Privacy Policy
Effective April 27, 2026 · Last updated August 5, 2026
1. Who We Are
Freebo Software Solutions LLC (“Freebo,” “we,” “us,” or “our”) provides online reservation and booking management software for tour and activity operators (the “Service”). Our principal place of business is in Austin, Texas, United States.
This Privacy Policy applies to all information collected through our marketing website (freebo.ai), our booking platform, mobile applications, APIs, and any related services, sales, marketing, or events (collectively, the “Services”).
By accessing or using any of our Services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Privacy Policy.
Contact: [email protected]
2. Roles: Operators, Customers, and Visitors
We interact with three categories of users:
- Operators (“Providers”): Tour and activity businesses who subscribe to Freebo. We are the data controller for Operator account and billing data.
- Customers (“Guests”): Individuals who book tours or activities through an Operator's Freebo-powered checkout. We process Customer data on behalf of the Operator. The Operator is the data controller for Customer booking data.
- Visitors: Individuals who browse our marketing website. We are the data controller for Visitor data.
Freebo has no direct relationship with Customers whose data it processes on behalf of Operators. Customers seeking to access, correct, amend, or delete data should contact the Operator directly. If an Operator requests that we remove Customer data, we will respond within 30 days.
3. Information We Collect
Information You Provide
- Name, email address, phone number, mailing address
- Business name, business address, tax identification numbers
- Bank account details, billing information
- Login credentials (passwords stored hashed only)
- Content you upload: photos, descriptions, logos, text, graphics, audio, video, and other materials
- Communications with us (support tickets, emails, chat)
- Customer data entered through booking forms: name, email, phone, party size, special requests, and any additional fields configured by the Operator
- Payment details (transmitted directly to Stripe; not stored on our servers)
Information Collected Automatically
- IP address, browser type, operating system, device type and identifiers
- Pages visited, features used, clicks, scrolls, session duration
- Referral URLs, search terms, and navigation paths
- Approximate geolocation (city/region level, derived from IP)
- Cookies, web beacons, pixels, and similar tracking technologies
- Log data (access timestamps, error logs, API usage)
Information from Third Parties
- Payment processor data (Stripe: transaction status, disputes, payouts)
- Calendar data from optional, Operator-authorized integrations (e.g., Google Calendar event times, titles, and busy/free status — see Section 8)
- Publicly available business information for verification
- Analytics and advertising platform data
All information collected is collectively referred to as “Collected Information.”
4. How We Use Information
For clarity, this Privacy Policy distinguishes two categories of Personal Data:
- Customer Personal Data: Information about an Operator’s end customers (e.g., guests booking a reservation) submitted through the Services. We process Customer Personal Data solely on behalf of the Operator under our Data Processing Addendum (DPA) as a Service Provider / Processor. Customer Personal Data is not sold, shared, or used for advertising. See Section 6 below.
- Visitor and Operator Data: Information collected from website visitors and from Operator account holders (e.g., business contact details, account email, usage of the Operator dashboard, marketing site browsing).
We use Visitor and Operator Data to:
- Provide, operate, maintain, and improve the Services
- Process Operator subscription and platform-fee transactions and send related information (confirmations, invoices, receipts)
- Send promotional communications, newsletters, marketing materials, and product updates to Operators and prospective Operators (you may opt out of marketing communications at any time)
- Respond to support requests and provide customer service
- Monitor usage patterns and analyze trends to improve user experience
- Detect, prevent, and address fraud, security issues, and technical problems
- Enforce our Terms of Service and other legal rights
- Comply with legal obligations, including tax reporting
- Develop new products, services, features, and functionality
- Conduct research, analysis, and benchmarking
- Create aggregated, de-identified, or anonymized data for any purpose
We use Customer Personal Data only to provide the booking service and other functions specified by the Operator, plus the limited Service Provider purposes permitted by the CCPA/CPRA (security, fraud prevention, debugging, internal use to improve the Service in a way that does not build a profile of any individual).
5. Aggregated and De-Identified Data
Freebo may analyze, compile, publish, license, and otherwise commercialize aggregated, de-identified, or anonymized information derived from Visitor and Operator Data, including without limitation derivative information, aggregated statistics, industry benchmarks, market reports, and analyses. Such aggregated, de-identified, or anonymized data is not considered Personal Data and may be used by Freebo for any lawful purpose without restriction or compensation to you, including research, analysis, benchmarking, product development, marketing, and industry reporting.
Customer Personal Data is excluded from this Section 5 except where it has first been irreversibly de-identified or aggregated such that no individual remains identifiable, consistent with the CCPA/CPRA standard for de-identified information and our obligations under the DPA.
6. Disclosure of Information
We do not sell or share Customer Personal Data. As stated in the DPA §12, Freebo acts as a CCPA/CPRA Service Provider with respect to Customer Personal Data and will not sell, share, or use it for cross-context behavioral advertising. The disclosures listed below apply to Visitor and Operator Data unless otherwise noted.
We may disclose information with or to:
- Service providers / sub-processors: Third parties who perform services on our behalf (hosting, payment processing, email delivery, analytics, customer support). A current list is maintained in the DPA §6.
- Payment processors: Stripe, Inc. processes all payment transactions. Operators maintain their own Stripe Connected Account. Card data flows directly from the user's browser to Stripe.
- Operators and their Customers: As inherent to the booking service (e.g., sharing booking confirmation details between parties to a reservation). The Operator is the controller of Customer Personal Data and may export, share, or use it under their own privacy policy.
- Affiliated companies: Current or future parent companies, subsidiaries, or affiliates.
- Business transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy. Your data may be transferred to the acquiring entity, subject to the same protections set out in this Privacy Policy and the DPA.
- Legal compliance: When required by law, regulation, court order, subpoena, or governmental request; to enforce our Terms; to protect our rights, property, or safety; or to protect against legal liability.
- With your consent: In other circumstances with your explicit consent.
Freebo does not engage in third-party advertising networks, retargeting, or cross-context behavioral advertising. We do not permit advertising or analytics partners to combine Customer Personal Data with their own data. To the extent any disclosure of Visitor or Operator Data may constitute a “sale” or “sharing” under California or other US state privacy laws, see Section 14 for your opt-out rights.
7. Payment Processing
All payment card processing is handled by Stripe, Inc., a PCI DSS Level 1 certified payment processor. Freebo does not store, process, or have access to complete payment card numbers on its own servers. Card information entered in checkout is transmitted directly from the user's browser to Stripe via their secure integration.
Freebo expressly disclaims any and all liability for the transmission, storage, or security of cardholder data. By using the Service, you acknowledge that payment processing is subject to Stripe's own terms, privacy policy, and security practices.
Operators are solely responsible for maintaining PCI compliance in any context where they handle payment card information outside the Freebo platform.
8. Third-Party Integrations & Google Calendar
Freebo offers optional integrations that let an Operator connect a third-party account to their Freebo location. These integrations are strictly opt-in. They are never enabled by default and are activated only when an authorized user of the Operator's account explicitly connects the third-party service. Disconnecting an integration is available at any time from the Operator dashboard.
Google Calendar
If an Operator chooses to connect a Google account, Freebo requests access using Google's OAuth 2.0 authorization flow. Freebo never asks for, receives, or stores your Google account password. You are shown the exact permissions requested by Google before you grant access.
- Scopes requested: We request the narrowest scopes required to operate the feature the Operator has enabled — read access to calendar events (to reconcile externally booked time against Freebo availability) and, where the Operator enables calendar sync, write access limited to calendars and events created or designated by the Operator for Freebo's use.
- Data accessed: Event start and end times, busy/free status, event titles and descriptions, attendee counts, and calendar identifiers. Where calendar sync is enabled, Freebo writes reservation time, product name, and guest name to the designated calendar.
- How we use it: Solely to provide and improve the user-facing features the Operator has requested — blocking Freebo availability against external commitments, surfacing scheduling conflicts, and mirroring confirmed reservations onto the Operator's calendar.
- What we do not do: We do not use Google user data for advertising or cross-context behavioral advertising; we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models; and we do not use it for any purpose unrelated to the integration. We do not sell Google user data, and we do not transfer it to third parties except as necessary to provide or improve the integration, to comply with applicable law, or as part of a merger or acquisition after obtaining explicit consent where required. We do not allow humans to read Google user data except with the Operator's explicit consent, as necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
Limited Use disclosure: Freebo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage, retention, and revocation: OAuth access and refresh tokens are stored encrypted at rest and are scoped to the connecting Operator's location. Calendar data is cached only as long as needed to serve availability and conflict checks. You may disconnect the integration at any time from your Freebo settings, or revoke Freebo's access directly at myaccount.google.com/permissions. On disconnection or revocation we delete stored Google OAuth tokens and cached Google Calendar content within 30 days, except where retention is required by law or as described in Section 10 (Data Retention). Deleting data from Freebo does not delete events already written to your Google Calendar; those remain under your control in Google.
Roles and responsibility: Where Customer Personal Data is read from or written to an Operator's Google Calendar, the Operator remains the data controller for that data and is responsible for having a lawful basis for the transfer and for the privacy practices of the Google account and any individuals with whom that calendar is shared. Google LLC acts as a sub-processor for this feature and is listed in DPA §6. Freebo is not responsible for how Google processes data once it resides in your Google account, which is governed by Google's own terms and privacy policy.
Other third-party integrations (for example, iCal feed subscriptions, analytics tags, or advertising pixels an Operator chooses to configure on their checkout) are governed by the same opt-in principle and by the third party's own privacy policy. Freebo does not control and is not responsible for the data practices of third-party services an Operator elects to connect.
9. Cookies & Tracking Technologies
We use the following tracking technologies:
- Session cookies: Required for authentication and basic site functionality. Expire when you close your browser.
- Persistent cookies: Remember your preferences and login state across sessions.
- Analytics: Track page views, feature usage, and user behavior to improve the Service.
- Web beacons / pixels: Used in emails and on-site to measure engagement and delivery.
Third-party services we integrate may set their own cookies. We do not control third-party cookies and recommend reviewing their respective privacy policies.
You may disable cookies through your browser settings. Disabling certain cookies may limit functionality of the Service.
10. Data Retention
- Collected Information is retained for as long as your account is active or as needed to provide the Services.
- After account termination, we may retain data as required by our Terms of Service, applicable law (including tax and financial reporting requirements), or as necessary for our legitimate business interests (fraud prevention, dispute resolution, enforcement of agreements).
- Residual copies of data may remain in backup systems for a reasonable period before being permanently deleted.
- Aggregated or de-identified data may be retained indefinitely.
11. Data Security
We implement commercially reasonable technical, administrative, and physical safeguards to protect Collected Information, including:
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access controls
- Password hashing using industry-standard algorithms
- Regular security updates and vulnerability monitoring
- Multi-tenant data isolation at the database layer
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. You acknowledge that you provide information at your own risk.
12. International Data Transfers
Our Services are hosted in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
By using the Services, you consent to the transfer of your information to the United States. Where required by applicable law (e.g., GDPR), we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
13. Users Outside the United States
Freebo is based in the United States and our Services are primarily directed to users in the United States. If you are located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with applicable data protection laws, you may have additional rights under those laws, including rights to access, correct, or request deletion of your personal data.
To exercise any such rights, email [email protected]. We will respond within 30 days where required by applicable law. We may require verification of your identity before processing requests.
By using the Services, you acknowledge that your information will be processed and stored in the United States, where data protection laws may differ from those in your jurisdiction.
14. Your Rights (California Residents — CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):
- Right to Know: What categories and specific pieces of personal information we have collected, used, disclosed, sold, or shared in the preceding 12 months.
- Right to Delete: Request deletion of personal information (subject to exceptions).
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: Opt out of the “sale” or “sharing” of personal information as defined by the CCPA/CPRA.
- Right to Limit Use: Limit use and disclosure of sensitive personal information.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Do Not Sell or Share My Personal Information
Freebo does not sell or share Customer Personal Data, and does not engage in cross-context behavioral advertising with respect to that data. With respect to Visitor and Operator Data, Freebo does not currently sell personal information for monetary consideration. To the extent any disclosure of Visitor or Operator Data may nevertheless qualify as a “sale” or “sharing” under California law, you have the right to opt out at any time.
To opt out, email [email protected] with the subject line “Do Not Sell or Share My Personal Information.” We will honor opt-out requests within 15 business days.
We also honor the Global Privacy Control (GPC) browser signal. When a GPC signal is detected, we treat it as a valid opt-out request for that browser session.
Exercising Other Rights
To exercise other rights, email [email protected] with the subject “California Privacy Request.” We will verify your identity and respond within 45 days (extendable by 45 additional days with notice).
Categories of information collected in the preceding 12 months: Identifiers, commercial information, internet/network activity, geolocation data, professional/employment information, and inferences.
Categories of information sold or shared: None. Freebo does not sell or share Customer Personal Data, and does not currently sell Visitor or Operator Data for monetary consideration. If this changes, this Privacy Policy will be updated and California residents will be given the opportunity to opt out before any such sale or sharing occurs.
Minors: We do not knowingly sell or share the personal information of consumers under 16 years of age without affirmative authorization.
15. Other US State Privacy Rights
Residents of Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Nevada, and other states with applicable consumer privacy laws may have similar rights to access, delete, correct, and opt out of certain processing. Contact [email protected] to exercise these rights.
16. Children's Privacy
The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it. If you believe a child has provided us with personal information, contact [email protected].
17. Do Not Track
Some browsers transmit “Do Not Track” (DNT) signals. There is currently no industry standard for how companies should respond to DNT signals. Accordingly, our Services do not currently alter their practices when a DNT signal is received.
18. Limitation of Liability
YOU EXPRESSLY ACKNOWLEDGE THAT FREEBO IS NOT LIABLE FOR ANY SPECIAL, INDIRECT, CONSEQUENTIAL, INCIDENTAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RESULTING FROM YOUR USE OF THE SERVICES, INCLUDING ANY LOSS, DISCLOSURE, OR UNAUTHORIZED USE OF YOUR PERSONAL INFORMATION OR OTHER COLLECTED INFORMATION.
19. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify affected users by email or by posting a notice on the Services at least 30 days before the changes take effect. Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.
20. SMS Messaging
If you book a reservation through a Freebo-powered checkout, you may choose to receive text messages about that booking. Consent is collected through an unchecked checkbox at checkout and is never a condition of booking or purchase.
What we collect: the mobile phone number you provide, the fact that you consented, and the date and time of that consent, stored with your reservation record. We also retain delivery status for the messages we send.
How we use it: solely to send transactional messages about your reservation — booking confirmations, trip reminders, reschedule and cancellation notices, payment and balance notices, and waiver requests. We do not send marketing or promotional text messages.
Who we share it with: our SMS delivery provider, Twilio Inc., which transmits the messages on our behalf, and the operator whose trip you booked. Neither may use your number for their own marketing. No mobile information is sold, and no mobile information or SMS consent is shared with third parties or affiliates for marketing or promotional purposes.
Your choices: reply STOP to any message to opt out at any time, or HELP for assistance. Opting out stops text messages only; reservation email continues. See the SMS Messaging Program section of our Terms of Service for full program details.
21. Contact Us
Freebo Software Solutions LLC
Austin, Texas, United States
Email: [email protected]