Thrill Seekers

Privacy Policy

This policy explains what personal information Thrill Seekers Adventures collects, why it is used and the choices available to you.

Effective September 19, 2026

1. Who is responsible for your information

Thrill Seekers Adventures, Costa Rica, with registered address at Puntarenas, Golfito, Costa Rica, trading as Thrill Seekers Adventures, is responsible for deciding how personal information is used for the activities described in this Privacy Policy. For privacy questions or to exercise a right, contact experience@thrillseekerscr.com or WhatsApp +506 7249-3355. To protect travelers, we may need to verify identity before completing a request. This Policy applies to information collected through the TSA website, booking and request forms, email, WhatsApp, payment and voucher flows, traveler forms, Journey operations, surveys, and direct interactions with our team. A provider that collects information for its own purposes may act as a separate responsible party under its own privacy notice.

2. Information we collect

Depending on the service, we may collect: Identity and contact information, such as name, preferred name, email, telephone number, country of residence, date of birth, and identification or passport details when required. Booking and traveler information, such as selected product, travel dates, group members, rooming, pickup and accommodation details, preferences, communications, requests, confirmations, vouchers, and attendance. Payment and transaction information, such as billing details, amount, currency, payment status, refund status, and transaction reference. Full card details are generally handled by the payment provider and are not intended to be stored by TSA. Safety and special-requirement information, such as allergies, dietary needs, accessibility needs, relevant health information voluntarily or necessarily provided, emergency contacts, and incident information. Journey insurance information, such as insurer, policy number, coverage dates, destination coverage, emergency-assistance contact, and confirmation of relevant coverage. We request only the information reasonably needed to verify the Journey requirement or respond to an incident. Travel-document information where required for transport, lodging, permits, border crossings, or supplier reservations. Website and device information, such as IP address, device and browser information, pages visited, referral source, cookie or similar identifiers, and basic interaction or security logs. Feedback and media, such as reviews, survey answers, complaints, photographs, or videos. Marketing consent is handled separately from operational collection. Information supplied by another person, such as the lead traveler, family member, company, travel advisor, or emergency contact. The person supplying it must be authorized to do so. Please provide only information relevant to the booking. Do not send medical records, full payment-card details, or copies of identity documents unless TSA specifically requests them through an appropriate channel.

3. Why we use it

We use personal information to: Respond to inquiries, prepare quotations, check availability, create and manage bookings, collect payment, issue confirmations and vouchers, and provide customer support. Deliver and coordinate Journeys, Day Thrills, transfers, add-ons, accommodation, activities, meals, and other confirmed services. Communicate operational information, including changes, meeting instructions, preparation details, safety notices, and emergency communications. Confirm eligibility, accommodations, insurance, dietary requirements, and safety-related needs. Prevent fraud, protect accounts and systems, keep business and transaction records, resolve disputes, and enforce our terms. Comply with legal, tax, accounting, consumer-protection, public-health, immigration, safety, and lawful authority requirements. Improve our services, website, traveler experience, provider performance, and internal processes using appropriate and proportionate information. Send optional marketing only when permitted by law. You may unsubscribe at any time without affecting a booking. Use photographs, testimonials, or identifiable media for marketing only with separate permission where required. Where international privacy laws require a legal basis, the basis may include performance of or steps toward a contract, compliance with law, consent, protection of vital interests, and legitimate interests that do not override the individual’s rights. Consent may be withdrawn for future processing, but withdrawal does not affect lawful processing already completed or information still required for a contract, safety, or legal obligation.

4. When information is shared

We share only information reasonably necessary for the stated purpose. Recipients may include: Activity operators, guides, Thrill Leaders, accommodation providers, transport companies, restaurants, and other suppliers needed to deliver a booking. Payment processors, banks, invoicing services, and fraud-prevention providers. Website hosting, cloud storage, booking, customer-support, communications, analytics, email, and business-software providers acting under appropriate arrangements. Insurers, medical responders, emergency services, consular authorities, public authorities, or family and emergency contacts when reasonably necessary for safety or legal obligations. Professional advisers, auditors, accountants, lawyers, and authorities where legally required or necessary to establish, exercise, or defend rights. A successor or transaction partner in a legitimate business reorganization, merger, financing, or sale, subject to appropriate confidentiality and legal protections. TSA does not sell personal information. We do not allow suppliers to use booking information for unrelated marketing unless the traveler separately agrees or independently enters into a relationship with that supplier.

5. International processing

TSA is based in Costa Rica, travelers may live in other countries, providers may operate in the destination country, and technology vendors may process information in multiple locations. When information is transferred or made accessible internationally, we take reasonable steps to use service providers, contracts, access controls, and other safeguards appropriate to the information and applicable law. Laws in a receiving country may differ from those in the traveler’s country. Where the EU GDPR, UK GDPR, or another cross-border transfer regime applies, TSA will use an available lawful transfer mechanism or applicable exception. Travelers may contact us for information about the safeguards relevant to their request.

6. Retention

We keep personal information only for as long as reasonably necessary for the purpose collected, including service delivery, traveler support, safety, dispute resolution, fraud prevention, and legal, tax, accounting, insurance, and recordkeeping obligations. Retention depends on the type of information and the booking. For example: Inquiry and unconfirmed-request information is retained only while reasonably useful for responding, follow-up, consented marketing, or resolving a related issue. Confirmed booking, payment, invoice, and contractual records may be retained for the period required by Costa Rican law and applicable limitation periods. Operational health, accessibility, insurance, and emergency information is restricted and deleted or anonymized when it is no longer needed for the Journey, incident response, legal claim, or required recordkeeping. Security logs, cookie data, and analytics information are retained according to the relevant tool settings and legitimate security or analysis needs. Information subject to a complaint, chargeback, investigation, litigation hold, or legal requirement may be kept until the matter is resolved. When retention is no longer justified, information is deleted, anonymized, or securely isolated as appropriate.

7. Your choices and rights

Subject to applicable law and reasonable identity verification, you may ask TSA to: Confirm whether we process your personal information and provide access to it. Correct inaccurate or incomplete information. Delete information that is no longer lawfully required. Withdraw consent for future processing where consent is the basis. Stop direct marketing. Object to or request restriction of certain processing where applicable. Receive or transfer certain information in a portable format where applicable. Some requests may be limited where information must be retained to deliver a booking, protect another person, comply with law, preserve evidence, or establish or defend legal rights. We will explain the reason when a request cannot be fulfilled in full. Costa Rican data-protection complaints may be presented to the Agencia de Protección de Datos de los Habitantes (PRODHAB). Travelers may also have the right to contact the competent authority in their country where another privacy law applies.

8. Security

TSA uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access restrictions, authentication, secure providers, staff controls, backups, monitoring, and procedures for responding to suspected incidents. No website, email, messaging service, payment system, or data transmission is completely secure. Travelers should avoid sending sensitive information through unsecured channels, protect their devices and accounts, and tell us promptly if they believe booking information has been compromised. If a personal-data incident creates a notification obligation, TSA will notify affected individuals and authorities as required by applicable law.

9. Analytics, cookies and external links

The website may use strictly necessary cookies or similar technologies for security, basic operation, preferences, forms, and booking functions. With consent where required, it may also use analytics or marketing technologies to understand website use and improve communications. A cookie banner or preference tool will identify available categories and allow non-essential choices where required. Disabling certain technologies may affect website features. The actual cookie notice and settings shown on the website control which optional tools are active. The website may link to provider, payment, map, social-media, or other third-party services. Those services control their own privacy and cookie practices. Travelers should review the notice presented by the relevant third party.

10. Children and policy updates

A person under 18 may not independently make a booking unless applicable law and the product expressly allow it. Information about a minor must be supplied or authorized by a parent or legal guardian. TSA collects only the minor’s information reasonably needed for booking, safety, eligibility, or legal compliance. We may update this Privacy Policy when our services, technology, providers, or legal obligations change. The current version will be posted with its effective date. If a change materially affects how information from an existing confirmed booking will be used, TSA will provide additional notice when required.