Privacy Policy

Last modified: Feb 21, 2023

At Folio, we take your privacy seriously. Please read this privacy policy (the “Privacy Policy”) to learn how we treat your personal data. By using or accessing the content and services provided on the Site (the “Services”) in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and share your information as described in this Privacy Policy.

Remember that your use of Folio’s Services is at all times subject to our Terms of Service (https://www.foliotravel.com/terms), which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Service.

You may print a copy of this Privacy Policy via your File → Print menu. If you have a disability, you may access this Privacy Policy in an alternative format by contacting support@foliotravel.com.

Privacy Policy Table of Contents

  • What this Privacy Policy Covers

  • Personal Data

    • Categories of Personal Data We Collect

    • Categories of Sources of Personal Data

    • Our Commercial or Business Purposes for Collecting Personal Data

  • How We Share Your Personal Data

  • Tracking Tools and Opt-Out

  • Data Security and Retention

  • Personal Data of Children

  • California Resident Rights

  • Other State Law Privacy Rights

  • European Union Data Subject Rights

  • Changes to this Privacy Policy

  • How to contact the appropriate authorities

  • Contact Information

What this Privacy Policy Covers

This Privacy Policy covers how we treat Personal Data and information that we gather or that you have provided to us when you access or use our Services, interact with the Site via email, text, or other electronic means, and through mobile and desktop applications you may download from this Site. “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules or regulations. This Privacy Policy does not cover the practices of companies we don’t own or control or third parties we don’t manage.  Without limiting the foregoing, this Privacy Policy does not cover the practices of you or other users of our Services who may collect or otherwise process Personal Data of End Users of Applications created using our Services.  As stated in the Terms of Service, all users of our Services are responsible for complying with all applicable data protection and privacy laws and for making available all required privacy notices and disclosures directly to their End Users.

Children Under the Age of 18

Our Services are not intended for children under 18 years of age. No one under age 18 may provide any information to or on the Services. We do not knowingly collect personal information from children under 18. If you are under 18, do not use or provide any information on this Services or through any of its features, register on the Services, make any purchases through the Services, use any of the interactive or public comment features of this Services, or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at the information provided below.

California residents under 18 years of age may have additional rights regarding the collection and sale of their personal information. Please see Your California Privacy Rights (below) for more information.

Personal Data

Categories of Personal Data We Collect 

The categories of Personal Data that we collect and have collected over the past 12 months:

Profile or Contact Data

  • Examples of Personal Data We Collect: First and Last name; Email; Unique Identifiers.

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers; Analytics Providers; Parties You Authorize, Access or Authenticate

Payment Data

  • Examples of Personal Data We Collect (on behalf of our payment processing partner, currently Stripe, Inc.): Information required to make payments

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers (specifically our payment processing partner, currently Stripe, Inc.)

Commercial Data

  • Examples of Personal Data We Collect: Purchase history

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers; Analytics Partners

Device/IP Data

  • Examples of Personal Data We Collect: IP address; Device ID; Domain server; Type of device/operating system/browser used to access the Services

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers; Analytics Partners

Web Analytics

  • Examples of Personal Data We Collect: Web page interactions; Referring webpage/source through which you accessed the Services; Non-identifiable request IDs; Statistics associated with the interaction between device or browser and the Services

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers; Analytics Partners; Parties You Authorize, Access or Authenticate

Other Identifying Information that You Voluntarily Choose to Provide

  • Examples of Personal Data We Collect: Support requests and conversations

  • Categories of Third Parties With Whom We Share this Personal Data: Service Providers

Categories of Sources of Personal Data

We collect Personal Data about you from the following categories of sources:

You

  • When you provide such information directly to us

    • When you create an account or use our interactive tools and Services.

    • When you voluntarily provide information in free-form text boxes through the Services.

    • When you send us an email or otherwise contact us.

  • When you use the Services and such information is collected automatically

    • Through Cookies (defined in the “Tracking Tools and Opt-Out” section below).

    • If you download and install certain applications and software we make available, we may receive and collect information transmitted from your computing device for the purpose of providing you the relevant Services, such as information regarding when you are logged on and available to receive updates or alert notices.

Third Parties

  • Vendors

    • We may use analytics providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.

Our Commercial or Business Purposes for Collecting Personal Data

Providing, Customizing and Improving the Services

  • Creating and managing your account or other user profiles.

  • Processing subscriptions or other transactions; billing.

  • Providing you with the Services or information you request.

  • Meeting or fulfilling the reason you provided the information to us.

  • Providing support and assistance for the Services.

  • Improving the Services, including testing, research, internal analytics and product development.

  • Personalizing the Services, Site content and communications based on your preferences.

  • Performing fraud protection, security and debugging.

  • Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws. 

Marketing the Services

The Company may send you information about products and Services of the Company, always with your consent. You consent to marketing and promotional communication when you use the Services.

If you have agreed to receive such marketing materials, you may always opt out at a later date.  You have the right at any time to stop the Company from contacting you for marketing purposes.

Corresponding with You

  • Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about the Company or the Services.

  • Sending emails and other communications according to your preferences or that display content that we think will interest you.

Meeting Legal Requirements and Enforcing Legal Terms

  • Fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities.

  • Protecting the rights, property or safety of you, Folio or another party.

  • Enforcing any agreements with you.

  • Responding to claims that any posting or other content violates third-party rights.

  • Resolving disputes.

You expressly and directly provide personal data, including payment information, to the Company via the Site when enrolling for the Services.

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice.

How We Share Your Personal Data

We disclose your Personal Data to the categories of service providers and other parties listed in this section.  Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your Personal Data. For more information, please refer to the state-specific sections below.

  • Service Providers. These parties help us provide the Services or perform business functions on our behalf. They include:

    • Hosting, technology and communication providers.

    • Security and fraud prevention consultants.

    • Support and customer service vendors.

    • Payment processors.

    • Our payment processing partner Stripe, Inc. (“Stripe”) collects your voluntarily-provided payment card information necessary to process your payment.

    • Please see Stripe’s terms of service and privacy policy for information on its use and storage of your Personal Data.

  • Analytics Partners. These parties provide analytics on web traffic or usage of the Services. They include:

    • Companies that track how users found or were referred to the Site or the Services.

    • Companies that track how users interact with the Services.

  • Business Partners. These parties partner with us in offering various Services. They include:

    • Businesses that you have a relationship with.

    • Companies that we partner with to offer joint promotional offers or opportunities.

  • Parties You Authorize, Access or Authenticate

    • Third parties you access through the services.

    • Other users.

Legal Obligations

We may share any Personal Data that we collect with third parties in conjunction with any of the activities set forth under “Meeting Legal Requirements and Enforcing Legal Terms” in the “Our Commercial or Business Purposes for Collecting Personal Data” section above.

Business Transfers

All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.

Data that is Not Personal Data

We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you. 

Users consent to the release of this information and data to the Company for the purpose of the performance of the Company’s Services for your benefit. This release of information and the relationship between you and the Company is also subject to the Terms of Use.

Tracking Tools and Opt-Out

The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser, tell us how and when you visit and use our Services, analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone or similar device when you use that device to access our Services. For further information, visit allaboutcookies.org. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). Please note that because of our use of Cookies, the Services do not support “Do Not Track” requests sent from a browser at this time.

We use the following types of Cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our website. For example, certain cookies enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services. Disabling these Cookies may make certain features and Services unavailable.

  • Analytical/Performance cookies. They allow us to understand how visitors use our Services. They do this by collecting information about the number of visitors to the Services, what pages visitors view on our Services and how long visitors are viewing pages on the Services. Performance/Analytical Cookies also help us measure the performance of our advertising campaigns in order to help us improve our campaigns and the Services’ content for those who engage with our advertising.

  • Functionality cookies. These are used to record your choices and settings regarding our Services, maintain your preferences over time and recognize you when you return to our Services. Functional Cookies enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

  • Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

Cookie Name Publisher Purpose More Information
_ga Google Analytics Analytical/Performance Google Analytics Cookie Usage on Websites
_ga_SLQJ0QDKR0 Google Analytics Analytical/Performance Google Analytics Cookie Usage on Websites
_ga_SLQJ0QDKR0 Google Analytics Analytical/Performance Google Analytics Cookie Usage on Websites
crumb Folio Analytical/Performance This cookie is used in order to recognise a computer when a user visits our website. It also prevents cross-site request forgery. (Expires when the user browsing session ends).
ss_cvr Folio Analytical/Performance This cookie is used to identify a unique user for website usage analysis. The value assigned is a random GUID and no personally identifying information is associated with this cookie.
ss_cvt Folio Analytical/Performance This cookie is used to identify a user’s session for website usage analysis. The value assigned is the timestamp of the initial page view for a session and no personally identifying information is associated with this cookie.
auth Folio Strictly necessary/Functionality Stores your user's session token while logged in to Folio's website.
accountId Folio Strictly necessary/Functionality Stores your user's account ID while logged in to Folio’s website.
redirectPath Folio Strictly necessary/Functionality Stores a path the user should be redirected to after signing in.
ss_cookieAllowed Folio Strictly necessary/Functionality Stores a flag when the user has accepted the cookie policy.

Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies

You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including strictly necessary cookies) you may not be able to access all or parts of our site.

Except for essential cookies, all cookies will expire after 2 years.

To find out more information about Cookies, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org or https://ico.org.uk/for-the-public/online/cookies if you are located in the European Union.

Data Security and Retention

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.

We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services. In some cases, we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

Unfortunately, the transmission of information, including Personal Data, via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to the Company’s Site. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Site.

Personal Data of Children

As noted in the Terms of Service, we do not knowingly collect or solicit Personal Data about children under 18 years of age; if you are a child under the age of 18, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 18 years of age, we will delete that information as quickly as possible. If you believe that a child under 18 years of age may have provided Personal Data to us, please contact us at support@foliotravel.com.

California Resident Rights

California Civil Code Section 1798.83 permits residents of the State of California to request from certain businesses with whom the California resident has an established business relationship a list of all third parties to which the business, during the immediately preceding calendar year, has disclosed certain personally identifiable information for direct marketing purposes. We are required to respond to a customer request only once during any calendar year. To make such a request you should contact the Company at the information provided below. In your request, please attest to the fact that you are a California resident and provide a current California address for our response. Please be aware that not all information sharing is covered by the California Privacy Rights requirements and only information sharing that is covered will be included in our response.

In order to submit such a request, please contact us at support@foliotravel.com.

Other State Law Privacy Rights 

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by contacting us at support@foliotravel.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account. [Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.]

European Union Data Subject Rights

EU Residents

If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway or Iceland, you may have additional rights under the EU General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below.

Personal Data Use and Processing Grounds

The “Our Commercial or Business Purposes for Collecting Personal Data” section above explains how we use your Personal Data.

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

  • Contractual Necessity: We process the following categories of Personal Data as a matter of “contractual necessity”, meaning that we need to process the data to perform under our Terms of Service with you, which enables us to provide you with the Services. When we process data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such data.

    • Profile or Contact Data

    • Payment Data

  • Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties:

    • Device/IP Data

    • Web Analytics

    • Support requests and conversations

    • We may also de-identify or anonymize Personal Data to further our legitimate interests.

  • Examples of these legitimate interests include:

    • Providing, customizing and improving the Services.

    • Marketing the Services.

    • Corresponding with you.

    • Meeting legal requirements and enforcing legal terms.

    • Completing corporate transactions.

  • Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.

  • Other Processing Grounds: From time to time, we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.

EU Data Subject Rights

The Company is committed to making you fully aware of all of your data protection rights. Every User is entitled to the following:

The right to access - You have the right to request from the Company copies of your personal data. We may charge you a small fee for this service.

The right to rectification - You have the right to request that the Company correct any information you believe is inaccurate. You also have the right to request the Company to complete information you believe is incomplete.

The right to erasure - You have the right to request that the Company erase your personal data, under certain conditions.

The right to restrict processing - You have the right to request that the Company restrict the processing of your personal data, under certain conditions.

The right to object to processing - You have the right to object to the Company’s processing of your personal data, under certain conditions.

The right to data portability - You have the right to request that the Company transfer the data collected to another organization, or directly to you, under certain conditions.

You have the right to lodge a complaint about Folio’s practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.

If you make a request, the Company has one month to respond to you. If you would like to exercise any of these rights, please contact us at the information provided below.

Transfers of Personal Data

The Services are hosted and operated in the United States (“U.S.”) through Folio and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Folio in the U.S. and will be hosted on U.S. servers, and you authorize Folio to transfer, store and process your information to and in the U.S., and possibly other countries. You hereby consent to the transfer of your data to the U.S. pursuant to the data processing agreement located at, which incorporates standard data protection clauses promulgated by the European Commission, a copy of which can be obtained at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32010D0087.

Changes to this Privacy Policy

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time, but we will alert you to any such changes by placing a notice on the Folio Site, by sending you an email and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices and the Privacy Policy will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.

How To Contact The Appropriate Authorities

Should you wish to report a complaint or if you feel that the Company has not addressed your concern in a satisfactory manner, you may contact your local Data Protection Authority.

Click here for a list of jurisdictions, together with their respective Data Protection Authority and related contact information.

Contact Information 

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at support@foliotravel.com.