What changed
Policy Changelog
In plain language
When we change a policy in a way that affects your rights or obligations, we record it here and bump the version. Material changes prompt a re-acceptance on your next sign-in so nothing important slips by you.
We maintain this changelog so you can see what changed since you last accepted our Terms. We re-prompt you to accept the Terms only when the change is material — minor clarifications and typos don’t trigger a re-prompt.
v4 — 2026-10-07
Tours and experiences written into every policy, consent at tour checkout, an honest cookie banner, and corrections where our pages no longer matched what the site does.
- Tours are now covered.When you book a tour we are the seller and take the payment (in US dollars, with a separate service fee shown before you pay); an independent guide runs the tour. Refunds follow the guide’s cancellation policy shown at checkout, and a departure the guide cancels is refunded in full. See the Terms and the Cancellation Policy.
- No 14-day cancellation right on dated bookings.We used to say the EU 14-day withdrawal right applied; for tours booked for a specific date it does not. Your cancellation rights are the guide’s policy shown before you pay.
- You agree at tour checkout.Booking a tour, with or without an account, now asks you to agree to the Terms and the guide’s cancellation policy.
- Who is responsible on a tour. The Terms now say plainly that the guide, not PalapaVibez, runs the tour and carries the insurance for it — and that nothing excludes our liability for death or injury caused by our own negligence, or for fraud.
- Privacy Policy rewritten for tours.It now explains what your guide receives (name, phone, party size, notes and answers), how messages and reviews are handled, health notes you choose to give, our backups in the United States, and exactly what is sent to Meta when you consent. Deleting your account now also clears your answers to a guide’s questions. See the Privacy Policy.
- Cookie banner corrected. It used to say our analytics were cookie-less; Google Analytics and the Meta Pixel do set cookies. The banner now names them, EU visitors get a real on/off switch for them, and Google Analytics cookies now last 13 months instead of 2 years. See the Cookie Policy.
- Removed wording left over from on-site flight booking (passports, tickets), corrected “miles” to rewards points, removed the link to the EU online dispute platform (closed in July 2025), and fixed the guide agreement’s description of no-show payouts and of what guides can see.
v3 — 2026-05-28
Consumer-protection clarity, dispute resolution, tighter data-minimisation, and signup-time consent UX.
- New arbitration clause + class-action waiver. Disputes now go to binding individual arbitration under AAA Consumer Rules. You have 30 days from accepting these Terms to opt out by emailing [email protected] if you'd rather keep your right to sue in court.
- Marketing emails are now opt-in only. Deals, destination guides, and newsletter sends require an explicit tick at signup. Transactional emails (booking confirmations, receipts, password resets) are unaffected. Existing accounts keep their current preference; one-click unsubscribe is unchanged.
- Liability cap + force majeure clarified. Our total liability for any claim is capped at the greater of $100 or what you paid us in the prior 12 months. New force-majeure clause covers weather, strikes, pandemics, and similar disruptions outside our control.
- We are not a travel-insurance broker. Restated explicitly — we do not sell, advise on, or administer travel-insurance policies. Affiliate referrals to partners like SafetyWing are labelled as such and we may earn commission.
- New: Flight Passenger Rights. Plain-language summary of US DOT § 259 rules that apply to your flight — tarmac delays, denied boarding, baggage policies, lithium battery prohibition, schedule-change handling.
- New: Rewards Program Terms. Standalone terms for the Rewards beta — miles have no cash value, earning rules may change, accounts terminated for cause forfeit miles.
- Privacy Policy retention schedule. Per-category data retention is now spelled out in a table — search events 90 days, security events 90/180 days by severity, abandoned carts 90 days, newsletter signups 2 years, price history 30 days.
- Stronger hotel-guest data encryption. Hotel-guest first and last names now encrypted at rest alongside email and phone (previously plaintext alongside encrypted contact info).
- Removed: passport-document storage. We don't store passport scans, visa documents, or travel-insurance policies. Those stay on your devices or with the issuing party.
- Hotel checkout merchant-of-record disclosure. The payment step now shows a banner explaining LiteAPI is the payment processor — hotel charges appear on your card statement as LiteAPI or a related descriptor.
- New: 18+ confirmation at signup. Account creation now requires an explicit age-affirming checkbox; the value is stored per account (
User.confirmedOver18). Existing accounts unaffected — your earlier ToS acceptance already attested to 18+ eligibility. - Removed: unverified credential claims. "IATA-accredited", "Best price guaranteed", and "No Hidden Fees Guaranteed" language has been removed from customer copy and replaced with verifiable statements ("Transparent pricing", "Encrypted booking data").
v2 — 2026-05-27
A full refresh of the legal surface focused on giving shop customers clear, discoverable policies for e-commerce concerns the v1 Terms only mentioned in passing.
- New: Shipping Policy. Made-to-order timeline (3–7 production days), regional transit windows, customs and duties, address-accuracy responsibility, lost-in-transit treatment.
- New: Returns & Exchanges. Defect / damage / wrong-item claims covered for 30 days; no buyer's-remorse returns. EU 14-day withdrawal exemption restated cleanly.
- New: Sizing & Care. Garment measurements by family, fabric composition, wash instructions, colour-variance disclosure for direct-to-garment prints.
- New: Product Safety (GPSR). Manufacturer information and the EU responsible person (HONSON VENTURES LTD, Cyprus) for customers reaching us from the EU.
- New: Accessibility Statement. WCAG 2.2 AA target, what works today, known gaps, how to report a barrier.
- New: DMCA / IP Policy. Takedown notice procedure, designated agent, counter-notice, repeat-infringer policy.
- Updated: Terms of Service. Governing law clarified as the State of Oregon. The shop section was condensed and now cross-links to the new dedicated pages.
- Updated: Privacy Policy. Wording cleanup, no substantive changes to data flows. Self-service paths for Access (Art. 15) and Erasure (Art. 17) clarified.
- Updated: Cancellation Policy. Refocused on flights and hotels; the shop section moved to the dedicated Returns and Shipping pages.
- Updated: Cookie Policy. Cookie inventory refreshed;
pv.sessionnow correctly listed (was previously listed as__session). - New: shop checkout consent. Before payment, the shop checkout requires you to confirm you've read the Shipping, Returns, and Terms. The accepted version is recorded on the order.
- New: product-page disclosures. Every shop product now shows a "Made to order" pill, a colour-variance note, and direct links to the three policy pages relevant to that purchase.
v1 — 2026-04-13
Initial published version of the Terms of Service and Privacy Policy. Subsequent May 17, 2026 update added flight + hotel cancellation policies and GDPR mechanics. See git history for diff.
