01Who this covers
EzraPro is booking and operations software for tours, activities, restaurants, events, classes and venues. This policy covers two kinds of people: operators, who run a business on EzraPro, and guests, who book with an operator through a storefront, a widget or a marketplace we sync with.
For guest data, the operator you booked with is the controller and EzraPro is the processor acting on their instructions. For operator account data, EzraPro is the controller. Where the distinction matters below, we say which one applies.
02What we collect
We collect only what a booking, a payout or an account needs to work.
- Booking details: the product, date, time, party size, price paid, add-ons, and any notes the guest adds such as dietary or accessibility needs.
- Contact details: name, email address and phone number, so confirmations, reminders and changes can reach the guest.
- Payment details: handled by our payment processor. EzraPro stores a token, the last four digits and the card type, never the full card number.
- Waivers and certifications, where an operator requires them, including the signature and the time it was given.
- Operator account details: business name, address, tax identifiers, bank account for payouts, and the people you invite to your team.
- Usage information: the pages and features used, device and browser type, and diagnostic logs, used to keep the service working and to improve it.
03How we use it
Each use below has a reason, and we do not use booking data for anything else.
- To take, confirm, change and refund bookings, and to run the day: manifests, check-in, rosters and payouts.
- To send confirmations, reminders, waivers and review requests on the operator’s behalf.
- To pay operators, reconcile fees and tips, and produce the records a bookkeeper needs.
- To keep the service secure, detect fraud and abuse, and meet legal obligations.
- To improve the product, using aggregated and de-identified information wherever possible.
05How long we keep it
Booking and payment records are kept for as long as the operator’s account is active and for seven years afterwards, which is what tax and accounting law generally requires. Waivers are kept for the period the operator sets, with a default of three years after the trip. Diagnostic logs are kept for ninety days.
When an operator closes their account, they can export everything first. After the retention period the data is deleted or de-identified.
06Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete personal data we hold about you, and to object to certain uses. Guests should contact the operator they booked with first, since the operator is the controller; we help operators answer these requests within the time the law allows. Operators can exercise their own rights, and act on their guests’ requests, from the dashboard or by writing to us.
If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority.
08Contact
Questions about this policy go to privacy@ezrapro.com. We reply within five business days. If we make a material change to this policy we will tell operators by email at least thirty days before it takes effect.