Privacy policy
Last updated 13 September 2026
[…] is a fact only you can supply. Have counsel check it against the DPDP Rules, and against the GDPR, UK GDPR and CCPA/CPRA, before the app is submitted to the App Store.Who we are
almost friday sells tickets to experiences and tours. It is operated by Stayoft Ventures Private Limited, registered in India at […]. We decide why and how your personal data is processed — we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023, and the controller under the GDPR.
To ask anything about this policy, or to exercise any right in it, write to support@almostfriday.app. That address reaches […], the person answerable for questions about how we process your data.
What we collect, and why
| Data | Why | Lawful basis |
|---|---|---|
| Email address | It is your account. We send a six-digit code to it to sign you in, and your booking confirmations and tickets. | Contract |
| Name and phone number | Passed to the operator running your experience so they can admit you, and reach you if something changes. | Contract |
| Bookings, prices and ticket references | To sell you the ticket, show it back to you, handle cancellations, and keep the financial records we are required to keep. | Contract, and legal obligation |
| Saved trips and reviews | Features you chose to use. | Contract |
| Advertising and analytics identifiers | To measure which adverts lead to bookings. You can turn this off — see Advertising below. | Consent |
We do not collect card numbers at any point. You enter them with PayU, and nothing that could reconstruct a card ever reaches us.
Children. almost friday is for adults. Under the DPDP Act a child is anyone under 18, and processing a child’s data needs verifiable consent from a parent or guardian, which we are not set up to obtain — so we do not knowingly open accounts for under-18s and we do not direct advertising at children. Where an adult books for a child travelling with them, we hold only what the operator needs to admit that child. If you believe a child has an account with us, write to us and we will remove it.
Who we share it with
- GlobalTix — our ticketing partner. The lead traveller’s name and email go to them, and on to the operator running the experience, so your ticket can be issued and honoured.
- PayU — payments. You enter card details with them, not with us.
- Meta — advertising measurement on our website. This is “sharing” as California defines it, and you can opt out.
- Cloudflare — hosting, our database, and sending the emails above.
We do not sell personal information for money.
Advertising, and your opt-out
Our website uses Meta’s pixel and Conversions API to see which adverts lead to bookings. Under the California Consumer Privacy Act as amended by the CPRA this counts as sharing personal information for cross-context behavioural advertising. You can switch it off under Do not sell or share my personal information in the app’s Profile tab, or by emailing us. We honour that choice for everyone who makes it, wherever they live — not only Californians — and we will never charge you a different price for making it.
How long we keep it
- Sign-in codes: ten minutes, and only ever as a hash.
- Your account, saved trips and reviews: until you delete your account.
- Bookings: kept after deletion as financial records, with your name and account removed so the record is no longer about an identifiable person. This is the retention GDPR Art. 17(3)(b) preserves.
Your rights
Wherever you live, you can do all of the following from the Profile tab in the app, or by emailing us. They are free, and we will not treat you differently for using them.
- See your data. Download everything we hold about you as a file. (GDPR Art. 15 and 20; CCPA right to know; PIPEDA access.)
- Correct it. Edit your name and phone number.
- Delete your account. Immediate and in-app. (GDPR Art. 17; CCPA right to delete.)
- Opt out of sharing for advertising, and of marketing email.
- Withdraw consent to anything you gave it for, as easily as you gave it. Turning off advertising and marketing in the Profile tab is that switch; it does not affect anything we did before you turned it off.
- Nominate someone to exercise these rights for you if you die or become incapacitated. Write to us with their details. (DPDP Act s. 14.)
- Complain to us first. Write to support@almostfriday.app. We acknowledge within 24 hours and aim to resolve within 15 days. Erasure requests are completed within 90 days.
- Then complain to a regulator. In India, to the Data Protection Board once you have been through us first, as the DPDP Act requires. In the EU your national authority, in the UK the ICO, in Canada the Office of the Privacy Commissioner or the CAI in Quebec.
Where your data goes
We are an Indian company running on Cloudflare’s global network, and the operators who run your experience are wherever the experience is. Your data therefore crosses borders — that is what booking a tour in another country means. The DPDP Act permits this except to countries the Indian government restricts, and we do not transfer to any such country.
For travellers in the EEA and the UK, transfers out rely on the standard contractual clauses or the recipient’s own approved transfer mechanism.
Keeping it safe
Sessions are signed, sign-in codes are stored only as hashes and expire in ten minutes, and card numbers never reach our servers. Access to production data is limited to the people who need it. No system is perfect; if a breach affects you we will tell you and the Data Protection Board, as the DPDP Act requires.
Changes
If we change this materially we will say so in the app before the change takes effect. See also our terms of service.