Privacy Policy

This Privacy Policy explains how Kora (“Kora”, “we”, “us”) collects, uses, discloses, and safeguards personal information when you visit our website, sign up for an account, or use the Kora booking and operations platform (collectively, the “Services”). It applies to operators that subscribe to Kora and to guests who book through an operator powered by Kora.

Kora is a software-as-a-service platform. When you book with a business that uses Kora, that business is the merchant of record and the controller of your booking data; Kora processes that data on the operator's behalf as a service provider/processor. For Kora's own marketing site, account signups, billing, and product analytics, Kora acts as the controller.

1. Information we collect

We collect the following categories of information:

  • Account information — name, email address, password hash, organization name, role, and optional profile details supplied during signup or in account settings.
  • Operator business information — listings, resources (e.g. properties, vehicles, staff), schedules, pricing rules, brand assets, and other content operators upload to run their business.
  • Guest and booking information — names, email addresses, phone numbers, booking dates, number of guests, special requests, addresses (for mobile services), and messages exchanged with the operator.
  • Payment information — payment card details and payout details are collected and processed by Stripe; Kora receives transaction metadata (amounts, status, last 4 digits, card brand, billing country) but does not store full card numbers.
  • Device and usage data — IP address, browser type, device identifiers, referring/exit pages, timestamps, and product analytics about how the Services are used.
  • Cookies and similar technologies — strictly-necessary cookies for authentication and security, and optional analytics cookies where consent is required.
  • Communications — emails and SMS we send or receive, support tickets, and call recordings or transcripts where the AI Voice Agent is enabled by an operator and disclosed to callers.

2. How we use information

We use personal information to:

  • provide, maintain, and improve the Services and operate operator booking flows;
  • create accounts, authenticate users, and prevent fraud or abuse;
  • process payments, payouts, refunds, and platform fees through Stripe;
  • send transactional messages (booking confirmations, reminders, receipts, password resets);
  • send product, billing, and security notices to operators;
  • respond to support requests and enforce our terms;
  • generate aggregated, de-identified analytics to improve the Services;
  • comply with legal obligations and respond to lawful requests.

3. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Services and process bookings), legitimate interests (to secure the Services, prevent fraud, and improve our product), consent (for non-essential cookies and certain marketing communications), and compliance with legal obligations.

4. How we share information

We share personal information only as described below:

  • With operators — guest booking information is shared with the operator you booked with so they can fulfil and support your booking.
  • With service providers (sub-processors) — vendors that host, secure, and operate the Services, including Stripe (payments), Resend (email), Twilio (SMS), Vercel (web hosting), and Railway (application and database hosting). See our sub-processors page for the current list.
  • For legal reasons — to comply with applicable law, lawful requests from authorities, or to protect the rights, property, or safety of Kora, our users, or others.
  • In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

5. International transfers

Kora and our sub-processors may process personal information in the United States and other countries. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.

6. Data retention

We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Booking, payment, and tax records are typically retained for at least seven (7) years. Operators may delete or export data through in-product tools; some records may be retained in encrypted backups for a limited period before being overwritten.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS), encryption at rest for sensitive fields, role-based access controls, audit logging, and routine vulnerability monitoring. No system is perfectly secure; please use a strong, unique password and enable any available two-factor protections.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. You may also have the right to withdraw consent at any time and to lodge a complaint with a supervisory authority. If you booked with an operator, please contact that operator first; for Kora-controlled data, contact us using the details below.

9. California residents

California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and limit use of sensitive personal information, and the right not to be discriminated against for exercising those rights. We do not “sell” personal information or share it for cross-context behavioral advertising as those terms are defined under California law.

10. Children

The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, if changes are material, provide additional notice through the Services or by email.

12. Contact us

Questions about this Privacy Policy or our data practices? Please use the contact link in the footer or reach out through your operator dashboard.

See also our Terms of Use and sub-processors.