At Spice & Compass, we design immersive culinary travel experiences—from Tokyo’s Tsukiji fish market tastings to Oaxacan mole workshops—and our privacy policy reflects the same care we apply to sourcing heirloom chiles or verifying artisanal mezcal producers. This policy explains exactly how we collect, use, store, share, and protect your personal information when you book a tour, subscribe to our newsletter, use our mobile app, or interact with our website. We process data only as necessary to deliver safe, personalized, and culturally respectful food experiences—never for undisclosed third-party advertising or unconsented profiling. All data handling complies with GDPR (EU Regulation 2016/679), CCPA (California Civil Code §1798.100), and Brazil’s LGPD (Law No. 13,709/2018). Your email address, passport number (required for international visa support), dietary restrictions (e.g., strict vegan, celiac-safe, shellfish allergy), and real-time GPS coordinates during guided walks are treated with the same rigor as a Michelin-starred kitchen’s hygiene logbook.
What Personal Information We Collect
We collect two categories of information: (1) data you actively provide and (2) data automatically gathered during digital interactions. When you book our ‘Lisbon Pastel de Nata Masterclass’ or the ‘Chiang Mai Street Food Safari’, you submit contact details (name, email, phone), travel documentation (passport number and expiry date for border-compliant group visas), emergency contact information, and precise dietary requirements—including clinical certifications like IgE test reports for severe allergies. For example, in 2023, 72% of our guests disclosed at least one dietary restriction; among those, 41% specified gluten-free needs verified by medical documentation. We also record physical address for insurance compliance and tax invoicing (required under Portuguese Decree-Law No. 198/2012).
Automatically collected data includes IP address, browser type (Chrome v124.0.6367.78, Safari v17.4.1), device identifiers, pages visited (e.g., /tours/mexico/oaxaca-mole-workshop), time stamps, and geolocation coordinates accurate to ±5 meters via GPS-enabled devices during active tours. Our mobile app (iOS v5.2.1, Android v4.8.3) logs session duration, tap heatmaps on recipe cards, and offline cache usage—all anonymized after 90 days unless tied to an active booking. We do not collect biometric data, keystroke dynamics, or microphone input without explicit, revocable consent documented per ISO/IEC 27001 Annex A.9 controls.
Information Collected During Live Experiences
During in-person activities, our certified guides capture minimal operational data using encrypted tablets. For instance, during our ‘Bologna Mortadella Tasting Trail’, guides record real-time attendance via QR code check-in, temperature readings from refrigerated transport units (maintained at 2–4°C per EU Regulation (EC) No 852/2004), and allergen cross-contact incidents logged in our internal safety dashboard. No audio or video recordings are made without prior written consent. In 2024, we audited 1,842 live sessions: 99.7% had zero unreported allergen exposures, and all incident reports were retained for 7 years per Italian Legislative Decree 193/2007.
How We Use Your Information
Your data enables core service delivery, regulatory compliance, and safety assurance—not marketing speculation. We use your passport number solely to pre-register groups with Spain’s SEF (Servicio de Extranjeros y Fronteras) for multi-day Andalusian tapas tours, where advance immigration coordination is mandatory. Dietary declarations directly inform chef briefings: for our ‘Kyoto Kaiseki Immersion’, we transmit allergen matrices to Kikunoi Restaurant’s kitchen team 72 hours prior, specifying exact thresholds (e.g., <5 ppm gluten, <10 ppm soy) aligned with Codex Alimentarius Standard 248-2003.
Booking history—including spend patterns ($1,295 average for 7-day Morocco tagine trail; $2,850 for 10-day Japan ramen deep-dive)—helps us calibrate group sizes and ingredient procurement. We analyze anonymized regional preference data (e.g., 68% of guests aged 35–44 selected fermentation-focused tours in 2023) to refine seasonal offerings—but never link this to individual identities. Location data during tours triggers automatic SMS alerts if you stray beyond geofenced zones (radius: 150 meters around Bangkok’s Chatuchak Market stalls), a feature mandated by Thai Tourism Authority safety protocols.
Legal Bases for Processing Under GDPR
- Contractual necessity: Processing passport data to secure group visas for our ‘Istanbul Spice Bazaar Expedition’.
- Legal obligation: Retaining financial records for 10 years per UK HMRC guidance (Notice 732) and German GoBD standards.
- Vital interests: Sharing emergency contact details with local hospitals in case of allergic reaction during our ‘Sicily Arancini Workshop’.
- Legitimate interests: Using anonymized GPS paths to optimize walking routes and reduce heat exposure—validated by WHO thermal stress guidelines (WBGT index ≤28°C).
Who We Share Your Information With
We disclose data only with vetted, contractually bound partners essential to service execution. Our primary sharing categories include: local licensed guides (e.g., certified by Japan’s JNTO Guide Association), culinary venues (like Mercado San Miguel in Madrid, which requires guest headcounts 48 hours pre-visit), insurance providers (Allianz Global Assistance Policy #AGA-SPICE2024-8891), and payment processors (Stripe, PCI DSS Level 1 compliant; transaction logs retained ≤180 days). All partners sign Data Processing Agreements (DPAs) referencing EU Commission SCCs (2021/914) and undergo annual security audits.
We do not sell data or permit behavioral ad targeting. Unlike data brokers such as Acxiom or LiveRamp, we prohibit third-party enrichment—meaning your ‘vegan traveler’ status is never appended to external profiles. In 2023, we rejected 17 vendor requests for audience segmentation access, including a proposal from a meal-kit company seeking email lists. Cross-border transfers follow strict safeguards: data sent to our Mexico City office uses AES-256 encryption and travels via AWS Transit Gateway (Region: us-east-1 → sa-east-1), audited quarterly under SOC 2 Type II.
Third-Party Service Providers: Roles and Safeguards
Our tech stack prioritizes transparency and minimal data flow. Below is a verified list of active vendors, their purpose, data scope, and retention period:
| Vendor | Purpose | Data Shared | Retention Period | Compliance Certifications |
|---|---|---|---|---|
| Mailchimp | Email campaign delivery | Name, email, tour preferences, open/click rates | 24 months post-last interaction | GDPR-compliant, ISO 27001 certified |
| ResDiary | Table reservation sync for partner restaurants | Name, party size, dietary notes, booking time | 90 days post-visit | PCI DSS Level 1, GDPR SCCs |
| Google Cloud Platform | Secure storage of encrypted backups | Full database snapshots (anonymized IDs) | 365 days | ISO 27001, HIPAA BAA signed |
| Twilio | SMS alerts during live tours | Phone number, geofence breach timestamp | 30 days | GDPR-compliant, SOC 2 Type II |
Data Security Measures
We treat data security with the precision of a Tokyo knife-sharpening master—every layer matters. All web traffic uses TLS 1.3 encryption (cipher suite: TLS_AES_256_GCM_SHA384); databases are encrypted at rest using AWS KMS keys rotated every 90 days. Access to PII (Personally Identifiable Information) follows principle of least privilege: only 12 staff members globally hold read/write access to passport fields, and all actions are logged in immutable audit trails (retained for 7 years per NIST SP 800-92). Our penetration testing, conducted biannually by Cure53 (Report ID: C53-SPICE-2024-Q2), achieved zero critical vulnerabilities; high-risk findings (e.g., misconfigured S3 bucket in staging environment) were remediated within 4 hours.
Physical security matches digital rigor: paper-based dietary forms from our ‘Paris Boulangerie Crawl’ are scanned within 24 hours, shredded using Fellowes 7CC cross-cut shredders (DIN 32757-1 Level P-5), and digital copies stored on air-gapped servers in Zurich (Swisscom Data Center Tier IV). Staff undergo mandatory annual training covering OWASP Top 10 risks and GDPR Article 32 obligations; completion rates averaged 99.4% across 217 employees in 2023. Multi-factor authentication (MFA) is enforced via YubiKey 5 NFC for all admin portals—no SMS fallback permitted.
Your Rights and How to Exercise Them
You retain full control over your data. Under GDPR, CCPA, and LGPD, you may request access, correction, deletion, or portability of your information at any time. To exercise these rights, email privacy@spiceandcompass.com with subject line ‘DATA REQUEST [Last Name]’ and attach a government-issued ID (blurred except photo and name). We respond within 5 business days for access/portability requests and 15 days for erasure—per GDPR Article 12 timelines. Deletion excludes data required by law: financial records (10 years), insurance claims (6 years per Swiss Insurance Contract Act Art. 49), and allergen incident reports (7 years).
Opting out of marketing is instant: click ‘Unsubscribe’ in any email (compliant with CAN-SPAM §301) or text STOP to +1-844-774-2345. Do Not Sell/Share requests under CCPA are honored within 15 days via our web form (spiceandcompass.com/dns-request), with verification requiring last booking date and email confirmation. In 2023, we fulfilled 1,204 individual rights requests; median resolution time was 2.1 days. We do not charge fees unless requests are manifestly unfounded or excessive (per GDPR Recital 63), defined as >3 similar requests within 12 months.
Children’s Data Protection
We do not knowingly collect data from children under 16. Our tours require minimum ages: 12 for Japan sake brewery visits (per Japan Liquor Tax Act Art. 42), 16 for Mexican distillery tours (Mexican General Health Law Art. 262), and 18 for French wine caves (French Public Health Code Art. L3323-1). If we discover unintentional collection, we delete the data within 72 hours and notify guardians. Our website employs age-gating via self-declaration (no ID verification), consistent with FTC COPPA enforcement guidelines for experiential services.
Data Retention Schedule
We retain data only as long as necessary for legal, operational, or safety purposes—never indefinitely. Financial transaction records (credit card last four digits, amount, VAT breakdown) are kept 10 years per German Handelsgesetzbuch §257. Tour-specific dietary documentation is archived 3 years post-experience to support potential allergy-related liability claims under UK Consumer Rights Act 2015. GPS tracking logs from our ‘Barcelona Paella Boat Tour’ expire after 180 days unless flagged for incident review. Email subscriber lists purge inactive addresses (no opens/clicks for 24 months) monthly, reducing spam complaints to 0.08%—well below Mailchimp’s industry benchmark of 0.2%.
- Passport data: deleted 30 days after tour completion, unless required for visa appeals (max 2 years).
- Emergency contact details: retained 1 year post-tour for insurance claim validation.
- Guide performance feedback: anonymized and aggregated after 6 months.
- Payment processor tokens (Stripe): stored indefinitely per PCI DSS Requirement 8.2.3 for recurring billing opt-ins.
- Photographic releases (signed on-site): kept 5 years, then shredded.
Retirement follows NIST SP 800-88 Rev. 1 sanitization standards: cryptographic erasure for cloud objects, degaussing for backup tapes, and physical destruction for paper files. Quarterly retention audits are performed by our Data Governance Council, chaired by our DPO (Data Protection Officer), a certified IAPP CIPP/E professional based in Dublin.
Changes to This Policy
We update this policy to reflect operational improvements, legal developments, or technology shifts. Material changes—such as introducing biometric consent for thermal screening at airport meetups or expanding data sharing to new regulatory bodies—are communicated via email 30 days prior to effect, with clear version history available at spiceandcompass.com/privacy-history. The current version (v4.2, effective July 1, 2024) introduces mandatory MFA for all guest-facing portals and extends CCPA ‘Do Not Sell’ coverage to include geolocation data used in route optimization. We maintain a public changelog showing every revision since v1.0 (January 2020), including dates, change types (‘addition’, ‘removal’, ‘clarification’), and regulatory drivers (e.g., ‘Added LGPD alignment per Brazilian ANPD Resolution 1/2022’).
Non-material updates—like correcting typographical errors or updating vendor certification expiry dates—are implemented immediately without notice. You can always access the latest policy at spiceandcompass.com/privacy. Printed copies are available upon request at no cost; mail requests to: Data Compliance Team, Spice & Compass Ltd., 12 Culinary Lane, London W1K 6AA, United Kingdom. We welcome feedback: our Privacy Advisory Panel includes food anthropologists, disability advocates, and GDPR legal scholars who review policy drafts quarterly.
Contact Our Data Protection Officer
For questions, concerns, or formal complaints, contact our certified DPO directly:
Dr. Lena Vogt, CIPP/E
privacy@spiceandcompass.com
+44 20 7123 4567 (Mon–Fri, 9:00–17:00 GMT)
Postal address: Data Protection Office, Spice & Compass Ltd., 12 Culinary Lane, London W1K 6AA
All inquiries receive acknowledgment within 24 hours. Formal complaints are investigated per ICO Guidance Note G12 and resolved within 30 days—or escalated to the UK Information Commissioner’s Office (Case ID: ICO-SPICE-2024-XXXXX) if unresolved.
This policy applies to all Spice & Compass services, including our flagship ‘Global Palate Passport’ subscription program, private chef collaborations with Le Cordon Bleu graduates, and educational webinars co-hosted with Slow Food International. It supersedes all prior versions and takes effect July 1, 2024. By engaging with our services—whether booking a $95 ‘Seville Jamón Tasting’ or downloading our free ‘Spice Routes’ podcast—you acknowledge and agree to these terms. We built this policy not as legal boilerplate, but as a promise: your trust in our kitchens, our guides, and our digital spaces is guarded with the same integrity we demand from a 30-year-old balsamic vinegar producer in Modena.




