Privacy Policy

This Privacy Policy explains and provides how Expago collects and processes User’s personal data in relation to User’s access to and use of the Expago Platform.

If User is located in the territory of the European Union, this collection and processing takes place in compliance with EU Regulation 2016/679 (hereinafter referred to as “GDPR”).

Terms that are undefined in this Privacy Policy (such as “Expago Platform”, “User”, “Tourist” or “Guide”) have the definition specified in the Terms and Conditions.

LAST UPDATED ON 20.06.2019

  1. PERSONAL DATA AND INFORMATION EXPAGO PLATFORM COLLECTS
    Personal data collected and processed by Expago may include: cookies, usage data, address, username, e-mail, password, name, surname, geographical position, photo, spoken languages, gender, telephone number, city, and other data specified in this Privacy Policy. User is responsible for the personal data User provides, including by guaranteeing that User has the right to provide and disclose the same data.
    More specifically, there are three general categories of personal data and information which Expago collects, as follows:
    1. PERSONAL DATA AND INFORMATION THAT USER PROVIDES TO EXPAGO PLATFORM
      1. PERSONAL DATA AND INFORMATION NECESSARY FOR THE USE OF EXPAGO PLATFORM
        Expago requests and collects personal data and information when User uses the Expago Platform. This information is necessary for the correct performance of the contract executed between Expago and User, and also to allow Expago to comply with its legal obligations. Without these data, Expago may not be in condition to provide User the services requested:
        1. Account and Profile Information. When User signs up for an Account, Expago requires certain information such as User’s name, surname, gender, profile picture, spoken languages, country of origin, phone number email address. Certain parts of User’s profile are a part of User’s public profile page and will be publicly visible to other Users.
        2. Other Authentication-Related Information. To help create and maintain a trusted environment, Expago may collect identification (like a photo of User’s government-issued ID) or other form of authentication from User.
        3. Payment Information. To process certain payments, we may collect certain financial information (like User’s bank account coordinates). Please note that we do not collect data concerning the payment instruments used by Users to pay for experiences: these data, like User’s credit card number, will only be processed by the gateway of payment services specified in point 4.4 below.
        4. Communications with Expago and other Users. When User communicates with Expago or uses the Expago Platform to communicate with other Users, Expago collects information about User’s communication and any information User chooses to provide.
      2. OPTIONAL INFORMATION THAT USER MAY PROVIDE
        User may also choose to provide Expago with the following optional personal data, which will only be processed with User’s consent:
        1. Additional Profile Information. User may choose to provide Expago with additional information in the context of User’s profile on the Expago Platform. Certain parts of User’s profile (like User’s description) are a part of User’s profile page and will be publicly visible to others.
        2. Other Information. User may also provide Expago information when User fills in a form, updates or adds information to User’s Account, participates in promotions or uses other features of the Expago Platform.
    2. PERSONAL DATA AND INFORMATION THAT EXPAGO AUTOMATICALLY COLLECTS FROM USER’S ACCESS TO AND USE OF THE EXPAGO PLATFORM
      When User uses Expago Platform, Expago collects data and information about the services User uses and how User uses them. This information is necessary for the correct performance of the contract executed between Expago and User, to allow Expago to comply with its legal obligations and on the basis of Expago’s legitimate interest to be able to improve and offer User the functionalities of the Expago Platform:
      1. Usage Information. When User uses certain functionalities of the Expago Platform, Expago may collect information about User’s interactions with the Expago Platform, such as User’s accesses, the pages or other content User views, User’s searches, bookings User has made, and other actions on the Expago Platform.
      2. Location Information. When User uses certain features of the Expago Platform, Expago may collect different types of information about User’s location, determined through User’s IP address, zip code or the GPS of User’s mobile device. Most mobile devices and Internet browsers allow User to allow, deny, control or disable the use of location services for applications and websites in the device’s or browser’s settings menu.
      3. Log Data. Expago may automatically collect log information when User uses the Expago Platform, even if User has not created an Account or logged in. That information includes, among other things: details about how User has used the Expago Platform (including links to third party applications), IP address, access dates and times, hardware and software information, device information, device event information (e.g., crashes, browser type), and the page that may have referred User to the Expago Platform.
      4. Transaction Information. Expago may collect information related to User’s transactions on the Expago Platform, including the date and time, amounts charged, type of instrument used, User’s address and other related transaction details.
      5. Cookies and Similar Technologies. Expago uses cookies and other similar technologies, such as web beacons, tokens, pixels, and mobile identifiers.
    3. PERSONAL DATA AND INFORMATION THAT EXPAGO COLLECTS FROM THIRD PARTIES
      1. Third Party Services. If User links, connects, or logins to User’s Account with a third party service (e.g., Facebook), the third-party service may send Expago information such as User’s registration and profile information from that service. This information varies and is controlled by that service or as authorized by User via User’s privacy settings at that service.
      2. Reviews about User. If someone has published a review about User, it will be published on User’s Expago profile page.
  2. PURPOSES AND LEGAL BASIS OF PROCESSING OF PERSONAL DATA
    1. Expago uses, stores, and processes User’s personal data mainly through electronic and automatic instruments, with organizational processes and logics strictly related to the following purposes:
      1. to provide Expago Platform. Expago processes User’s personal data in order to:
        1. enable User to access and use the Expago Platform;
        2. enable User to communicate with other Users;
        3. provide customer service, including investigating, answering and solving complaints and problems related to the Expago Platform;
        4. contact User and send User service or support messages, such as updates, security alerts, and Account notifications;
        This processing is necessary for the performance by Expago of the contract for the provision of services to which User is a party under the Terms of Service
      2. to maintain a trusted and safe environment and comply with Expago’s legal obligations. Expago processes User’s personal data in order to:
        1. detect and prevent fraud, spam, abuse, security incidents, and other harmful activity;
        2. verify or authenticate information or identifications provided by User;
        3. resolve any disputes with our Users;
        4. enforce Terms and Conditions and other policies;
        5. comply with Expago’s legal obligations;
        6. perform security assessment and risk evaluations.
        This processing is performed on the basis of Expago’s legitimate interest to protect the Expago Platform and ensure that it remains a trusted and safe environment, as well as for the performance by Expago of the contract for the provision of services to which User is a party under the Terms and Conditions, and to allow Expago to comply with its legal obligations.
      3. to improve and develop the Expago Platform. Expago also processes User’s personal data to protect, improve and optimize the Expago Platform and the experience of Users, including conducting analysis and research activities.
        This processing is performed on the basis of Expago’s legitimate interest to improve the Expago Platform and the User experience.
  3. CONSEQUENCES OF NON-PROVISION OF PERSONAL DATA
    1. In general, provision of User’s personal data constitutes a contractual obligation, and is indispensable to assure the functionality of the services Expago provides through the Expago Platform. In case User decides not to provide the personal data required to access such services, User will not be allowed to use the Expago Platform and the services provided through the Expago Platform.
    2. Occasionally, the provision of certain personal data may not be indispensable for the above purpose. In such cases the Expago Platform will duly inform User, and not providing such data will not affect the general functionality of the Expago Platform.
    3. Please note that the provision of certain personal data may also be required to access some specific functions of the Expago Platform but not others; this will also be clarified to User by the Expago Platform when User requests access to any functions that require provision on User’s part of additional personal data.
  4. SHARING AND DISCLOSURE OF PERSONAL DATA OF USER
    The personal data of the User will be shared as follows:
    1. AT USER’S DIRECTION
      Expago may share User’s information at User direction or as described at the time of sharing, such as when User authorizes a third-party application or website to access Account. The legal basis for this sharing is User’s consent, expressed at the time of User’s authorization.
      User may of course withdraw User’s consent at any time through the same means by which User authorized the sharing, but such withdrawal will not affect the lawfulness of any processing based on consent before its withdrawal.
    2. BETWEEN USERS
      In order to help facilitate bookings, Expago may share User’s certain part of User’s account and public information with other Users.
      Nevertheless, Expago does not share User’s billing and payout information with other Users.
    3. PROFILES, GUIDE MENUS AND OTHER PUBLIC INFORMATION
      The Expago Platform lets Users publish information that is visible to the general public, including, but not limited to:
      1. User’s public profile page,
      2. Tours posted by Guide are publicly visible and include information like name and description of the Tour, time availability of each and every Tour, Photos and videos describing the Tour, and after completion of the booked tour, Tourists may write and review Guides. Reviews are a part of User’s public profile page;
      3. if User submits content in a public forum or social media post, or uses a similar feature on the Expago Platform, that content is publicly visible;
      This sharing falls under the purpose of processing specified in point 2.1.1 of this Privacy Policy, and has the legal basis there specified.
    4. PAYMENTS
      Expago does not collect, process or share User’s personal information concerning payment instruments used to allow payment by User of the amounts due for the dining services and experiences. Currently payments on the Expago Platform are managed through Stripe, Inc. the online payment processing for internet businesses. Users share their payment information and data directly with Stripe, Inc. Expago may share with Stripe, Inc. other personal information, like User’s name and address, necessary for Stripe, Inc. to process the payment.
      While Guide’s payout is implemented via PayPal Holding Inc. Expago shares Guide's personal information (e-mail) with PayPal Holding, Inc.
      This sharing falls under the purpose of processing specified in point 2.1.1 of this Privacy Policy, and has the legal basis there specified.
    5. SAFETY AND COMPLIANCE WITH LAW
      Expago may disclose User’s information to courts, law enforcement or governmental authorities, or authorized third parties, if and to the extent Expago is required to do so by law or if such disclosure is reasonably necessary in order to:
      1. comply with legal process and to respond to claims asserted against Expago,
      2. respond to verified requests relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our Users to legal liability,
      3. enforce and administer Terms and Conditions or other agreements with Users; and
      4. protect the rights, property or personal safety of Expago, its employees, its Users, or members of the public.
        Expago will attempt to notify Users about these requests unless:
        1. providing notice is prohibited by the legal process itself, by court order Expago receives, or by applicable law, or
        2. Expago believes that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon Expago’s property, its Users and the Expago Platform.
        This sharing falls under the purpose of processing specified in point 2.1.2 of this Privacy Policy, and has the legal basis there specified.
    6. EMPLOYEES AND CONSULTANTS
      User’s personal data may be accessed by certain categories of employees and collaborators entrusted with the organization, management and maintenance of the Expago Platform and authorized in writing by Expago to access such data, including administrative personnel, commercial and marketing personnel, system administrators and IT personnel, personnel providing customer support.
      In addition, User’s personal data may need to be accessed by Expago’s external professionals, consultants and service providers, who will be located in the territory of the European Union, authorized by Expago to access such data and bound in writing to comply with this Privacy Policy.
      This sharing falls under the purpose of processing specified in point 2.1.1 of this Privacy Policy, and has the legal basis there specified.
    7. TAX AUTHORITIES
      Expago may be required to share, without further notice, User’s information and data relating to them or to their transactions, bookings, experiences to the relevant tax authorities, including, but not limited to, the Guide or Tourist’s name, experiences addresses, transaction dates and amounts, tax identification number(s), the amount of taxes received (or due) by Guides from Tourists, and contact information. This sharing falls under the purpose of processing specified in point 2.1.2 of this Privacy Policy, and has the legal basis there specified.
    8. BUSINESS TRANSFERS
      If Expago undertakes or is involved in any merger, acquisition, reorganization, sale of assets, bankruptcy, or insolvency event, then Expago may sell, transfer or share some or all of Expago’s assets, including User’s information. In this event, Expago will notify User before User’s personal information is transferred.
    9. AGGREGATED DATA
      We may also share aggregated information (information about our users that we combine together and anonymize so that it no longer identifies or references an individual user) and non-personally identifiable information for industry and market analysis, demographic profiling, marketing, and other business purposes. This information does not qualify as personal data as it does not allow identification.
  5. OTHER MANNERS OF PROCESSING
    1. ANALYZING USER’S COMMUNICATIONS
      Expago may review, scan, or analyze User’s communications on the Expago Platform for fraud and abuse prevention, risk assessment, and customer support purposes. For example, as part of Expago’s fraud prevention efforts, Expago may scan and analyze messages to mask contact information and references to other websites. This processing falls under the purposes specified in points 2.1.1 and 2.1.2 of this Privacy Policy, and has the legal bases there specified.
      If User has provided User’s consent to processing for the purposes under point 2.1.2.1 of this Privacy Policy, Expago may also scan, review, or analyze messages to improve and expand service offerings. This processing falls under the purpose specified in point 2.1.2.1 of this Privacy Policy, and has the legal basis there specified.
      Expago may use automated methods where reasonably possible; however, occasionally Expago may need to manually review some communications, such as for fraud investigations and customer support, or to assess and improve the functionality of these automated tools.
      Expago will not review, scan, or analyze User’s communications to profile User or to send third party marketing messages to User, and Expago will not sell reviews or analyses of these communications.
    2. LINKING THIRD PARTY ACCOUNTS
      User may link User Account with User account at a third-party social networking service. User contacts on these third-party services are referred to as “friends.” When User creates this link:
      1. a link to User’s public profile on that third party social networking service may be included in User’s Expago public profile;
      2. the information User provide to Expago from the linking of User’s accounts may be stored, processed and transmitted for fraud prevention and risk assessment purposes; and
      3. the publication and display of information that User provide to Expago through this linkage is subject to User’s settings and authorizations on the Expago Platform and the third-party site.
      The legal basis for this processing is User’s consent, expressed at the time of linking. User may of course withdraw his/her consent at any time through the same means by which User authorized the linking, but withdrawal of consent will not affect the lawfulness of any processing based on consent before its withdrawal.
    3. MAPBOX/MAPS
      Mapbox is the location data platform for mobile and web applications. Parts of the Expago Platform use Mapbox/Maps services, including the Mapbox API(s). Use of Mapbox/Maps is subject to Mapbox, Inc. additional Terms of Use and the Mapbox, Inc. Privacy Policy.
    4. COOKIES
      Cookies are also subject to the specific and separate Cookie Policy provided on the Expago Platform.
  6. LINKS TO THIRD PARTIES
    The Expago Platform may contain links to third party websites or services, such as third-party integrations, co-branded services, or third party-branded services (“Third Parties”). Expago does not own or control these Third Parties and when User interacts with them, User may be providing information directly to the Third Party. These Third Parties will have their own rules about the collection, use, and disclosure of information. Expago encourages User to review the Privacy Policies of the other websites User visits.
  7. RIGHTS OF USER
    If User is located in the European Union, User is entitled to exercise all rights provided under articles 15 to 22 of the GDPR. In particular, User is entitled to exercise the following rights, either through the Expago Platform or by contacting Expago at the address specified in point 13 of this Privacy Policy. If User chooses to exercise User’s rights by contacting Expago, Expago may request proof of identification to verify User’s request if necessary, e.g. if User’s request does not come from User’s registered e-mail.
    1. ACCESS, UPDATE AND RECTIFICATION OF PERSONAL DATA
      User may access, review, update, or delete the information in User’s account by logging into his/her account and reviewing User’s account settings and profile. In general, User may freely exercise User’s right to obtain the rectification of inaccurate personal data concerning User, and to have incomplete personal data completed, including by means of providing a supplementary statement.
    2. ACCOUNT CANCELLATION AND ERASURE OF PERSONAL DATA
      To obtain erasure of User’s personal data, User may cancel User’s Account as provided under the Terms and Conditions.
      Please note that information that User has shared with others (like reviews or forum postings) may continue to be publicly visible on the Expago Platform, even after User’s Account is cancelled. However, attribution of such information to User will be removed. Additionally, some copies of User’s information (e.g., log records) may remain in our database, but are disassociated from personal identifiers. In addition, Expago may retain some of User’s personal information as necessary for User’s legitimate business interests, such as fraud detection or enhancing safety, and to the extent necessary to comply with Expago legal obligations.
    3. COPIES OF PERSONAL DATA
      User may request copies in writing of User’s personal information held by Expago. Expago will provide User with a copy of the personal information held by Expago as soon as practicable, and in any event not more than 30 days after receiving a valid request in writing.
    4. WITHDRAWAL OF CONSENT TO PROCESSING OF PERSONAL DATA FOR THE PURPOSES OF POINT 2.1.3 OF THIS PRIVACY POLICY
      User has the right to withdraw at any time, through the Expago Platform, any consent expressed to processing of User’s personal data for the purposes under point 2.1.3 of this Privacy Policy, which include
      1. personalizing or otherwise customizing User’s experience through profiling; and
      2. sending User promotional messages, marketing, and other information that may be of interest to User.
      User may also withdraw at any time the consent User may have expressed for the purposes under points 4.1 and 5.2 of this Privacy Policy. In all such cases, withdrawal of consent will not affect the lawfulness of any processing based on consent before its withdrawal.
      Please note that User may also limit his/her consent to one or more of the preceding purposes.
    5. OBJECTION TO PROCESSING BASED ON LEGITIMATE INTERESTS
      Where processing is based on legitimate interests of Expago, User also has a right to object to the processing of personal data on grounds relating to User’s particular situation; in this case, Expago shall no longer process User’s personal data unless Expago demonstrates compelling legitimate grounds for the processing which override User’s interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
    6. RESTRICTION OF DATA PROCESSING
      User has the right to obtain restriction of processing of User personal data if:
      1. User contests the accuracy of User’s personal data, for a period enabling Expago to verify this accuracy;
      2. the processing is unlawful and User opposes the erasure of User’s personal data and request the restriction of their use instead;
      3. Expago no longer needs the personal data for the purposes of the processing, but they are required by Expago for the establishment, exercise or defense of legal claims; or
      4. User has objected to the processing as specified point 7.5 above, pending the verification whether Expago’s legitimate grounds override User’s.
      Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with User’s consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person.
    7. DATA PORTABILITY
      User has the right to receive the personal data User has provided Expago in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller, where:
      1. the processing is based on consent or is necessary to perform a contract executed with User; and
      2. the processing is carried out by automated means.
    8. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
      User has the right to lodge a complaint with a supervisory authority, in particular in the Member State of User’s habitual residence, place of work or place of the alleged infringement of the GDPR.
  8. DATA CONTROLLER
    When Privacy Policy mentions “Expago”, “we”, “us”, or “our”, it refers to the company that is responsible for decisions concerning ways, instruments and purposes of processing of User’s personal data under this Privacy Policy, which is Expago, Inc., a company incorporated under the laws of Delaware, United States of America, with postal address at 12400 Ventura Blvd., Studio City, CA, 91604, United States of America, e-mail: info@expago.com.
  9. SECURITY
    Expago is continuously implementing and updating administrative, technical, and physical security measures to help protect User information against unauthorized access, loss, destruction, or alteration. Expago will take all steps to immediately notify User in case we become aware that an unlawful access to User’s personal data has taken place.
  10. DURATION OF STORAGE OF PERSONAL DATA
    1. In general, personal data about User is stored for as long as User’s Account remains registered on the Expago Platform, even if User does not access User’s Account for a prolonged time. Data concerning User’s location will not be stored unless rendered anonymous.
    2. Some of User’s personal data may also be kept after User cancels his or her registration. While we generally delete personal data from a closed Account within 90 days from closure, Expago may keep User’s personal data even after such term if this is reasonably necessary to comply with Expago legal obligations, solve disputes, preserve security, prevent fraud or abuse, enforce Terms and Conditions or satisfy User’s request to not receive any additional messages from Expago. Information User shared with other Users may remain visible even after closure of User’s Account.
    3. In addition, Expago may keep anonymized and aggregated information after closure of User’s Account.
  11. CHANGES TO THIS PRIVACY POLICY
    Expago reserves the right to modify this Privacy Policy at any time in accordance with this provision. If Expago makes changes to this Privacy Policy, Expago will post the revised Privacy Policy on the Expago Platform and Expago will also provide User with notice of the modification by e-mail. If User disagrees with the revised Privacy Policy, User may cancel his or her Account. If User does not cancel his/her Account before the date the revised Privacy Policy becomes effective, User continued access to or use of the Expago Platform will constitute acceptance of the revised Privacy Policy.
  12. CONTACTS
    If you have any questions or complaints about this Privacy Policy or Expago’s information and data processing practices or if you wish to exercise your rights hereunder, you may contact us at: Expago, Inc., with postal address at 12400 Ventura Blvd., Studio City, CA, 91604, United States of America; e-mail: info@expago.com.

Join Expago

Whether it’s solo or large group travel, family holiday or honeymoon, Expago can help find the best experiences to suit all tastes and requirements.

Book tours online
Book Online
App screenshots

Talk to us

Any questions?

Contact us

Stay in touch

For us, Expago is not just a product but a lifestyle. We do care about its quality and are continuously working to make it even cooler. That is why your opinions and suggestions are important.

Never hesitate to contact us at: