Last updated: 14 May 2025
Your privacy matters to us. This policy explains clearly what data we collect, how we use it, and the choices you have.
Contents
GuideSL ("we", "us", "our") is a Sri Lanka-based platform connecting tourists with verified local guides. Our registered contact email is hello@guidesl.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services.
We collect information you provide directly when you create an account (name, email address, password hash), submit a guide application (national identity documents, licence details, phone number, district, photo), or use the platform (tour requests, messages, reviews, dispute records). When you sign in with Google, we receive your name, email, and profile picture from Google — we do not receive your Google password. We also collect technical information automatically, including your IP address, browser type, device identifiers, and pages visited, through standard web server logs and cookies.
We use your information to: (a) operate and personalise your account and bookings; (b) match tourists with suitable guides; (c) facilitate secure real-time communication between tourists and guides; (d) process and record payments and payouts; (e) verify guide identity and credentials; (f) resolve disputes and enforce our Terms of Service; (g) send transactional and service emails (account verification, booking confirmations, dispute updates); (h) improve the platform through aggregated analytics. We do not sell your personal data to third parties.
To operate the platform, GuideSL relies on a set of trusted third-party service providers. These providers fall into the following categories: • Authentication providers — enable optional social sign-in. • Real-time communication providers — power secure, encrypted in-platform messaging between tourists and guides. • Cloud hosting and infrastructure providers — host our application and database on infrastructure that meets industry security standards. • Cloud storage providers — securely store guide identity documents and media files. Each provider processes only the data necessary for their specific function. We select providers who maintain appropriate data protection standards and, where required, enter into data processing agreements with them. We do not share your data with these providers for their own marketing or commercial purposes.
Guides are required to submit National Identity Card (NIC) images and a tourism licence for verification. These documents are stored securely in encrypted cloud storage (Cloudflare R2) and are only accessible to GuideSL administrators for verification purposes. They are not shared with tourists or third parties. Documents of rejected or deleted guide accounts are permanently deleted from storage.
We retain your account information for as long as your account is active. Tour records, payment records, and reviews are retained for a minimum of 7 years for accounting, legal, and dispute resolution purposes. Guide identity documents are retained for the duration of the guide's active status on the platform, and deleted within 30 days of account deletion. You may request deletion of your account at any time by contacting hello@guidesl.com; we will delete your data except where retention is required by law.
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data (subject to legal retention requirements); restrict or object to certain processing; receive your data in a portable format; withdraw consent where processing is based on consent. To exercise any of these rights, contact us at hello@guidesl.com. We will respond within 30 days.
We implement technical and organisational measures to protect your personal data, including password hashing (bcrypt), HTTPS-only connections, HTTP-only session cookies, rate limiting on authentication endpoints, server-side input validation, and role-based access controls. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security, but we are committed to protecting your data to a high standard.
GuideSL is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has created an account on our platform, please contact us at hello@guidesl.com and we will promptly delete their information.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-platform notice at least 14 days before they take effect. The date at the top of this page reflects when the policy was last updated. Your continued use of GuideSL after the effective date constitutes acceptance of the updated policy.
For privacy-related questions, requests, or complaints, contact our team at hello@guidesl.com. We aim to respond to all privacy enquiries within 30 days.
For privacy questions, contact us at hello@guidesl.com