Vai al contenuto
Home / Privacy Policy

Privacy Policy

Explorio — operated by GC Hospitality Labs LTD

This Privacy Policy explains how GC Hospitality Labs LTD (“Explorio”, “we”, “us”, “our”) collects, uses, shares and protects your personal data when you visit myexplorio.com, browse activities, or make a booking. We are committed to protecting your privacy in compliance with Regulation (EU) 2016/679 (the “GDPR”) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).

Last updated: 26 September 2026

1. Data Controller

The data controller responsible for your personal data is:

CompanyGC Hospitality Labs LTD
Registered addressAeolias 1, Paralimni 5292, Cyprus
Tax Identification Code60342505Q
Contact[email protected]

For any question about this policy or to exercise your rights, contact us at [email protected].

Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer (Art. 37 GDPR) and have not appointed one; all data-protection matters are handled at the contact above.

2. Our role: booking intermediary

Explorio is a booking service that connects you with independent third-party activity providers in Cyprus. We facilitate the discovery and reservation of activities and collect a booking fee online; the activities themselves are performed by the providers, not by us. Because of this model, your personal data is shared with the relevant activity provider so that they can honour your booking (see Section 6).

3. Data we collect

3.1 Booking and contact data

When you make a booking, we collect your first name, last name, email address and mobile phone number, together with the details of your booking (the activity, date, time slot, number of participants and any options you select).

3.2 Verification data

To confirm that you control the email address and phone number you provide, we send one-time verification codes (OTPs) and process your entry of those codes. We do not store the codes after they have been used or have expired.

3.3 Payment data

Online payments are processed by Stripe. You enter your card or payment-method details directly into Stripe’s secure form. Full card numbers never reach our servers. We receive only a payment confirmation, a payment reference, the amount, the payment method type and the status.

3.4 Technical and usage data

When you use the website we automatically receive technical data such as your IP address, browser type, device type, the pages you view and the time of your visit. This is used for security, fraud prevention and to keep the service running reliably.

3.5 Communications

If you contact our support team, we keep a record of your message and our reply so we can assist you and resolve any issue with your booking.

Providing your name, email address and mobile phone number is necessary to enter into and perform your booking (Art. 13(2)(e) GDPR). If you do not provide it, we cannot process your reservation. Technical and usage data is collected automatically as described above.

4. Legal basis for processing

  • Performance of a contract (Art. 6(1)(b) GDPR) — processing your booking, verifying your contact details, taking payment of the booking fee and passing your reservation to the activity provider.
  • Legitimate interests (Art. 6(1)(f) GDPR) — website security, fraud prevention, error monitoring and improving our service. We balance these interests against your rights and freedoms.
  • Legal obligation (Art. 6(1)(c) GDPR) — keeping accounting and tax records as required by Cypriot law.
  • Consent (Art. 6(1)(a) GDPR) — for any non-essential cookies or optional communications, where applicable. You may withdraw consent at any time.

Automated decision-making (Art. 13(2)(f) GDPR): we do not take decisions producing legal or similarly significant effects about you by solely automated means. Our payment processor (Stripe) may carry out automated fraud and risk checks that are necessary to process your payment securely.

5. How we use your data

  • Create, confirm and manage your activity booking
  • Verify your email address and phone number
  • Process the online booking-fee payment securely
  • Share the booking with the activity provider so they can deliver the experience
  • Send you booking confirmations and your activity pass
  • Respond to your enquiries and provide customer support
  • Detect, prevent and investigate fraud and misuse
  • Comply with our legal, accounting and tax obligations

6. Who we share your data with

We share your personal data only where necessary, with the following categories of recipients:

Activity Providers

The independent operator that delivers your chosen activity receives the data needed to honour your booking — typically your name, the booking details and the number of participants — so they can check you in and collect any balance due on the day. Each provider is an independent controller of the data once it is shared with them for that purpose.

Explorio (activity marketplace platform)

Bookings are created and managed through the Explorio activity-marketplace platform, which processes booking and participant data on our behalf to register your reservation and make it available to the activity provider. Legal basis: Art. 6(1)(b) GDPR.

Stripe (payment processing)

Online payments are processed by Stripe Payments Europe, Ltd. Data shared: name, email and the booking amount. Card data is handled directly by Stripe (PCI-DSS Level 1 certified). Legal basis: Art. 6(1)(b) GDPR. Privacy: stripe.com/privacy.

Sentry (error monitoring)

We use Sentry to detect and diagnose technical errors so we can keep the service stable. Data: anonymised error reports, IP address (for security) and browser/device information. We do not send names, emails or payment details to Sentry. Legal basis: Art. 6(1)(f) GDPR. Privacy: sentry.io/privacy.

Email delivery

Booking confirmations and transactional emails are sent through a third-party email-delivery provider. Data shared: your name, email address and booking details. Legal basis: Art. 6(1)(b) GDPR.

SMS verification

To verify your mobile number, the one-time code is sent through a third-party SMS / telephony provider. Data shared: your phone number and the verification message. Legal basis: Art. 6(1)(b) GDPR (necessary to confirm your booking).

Explorio Assistant (AI chat and voice)

The Explorio Assistant is an AI system: its answers are generated automatically and can contain mistakes. It helps you find an activity and prepares a booking; before you pay, the booking is always shown on the regular booking page. To use it you sign in with your email address. Your messages, your choices in the chat and the booking details you enter there are processed by OpenRouter (a routing service) and by an AI model from OpenAI, both based in the United States. To check the assistant’s understanding of your request (for example the dates and the number of people you asked for), your messages — with e-mail addresses and phone numbers masked — and the draft booking are also analysed by an AI model from TypeSafe, likewise accessed through OpenRouter. Legal basis: Art. 6(1)(b) GDPR (steps you ask us to take before a booking).

Voice mode is optional and starts only after you tap the microphone and confirm. While it is on, your voice is streamed to OpenAI for speech recognition and the spoken answer; we do not record the audio. A text transcript of the spoken conversation is kept in the chat history. Legal basis: Art. 6(1)(a) GDPR (consent) — you can stop voice mode at any time. Do not share sensitive information (for example health data or payment card numbers) in the chat.

Google (measurement and advertising) — only with your consent

If you allow statistics or marketing in the consent dialog, we use Google Analytics and Google Ads to see how the site is used and which of our ads lead to a booking. Data shared: online identifiers and cookie IDs, IP address (shortened by Google), pages viewed, device and browser information, and — for marketing — the click ID of the ad you arrived from. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Art. 6(1)(a) GDPR (consent). Without your consent these tools set no cookies and send no measurement data; we operate Google Consent Mode, which withholds them until you choose. You can withdraw your consent at any time (see Cookies below). Privacy: policies.google.com/privacy.

Hosting, CDN & infrastructure

The website and its supporting services are hosted by reputable cloud infrastructure providers that process data (including IP addresses and request metadata) strictly to operate, secure and deliver the service. Legal basis: Art. 6(1)(f) GDPR.

All processors act under written data-processing agreements and may only process your data on our instructions. We do not sell your personal data. We use it for our own advertising measurement only where you have given consent, as described above.

7. International data transfers

Some of our service providers (such as Stripe, Sentry, Google, OpenRouter, OpenAI, TypeSafe and certain hosting services) may process data outside the European Economic Area, including in the United States. Where this happens, the transfer is protected by appropriate safeguards — the EU-U.S. Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses, together with supplementary technical and organisational measures where required. You may request a copy of the relevant safeguards by contacting us at [email protected] (Art. 13(1)(f) / Art. 46 GDPR).

8. Data retention

We keep your personal data only for as long as necessary for the purposes described above:

  • Booking and payment records: 7 years (Cypriot tax and accounting law)
  • Verification codes (OTPs): deleted immediately after use or expiry
  • Support communications: up to 2 years from last contact
  • Explorio Assistant conversations: deleted automatically, normally within a few hours of your last message; usage records without the conversation content are kept for cost accounting
  • Technical / security logs: typically up to 90 days, after which IP addresses are deleted or pseudonymised

9. Your GDPR rights

Subject to the conditions in the GDPR, you have the right to:

  • Access — obtain a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data (the “right to be forgotten”)
  • Restriction — limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on our legitimate interests
  • Withdraw consent — at any time, where processing is based on consent

To exercise any right, email [email protected]. We will respond within one month. Note that some data must be retained to meet legal obligations even after an erasure request.

10. Security

We apply appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, the use of PCI-DSS-certified payment processing, and the principle of data minimisation. No method of transmission over the internet is completely secure, but we work continuously to protect your information.

11. Cookies

We use strictly necessary cookies and local storage to operate the site, remember your preferences and keep your booking session secure. Our payment processor (Stripe) may set cookies that are necessary for fraud prevention and to complete a payment. These are always active — the service cannot work without them.

Beyond those, we set cookies only with your consent, and we ask before anything is set. The dialog offers two separate choices, and you can accept one without the other:

  • Statistics — Google Analytics, so we can see which pages are used and improve them.
  • Marketing — Google Ads, so we can measure which ads lead to a booking. This also stores the click ID of the ad you arrived from.

See section 12 for what is measured.

Your choice is stored for 12 months and then expires, so you are asked again. To change or withdraw it before then, clear this site’s data in your browser — the dialog will appear on your next visit. Withdrawing has no effect on processing that already happened.

12. How we measure where visitors come from

When you first open myexplorio.com we note, in your browser’s local storage, how you reached us: the referring website’s host name, campaign parameters in the link (UTM), the label of a QR code you scanned, and the first page you opened. It is kept for 90 days, contains no name, e-mail address, IP address or device fingerprint, and is sent to us only together with a booking or an assistant conversation, so we can see which channels lead to bookings. Advertising click identifiers (such as Google’s gclid or Meta’s fbclid) are stored and sent only if you have allowed Marketing in the cookie settings, and are deleted from your browser when you withdraw that choice.

Usage statistics without cookies. To see which booking steps are hard to use, the website, the app and the hotel screens send a short record for each step (for example “activity opened”, “payment step shown”, “booking paid”). It contains the step, the activity, the language, the device type (phone, tablet or computer), how the visit started (for example a search engine, a QR code or an e-mail link), for a completed booking its value, for the hotel screens which screen was used, and a random visit number that is created for this visit only and is not stored in a cookie. It contains no name, e-mail address, phone number or IP address. We do not use these records to identify you and do not combine them with your booking or with other visits. We keep them for 180 days. Legal basis: our legitimate interest in running and improving the booking service (Art. 6(1)(f) GDPR).

Google measurement with your consent. If you allow statistics, Google Analytics also receives these steps; in the app, Firebase Analytics does. If you allow marketing, Google Ads receives the email address you booked with at the moment of booking, in hashed form, to measure which ads lead to bookings (Enhanced Conversions). Without your consent none of this is sent to Google.

13. Children

Explorio is intended for adults. The person making a booking must be at least 18 years old. We do not knowingly collect personal data directly from children. Where an activity includes minors, the booking adult is responsible for providing their details and for their participation.

14. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest version. Material changes will be highlighted on this page. Please review it periodically.

15. Complaints & contact

If you have a concern about how we handle your data, please contact us first at [email protected] so we can put it right.

You also have the right to lodge a complaint with the Cypriot supervisory authority, the Office of the Commissioner for Personal Data Protection: www.dataprotection.gov.cy.