Privacy policy
Last updated: 2026-10-08
1. Data controller
The data controller is Manuel Joaquín Izquierdo Tomás, Spanish ID 22596796D, operating the Walkingfy platform (https://walkingfy.com).
Privacy contact: info@walkingfy.com · walkingfyapp@gmail.com
2. Data we process
- Operators (SaaS): name, email, company, country, billing data and Stripe Connect details needed for subscription and payouts.
- Travellers (Explore): contact and booking data you provide when discovering a tour; the booking is attributed to the operator and the service contract is completed on the operator’s website.
- Technical use: logs, technical cookies, locale and UI preferences.
3. Purposes and legal bases
- Providing the SaaS and marketplace (contract / pre-contractual steps).
- Billing, fraud prevention and legal compliance (legal obligation / legitimate interest).
- Operational communications tied to the service.
- Product improvement with aggregated metrics where applicable (legitimate interest or consent when cookies require it).
4. Recipients
We do not sell personal data. We may share data with:
- The operator attributed to a booking started on Explore.
- Processors that run the service (hosting, database, Stripe, email), under GDPR safeguards.
- Authorities when legally required.
5. Retention
We keep data for the life of the contract and applicable legal retention periods (billing, claims, accounting). Technical logs are rotated on security criteria.
6. Your rights
You may request access, rectification, erasure, objection, restriction and portability at info@walkingfy.com. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
7. Security
We apply reasonable technical and organisational measures (restricted access, encrypted connections, tenant segregation). No system is fully secure; please report incidents to us.
8. International transfers
Some providers may process data outside the EEA. Where required we use recognised safeguards (e.g. standard contractual clauses).
9. Children
The service is not directed at children under 14. Unauthorised children’s data will be deleted.
10. Changes
We may update this policy and will show the revision date on this page.