Tragovel
  • Places
  • Events
  • Festivals
Tragovel

Discover the world, one trip at a time. Find events, festivals and markets near you.

Explore

  • Places
  • Events
  • Festivals
  • Markets

Company

  • About us
  • Press
  • Blog

Support

  • Help center
  • Contact us
  • Privacy policy
  • Terms of use

© 2026 Tragovel. All rights reserved.

Personal Data Privacy Policy

Last updated: June 27, 2026

Tragovel, operated by [RAZÓN SOCIAL] (hereinafter "the Company" or "the Data Controller"), recognizes and respects the fundamental right to Habeas Data enshrined in Article 15 of the Political Constitution of Colombia, in Statutory Law 1581 of 2012 and in Regulatory Decree 1377 of 2013. This Personal Data Privacy Policy (hereinafter "the Policy") establishes the principles, guidelines and procedures governing the collection, storage, use, circulation, transfer, transmission and deletion of personal data of those who interact with the Tragovel platform.

The use of the platform, the creation of an account, the making of bookings or any other interaction with Tragovel services implies acceptance of this Policy. We recommend reading it in its entirety before providing any personal data.

Contents

  1. 1. Data Controller
  2. 2. Definitions
  3. 3. Scope and acceptance
  4. 4. Personal data we collect
  5. 5. Purposes of processing
  6. 6. Processing of sensitive data
  7. 7. Personal data of children and adolescents
  8. 8. Rights of the data subject
  9. 9. Procedure for queries and claims
  10. 10. Authorization of the data subject
  11. 11. Transfer and transmission of data
  12. 12. Information security measures
  13. 13. Cookies and similar technologies
  14. 14. Policy validity and database retention
  15. 15. Supervisory authority and contact information

1. Data Controller

The Data Controller for personal data collected through the Tragovel platform is:

Legal name: [RAZÓN SOCIAL]

Tax ID (NIT): [NIT]

Address: [DIRECCIÓN], [CIUDAD], Colombia

Contact email for personal data matters: [CORREO]

Phone: [TELÉFONO]

In compliance with Article 17 of Law 1581 of 2012, the Company acts as Data Controller when it determines the purposes and means of personal data processing. When the Company acts as a Data Processor under a third party's instruction, such relationship shall be governed by the corresponding contract.

2. Definitions

For the purposes of this Policy, and in accordance with the definitions established in Article 3 of Law 1581 of 2012 and Article 3 of Decree 1377 of 2013, the following terms shall mean:

  • Data Subject (Titular): The natural person whose personal data is being processed.
  • Personal data: Any information linked or that can be associated with one or more determined or determinable natural persons.
  • Public data: Data that is not semi-private, private or sensitive. Public data includes, among others, data relating to a person's civil status, profession or trade, and status as a trader or public servant.
  • Semi-private data: Data that is not intimate, reserved or public in nature, and whose knowledge or disclosure may be of interest not only to its owner but also to a certain sector or group of people or to society at large.
  • Private data: Data that, by its intimate or reserved nature, is only relevant to the data subject.
  • Sensitive data: Data that affects the privacy of the data subject or whose improper use may generate discrimination, such as racial or ethnic origin, political orientation, religious beliefs, health data, sexual life, biometric data and data relating to criminal convictions or administrative offences.
  • Processing (Tratamiento): Any operation or set of operations on personal data, such as collection, storage, use, circulation, transfer, transmission or deletion.
  • Data Controller (Responsable): A natural or legal person, public or private, who alone or in association with others decides on the database and/or the processing of personal data.
  • Data Processor (Encargado): A natural or legal person, public or private, who alone or in association with others carries out personal data processing on behalf of the Data Controller.
  • Authorization: Prior, express and informed consent of the data subject for personal data processing.
  • Database: Organized set of personal data that is subject to processing.
  • Transfer (Transferencia): Processing of personal data involving communication thereof within or outside Colombian territory, where the recipient is another Data Controller.
  • Transmission (Transmisión): Communication of personal data to a Data Processor within or outside Colombian territory, for the Processor to carry out processing on behalf of the Controller.
  • Privacy notice: Verbal or written communication directed to data subjects to inform them of the existence of the personal data privacy policy and how to access it.

3. Scope and acceptance

This Policy applies to all personal data collected by the Company through the Tragovel platform (website, mobile application and any associated digital channel), as well as data obtained by physical or verbal means during the commercial relationship.

All natural persons who, as users, customers, experience providers, visitors or in any other capacity, provide personal data to Tragovel or whose data is collected in the course of providing the services, are subject to this Policy.

By registering on the platform, completing a form, making a booking or interacting in any other way with Tragovel, the data subject grants authorization for the processing of their personal data in accordance with the terms of this Policy. Where authorization cannot be obtained through unequivocal conduct, the Company will request express consent before initiating processing.

4. Personal data we collect

The Company collects only personal data that is adequate, relevant and necessary for the purposes described in this Policy, in accordance with the data minimization principle. The categories of data that Tragovel may collect include:

  • Identification data: full name, identity document number, nationality and date of birth.
  • Contact data: email address, phone number, city and country of residence.
  • Account data: username, password (stored in encrypted form), profile photo and travel preferences.
  • Browsing and usage data: IP address, browser type, operating system, pages visited, session time, device identifiers and approximate geolocation data when expressly authorized by the user.
  • Bookings and transaction data: search history, booked experiences, dates, number of participants and history of interactions with providers.
  • Payment data: Tragovel does not store credit or debit card numbers. Payments are processed directly by certified payment gateways (e.g., under PCI-DSS standard). The Company only receives transaction confirmations and payment references necessary to validate bookings.
  • Communications data: messages sent to the support team, ratings and reviews published on the platform.

5. Purposes of processing

The Company processes data subjects' personal data for the following purposes, all of which are covered by the data subject's authorization, the performance of a contract or the fulfilment of legal obligations:

  • Service delivery: managing registration, authentication and maintenance of the user's account; facilitating the search, comparison and booking of travel experiences through the Tragovel platform.
  • Booking and transaction management: processing, confirming and managing bookings; communicating to the provider the data necessary for the delivery of the booked experience; issuing receipts and invoices.
  • Customer service and support: handling queries, complaints, claims and requests related to the services; resolving technical and operational incidents.
  • Marketing communications: sending information about news, promotions, discounts and editorial content related to travel, only when the data subject has given prior and express authorization. The data subject may revoke this authorization at any time.
  • Product improvement and analytics: conducting statistical and behavioral analyses in aggregate or pseudonymized form to improve the platform, personalize the user experience, develop new features and optimize service performance.
  • Security and fraud prevention: detecting, investigating and preventing fraudulent activities, unauthorized access and other conduct that endangers the security of the platform or its users.
  • Legal compliance: complying with requirements from judicial, administrative or supervisory authorities; retaining records as required by Colombian law.

6. Processing of sensitive data

Tragovel does not routinely collect sensitive data as defined in Article 5 of Law 1581 of 2012. However, in certain specific contexts — for example, when the user voluntarily discloses a health condition relevant to the safe practice of an adventure experience — the platform may receive this type of data.

The provision of sensitive data is strictly voluntary. No data subject will be required to disclose sensitive data to access Tragovel's general services. Where the processing of sensitive data is necessary, the Company will request an explicit, separate and informed authorization, clearly indicating the sensitive nature of the data and the specific purpose of the processing.

In no case will the Company condition access to essential services on the provision of sensitive data, nor will it process sensitive data without the express and specific authorization of the data subject.

7. Personal data of children and adolescents

Tragovel recognizes that children and adolescents (persons under 18 years of age) are entitled to special protection under Article 7 of Law 1581 of 2012, Law 1098 of 2006 (Code of Childhood and Adolescence) and the Convention on the Rights of the Child.

The Tragovel platform is intended for persons over 18 years of age. The Company does not deliberately collect personal data from minors without the express and verifiable consent of the parent or legal guardian. If the Company becomes aware of having collected personal data from a minor without proper authorization, it will proceed to immediate deletion.

When a minor's participation in an experience requires the provision of their data (e.g., full name for a family group booking), the responsible adult must provide such information and, in doing so, declares acting with the legal guardian's consent and in the best interest of the minor.

8. Rights of the data subject

In accordance with Article 8 of Law 1581 of 2012, the personal data subject has the following rights, the exercise of which is free of charge:

  • Right to access: access their personal data that is being processed by the Company at any time.
  • Right to update: request the update of their personal data when it is inaccurate, incomplete or has changed.
  • Right to rectification: request the correction of inaccurate or erroneous personal data.
  • Right to proof of authorization: request from the Company proof of the authorization granted for data processing, except in cases expressly exempted by law.
  • Right to be informed: learn, upon request, for what purposes their personal data has been and is being used.
  • Right to complain to the SIC: file complaints with the Superintendencia de Industria y Comercio (SIC) for infringements of Law 1581 of 2012, once the consultation or claim procedure before the Controller has been exhausted.
  • Right to revoke authorization: withdraw at any time the consent granted for processing, provided there is no legal or contractual obligation that prevents it. Revocation will not have retroactive effect.
  • Right to deletion: request the elimination of personal data when it is no longer necessary for the purposes that justified the processing, when the authorized retention period has expired, or when processing does not comply with the law, provided there is no legal obligation to retain it.

9. Procedure for queries and claims

The data subject, their heirs or representatives may exercise their rights through the channel provided by the Company:

Email: [CORREO]

The data subject must fully identify themselves, indicate the type of request (query or claim), describe the facts and attach any documents they deem relevant.

Queries: The Company will respond within a maximum period of ten (10) business days from the date of receipt. If it is not possible to attend to the query within this period, the interested party will be informed of the reasons for the delay and the date on which their query will be addressed, which may in no case exceed five (5) additional business days following the expiry of the first period, pursuant to Article 14 of Law 1581 of 2012.

Claims: If the data subject believes that information should be corrected, updated or deleted, or when they observe presumed non-compliance with any of the Controller's duties, they may file a claim following this procedure: (i) If the claim is incomplete, the Company will notify the interested party within five (5) days of receipt to remedy the deficiencies; if two (2) months elapse without the data subject remedying them, the claim will be deemed withdrawn. (ii) The Company will respond within a maximum period of fifteen (15) business days from the day following the date of receipt of the complete claim. If it is not possible to attend to the claim within this period, the interested party will be informed, and the date for addressing the claim may in no case exceed eight (8) additional business days following the expiry of the first period, pursuant to Article 15 of Law 1581 of 2012.

10. Authorization of the data subject

Pursuant to Article 9 of Law 1581 of 2012, the processing of personal data requires the prior, express and informed authorization of the data subject, except in cases exempted by law (public data, medical or health emergencies, processing authorized by law, Civil Registry data, among others).

Tragovel obtains authorization through the following mechanisms:

  • Express acceptance during registration: the user checks a box declaring that they have read and accepted this Policy before creating their account.
  • Unequivocal conduct: when the data subject voluntarily provides their data in contact forms, booking processes or other channels, having been previously informed of the existence and content of this Policy through the corresponding privacy notice.
  • Physical format: in the case of in-person collection, by signing the authorization form provided by the Company.

11. Transfer and transmission of data

The Company may share personal data with third parties in the following circumstances:

  • Data Processors: technology service providers (cloud hosting, payment processing, analytics, transactional email) who act on behalf of the Company and are contractually obligated to process data only in accordance with the Controller's instructions and under the same data protection standards required by Law 1581 of 2012.
  • Experience providers: when the user makes a booking, the Company transmits to the experience provider the necessary data (name, contact, number of participants) for the delivery of the contracted service.
  • Competent authorities: the Company will disclose personal data to judicial, administrative or supervisory authorities when there is a legal obligation or formal request.
  • International transfers: when it is necessary to transfer personal data to countries that do not offer adequate levels of protection according to Colombian standards, the Company will adopt the contractual safeguards, data protection clauses or other measures required by the Superintendencia de Industria y Comercio to ensure the effective protection of data subjects' rights.

12. Information security measures

The Company adopts the technical, human and administrative measures necessary to secure records, preventing their alteration, loss, unauthorized or fraudulent consultation, use or access, pursuant to Article 17(d) of Law 1581 of 2012.

Measures in place include: encryption of user passwords using secure hashing algorithms (bcrypt); data transmission using encrypted protocols (HTTPS/TLS); role-based access controls for Company staff; periodic security audits; and confidentiality agreements with all Data Processors.

In the event of a security incident affecting personal data, the Company will notify affected data subjects and the Superintendencia de Industria y Comercio within the terms and timeframes established by applicable regulations.

13. Cookies and similar technologies

Tragovel uses cookies and similar tracking technologies (tracking pixels, browser local storage) to improve the user experience, maintain active sessions, remember preferences and collect analytical information about the use of the platform.

Cookies may be: (i) essential, necessary for the basic functioning of the platform and not requiring additional consent; (ii) analytics or performance cookies, which enable understanding of how users interact with the platform and which require consent; (iii) personalization cookies, which allow content to be adapted to user preferences; and (iv) advertising cookies, used to display relevant commercial content, always with the data subject's consent.

The user may configure their browser to reject all cookies or to receive an alert when a cookie is sent. However, disabling essential cookies may affect platform functionality. To manage cookie preferences, the user may access the settings panel available on the platform or modify their browser settings.

Product analytics: the Company uses a random anonymous identifier (not a device identifier or fingerprint) to measure aggregate use of the platform — searches performed, content viewed and retention. This information is processed in pseudonymized form, contains no contact details, and may be processed by analytics providers located outside Colombia under the contractual safeguards described in the international transfers section. The identifier is reset on logout or when application data is cleared.

14. Policy validity and database retention

This Policy comes into force from the date of its publication and will remain in force for as long as the Company carries out personal data processing.

Personal data will be retained for the time necessary to fulfil the processing purposes described in this Policy, or until the data subject requests deletion, provided there is no legal or contractual obligation to retain it for a longer period. In particular, data related to commercial transactions may be retained for a minimum of five (5) years in accordance with Colombian tax and accounting regulations.

The Company reserves the right to modify this Policy at any time in order to adapt it to regulatory, jurisprudential or business practice changes. Substantial modifications will be communicated to data subjects through the means available to the Company (email, notice on the platform or others), with such advance notice as circumstances allow, and will be published on the platform with an indication of the date of the last update.

15. Supervisory authority and contact information

The personal data protection authority in Colombia is the Superintendencia de Industria y Comercio (SIC), before which data subjects may file complaints, queries and claims related to the processing of their personal data, once the procedure before the Controller has been exhausted. The SIC can be contacted through its official website: www.sic.gov.co, or at its offices in Bogotá D.C., Colombia.

For any query, claim or request related to the processing of your personal data, you may contact the Controller through the following channels:

Email: [CORREO]

Phone: [TELÉFONO]

Postal address: [DIRECCIÓN], [CIUDAD], Colombia

The team responsible for handling personal data requests will respond within the legal terms established in section 9 of this Policy.