tours processes passenger data as a Data Processor, end-passengers seeking to exercise these rights should direct their inquiry to the applicable Tour Agency (the Data Controller). We assist our Customer Agencies in responding to verified data subject requests as contractually agreed.
9. Updates to This Privacy Policy
We may modify this Privacy Policy periodically to reflect changes in legal obligations or Platform functionality. Material modifications will be notified to Customer accounts via email or in-app notification prior to taking effect.
10. Contact Information
For questions, privacy inquiries, or data protection officer (DPO) requests, please contact us at:
- Email: privacy@pragmatictours.com
- Address: Pragmatic Tours Legal Dept., [Your Legal Business Address]