Finding things to do…
Finding things to do…
Last updated 13 September 2026
[…] is a fact only you can supply. Have counsel check it against the DPDP Rules, and against the GDPR, UK GDPR and CCPA/CPRA, before the app is submitted to the App Store.almost friday sells tickets to experiences and tours. It is operated by Stayoft Ventures Private Limited, registered in India at […]. We decide why and how your personal data is processed — we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023, and the controller under the GDPR.
To ask anything about this policy, or to exercise any right in it, write to support@almostfriday.app. That address reaches […], the person answerable for questions about how we process your data.
| Data | Why | Lawful basis |
|---|---|---|
| Email address | It is your account. We send a six-digit code to it to sign you in, and your booking confirmations and tickets. | Contract |
| Name and phone number | Passed to the operator running your experience so they can admit you, and reach you if something changes. | Contract |
| Bookings, prices and ticket references | To sell you the ticket, show it back to you, handle cancellations, and keep the financial records we are required to keep. | Contract, and legal obligation |
| Saved trips and reviews | Features you chose to use. | Contract |
| Advertising and analytics identifiers | To measure which adverts lead to bookings. You can turn this off — see Advertising below. | Consent |
We do not collect card numbers at any point — Razorpay does, and what comes back to us is the last four digits and the network.
Children. almost friday is for adults. Under the DPDP Act a child is anyone under 18, and processing a child’s data needs verifiable consent from a parent or guardian, which we are not set up to obtain — so we do not knowingly open accounts for under-18s and we do not direct advertising at children. Where an adult books for a child travelling with them, we hold only what the operator needs to admit that child. If you believe a child has an account with us, write to us and we will remove it.
We do not sell personal information for money.
Our website uses Meta’s pixel and Conversions API to see which adverts lead to bookings. Under the California Consumer Privacy Act as amended by the CPRA this counts as sharing personal information for cross-context behavioural advertising. You can switch it off under Do not sell or share my personal information in the app’s Profile tab, or by emailing us. We honour that choice for everyone who makes it, wherever they live — not only Californians — and we will never charge you a different price for making it.
Wherever you live, you can do all of the following from the Profile tab in the app, or by emailing us. They are free, and we will not treat you differently for using them.
We are an Indian company running on Cloudflare’s global network, and the operators who run your experience are wherever the experience is. Your data therefore crosses borders — that is what booking a tour in another country means. The DPDP Act permits this except to countries the Indian government restricts, and we do not transfer to any such country.
For travellers in the EEA and the UK, transfers out rely on the standard contractual clauses or the recipient’s own approved transfer mechanism.
Sessions are signed, sign-in codes are stored only as hashes and expire in ten minutes, and card numbers never reach our servers. Access to production data is limited to the people who need it. No system is perfect; if a breach affects you we will tell you and the Data Protection Board, as the DPDP Act requires.
If we change this materially we will say so in the app before the change takes effect. See also our terms of service.