Effective date: October 9, 2026
Avatar Walk is a marketplace where Avatars host live walking tours from their phones and guests pay to watch and direct them. This policy describes what the platform actually collects, why, who else sees it, and how long it is kept. Two things it describes are easy to miss and are stated plainly here rather than buried: an Avatar's precise location is sent to Avatar Walk while they are hosting, and is shown to the guest who booked that walk while it is live (section 4), and Avatar Walk staff can watch any live session — you are told before a session starts that this may happen, and you are not told when it does (section 5).
This policy covers everyone who uses Avatar Walk: guests who book and watch sessions, friends they invite to watch with them (section 9), and Avatars who host them. Where a practice applies to only one of these, this policy says which.
Avatars are independent contractors, not employees. That does not change what is collected about them; it is spelled out because sections 4 and 5 describe collection that happens while an Avatar is working.
Creating an account stores your email address, a display name, and whether the account hosts tours. Passwords are handled by Firebase Authentication (Google) and are never stored by Avatar Walk. If you sign in with Google or Apple instead, those providers tell Avatar Walk your email address and name.
A profile photo is optional. When you upload one it is stored in Firebase Storage and is visible to other users wherever you appear — on a tour, in a chat thread, on a review you wrote, and in the admin console.
Avatars may also publish a bio, social links, specialties, the languages they guide in, and a city and country on their public profile. Everything in that profile is public by design.
Avatar Walk also records roughly when you last used the app, so staff can see how many accounts are still in use. This is a single date and time on your account that is overwritten each time, at most once an hour. No history is kept, and nothing records what you looked at, how long you stayed, or which pages you visited — the only thing stored is that you were here.
The people you chat with can see when you are online and when you have read their messages, unless you turn this off in Settings. While the app is open on your screen, it refreshes a separate "last active" time on your account about once a minute to show this; it too is overwritten each time, with no history kept. When you read a thread, the time you read it is stored on that conversation. Turning this off hides it from the people you chat with in the app; it does not erase read times already saved. Blocking someone also hides it from them. Avatar Walk's support team can always see when you are online and whether you have read a support message.
Applying to host collects your phone brand and model, whether you own a gimbal, and your city, state, ZIP or postal code and phone number. Your name, email address and profile photo are copied onto the application at the moment you submit it, because the review queue could not otherwise show an administrator who applied.
This information exists so a person can decide whether your equipment can carry the video of a paid live walk, and so support can reach you about a session in progress. Applications are read by Avatar Walk administrators and by you.
Once your application is approved, three things from it are shown publicly on your tours: that you are a verified host, your phone model, and whether you use a gimbal. They tell a client what the walk they are paying for will be filmed on. The languages you said you can guide a tour in are shown on your profile and tours too, until you change them in Edit profile. Nothing else on the application — your city, state, ZIP or postal code, phone number, or an administrator's comment — is ever shown to other users.
An administrator's decision, the reviewing administrator's identity, and any comment they wrote are stored on the application. The comment is shown to you when an application is rejected.
This section applies to Avatars only.
While you are hosting a live session, your device sends your location to Avatar Walk roughly every ten seconds. Avatar Walk uses it for three things: a real-time operations map of sessions currently in progress, so that staff can see where hosting is happening and respond if something goes wrong; the walk's live map, so that the guest who booked you can follow where you are while the walk is happening; and, when that guest drops a pin for you to walk to, checking the pin is within reach and working out walking directions to it. While a pin is set, your app and your guest's app each ask for directions from your current position, again every 75 metres or so you walk (section 11).
Specifically, and with no part of this softened:
Your browser will ask for location permission before any of this can happen, and you can withdraw that permission in your browser or device settings. Location is what the operations map and the walk's live map are built on, so withdrawing it means neither Avatar Walk nor your guest can see where a session in progress is taking place.
Avatar Walk staff can join and watch any live session while it is happening. This is done for safety, security and fraud prevention.
You are told in advance. Before a session begins, both the Avatar hosting it and the guest who booked it are shown a notice that the session may be monitored for safety and security, and have to acknowledge that notice to continue. Avatar Walk records that acknowledgement for each session.
You are not told when it happens. There is no on-screen indicator during a session and no notification at the moment a member of staff joins — not at the time, and not afterwards. Neither party ever learns that a particular session was watched.
That distinction is the whole of it: you know in advance that any session may be watched, and you do not know when any given session is being watched. Treat every live session as one Avatar Walk may be viewing at that moment.
Staff join as viewers only. They cannot send video or audio into a session, appear in the chat, or speak to either party.
Because the people in a session cannot see monitoring happening, the control on it is internal rather than visible: every time a member of staff is given access to watch a session, Avatar Walk writes an audit record of who they are, which session it was, and the reason they gave. Those records are not readable by any user, including the parties to the session.
Stated so this policy does not over-claim in either direction:
A booking stores who booked, which tour, how many minutes, the price agreed and the commission rates in force at that moment, the session's status and its timestamps. If you leave a note for the Avatar when booking, that note is stored on the booking and shown to the Avatar. If you have been reviewed as a guest, the booking also keeps your rating at that moment — your average and how many reviews it comes from — and shows it to the Avatar, so they can see it when deciding whether to accept.
The booking also keeps the time zone your device reports when you book, the language your app is set to, and the hometown on your profile if you have added one. The Avatar sees your hometown and what time it is for you — at the walk's start on the booking, and the current time during the walk — and your app's language when it differs from theirs, so they know whether to say good morning or good evening. Your exact location is never taken for this. Like the rest of the booking, these details can also be read by friends you invite to a watch party (section 9).
The destination pin. The guest can drop a pin for the Avatar to walk to only while the walk is live and its paid time has not run out. The current pin — its coordinates, who set it and when — is kept on the booking while the walk is live, both of you can see it, and either of you can remove it. When the walk ends, however it ends — either of you ends it, the time runs out, a safety stop, or the Avatar ends it early — the pin is deleted from the booking in the same step that ends the walk, and a pin dropped at that moment is refused rather than stored. If a walk is never formally ended (the timer and both apps fail to end it), an automatic job that runs once a day deletes its pin once the walk's time has been up for more than an hour, so no pin stays on a booking for more than about a day after the walk's scheduled end. Pins left on walks that ended before this change have been deleted as well. While the walk is live, friends the guest has invited to a watch party can read the booking record, pin included, although the app does not show them a map (section 9).
Gifts. When you buy a tour for someone, Avatar Walk stores a gift record: your account and name, the recipient's email address (and their account, once the gift is linked to one), the link's code, the tour and number of minutes, the price and commission rates at that moment, the amount paid and its Stripe identifiers, the note you write to the recipient, any brief you write for the Avatar, and the gift's status and dates. You cannot buy a gift for your own email address. The recipient's email address is used to find their Avatar Walk account, if they have one, so they can be told about the gift. If it does belong to an account, the gift is added to it at once and your gift list shows it as ready to book, so you can tell that the address has an account. Otherwise the gift is added to the account of whoever first opens the gift link while signed in — except you: opening your own link shows you what the recipient will see and does not accept it. Anyone else you pass the link to can accept it, so share it only with the person it is for.
No app or browser reads the gift record directly; Avatar Walk's servers read it and send each of you only your side of it. You are sent the tour, the minutes, the amount paid, the email address you typed, your note, the gift's status, any refund reason and its dates, and the gift link until someone accepts it. The recipient is sent the tour, the minutes, the amount paid, your name, your note, your brief for the Avatar, the status, any refund reason and the dates. Neither of you is sent the other's account identifier, and the recipient is not sent the email address you typed, the link's code, the Stripe identifiers or the commission rates.
When the gift is booked, the booking stores your name and your brief — it does not record who paid, and no older booking does either — and the Avatar is shown your name and your brief. Your name and brief on the booking can be read by everyone who can read that booking: the recipient, the Avatar and any friends the recipient invites to a watch party (section 9). The recipient can see your brief too before booking: it is sent to them from the moment the gift reaches them, and it is shown to them when they choose a time, so they can ask the Avatar for something different. If you start paying for a gift and do not finish, the gift record — with the recipient's email address, your name and your notes — is kept, although the gift is never sent. While you fill in the gift form, what you have typed — including the recipient's email address and your notes — is kept only in that browser tab, so it survives signing in. It is cleared when you go on to payment, and gone when the tab (or, in the app, the app itself) is closed.
Gifts when you delete your account. On gifts you bought, your name, your note, your brief for the Avatar and the recipient's email address are removed. A gift you had started paying for and not finished is cancelled with Stripe, so it can never be charged, and its email address is removed at once; if you had paid but the gift had not yet reached the recipient, the email address is kept only until it does — it is how the gift finds them — and removed then. On gifts you received, your email address is removed. On every booking a gift of yours paid for, including cancelled ones, your name and brief are removed. What stays, so that a gift you sent before leaving can still be accepted, booked, refunded or expire as normal: both people's account identifiers on the gift record (which, as above, neither person is sent), the link's code, the amounts and commission rates, the Stripe identifiers, the status and the dates. Stripe keeps its own record of the purchase, including your account identifier and the billing details you gave it, under its own policy. Notifications and emails already sent — such as the one telling the recipient who the gift is from — are not changed. If Avatar Walk cannot reach Stripe while deleting your account, the deletion stops before any gift is changed and can be tried again.
Card details are entered directly into Stripe and never reach Avatar Walk's servers or database. On Stripe's checkout page you also give Stripe your email address and billing details; Stripe includes them in the payment confirmation it sends Avatar Walk, but Avatar Walk does not store them. Avatar Walk gives Stripe your account identifier and what you are paying for; for a tip it also gives Stripe your account email address, so the checkout page is filled in, and your display name. Avatar Walk stores the Stripe payment identifiers so a charge, refund or payout can be matched to a booking or a gift. What Stripe does with your payment information is governed by Stripe's own privacy policy.
Avatars who take payouts connect a Stripe account. Stripe collects the identity and bank details it needs to pay them and to meet its own legal obligations; Avatar Walk stores the resulting account identifier, the payout status, and its own ledger of earnings, payouts and fees.
Private conversations. Messages between a guest and an Avatar are stored and readable by the two participants. Once sent, a message cannot be edited or deleted by either party — money changes hands on this marketplace and the record of what was agreed has to stay trustworthy for disputes.
Live chat. Chat during a live walk is visible to everyone watching that walk and is stored with your account identifier, display name and profile photo.
Reviews. A review stores your star rating, any category scores, your written text, and your display name and profile photo copied at the time of writing. Reviews are public.
Reports. If you report a profile, Avatar Walk stores who you reported, the reason, any detail you wrote, and your identity as the reporter. Reports are readable by administrators and are not shown to the person reported.
Support chats. A support chat stores your messages and Support's replies, the topic and the walk you attach, and your display name copied at the time of writing. It is readable by you and by Avatar Walk administrators, and by nobody else. Tickets sent before support chats existed (which stored your name and email address) were copied into your chat.
A guest who has booked a walk can invite up to four friends to watch it with them, free. This section covers what that means for the guest who invites, for the friends who join, and for the Avatar.
The invitation. Only the guest who booked can invite, from the time the booking is made until the walk ends. There is one link per booking. Avatar Walk does not send it to anyone: the guest shares it themselves, through their phone's share sheet, by opening Messages, WhatsApp or email with the link already written in, or by copying it. A friend has to sign in to an Avatar Walk account to accept — the same 18-and-over accounts as everyone else (section 14). Anyone holding the link can accept while places remain; no one approves each person. The guest can reset the link, after which the old one admits nobody new (friends already in stay in), and can remove any friend. Before accepting, someone signed in with the link is shown the Avatar's name and photo, the inviting guest's first name, the walk's status and scheduled time, and how many friends have joined. The Avatar cannot join the watch party for their own walk.
The link's preview. When the link is pasted into a messaging app, the app fetches a short preview from Avatar Walk: the inviting guest's first name, the tour's photo and city, and its date, time and length. Messaging apps that show the preview may keep their own copy of it. Once the link is reset or the walk is over, the preview no longer names anyone. The link itself reads like avatarwalk.com/party/sophia-madrid-7kq2xv9mwpt4h: the Avatar's first name and the tour's city, then a private code. Those words stay in the link wherever it has been sent, after a reset too.
What is stored about each friend. When a friend accepts, the booking keeps a record of them: their account identifier, their display name and profile photo as they were at that moment (“Guest” if they had no name), when they accepted, and when they were removed, if they were. The booking also keeps a count of how many friends are in, which the Avatar can see. The link's code is kept where only Avatar Walk's servers can read it. The guest who invited can read each friend's record: their account identifier, name and photo, and when they accepted or were removed. None of this is deleted when the walk ends, and deleting a friend's account does not remove it: the record, with the name and photo copied when they accepted, stays on the booking indefinitely, and messages they posted in the walk's chat keep the name and photo they were posted with (sections 12 and 13).
What friends can see. A friend who has been let in can read the whole booking record — including the guest's note to the Avatar, the price, the guest's rating, the guest's and the Avatar's account identifiers, any gift giver's name and brief (section 7) and, while the walk is live, the destination pin — and can read and post in the walk's chat. That access does not end when the walk ends; it lasts until the guest removes them. Friends are not given the Avatar's position: Avatar Walk's servers refuse it to them (section 4). They cannot read the other friends' records; inside the party they see the inviting guest's first name, and everyone else is labelled “Friend”. Anything a friend posts in the walk's chat carries their account identifier, display name and profile photo and is visible to everyone in the walk, the Avatar included (section 8).
Camera and microphone. During a live walk, joining the party turns on your camera and microphone — the microphone starts on — and sends them, through Agora, to the inviting guest and the other friends who have joined, and to nobody else. The Avatar does not see or hear the party call; from it they learn only how many friends there are, although anything a friend posts in the walk's chat reaches them as described above. A camera or microphone you switch off before joining is not sent. The camera preview shown before you join stays on your device. If you choose to watch only, or refuse the camera or microphone permission and then watch only, you are not in the party call at all and nothing of yours is sent.
Not recorded, and not watched by staff. The party call is not recorded, and staff monitoring (section 5) does not reach it. The walk itself is still subject to staff monitoring. The walk's chat, friends' posts included, is stored like any live chat (section 8).
Notification. When the walk starts, each friend who is in the party is sent one “Your watch party is live” notification — in the app, and by push and email subject to their own notification settings (section 10). Friends are not notified when they are removed or when the walk is cancelled.
Removal. When the guest removes a friend, the friend loses access to the booking and the chat at once, and is cut off from the party call within about ten minutes at most. The app stops showing them the walk at once, and Avatar Walk's servers refuse them any new access to its video, but video access already issued to them runs out only within 24 hours. A removed friend cannot rejoin that party, and can still see their own record, which says they were removed.
Availability. Avatar Walk can switch watch parties off, for everyone or for a particular guest. Doing so stops new invitations, the party call and the notification, but friends already let in keep their access to the booking and the chat until they are removed.
Avatar Walk sends in-app notifications about your bookings, payments, reviews, messages and equipment application, and about a watch party you are in going live (section 9). Email notifications are on by default and can be turned off in your settings; browser push notifications are off until you enable them and grant your browser's permission.
Enabling push stores a device registration token and your browser's user-agent string, so a stale registration can be identified. Turning push off deletes the registration.
Avatar Walk does not sell your information. It is shared with:
Other users see what the product shows them: your display name and profile photo, your public profile and tours if you host (with your phone model and gimbal, as described in section 3), your reviews, and messages you send. While you host a live walk, the guest who booked it also sees your exact position on the walk's map (section 4). If you buy someone a tour, the recipient sees your name, your note, the amount you paid and your brief, and the Avatar sees your name and your brief (section 7). If someone buys you a tour, they see the email address they typed, whether the gift has been added to an account — straight away if that address is yours — and whether it has been booked and taken. Neither of you is given the other's account identifier by the gift. If it goes unused for 90 days they are told it was refunded, and any refund on the walk — for minutes not used, or the whole amount if the Avatar does not turn up — goes back to their card.
If you join a watch party, the guest who invited you sees your account identifier, display name and profile photo, and the people in the party call see and hear you while your camera and microphone are on. The Avatar is not in the party call and is told only how many friends are in the party, but sees your name and photo on anything you post in the walk's chat (section 9).
Live location is deleted when the session ends, and Avatar Walk holds only the latest position at any moment before that. The guest's map keeps the recent path on their screen only while the walk is open. A destination pin is deleted from the booking when the walk ends, and in any case within about a day of the walk's scheduled end (sections 4 and 7).
Staff monitoring produces no recording, so there is no session footage to retain (section 6). Two records around it are kept: your acknowledgement of the pre-session monitoring notice, and the internal audit record written each time a member of staff is given access to watch. Both are kept as part of the session's history rather than deleted when the session ends, because a record of who watched what is only useful if it outlives the thing it describes.
Everything else — your account, bookings, gifts (the giver's name and both notes stay on the gift record, and the giver's name and brief on every booking it paid for, after the gift is used or refunded, until the giver deletes their account; the recipient's email address stays until either person deletes theirs; a gift that was started and never paid for is kept with the same details; section 7 sets out what deleting an account removes), payment records, messages, reviews, equipment application, reports and support chats (and the tickets sent before them) — is kept for as long as your account exists, and afterwards where a record is needed for accounting, tax, fraud or dispute purposes. Avatar Walk does not currently run an automatic deletion schedule for these records; deletion happens when you ask for it under section 13.
Watch-party records — each friend's record on a booking, with the name and photo copied when they accepted — are kept with the booking indefinitely, including after the friend deletes their account (section 9).
You can see and change most of your own information in the app: your profile and photo, your notification settings, your tours and availability if you host, your bookings, and your equipment application status.
You can delete your account yourself, from Profile. It asks you to confirm first, because it cannot be undone. To ask for a copy of your information or a correction — or for help with a deletion that did not complete — email Info@avatarwalk.com from the address on your account. Avatar Walk will confirm your identity before acting on a request made by email, since these requests are also the shape a takeover attempt takes.
Some things cannot be deleted on request. Messages are immutable once sent, so a conversation cannot be edited after the fact. A watch-party record — your account identifier, name and photo as they were when you accepted — stays on the booking of a walk you were invited to, and deleting your account does not remove it (section 9). Payment and payout records are kept where accounting, tax or anti-fraud obligations require them. Where a request cannot be met in full, Avatar Walk will say which part it could not do and why.
Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to or restrict certain processing and the right to complain to your local data protection authority. Use the same address to exercise them.
Avatar Walk is for adults. You must be at least 18 years old to use it, as a guest or as an Avatar, and the platform is not directed at children. Avatar Walk does not knowingly collect information from anyone under 18. If you believe a child has created an account, email Info@avatarwalk.com and the account and its information will be removed.
Access is enforced in the database itself rather than only in the interface: a user can read their own account, their own bookings, their own tickets and the conversations they are part of, and the collections holding payment ledgers, tours, notifications and live locations cannot be written by any client at all. Administrator status is granted out of band and cannot be self-assigned.
No system is perfectly secure, and Avatar Walk does not claim otherwise. If you find a problem, report it to Info@avatarwalk.com.
This policy describes what the platform does today. When the platform's behaviour changes — including if session monitoring, live location handling, or recording ever change — this policy is updated to match, and the effective date at the top changes with it. A policy that promises something the code does not do is worse than no policy.
Questions about this policy, or about anything in it, go to Info@avatarwalk.com.