Gollo
Menu
HomeBrowse toursReels
Become a local guideBecome a collaborator
Log inSign up
Gollo · Australia
Become a local guideLog inSign up

Privacy Policy

How Avino Pty Ltd (trading as Gollo) collects, uses, and protects your personal information.

Last updated: 4 August 2026

This Privacy Notice for Avino Pty Ltd (doing business as Gollo) ('we', 'us', or 'our') describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you:

  • Visit our website at https://gollo.co or any website of ours that links to this Privacy Notice
  • Download and use our mobile application (Gollo) on iOS or Android
  • Use Gollo as a traveller (browsing, booking, and reviewing tours), a host (creating and running tour listings), or a Collaborator (posting reels and earning referral commissions)
  • Engage with us in other related ways, including any marketing or events

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support@gollo.co.


Summary of key points

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by reading the full Notice below.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us, the choices you make, and the products and features you use.

Do we process any sensitive personal information? We do not process sensitive personal information (such as racial or ethnic origins, sexual orientation, or religious beliefs).

Do we collect any information from third parties? We collect limited profile information from third-party OAuth providers (Google, and Apple when enabled) if you choose to sign in that way. Otherwise, we do not collect information from third parties.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, prevent fraud, and comply with law. We may also process your information for other purposes with your consent.

In what situations and with which types of parties do we share personal information? We share information with functional sub-processors (payments, hosting, mapping, error monitoring, email delivery, AI-powered search, push notifications) to run the Services. We do not sell or share personal information for advertising or commercial consideration.

How do we keep your information safe? We have organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission or storage can be guaranteed to be 100% secure.

What are your rights? Depending on where you are located, applicable privacy law may give you rights regarding your personal information — access, correction, deletion, portability, and objection.

How do you exercise your rights? Contact us at Contact us or by email at support@gollo.co. We will consider and act upon any request in accordance with applicable data protection laws.


Table of contents

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on?
  4. When and with whom do we share your personal information?
  5. Do we use cookies and other tracking technologies?
  6. Do we offer artificial intelligence-based products?
  7. How do we handle your social logins?
  8. How long do we keep your information?
  9. How do we keep your information safe?
  10. Do we collect information from minors?
  11. What are your privacy rights?
  12. Controls for Do-Not-Track features
  13. Do United States residents have specific privacy rights?
  14. Do other regions have specific privacy rights?
  15. Do we make updates to this notice?
  16. How can you contact us about this notice?
  17. How can you review, update, or delete the data we collect from you?

1. What information do we collect?

Personal information you disclose to us

In short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you register for the Services, express an interest in obtaining information about us, participate in activities on the Services, or otherwise contact us.

The personal information we collect depends on the context of your interactions with us and may include:

  • Name, email address, and password
  • Profile photo, bio, and preferred language / currency
  • Phone number (if you provide one)
  • Tour listings — title, description, itinerary, photos, meeting-point details, pricing, availability (hosts)
  • Reviews, comments, and reels (user-generated content)
  • In-app messages exchanged between users
  • Support tickets and any attachments you send
  • Application information — city, country, bio, languages, categories, experience (host applicants); portfolio URL, social handle, reason (Collaborator applicants)

Sensitive information. We do not collect or process sensitive information.

Identity verification data. When you apply to become a host or Collaborator, we collect identity verification data via Stripe Identity (ID document check). Stripe processes and stores this data; we retain only the verification status and a reference.

Payment data. When you book a tour or receive payouts, we use Stripe and Stripe Connect. Payment card and bank account details are handled entirely by Stripe — this data never touches Gollo servers. See Stripe's privacy notice: https://stripe.com/legal/privacy-center.

Social login data. If you register or sign in using a third-party OAuth provider (Google, and Apple when enabled), we receive certain profile information — see Section 7.

Application (mobile app) data. If you use our iOS or Android app, we may also collect:

  • Geolocation. We request permission for approximate location (from IP or device) for city detection and precise location only for meeting-point navigation. You can revoke permission in your device settings.
  • Camera and photo library. We request access to attach photos to tour listings, profile photos, reels, or support tickets. Access is used only when you initiate an upload.
  • Push notifications. With your permission, we send booking updates, messages, and other transactional notifications via APNs (Apple) or FCM (Google).

All personal information you provide must be true, complete, and accurate. Notify us of any changes.

Information automatically collected

In short: Some information — such as your IP address and browser or device characteristics — is collected automatically when you use our Services.

We automatically collect certain technical information when you visit or use the Services:

  • Log and usage data — IP address, device type, browser type and version, operating system, referring URLs, actions taken on the Services, timestamps, error reports.
  • Device data — device identifiers, hardware model, mobile carrier, system configuration.
  • Location data — approximate location (from IP) for city detection; precise location only if you grant permission for map features or meeting-point navigation.
  • Cookies and similar technologies — see Section 5.

This information is used to operate the Services, prevent fraud, and improve user experience.


2. How do we process your information?

In short: We process your information to provide, improve, and administer our Services, communicate with you, prevent fraud and abuse, and comply with law. We may also process your information for other purposes with your consent.

We process your personal information for the following purposes:

  • To facilitate account creation and authentication — so you can register, sign in, and use your account.
  • To deliver and facilitate delivery of Services — bookings, messages, reviews, host tools, Collaborator dashboards, payouts.
  • To respond to user inquiries and offer support — via our Help & Support channel and support@gollo.co.
  • To send administrative information — booking confirmations, changes to our terms and policies, service updates.
  • To enable user-to-user communications — in-app messaging between travellers and hosts.
  • To request feedback and reviews — after completed tours.
  • To personalise your experience — recommend tours, destinations, and content based on prior activity. We do not use this to deliver third-party advertising.
  • To protect our Services — fraud monitoring, rate limiting, abuse prevention, security audits.
  • To identify usage trends — analytics on aggregate use to improve the platform.
  • To comply with legal obligations — tax reporting, financial audit, cooperating with authorities where legally required.
  • To save or protect vital interests — where necessary to prevent harm.

3. What legal bases do we rely on to process your information?

In short: We only process your personal information when we have a valid legal reason to do so — including with your consent, to fulfil a contract with you, to comply with laws, to protect your rights, or to fulfil legitimate business interests.

If you are located in the EU or UK

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the legal bases we rely on. We may rely on:

  • Consent — where you have given us permission to use your personal information for a specific purpose. You can withdraw consent at any time.
  • Performance of a contract — where processing is necessary to fulfil our Services (bookings, messaging, payouts).
  • Legitimate interests — where processing is reasonably necessary to achieve our legitimate business interests, provided those interests do not override your rights. Examples: personalising recommendations, analysing usage patterns, preventing fraud, improving the platform.
  • Legal obligations — where required to comply with law, respond to authorities, or defend legal rights.
  • Vital interests — where necessary to protect the safety of a person.

If you are located in Canada

We may process your information with your express or implied consent, or where legally permitted without consent (fraud detection, business transactions, legal proceedings, publicly available information, etc.).


4. When and with whom do we share your personal information?

In short: We share information with sub-processors that help us run the Services. We do not sell or disclose personal information for advertising or commercial consideration.

Sub-processors. We share personal information with third-party service providers that perform functions on our behalf, under contract, with data handling terms in place. The categories of sub-processors we currently use include:

  • Payment processing and payouts — Stripe (payments, Stripe Connect payouts, Stripe Identity verification). https://stripe.com/legal/privacy-center
  • Database, authentication, and file storage — Supabase.
  • Application hosting and edge functions — Vercel.
  • Content delivery, DDoS protection, and CAPTCHA — Cloudflare (including Cloudflare Turnstile).
  • Maps and geocoding — Mapbox (used in place of Google Maps Platform). https://www.mapbox.com/legal/privacy
  • Transactional email — Resend.
  • AI-powered natural-language search ("Talk to Gollo") — Anthropic (Claude) for query understanding, OpenAI for semantic embeddings. Query text may be shared with these providers to generate results; queries are not linked to individual profiles beyond a rate-limit key.
  • Error and performance monitoring — Sentry.
  • Push notifications — Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM), via Expo.
  • Rate limiting — Upstash Redis.
  • OAuth sign-in — Google (shipped) and Apple (planned) — see Section 7.

We share only the minimum data required for each provider to perform its function. We have contracts in place obligating each provider to protect the data and use it only for the purposes we specify.

We may also share your information in these situations:

  • Business transfers. We may share or transfer your information in connection with a merger, acquisition, sale of assets, or financing.
  • Other users of the Services. Content you post publicly — reviews, tour listings, host profiles, reels, comments — is visible to other users and may be indexed by search engines.
  • Legal obligations. We may disclose your information where required by law, court order, or to protect our legal rights.
  • With your consent. Any other sharing not covered above requires your explicit consent.

What we do not do:

  • We do not sell personal information for money or other valuable consideration.
  • We do not share personal information with third-party advertising networks.
  • We do not use Google Maps Platform APIs (our mapping is Mapbox).

5. Do we use cookies and other tracking technologies?

In short: We use essential cookies to operate the Services and functional cookies to remember your preferences. We do not use advertising cookies.

We use cookies and similar technologies to:

  • Maintain your session and authentication (essential)
  • Remember your currency and language preferences (functional)
  • Prevent fraud and CSRF attacks (essential — via Cloudflare Turnstile and Supabase auth)
  • Analyse aggregate usage where analytics is enabled

We do not currently use third-party advertising cookies, targeting cookies, or social media plugins. If we enable analytics tools such as Google Analytics or Vercel Analytics in the future, we will update this Privacy Notice.

Most browsers accept cookies by default. You can set your browser to reject cookies or notify you when a cookie is being sent — but doing so may affect certain features of the Services.

For details on specific cookies, see our Cookie Notice.


6. Do we offer artificial intelligence-based products?

In short: Yes — "Talk to Gollo" is our AI-powered natural-language search. Query text may be shared with third-party AI providers to generate results.

Gollo includes an AI-powered search feature called Talk to Gollo, which uses natural-language understanding to help you find tours matching what you describe (e.g. "a relaxed morning coffee tour near me").

AI service providers:

  • Anthropic (Claude) — for query understanding and response generation.
  • OpenAI — for semantic embeddings used to match your query against tour listings.

How your data is handled:

  • Query text is sent to the AI provider(s) to generate results.
  • Queries are not linked to your account beyond a short-term rate-limit key.
  • Query logs are retained for 6 months and then automatically purged.
  • Sensitive personal information is stripped from queries before logging.

We do not use your account data or personal information to train third-party AI models. Your Gollo activity is not shared with AI providers beyond the query text you type into the Talk to Gollo search field.


7. How do we handle your social logins?

In short: If you sign in with Google (or Apple when enabled), we receive limited profile information from that provider.

We offer sign-in via Google OAuth. Apple Sign-In is planned and will be enabled in a future release.

When you sign in with Google, we receive:

  • Your name
  • Your email address
  • Your Google profile picture (used as your default Gollo avatar)

We do not receive contacts, friends lists, or any other data from your Google account.

We use this information solely to create and manage your Gollo account. We recommend you review Google's Privacy Policy and Apple's Privacy Policy to understand how they handle your data.


8. How long do we keep your information?

In short: We keep your data for as long as your account is active. On deletion, we hard-purge personal data after a 30-day grace period, retaining only anonymised transaction and review records where legally required.

While your account is active, we retain your personal information for as long as necessary to operate the Services.

When you request account deletion (from Account & Privacy → Delete account):

  1. 30-day grace period. Your account is marked for deletion but retained. During this window you can sign back in to cancel the deletion.
  2. After 30 days — hard purge (via daily cron): Personal profile data (name, email, password, bio, profile photo, preferences) is permanently deleted. Wishlists, saved destinations, follows, notifications, and device tokens are permanently deleted. In-app messages and support tickets are permanently deleted. The underlying authentication record is permanently deleted (email freed for re-registration).
  3. What is retained (anonymised): Booking records are retained with your identity nulled but name and email preserved as immutable snapshots on the booking row. This supports tax reporting, dispute resolution, and Stripe's audit trail. Retention matches Australian tax record obligations (typically 5–7 years). Reviews are retained with the reviewer's identity nulled — the byline becomes "Anonymous" but content and star rating remain so aggregate ratings on tours are preserved.

Retention windows for auxiliary data:

  • Account data exports (self-service GDPR archives) — 2 years, then automatically purged.
  • Search query logs (Talk to Gollo) — 6 months, then automatically purged. Queries are not linked to individual profiles beyond a rate-limit key.
  • Error and performance logs (Sentry) — subject to Sentry's default retention (typically 30–90 days).
  • Database backups — retained for up to 30 days per Supabase platform defaults, then permanently deleted.

Legal basis for retention beyond account deletion:

  • Financial records: legitimate interest + statutory obligation (Australian tax law, Stripe audit).
  • Review content: legitimate interest (marketplace integrity — aggregate ratings protect other users).

All retained data is anonymised at the point of user deletion — no personally identifying information is preserved.


9. How do we keep your information safe?

In short: We use organisational and technical security measures to protect your information.

Security measures in place:

  • Transport encryption (HTTPS/TLS) for all data in transit
  • At-rest encryption for data in our database (via Supabase)
  • Cookie-based sessions with CSRF protection
  • Rate limiting via Upstash Redis on sensitive endpoints
  • CSP (Content Security Policy) with per-request nonces
  • CAPTCHA (Cloudflare Turnstile) on abuse-prone routes
  • Regular security audits and dependency updates
  • Sensitive fields (payment, ID verification) processed entirely by Stripe — never stored by Gollo

Despite our safeguards, no electronic transmission over the internet or storage technology can be guaranteed to be 100% secure. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

If you become aware of a security issue, please contact us immediately at support@gollo.co.


10. Do we collect information from minors?

In short: No. Gollo is an 18+ platform. We do not knowingly collect information from anyone under 18.

We do not knowingly collect data from or market to children under 18 years of age (or the equivalent age of majority in your jurisdiction), nor do we knowingly sell such personal information.

By using the Services, you represent that you are at least 18 years old. If we learn that personal information from users under 18 has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records.

If you become aware of any data we may have collected from children under 18, please contact us at support@gollo.co.


11. What are your privacy rights?

In short: Depending on your state or country of residence, you may have rights to access, correct, delete, port, or object to processing of your personal information.

In some regions (including the EEA, UK, Switzerland, Canada, Australia, and certain US states — see Section 13), you have rights under applicable data protection laws. These may include:

  • Right of access — obtain a copy of your personal information.
  • Right to rectification — correct inaccurate information.
  • Right to erasure — request deletion of your personal information.
  • Right to restrict processing — limit how we process your information.
  • Right to data portability — receive your data in a portable format.
  • Right to object — object to processing based on legitimate interests.
  • Right not to be subject to automated decision-making — including profiling that has legal or similarly significant effects.

You can exercise your rights by:

  • Contacting us via Contact us
  • Emailing support@gollo.co

We will consider and act upon any request in accordance with applicable data protection laws.

If you are in the UK and are unhappy with how we have handled your personal information, you can make a complaint directly to us. If you are not satisfied with our response, you can refer your complaint to the Information Commissioner's Office (ico.org.uk/make-a-complaint).

If you are in the EEA and believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority.

If you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw consent at any time by contacting us. This will not affect the lawfulness of processing before your withdrawal.

Opting out of marketing communications. You can unsubscribe from marketing emails by using the unsubscribe link in any marketing message, or by contacting us. We will still send you service-related messages (booking confirmations, security notifications, etc.) that are necessary for the administration of your account.

Account information. You can review or update your account information at any time via Account & Privacy in your profile settings. You can also request account deletion from that page — see Section 8 for what happens on deletion.

Cookies and similar technologies. Most browsers accept cookies by default. You can set your browser to reject cookies — this may affect some features.

If you have questions about your privacy rights, email us at support@gollo.co.


12. Controls for Do-Not-Track features

Most web browsers and some mobile operating systems and applications include a Do-Not-Track ('DNT') feature or setting you can activate. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. We do not currently respond to DNT browser signals. If a standard for online tracking is adopted that we must follow in the future, we will inform you in a revised version of this Privacy Notice.

California law requires us to let you know how we respond to DNT signals — because no industry or legal standard currently exists, we do not respond at this time.


13. Do United States residents have specific privacy rights?

In short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have specific rights over your personal information.

Categories of personal information we collect

We collect the following categories of personal information (from the CCPA taxonomy):

  • A. Identifiers — name, email, IP address, account name, unique identifiers. Collected: Yes.
  • B. Personal information under California Customer Records statute — name and contact information (subset of A). Collected: Yes (limited to name + contact).
  • C. Protected classification characteristics (gender, age, race, etc.). Collected: No.
  • D. Commercial information — transaction records, booking history, payment records. Collected: Yes.
  • E. Biometric information. Collected: No.
  • F. Internet or other network activity — browsing behaviour, search history, interactions with the Services. Collected: Yes.
  • G. Geolocation data — approximate location (from IP) and precise location (only with permission). Collected: Yes.
  • H. Audio, electronic, sensory information. Collected: No (except reels/photos you voluntarily upload).
  • I. Professional or employment-related information. Collected: No.
  • J. Education information. Collected: No.
  • K. Inferences — recommendations derived from your activity. Collected: Yes.
  • L. Sensitive personal information. Collected: No.

Sources of personal information

See Section 1 (What information do we collect?).

Have we sold or shared personal information?

No. In the preceding twelve (12) months, we have not sold or shared personal information for cross-context behavioural advertising or other monetary consideration.

We have disclosed the categories of personal information listed above to third-party sub-processors for business purposes as described in Section 4.

Your rights under US state data protection laws

  • Right to know whether we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to request deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to non-discrimination for exercising your rights
  • Right to opt out of the sale or sharing of personal data, targeted advertising, or profiling for decisions that produce legal or similarly significant effects

Depending on your state, you may also have additional rights (e.g. to obtain a list of specific third parties to which we have disclosed personal data — as permitted by law in California, Delaware, Maryland, Minnesota, and Oregon).

How to exercise your rights

Contact us via Contact us, or email support@gollo.co. You may designate an authorised agent to submit a request on your behalf; we may require proof of authority.

Request verification

Upon receiving your request, we will need to verify your identity. We will use the information provided only for verification purposes.

Appeals

If we decline to take action on your request, you may appeal our decision by emailing support@gollo.co. If your appeal is denied, you may submit a complaint to your state attorney general.


14. Do other regions have specific privacy rights?

In short: You may have additional rights based on the country you reside in.

Australia and New Zealand

We collect and process your personal information in accordance with Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. This Privacy Notice satisfies the notice requirements under both Acts.

You have the right to request access to or correction of your personal information — contact us at support@gollo.co.

If you believe we have processed your information unlawfully, you may complain to:

  • Australia — Office of the Australian Information Commissioner (oaic.gov.au)
  • New Zealand — Office of the Privacy Commissioner (privacy.org.nz)

Republic of South Africa

You have the right to request access to or correction of your personal information. Contact us at support@gollo.co.

If unsatisfied, you may complain to the Information Regulator (South Africa): general enquiries enquiries@inforegulator.org.za, complaints POPIAComplaints@inforegulator.org.za.


15. Do we make updates to this notice?

In short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top. If we make material changes, we may notify you by prominently posting a notice or by direct notification. We encourage you to review this Privacy Notice frequently.


16. How can you contact us about this notice?

If you have questions or comments about this Privacy Notice, you may contact us by:

  • Email — support@gollo.co
  • Online — Contact us

17. How can you review, update, or delete the data we collect from you?

Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect, correct inaccuracies, or request deletion.

To review, update, or delete your data:

  • Log in to your account and go to Account & Privacy to update your profile, export your data, or request account deletion.
  • Or contact us via Contact us or support@gollo.co.

Last updated: 4 August 2026

  • About
  • How we work
  • All tours
  • Destinations
  • Categories
  • Help Center
  • Contact us
  • Trust & Safety
  • Cancellation policy
  • Accessibility
  • Become a local guide
  • List your tour
  • Partner program
  • Host resources

Get the Gollo app

Coming soon
Coming soon
Gollo© 2026 GolloPrivacyTerms & ConditionsCookie policy
We accept