Effective date: August 29, 2026
This Privacy Policy explains how The Travel Spark Company LLC (“we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you visit Tourism SF, use its forms, subscribe to updates, or follow links to third-party services. It also explains choices that may be available to you.
This policy applies to the Tourism SF website and communications initiated through it. It does not govern the independent practices of a tour operator, hotel, booking platform, transit agency, park, venue, social network, or other third party. Review a third party’s own privacy notice before providing information to that party.
Information we collect
The information we collect depends on how you use the website and which optional services are configured.
Information you provide
You may provide information when you:
- send a message through the contact form;
- submit a factual correction, accessibility report, technical issue, or image or rights concern;
- subscribe to an email newsletter or other update;
- respond to a survey or other request that clearly explains what will be collected; or
- communicate with us about a privacy request.
This information may include your name, email address, selected message topic, page URL, message content, subscription preferences, and any other information you choose to include. Do not submit sensitive personal information, payment-card details, account passwords, travel documents, or urgent medical or safety information through the contact form.
Information collected automatically
When you use the website, our hosting, security, caching, and content-delivery systems may automatically receive technical information such as:
- Internet Protocol address;
- browser type and version;
- device and operating-system information;
- referring and requested URLs;
- date and time of a request;
- response status, transferred data, and diagnostic information;
- approximate location inferred from an IP address;
- security signals, suspected abuse, and form-rate information; and
- cookie or similar-technology identifiers when those technologies are used.
Server logs are used to deliver the site, maintain reliability, detect abuse, investigate errors, and protect the website. They are not intended to reveal your precise physical location.
Affiliate and provider interactions
Tourism SF may display tours, activities, hotels, or other travel products supplied by third-party providers such as TravelSpark, Viator, or Nuitee. When a configured integration returns provider content, the website may receive or transmit product identifiers, destination or search selections, referral information, and technical request data needed to display or attribute the result.
If you select a provider link, the provider may collect information under its own privacy policy, including device data, referral information, account details, traveler details, booking information, and payment information. Tourism SF does not need to receive your payment-card number merely because you follow an affiliate link. Any booking, payment, cancellation, or traveler-data collection on a provider’s site is governed by that provider’s terms and privacy notice.
Cookies and similar technologies
Cookies are small files placed on a browser or device. Similar technologies include local storage, pixels, and request identifiers. The site may use technologies that are necessary for:
- security, fraud prevention, and rate limiting;
- load balancing, caching, and reliable delivery;
- remembering a privacy or interface preference;
- operating a form and preserving its security token; and
- measuring whether an affiliate referral resulted in a provider interaction.
Optional analytics, advertising, embedded media, mapping, or behavioral technologies should not be loaded merely because the site can support them. If a nonessential service is added and applicable law requires consent, the site will present an appropriate choice before activating that service. Blocking necessary cookies may affect security features or form operation.
You can use browser controls to delete or block cookies. Those controls vary by browser, and they do not necessarily prevent server-side logging or information transmitted when you intentionally follow a third-party link.
How we use information
We may use information to:
- provide, secure, maintain, and troubleshoot the website;
- respond to a message or privacy request;
- send an update you requested and manage subscription preferences;
- validate a form, prevent spam, and enforce reasonable rate limits;
- investigate suspected abuse, malicious activity, or a technical incident;
- understand aggregate site performance and improve useful content;
- display authorized provider results and attribute affiliate referrals;
- correct factual, accessibility, attribution, or rights issues;
- comply with law, legal process, and enforceable requests; and
- establish, exercise, or defend legal rights.
We do not use a contact-form message to enroll you in marketing without a separate, clear choice. We do not claim that a newsletter subscription, contact message, or booking inquiry was completed unless the relevant system returns a successful result.
Legal grounds where required
Where applicable law requires a legal basis, our bases may include:
- performance of a service you requested, such as responding to your message;
- consent, such as when you voluntarily subscribe to marketing updates;
- legitimate interests in operating, securing, measuring, and improving the website, balanced against your rights;
- compliance with a legal obligation; and
- protection of legal rights and the safety or integrity of users, the website, and others.
You may withdraw consent for future processing where consent is the basis. Withdrawal does not make earlier processing unlawful.
How we disclose information
We may disclose information in the following circumstances.
Vendors acting for us
Service providers may process information to host the site, deliver email, provide security, cache pages, maintain WordPress, diagnose errors, or support forms. For example, Brevo may process an email address and related delivery data when an authorized newsletter or contact workflow uses its service. Wordfence or comparable security tooling may process request and security information. A hosting or caching provider may process logs and network data. ManageWP may process administrative and technical information only if an authorized dashboard connection is later established.
Vendors may use information only as permitted by their agreements and applicable law. The exact vendors in use may change as systems are maintained; a plugin’s presence alone does not mean its external service is connected.
Travel and affiliate providers
We may transmit referral and product context to TravelSpark, Viator, Nuitee, or another displayed provider when you interact with a configured result or outbound link. The receiving provider processes information under its own policies. Tourism SF may receive an affiliate commission if a qualifying transaction is attributed to a link, but a commission does not give us control over the provider’s data practices.
Search and indexing services
When public indexing is enabled, systems such as WordPress, Yoast SEO, or IndexNow may expose or notify search engines of public URLs and update signals. These tools are not intended to transmit the private contents of a contact form. Search engines independently determine how they crawl, cache, and display public pages.
Legal, safety, and organizational reasons
We may disclose information when reasonably necessary to comply with applicable law or valid legal process; protect rights, safety, and security; investigate fraud or abuse; or respond to an emergency involving risk of harm. We may also transfer information as part of a merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate notice and safeguards required by law.
We do not sell personal information for money. We do not use information from a contact message to create a profile for unrelated behavioral advertising. If these practices change, this policy and any legally required choices must be updated before the change applies.
Email communications
If you subscribe to editorial updates, we may use the submitted email address and subscription records to send them. Each marketing email should include a functional unsubscribe method. Unsubscribing from marketing does not prevent a necessary response to a request you initiated or a legally required notice.
Delivery systems may record whether a message was accepted, bounced, or unsubscribed. If optional open or click measurement is used, it should be disclosed in the signup experience and configured in accordance with applicable requirements.
Form security and reCAPTCHA
Forms use security controls such as nonces, validation, a honeypot, and reasonable rate limits. If reCAPTCHA or another third-party challenge is actually enabled, the form will identify the service and provide any required privacy and terms notice. When no such service is enabled, the site should not display a reCAPTCHA disclosure or load its scripts.
Security controls reduce abuse but cannot guarantee that every transmission is secure. Do not use a public web form for urgent, confidential, or highly sensitive information.
Data retention
We retain information only for as long as reasonably necessary for the purpose described, including to respond to requests, maintain subscription records, secure the site, comply with law, resolve disputes, and enforce agreements. Retention periods vary by record type.
For example, subscription records may be kept while a subscription is active and for a limited period afterward to document an unsubscribe. Contact messages may be retained while the matter is handled and for a reasonable recordkeeping period. Security logs may be retained for a shorter operational period unless an incident requires further investigation. Backups may preserve information for a limited rotation period before deletion or overwrite.
We may retain a minimal suppression record so that an unsubscribed address is not inadvertently added again. We may also retain information when law requires it or when needed for a legal claim.
International processing
The website and its service providers may process information in countries other than the one where you live. Data-protection laws may differ across those locations. Where applicable law requires it, we use recognized transfer mechanisms or other safeguards for international processing. Third-party travel providers handle their own international transfers under their policies.
Security
We use administrative, technical, and organizational measures intended to protect information. These may include access controls, transport encryption, software updates, least-privilege practices, backups, monitoring, validation, and security tooling. No website, transmission method, or storage system can be guaranteed completely secure.
If you believe information submitted through Tourism SF has been affected by a security issue, use the Contact page and select the technical-problem topic. Do not include passwords or sensitive credentials in the message.
Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access to, correction of, deletion of, restriction on, or portability of personal information. You may also have the right to object to certain processing, withdraw consent, opt out of certain disclosures, or appeal a decision concerning a request.
To make a request, use the Contact page and clearly identify it as a privacy request. Describe the request and the information or interaction involved. We may need to verify your identity and authority before acting, and we will not ask for more verification information than reasonably necessary. Authorized agents may be required to provide proof of authority. We will respond within the period required by applicable law.
You can unsubscribe from marketing using the link in the message. You can manage cookies through available site and browser controls. You may use provider or device privacy controls for data processed independently by third parties.
We will not discriminate against you for exercising a privacy right recognized by applicable law.
Children’s privacy
Tourism SF is a general-audience travel-information site and is not directed to children under the age at which parental consent is required by applicable law. We do not knowingly seek personal information from children through the contact or newsletter forms. If you believe a child submitted personal information without appropriate consent, use the Contact page so the matter can be reviewed.
External links and embedded content
The site links to government agencies, parks, cultural organizations, venues, businesses, travel providers, and other independent websites. A link does not mean that we control or endorse a third party’s privacy practices. If embedded content is enabled, it may allow the provider to collect information as if you visited its site directly. Nonessential embeds should remain inactive until any required privacy choice is made.
Changes to this policy
We may update this Privacy Policy to reflect changes in the website, services, law, or operational practices. The effective date at the top identifies the current version. If a change materially affects how previously collected information is used, we will provide additional notice or seek consent when required.
Contact
Questions or requests about this Privacy Policy can be sent through the Contact page. Select the most relevant topic and state that the message concerns privacy. Do not include identity documents unless we specifically request an appropriate verification method.
