Skip to content
TourOn

Legal

TourOn Privacy Policy

This page explains the data processed when you sign in, submit a booking request, and pay; who may access it as needed; and the current security and retention boundaries.

Account, OTP, and booking data

We process your mobile number to send a one-time code and sign you in. When you submit a booking request, we keep the booking contact name, phone, and national ID (one ID for the booking contact, not one for every companion), participant count, tour and booking identifiers, request status, and related timestamps so the request can be created and tracked, reviewed by the tour leader, and followed by status updates. The booking contact national ID is encrypted at rest and available only in booking detail to the leader of that tour. Never share your one-time code with anyone else.

Gateway and direct-transfer payments

For a gateway payment, full card details, passwords, and CVV2 are processed only on the official page of the provider shown for that transaction and by the bank. TourOn keeps the amount, provider name, status, and references required for verification and support. The current checked-in configuration defaults new initiation to Zibal and retains ZarinPal only to verify historical transactions; a method appears only when it is enabled and available. For a direct transfer, the principal goes to the tour leader’s verified account and is not received by TourOn. The private proof may include its image, amount, timestamp, and optional transfer reference, payer name, and source-card last four digits; a full source-card number is not accepted.

Sharing and access

The tour leader for the booked tour receives the name and contact details needed to deliver the booking. Direct-transfer proof is available only to the booking owner, the relevant tour leader, and authorized support or review roles. SMS, payment, infrastructure, and storage providers process only the data needed for their service. Information may be disclosed to a competent authority within the scope of a valid request.

Security, retention, and your choices

TLS protects service connections; full tour-leader bank-destination values are encrypted at rest, and direct-transfer proof is kept in private storage behind authorized access. TourOn does not claim one fixed retention period for every data category. Automatic proof deletion stays disabled until a valid duration is approved. An in-app account-deletion request has a 30-day recovery period when no active obligation blocks it; booking, payment, security, or dispute records may remain for an applicable operational or legal need.

Operational web logs

When a page or API is requested, web and security infrastructure may process standard request data such as IP address, user-agent, request identifier, and a geographic hint supplied by a proxy for service delivery, security, troubleshooting, and valid access requests. The current public website does not run a consent banner or collect canvas, WebGL, or audio-derived identifiers. These logs are not proof of payment; a payment result comes only from authoritative server state.

Your requests and choices

You can leave the booking flow before submitting a request and manage or correct account information from your account. To request access or correction, ask about processing, or follow up on a privacy request, use the contact page or in-app support after signing in. Contact TourOn