Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.
Last Updated: December 9, 2025
1. Introduction
Welcome to Windowseat Tours ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it.
By using our website, mobile application, or services (collectively, the "Services"), you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Personal Information: When you purchase a tour or create an account, we collect information such as your name, email address, and payment information (processed securely through Stripe).
Usage Data: We automatically collect information about how you interact with our Services, including your device type, browser type, IP address, pages visited, and time spent on pages.
Location Data: With your permission, we collect precise location data to trigger audio content at specific landmarks during tours. You can disable location services at any time through your device settings.
Analytics Data: We use third-party analytics services (such as PostHog) to understand how our Services are used and to improve the user experience.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our Services
- Process your purchases and send you access links to your tours
- Send you emails with tour information, receipts, and customer support responses
- Improve and personalize your experience with our Services
- Understand and analyze how you use our Services
- Develop new features, products, and services
- Communicate with you about updates, promotions, and news (with your consent)
- Detect and prevent fraud, abuse, and security issues
- Comply with legal obligations and enforce our terms of service
4. Sharing Your Information
We do not sell your personal information. We may share your information with:
Service Providers: We work with third-party companies to provide essential services:
- Stripe: Payment processing (subject to Stripe's privacy policy)
- Supabase: Database and authentication services
- Vercel: Website hosting and content delivery
- PostHog: Analytics and product insights
- Resend: Email delivery services
Legal Requirements: We may disclose your information if required by law, court order, or governmental authority, or to protect our rights, property, or safety.
Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:
- Encryption of data in transit using SSL/TLS
- Secure storage of data in encrypted databases
- Regular security audits and monitoring
- Limited access to personal information on a need-to-know basis
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Services and store certain information. Cookies are small data files stored on your device.
Types of cookies we use:
- Essential Cookies: Required for the Services to function properly
- Analytics Cookies: Help us understand how visitors use our Services
- Preference Cookies: Remember your settings and preferences
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some portions of our Services may not function properly.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Purchase records and tour access information are retained for accounting and legal compliance purposes. You may request deletion of your account and associated data at any time.
8. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data to another service
- Objection: Object to our processing of your personal information
- Withdrawal of Consent: Withdraw consent for data processing where applicable
To exercise these rights, please contact us at privacy@windowseat.sg.
9. Children's Privacy
Our Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete it.
10. International Data Transfers
Your information may be transferred to and processed in countries other than Singapore. These countries may have different data protection laws. By using our Services, you consent to such transfers. We take appropriate measures to ensure your data is treated securely and in accordance with this Privacy Policy.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
We will respond to your inquiry within 30 days.