Overview

Security & data handling

This page explains, in plain terms, how TourConvert is installed on your site, what the assistant is and isn't allowed to do, and how data is processed. It is an overview, not a contract — see our Privacy policy and Terms for the full detail.

How it's installed

  • You add one embed script to your existing website. The assistant's interface loads in a self-contained panel served from the TourConvert application host.
  • The assistant runtime, its configuration, and your approved tour information stay on the TourConvert host — they are not copied into your website's code.
  • The embed only activates for website origins you have authorised.

What the assistant can and cannot do

  • Can: answer pre-booking questions using the tour information you approve, help a visitor choose an experience, check availability where your setup supports it, and pass a qualified enquiry to your team.
  • Guardrails: the assistant is instructed to use approved sources and hand off when a person should confirm. It cannot take payments or create, change, or cancel bookings on its own.

What data is processed

DataWhy
Visitor chat messages and the assistant's repliesTo answer questions and to let your team follow up on an enquiry.
Basic page context (page path and title, and same-site referring path)To give the assistant context about what the visitor is looking at.
Enquiry details a visitor chooses to share (for example dates, group size, contact details)To hand a qualified enquiry to your team so a person can respond.
Operational logs (counts, timings, error signals)To keep the service running and to help diagnose problems.

The assistant is designed to work without storing raw visitor IP addresses in its activity logs. Conversation content is kept so that your team can respond to an enquiry and so you can review answer quality.

Roles and responsibilities

  • You remain responsible for the tour information you approve and for handling the enquiries handed to your team.
  • For personal data your visitors share through the assistant, you act as the data controller and TourConvert processes it on your behalf. Contact us to discuss the data-processing terms required for your rollout.
  • You are responsible for telling your website visitors that a chat assistant is in use, in line with your own privacy notice.

Access and retention

  • Access to conversations and enquiries is limited to your authorised operator access and to TourConvert staff who need it to run and support the service.
  • Retention periods and deletion requests are covered in the Privacy policy; you can also contact us to discuss your requirements.

Questions or a security review?

Email tourconvert@gmail.com and we'll help. If you have data-processing or security requirements, tell us what your compliance team needs before rollout.