Privacy Policy
Privacy Practices
Last updated: July 15, 2026
Xperium Adventure Ltd. ("Xperium," "we," "us," or "our") provides a marketplace and community platform for discovering, creating, advertising, discussing, and booking activities. This Privacy Policy describes how Xperium collects, uses, discloses, retains, and protects personal information when you access or use Xperium.
This Privacy Policy applies to our websites, applications, account tools, public profiles, search/maps, listings, booking and payment flows, messages, support, reports, reviews, notifications, moderation tools, and related services. It should be read together with our Terms of Service. Nothing in this Privacy Policy limits Xperium's ability to collect, use, disclose, preserve, or retain information where permitted or required by applicable law, payment-network rules, legal process, safety obligations, fraud-prevention needs, or the establishment, exercise, or defence of legal claims.
1. Privacy Summary
This summary is provided for convenience only and is qualified in full by the remainder of this Privacy Policy:
- Xperium collects account, profile, listing, booking, payment, support, message, review, report, device, usage, and security information needed to operate Xperium.
- Public content such as listings, host profiles, Event pages, Meet Up pages, public comments, reviews, and public discovery markers may be visible to anyone.
- Stripe processes payment cards, Connect onboarding, payouts, refunds, disputes, and related compliance information.
- Xperium admins/support may review relevant records and messages for support, safety, refunds, payouts, disputes, incidents, fraud prevention, moderation, and legal compliance.
- Optional email notification settings do not stop required account, security, booking, payment, payout, support, legal, policy, or safety notices.
- Account deletion removes sign-in access and anonymizes public identity, but Xperium preserves required operational, transactional, audit, moderation, tax/accounting, support, security, and legal records.
- Xperium does not sell personal information for money and does not currently share personal information for cross-context behavioral advertising.
2. Who Controls Your Information
Xperium Adventure Ltd. is responsible for the personal information described in this policy. Some third parties, such as Stripe, social login providers, map providers, and external Event or ticket sites, may independently control information they collect when you use their services. Their own terms and privacy policies apply to those services.
3. Personal Information We Collect
Depending on how you use Xperium, Xperium may collect the following categories of personal information:
- Account identifiers and contact information: name, email, phone number, profile slug, user ID, avatar, activation status, account status, account roles, pending email changes, email confirmation tokens, activation records, and terms acceptance records.
- Authentication and security information: password hashes, remember tokens, session identifiers, login method, linked social providers, provider email verification status, last login metadata, IP address, browser/device information, security logs, CSRF tokens, and password reset or account-claim records.
- Host eligibility and payout setup information: date of birth, age eligibility, Canadian address, phone number, country, province, postal code, host company, short and long host descriptions, host terms acceptance, Stripe Connect account status, payout readiness, payout freeze status, and related Host contact records.
- Profile and public content: public display name, public profile settings, profile text, host bio, photos, host credentials, credential snapshots, Experience listings, Event listings, Meet Up plans, public comments, reviews, host responses, public ratings, report snapshots, and other content you choose to submit.
- Experience and listing information: titles, descriptions, categories, locations, coordinates, schedules, itinerary items, add-ons, prices, fees, availability windows, guest fit and safety details, accessibility summaries, language information, guest requirements, meeting instructions, parking/transit notes, late-arrival rules, weather plans, cancellation thresholds, FAQs, images, publish status, and host responsibility attestations.
- Event information: organizer attribution, public venue/location details, date/time, visitor-readiness details, accessibility and amenity fields, informational entry-fee details, external organizer links, timelines, FAQs, media, publish state, and moderation state.
- Meet Up information: created Meet Ups, editor relationships, going responses, activity type, public location name and notes, what-to-bring notes, planner notes, cancellation notes, discussion comments, hidden-comment state, comment reports, and resolved @ mentions.
- Private planning information: Experiences, Events, Meet Ups, and Spots you add to Wanna Do, including when you saved or removed them. These private choices are separate from bookings, reservations, tickets, and Going responses.
- Booking and reservation information: booking requests, reservations, booking IDs, dates, times, quantities, spot counts, add-ons, prices, totals, statuses, cancellation policies, cancellation/refund requests, disputes, incidents, check-in or attendance evidence if launched, disclosure snapshots, acknowledgment text/version/time, and related Host/Guest records.
- Payment, refund, payout, and billing information: payment records, payment status, selected saved-card references, card brand and last four digits, expiration month/year, billing name, Stripe customer/payment/charge/refund/payout identifiers, refund records, payout records, invoice records, failure reasons, chargeback/dispute information, and payment metadata. Full card numbers and bank-account details are handled by Stripe and do not directly pass through Xperium's servers in normal card or Connect flows.
- Messages and support information: message threads, message bodies, message metadata, participants, read/unread state, hidden/left conversation state, support context, support subject, support messages, support workflow status, user-visible resolution notes, assignment and priority metadata, and internal support notes.
- Reviews, reports, and moderation information: review text, star ratings, host responses, report reasons, flag snapshots, moderation decisions, moderation logs, restriction records, admin reasons, audit events, and account health or trust signals used for review.
- Search, map, and location information: listing locations, shared location records, public location labels, coordinates for public discovery markers, selected places, geocoder results, timezone derived from location, search text, filters, categories, query parameters, and approximate location context when you use location-based features.
- Device, usage, diagnostics, and cookies: IP address, browser type, device type, operating system, referral URL, pages viewed, timestamps, clicks or feature use, session data, cookies, local storage, error logs, performance data, and diagnostic information.
- Communications: emails, in-app notifications, contact-form submissions, support requests, activation emails, password reset emails, payment notices, booking notices, payout notices, legal/policy notices, marketing/newsletter preferences if launched, and optional notification preferences.
- Sensitive information you provide or create: date of birth for Host eligibility, precise meeting instructions after booking, accessibility or health-related details if you include them in listings/messages/support evidence, incident/dispute evidence, safety complaints, and legal or emergency information. You should avoid submitting sensitive information unless it is necessary for the applicable feature or support issue.
4. Sources Of Information
Xperium collects information from:
- You: when you create an account, set up a Host profile, create listings, book, pay, message, review, report, request support, update settings, or otherwise use Xperium.
- Other users: when they message you, book with you, host you, review you, report content, submit support evidence, mention you, or interact with your listings.
- Your device and browser: through logs, cookies, sessions, security tools, usage events, and diagnostic data.
- Service providers: including Stripe, email providers, hosting/storage providers, map/geocoding providers, search providers, analytics/logging providers, and security tools.
- Social login providers: if you use Google, Facebook, Apple, Google One Tap, or another launched provider.
- Public or legally available sources: when needed for safety, fraud prevention, compliance, support, dispute handling, or legal claims.
5. How Xperium Uses Personal Information
Xperium uses personal information to:
- create, authenticate, activate, secure, and maintain accounts;
- process registrations, email changes, password resets, social login, social account linking/unlinking, account claims, and account deletion;
- provide public profiles, host profiles, privacy settings, notification settings, security settings, login-method settings, account-data export, and account deletion previews;
- provide listings, search, discovery, maps, categories, host discovery, public pages, Events, Meet Ups, Experiences, and related filters;
- remember Experiences, Events, Meet Ups, and Spots you privately add to Wanna Do;
- enable booking requests, reservations, checkout, saved cards, scheduled payments, payment retries, cancellations, refunds, disputes, incidents, payouts, add-ons, stored disclosures, and acknowledgments;
- send required account, activation, password, security, booking, payment, refund, payout, support, safety, policy, and legal notices;
- send optional emails such as booking confirmations, booking cancellation notices, review emails, host-response emails, reservation reminders, and unread-message digests when your preferences allow them;
- support messaging, support conversations, Host Inbox features, quick replies, read/unread state, hidden conversation recovery, support context, and admin support workflows;
- moderate reviews, host responses, Meet Up comments, listings, reports, flags, accounts, and public content;
- investigate reports, safety issues, fraud, abuse, chargebacks, payment misuse, policy violations, disputes, incidents, refund requests, and payout issues;
- freeze, release, prevent, reverse, or adjust payouts and refunds when needed for support, fraud prevention, compliance, or risk management;
- enforce the Terms, apply account restrictions, prevent misuse, and protect users, Xperium, payment partners, venues, and the public;
- operate, troubleshoot, test, analyze, maintain, secure, and improve Xperium;
- generate audit events, support records, tax/accounting records, receipts, internal reports, and operational evidence;
- comply with legal, regulatory, tax, accounting, law-enforcement, payment-network, insurance, and dispute-resolution obligations; and
- establish, exercise, or defend legal claims.
6. Legal Bases Where Required
Where a legal basis is required, Xperium processes personal information because:
- Contract: processing is necessary to provide Xperium, accounts, bookings, payments, support, and other requested services.
- Consent: you consented to optional processing, such as certain optional communications, account settings, or user-submitted content.
- Legitimate interests: processing is needed to operate, secure, improve, enforce, and protect Xperium, users, payment integrity, and the public.
- Legal obligations: processing is needed for tax, accounting, payment, regulatory, court, law-enforcement, consumer protection, privacy, or other legal duties.
- Vital interests and safety: processing is needed to protect health, safety, or emergency interests.
- Legal claims: processing is needed to establish, exercise, investigate, settle, or defend claims.
6A. Consent, Withdrawal, And Required Processing
Where Xperium relies on consent, consent may be express or implied depending on the context and applicable law. By submitting information, creating content, using a feature, completing checkout, saving a payment method, messaging, requesting support, or enabling an optional setting, you consent to the processing reasonably necessary for that feature or request.
You may withdraw consent where withdrawal is legally available, but withdrawal does not affect processing that already occurred, processing required to complete pending transactions, processing based on another legal basis, or records Xperium must retain for legal, security, payment, tax/accounting, safety, fraud-prevention, dispute-resolution, or platform-integrity reasons. Withdrawing consent may prevent Xperium from providing some features.
Xperium treats sensitive information, payment-related information, precise meeting/location details, support/dispute evidence, safety reports, and account-security information as higher-risk information and limits use and access based on operational need, legal requirements, payment requirements, support requirements, safety, and fraud-prevention needs.
7. How Information Is Shared
Xperium may disclose personal information as follows:
- With the public: public profiles, host information, public listings, Event details, Meet Up details, public comments, review content, host responses, public ratings, images, public discovery markers, and public location labels may be visible to anyone.
- Between Hosts and Guests: booking, request, reservation, disclosure, acknowledgment, cancellation, refund, add-on, message, support context, and relevant profile information may be shared with the Host, Guest, or related participants as needed to manage the activity.
- With Meet Up participants and viewers: public Meet Up details and discussion comments are visible publicly. Going counts are visible, but attendee names are not public in the launch version.
- Your private Wanna Do list: Listings you save to Wanna Do are not shared with organizers or planners as interest, an RSVP, attendance, a booking, or a ticket record. Authorized Xperium admins/support may access these records only when needed for account support, security, legal compliance, or platform operations.
- With organizers and external sites: if you click an Event link or external organizer link, the third-party site may receive information from your browser and your interactions with that site.
- With admins and support: authorized Xperium admins/support users may access account, profile, listing, booking, payment, refund, payout, message, support, report, dispute, incident, review, moderation, audit, restriction, and security information when needed for operations.
- With payment providers: Stripe and related payment partners receive information needed for card setup, payment processing, scheduled charging, refunds, disputes, chargebacks, fraud checks, Connect onboarding, tax/payment compliance, and payouts.
- With infrastructure providers: hosting, database, storage, queue, email, logging, analytics, security, search, map, geocoding, and support providers may process information for Xperium.
- With social login providers: if you use a launched social login provider, information is exchanged as needed to authenticate, verify email, link, unlink, or secure your account.
- With professional advisers: lawyers, accountants, auditors, insurers, security consultants, and other advisers may receive information when needed for business, legal, security, insurance, or compliance reasons.
- With authorities and other parties for legal or safety reasons: Xperium may disclose information to courts, regulators, law enforcement, emergency responders, payment networks, banks, insurers, venues, or other parties when Xperium believes disclosure is required or appropriate for legal compliance, safety, fraud prevention, enforcement of our Terms, or protection of rights.
- Business transactions: information may be transferred as part of a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction.
8. Public Content And Visibility Choices
Some Xperium features are public by design. Public profile pages, Host profiles, published Experiences, public Events, public Meet Ups, public discussion comments, public reviews, Host responses, public ratings, images, offering counts, and discovery results may be indexed or viewed by other users or the public.
Privacy settings exposed in the Platform are intended to control only the behaviors described by those settings. For launch, profile visibility, profile experience visibility, and Host bio visibility are enforceable controls. Some visibility may remain available when active public hosting content requires it.
You should not submit personal, sensitive, confidential, or third-party information in public fields unless you intend that information to be public and have all rights and permissions required to share it.
9. Payments, Stripe, And Financial Data
Stripe processes payment cards, saved payment methods, Connect onboarding, identity or compliance information, bank-account details, payment authorizations, captures, scheduled charges, refunds, disputes, chargebacks, transfers, and payouts. Xperium stores payment records and Stripe identifiers needed to operate bookings, refunds, payouts, support, audit, accounting, and compliance workflows.
Full card numbers, CVC codes, and bank-account numbers are handled by Stripe in normal card and Connect flows and do not directly pass through Xperium's servers. Xperium may store card brand, last four digits, expiration month/year, billing name, Stripe references, payment status, refund status, payout status, and related metadata.
Stripe may independently collect and process information under its own terms and privacy policies. Hosts should review Stripe's Connect terms and privacy information.
10. Messages, Support, Disputes, And Moderation Review
Xperium messages are not guaranteed to be private from Xperium. Xperium may review messages and related records when needed for support, safety, refunds, payouts, disputes, incidents, moderation, fraud prevention, legal compliance, or enforcement of the Terms.
Support conversations may be linked to bookings, booking requests, reservations, Experiences, reviews, related users, or other context. Admin/support users may see the related context when handling the support issue.
Internal admin notes, trust signals, audit logs, and internal risk assessments are for Xperium operations and may not be included in user-facing messages or account exports where they contain internal, privileged, security-sensitive, fraud-prevention, or third-party information.
11. Cookies, Sessions, Analytics, And Similar Technologies
Xperium uses cookies, sessions, local storage, pixels, logs, and similar technologies to keep you signed in, secure the site, remember preferences, operate checkout and maps, prevent fraud, understand usage, diagnose errors, test features, and improve Xperium.
Examples include session cookies, security cookies, CSRF tokens, preference cookies, remember-me tokens, analytics or diagnostic tools, and browser storage used by interactive features. You can control cookies through your browser, but required features may not work without them.
Xperium does not currently sell personal information for money or share personal information for cross-context behavioral advertising. If Xperium later launches advertising or tracking practices that legally require an opt-out, Xperium will update this Privacy Policy and provide the required choice mechanism. Xperium does not currently respond to browser "Do Not Track" signals. Where legally required, Xperium will honor recognized opt-out preference signals for practices to which those signals apply.
12. Notifications And Communications
You can control launched optional email notifications in settings. Required account, security, activation, password, booking, payment, payout, support, safety, policy, legal, and deletion-blocker notices may still be sent even if you opt out of optional emails because they affect access, money, safety, legal rights, or platform operations.
In-app/database notifications may remain required unless Xperium launches a specific preference for them. Xperium may also send administrative notices about changes to these policies or the Platform.
Commercial electronic messages, if launched, will be sent with consent where required and will include legally required sender identification and unsubscribe mechanisms. Unsubscribing from marketing or promotional messages does not stop required transactional, security, booking, payment, payout, support, legal, policy, or safety messages.
13. Account Data Export
Xperium provides a self-service account-data export in settings. The export includes accessible account/profile/settings information, Host profile information, hosted experiences, booking/reservation summaries, reviews, message summaries, saved-card summaries, and login-method summaries.
The export redacts credentials, session data, provider IDs, raw OAuth payloads, Stripe/payment identifiers, and internal admin/support notes. The export is intended as a practical self-service record, not a complete copy of every backup, log, fraud-prevention record, privileged record, security record, or third-party processor record.
14. Correction And Account Settings
You can update many account, profile, privacy, notification, login, and Host contact details in settings. Some corrections, such as Host date of birth, Stripe Connect details, payment records, tax/accounting records, dispute records, or compliance records, may require support or may need to be corrected with a third-party provider such as Stripe.
Xperium may decline or limit correction requests where the requested change would be inaccurate, fraudulent, legally restricted, operationally unsafe, inconsistent with required records, or harmful to another person.
15. Account Deletion And Anonymization
Account deletion removes sign-in access and anonymizes public identity, but it does not erase every record. Xperium preserves booking, reservation, payment, refund, payout, receipt, tax, audit, moderation, support, dispute, incident, security, fraud-prevention, and legal records where needed for operations, compliance, safety, fraud prevention, or dispute resolution.
Deletion may be blocked until unresolved bookings, payouts, refunds, disputes, incidents, cancellation/refund requests, account restrictions, moderation issues, payment obligations, or support obligations are resolved. Hosts deleting accounts may have future hosted bookings canceled first and hosted listings removed from public access while historical records are preserved.
After deletion, public-facing identity is intended to appear as "Deleted member" or a similar anonymized label. Admin/support records may retain synthetic deleted-user identifiers, deletion timestamps, transactional snapshots, and records needed for support, tax/accounting, payments, refunds, payouts, safety, audit, or legal purposes.
16. Retention
Xperium keeps personal information for as long as needed for the purposes described in this policy. Retention periods vary by record type, sensitivity, legal requirements, operational need, and risk.
Examples of retained records may include:
- account records while your account is active and for a reasonable period afterward;
- unactivated account records until expiry, release, deletion, or purge workflows apply;
- booking, reservation, payment, refund, payout, receipt, invoice, tax/accounting, and audit records for operational, legal, financial, and dispute-resolution purposes;
- messages, support records, dispute records, incident records, reports, moderation logs, and restriction records while needed for support, safety, fraud prevention, legal claims, or platform integrity;
- public content while it remains published or while needed for historical, transactional, moderation, legal, or audit purposes;
- security logs, diagnostic logs, and session records for security, troubleshooting, fraud prevention, and operational needs; and
- backups until they rotate out under backup retention practices.
When information is no longer needed, Xperium deletes, anonymizes, aggregates, or otherwise disposes of it using reasonable measures.
17. Privacy Choices And Rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, object to, or withdraw consent for certain personal information. You may also have the right to complain to a privacy regulator.
Canadian users may contact Xperium about access, correction, consent, and privacy questions under applicable Canadian privacy law. California users may have rights to know/access, delete, correct, opt out of sale/share, limit use of sensitive personal information, and not be discriminated against for exercising rights. European Economic Area and United Kingdom users may have GDPR-style rights, including access, rectification, erasure, restriction, objection, portability, withdrawal of consent where processing is consent-based, and complaint rights.
Xperium may need to verify your identity before fulfilling a request. Some requests may be denied, delayed, or limited by legal, safety, fraud-prevention, payment, tax/accounting, dispute, moderation, security, privilege, third-party privacy, or operational obligations.
If an authorized agent submits a request for you where allowed by law, Xperium may require proof of authorization and may still need to verify your identity directly.
17A. Canadian Privacy Jurisdictions
Xperium is based in Saskatchewan and may be subject to Canada's federal private-sector privacy law, including PIPEDA, and to substantially similar or supplemental provincial private-sector privacy laws where applicable, including laws in Alberta, British Columbia, and Quebec. Users in other provinces and territories may also have rights under federal privacy law, provincial consumer protection law, sector-specific law, or other applicable law.
Nothing in this Privacy Policy is intended to limit a non-waivable privacy right available under the laws of Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, Quebec, Saskatchewan, Yukon, Northwest Territories, Nunavut, or applicable federal law.
Where a provincial privacy law requires additional notice, consent, access, correction, portability, de-indexing, transparency, governance, language, breach, or complaint-handling rights, Xperium will comply to the extent those requirements apply to Xperium and the relevant processing.
18. California Privacy Notice
This section applies only where California privacy law applies to Xperium and your information. In the past 12 months, depending on your use of Xperium, Xperium may have collected the categories of personal information described in Section 3, including identifiers, customer records, protected classification information where voluntarily provided or legally needed, commercial information, internet or network activity, geolocation-related information, audio/visual content such as photos you upload, professional or employment-related information if included in Host credentials or profiles, inferences related to platform safety or preferences, and sensitive personal information such as account login credentials, precise information you provide in support or disputes, date of birth, and payment-related information handled through Stripe.
Xperium collects, uses, discloses, and retains those categories for the purposes described in Sections 4, 5, 7, 9, 10, and 16. Xperium does not sell personal information for money and does not currently share personal information for cross-context behavioral advertising. Xperium does not knowingly sell or share personal information of people under 18.
California residents may request to know/access, delete, correct, opt out of sale/share if applicable, limit certain sensitive personal information uses if applicable, and not receive discriminatory treatment for exercising rights. Because Xperium does not currently sell or share personal information for cross-context behavioral advertising, Xperium does not currently provide a sale/share opt-out link.
19. International Transfers
Xperium is based in Canada, but Xperium users, service providers, payment processors, hosting providers, storage providers, email providers, analytics/logging providers, security providers, and other partners may be located in Canada, the United States, or other countries. Your information may be processed in jurisdictions with privacy laws different from those where you live.
Where required, Xperium uses reasonable safeguards appropriate to the service and information involved, which may include contractual protections, service-provider agreements, data-processing terms, transfer mechanisms, access controls, and security measures.
20. Security
Xperium uses administrative, technical, and physical safeguards designed to protect personal information. Measures may include access controls, authentication, password hashing, session security, CSRF protection, logging, monitoring, backups, provider security controls, and role-based access for admin/support features.
No method of transmission or storage is completely secure, and Xperium cannot guarantee absolute security. You are responsible for keeping your login credentials secure, using a secure device, signing out of shared devices, and notifying Xperium if you believe your account has been compromised.
20A. Security Incidents
If Xperium becomes aware of a security incident affecting personal information, Xperium will assess the incident and take steps it considers appropriate under the circumstances, which may include containment, investigation, remediation, recordkeeping, notification to affected individuals, notification to privacy regulators, notification to service providers, notification to payment partners, or cooperation with law enforcement where required or appropriate under applicable law.
Xperium may delay or limit incident notices where permitted or required by law, law-enforcement requests, security needs, fraud-prevention needs, or the need to protect other users or systems.
21. Children's Privacy
Xperium is not intended for children under 18. Xperium does not knowingly allow children under 18 to create accounts or submit personal information. If you believe a child provided personal information to Xperium, contact Xperium so the matter can be reviewed and appropriate action can be taken.
22. Third-Party Links And External Sites
Xperium may include links to external organizer sites, ticketing pages, venue pages, social sites, map services, payment services, and other third-party resources. Xperium does not control those third parties and is not responsible for their privacy practices, security, content, availability, payments, refunds, or decisions. You should review their terms and privacy policies before using them.
23. Automated Processing, Risk Signals, And Personalization
Xperium may use rules, flags, search ranking, filters, readiness checks, fraud signals, payment status, account status, and trust/safety signals to operate the Platform. These may affect search results, listing visibility, publish readiness, payment handling, payout holds, support queues, moderation review, account restrictions, and feature access.
At launch, behavioral trust signals are generally intended to flag accounts or records for admin/support review rather than make fully automated final decisions about serious account standing. Some hard safety, payment, fraud, legal, or compliance triggers may automatically block actions or hold funds where needed to protect users and the Platform.
24. Changes To This Policy
Xperium may update this Privacy Policy from time to time. Xperium will post the updated policy and change the "Last updated" date. If changes are material, Xperium may provide additional notice or require renewed acceptance through the product.
25. Contact Us
Questions or privacy requests can be sent through Contact Us or by mail to Xperium Adventure Ltd., Box 905, North Battleford, Saskatchewan, Canada S9A 2Z3, c/o DBF Law Office.