Privacy Policy
1. Data controller
CulturaTrip SAS, with its registered office in Cotonou, Benin, is the controller of your personal data.
2. Data collected
CulturaTrip collects only the data necessary for the platform to function properly:
Registration data: last name, first name, email address, phone number, encrypted password, date of birth, nationality.
Profile data: profile photo, bio, travel preferences, languages spoken.
Booking data: stay dates, number of travelers, messages exchanged with the family, payment history.
Navigation data: IP address, browser type, pages visited, visit duration (via analytical cookies with consent).
3. Purposes of processing
Your data is used to:
- Manage your account and authenticate you
- Process your bookings and payments
- Send you notifications and communications related to your stays
- Ensure platform security
- Improve our services (anonymised statistics)
- Comply with our legal obligations
4. Data sharing
Your data is never sold to third parties. It may be shared with:
- The host family (name, first name, photo, introduction message) upon confirmed booking
- Our payment provider CinetPay (data strictly necessary for payment)
- Our technical hosting providers (secure servers in Europe)
5. Data retention
Your data is retained for the duration of your active account, then 3 years after closure for legal compliance purposes. Payment data is retained for 10 years in accordance with accounting obligations.
6. Your rights
Under GDPR, you have the following rights:
- Right of access: obtain a copy of your data
- Right of rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to portability: receive your data in a structured format
- Right to object: object to certain processing activities
To exercise these rights, contact: privacy@culturatrip.com
7. Cookies
We use technical cookies (necessary for operation) and analytical cookies (with your consent). You can manage your preferences via our cookie banner.
8. Security
Your data is protected by SSL/TLS encryption in transit and AES-256 at rest. We apply the data minimization principle and conduct regular security audits.
Last updated 13 April 2026