Privacy Policy

Effective date: October 9, 2026

Avatar Walk is a marketplace where Avatars host live walking tours from their phones and guests pay to watch and direct them. This policy describes what the platform actually collects, why, who else sees it, and how long it is kept. Two things it describes are easy to miss and are stated plainly here rather than buried: an Avatar's precise location is sent to Avatar Walk while they are hosting, and is shown to the guest who booked that walk while it is live (section 4), and Avatar Walk staff can watch any live session — you are told before a session starts that this may happen, and you are not told when it does (section 5).

1. Who this applies to

This policy covers everyone who uses Avatar Walk: guests who book and watch sessions, friends they invite to watch with them (section 9), and Avatars who host them. Where a practice applies to only one of these, this policy says which.

Avatars are independent contractors, not employees. That does not change what is collected about them; it is spelled out because sections 4 and 5 describe collection that happens while an Avatar is working.

2. Account information

Creating an account stores your email address, a display name, and whether the account hosts tours. Passwords are handled by Firebase Authentication (Google) and are never stored by Avatar Walk. If you sign in with Google or Apple instead, those providers tell Avatar Walk your email address and name.

A profile photo is optional. When you upload one it is stored in Firebase Storage and is visible to other users wherever you appear — on a tour, in a chat thread, on a review you wrote, and in the admin console.

Avatars may also publish a bio, social links, specialties, the languages they guide in, and a city and country on their public profile. Everything in that profile is public by design.

Avatar Walk also records roughly when you last used the app, so staff can see how many accounts are still in use. This is a single date and time on your account that is overwritten each time, at most once an hour. No history is kept, and nothing records what you looked at, how long you stayed, or which pages you visited — the only thing stored is that you were here.

The people you chat with can see when you are online and when you have read their messages, unless you turn this off in Settings. While the app is open on your screen, it refreshes a separate "last active" time on your account about once a minute to show this; it too is overwritten each time, with no history kept. When you read a thread, the time you read it is stored on that conversation. Turning this off hides it from the people you chat with in the app; it does not erase read times already saved. Blocking someone also hides it from them. Avatar Walk's support team can always see when you are online and whether you have read a support message.

3. Becoming an Avatar: the equipment application

Applying to host collects your phone brand and model, whether you own a gimbal, and your city, state, ZIP or postal code and phone number. Your name, email address and profile photo are copied onto the application at the moment you submit it, because the review queue could not otherwise show an administrator who applied.

This information exists so a person can decide whether your equipment can carry the video of a paid live walk, and so support can reach you about a session in progress. Applications are read by Avatar Walk administrators and by you.

Once your application is approved, three things from it are shown publicly on your tours: that you are a verified host, your phone model, and whether you use a gimbal. They tell a client what the walk they are paying for will be filmed on. The languages you said you can guide a tour in are shown on your profile and tours too, until you change them in Edit profile. Nothing else on the application — your city, state, ZIP or postal code, phone number, or an administrator's comment — is ever shown to other users.

An administrator's decision, the reviewing administrator's identity, and any comment they wrote are stored on the application. The comment is shown to you when an application is rejected.

4. Live location while you are hosting

This section applies to Avatars only.

While you are hosting a live session, your device sends your location to Avatar Walk roughly every ten seconds. Avatar Walk uses it for three things: a real-time operations map of sessions currently in progress, so that staff can see where hosting is happening and respond if something goes wrong; the walk's live map, so that the guest who booked you can follow where you are while the walk is happening; and, when that guest drops a pin for you to walk to, checking the pin is within reach and working out walking directions to it. While a pin is set, your app and your guest's app each ask for directions from your current position, again every 75 metres or so you walk (section 11).

Specifically, and with no part of this softened:

  • It is precise. These are your actual coordinates, along with the accuracy, heading and speed your browser reports. They are not rounded, blurred or approximated. This is different from the location shown publicly on a tour's page and map, which is deliberately offset by a random distance of up to 200 metres so that strangers cannot find where you are standing.
  • It happens only during a live session. Your location is not collected between sessions, before one starts, or after one ends. Avatar Walk does not track you when you are not hosting.
  • Only the latest position is kept. Each update overwrites the previous one. There is one record per hosting Avatar and it holds a single point. No movement history, route, or trail is stored, so there is no record of where you walked — only where you were as of the most recent update. A destination pin a guest sets for you is kept on the booking only while the walk is live, and is deleted from it when the walk ends (section 7). During the walk, the guest's map also draws the path you have walked since they opened the walk, up to roughly your last half hour of walking. That path exists only on the guest's screen while they have the walk open; it is never sent back to or stored by Avatar Walk, and it is gone when they leave the page or the walk ends.
  • It is deleted when the session ends. The record is removed at that point and nothing about it is retained afterwards.
  • Staff see it, and so does the guest who booked you. The precise position is visible to Avatar Walk administrators through the internal operations map, and to the guest who booked the walk: their app receives your exact position, with the direction you are moving (when your device reports it) and how accurate the reading is, but not your speed, and shows your position on the walk's live map. The guest sees it only while the walk is live — not before it starts and not after it ends. It is not shown to anyone else, including anybody else watching the walk and friends the guest invites to a watch party (section 9), and it is not published in any collection or endpoint the public can read.

Your browser will ask for location permission before any of this can happen, and you can withdraw that permission in your browser or device settings. Location is what the operations map and the walk's live map are built on, so withdrawing it means neither Avatar Walk nor your guest can see where a session in progress is taking place.

5. Avatar Walk staff can watch live sessions

Avatar Walk staff can join and watch any live session while it is happening. This is done for safety, security and fraud prevention.

You are told in advance. Before a session begins, both the Avatar hosting it and the guest who booked it are shown a notice that the session may be monitored for safety and security, and have to acknowledge that notice to continue. Avatar Walk records that acknowledgement for each session.

You are not told when it happens. There is no on-screen indicator during a session and no notification at the moment a member of staff joins — not at the time, and not afterwards. Neither party ever learns that a particular session was watched.

That distinction is the whole of it: you know in advance that any session may be watched, and you do not know when any given session is being watched. Treat every live session as one Avatar Walk may be viewing at that moment.

Staff join as viewers only. They cannot send video or audio into a session, appear in the chat, or speak to either party.

Because the people in a session cannot see monitoring happening, the control on it is internal rather than visible: every time a member of staff is given access to watch a session, Avatar Walk writes an audit record of who they are, which session it was, and the reason they gave. Those records are not readable by any user, including the parties to the session.

6. What is not happening

Stated so this policy does not over-claim in either direction:

  • Staff monitoring under section 5 does not record the session. Watching produces no video or audio file. It is live viewing only, and when a member of staff stops watching, nothing of what they saw is kept. The internal audit record described in section 5 notes that a session was watched and by whom; it holds none of its content.
  • Avatar Walk does not sell your location data, and does not sell what staff observe while monitoring. It does not sell any of the other information described in this policy either.
  • Sessions themselves are not recorded, and neither are the watch-party calls beside them (section 9). Avatar Walk does not generate, store, or deliver a recording of a session or a watch party, and the booking page no longer offers an option to request one. Bookings made earlier, while that option was still shown, still carry the choice that was made at the time; nothing was ever produced from it. If recording is introduced, this policy changes with it.
  • Avatar Walk counts visits. In the European Union, the European Economic Area and the United Kingdom it does so only if you agree to it; everywhere else it counts them unless you turn it off with the switch below. Which of the two applies is decided from the country your network resolves to. A random identifier is kept in your browser so a returning visitor can be told apart from a new one, alongside the path of each page you open, and the country and city your network resolves to — never the rest of the query string, never a name or an email, and never a location more precise than a city. With the first page of a visit it also keeps the name of the website that sent you (not the address of the page), the name of the app whose browser the page opened in if it was one, such as Instagram or TikTok (just the app's name, not your browser's details), your browser's language and time zone (such as America/Los_Angeles) and the app's version, and during the visit a few things you do: what you search for, the time you pick for a tour, and whether a payment failed. If you sign in during a visit, that visit is linked to your account, so Avatar Walk staff can see where something went wrong and help. In the European Union, the European Economic Area and the United Kingdom nothing is recorded until you accept the banner. Anywhere, declining the banner or turning the switch below off stops it and erases the identifier, and signing in and paying work either way.
  • When you share a profile, a tour or an invite from the app while signed in, the link carries a short random code. Avatar Walk keeps which account that code belongs to and which page it points to, so that staff can see how many visits, sign-ups and bookings the links you share bring in. Someone who opens the link sees only the code, not your name or account. If you open a link someone else shared, your visit is marked with their code under the same terms as the visit itself. Avatars see how many people opened the links they shared, and which app those links were opened in — never who.
  • Avatar Walk does not run advertising trackers, and does not use any of the above to build a profile of you or to sell to anybody. Your signed-in session is kept in your browser's storage by Firebase Authentication so you stay logged in. Third-party components the site loads — Stripe, Google Maps, Agora — set their own storage under their own policies.

7. Bookings, payments and payouts

A booking stores who booked, which tour, how many minutes, the price agreed and the commission rates in force at that moment, the session's status and its timestamps. If you leave a note for the Avatar when booking, that note is stored on the booking and shown to the Avatar. If you have been reviewed as a guest, the booking also keeps your rating at that moment — your average and how many reviews it comes from — and shows it to the Avatar, so they can see it when deciding whether to accept.

The booking also keeps the time zone your device reports when you book, the language your app is set to, and the hometown on your profile if you have added one. The Avatar sees your hometown and what time it is for you — at the walk's start on the booking, and the current time during the walk — and your app's language when it differs from theirs, so they know whether to say good morning or good evening. Your exact location is never taken for this. Like the rest of the booking, these details can also be read by friends you invite to a watch party (section 9).

The destination pin. The guest can drop a pin for the Avatar to walk to only while the walk is live and its paid time has not run out. The current pin — its coordinates, who set it and when — is kept on the booking while the walk is live, both of you can see it, and either of you can remove it. When the walk ends, however it ends — either of you ends it, the time runs out, a safety stop, or the Avatar ends it early — the pin is deleted from the booking in the same step that ends the walk, and a pin dropped at that moment is refused rather than stored. If a walk is never formally ended (the timer and both apps fail to end it), an automatic job that runs once a day deletes its pin once the walk's time has been up for more than an hour, so no pin stays on a booking for more than about a day after the walk's scheduled end. Pins left on walks that ended before this change have been deleted as well. While the walk is live, friends the guest has invited to a watch party can read the booking record, pin included, although the app does not show them a map (section 9).

Gifts. When you buy a tour for someone, Avatar Walk stores a gift record: your account and name, the recipient's email address (and their account, once the gift is linked to one), the link's code, the tour and number of minutes, the price and commission rates at that moment, the amount paid and its Stripe identifiers, the note you write to the recipient, any brief you write for the Avatar, and the gift's status and dates. You cannot buy a gift for your own email address. The recipient's email address is used to find their Avatar Walk account, if they have one, so they can be told about the gift. If it does belong to an account, the gift is added to it at once and your gift list shows it as ready to book, so you can tell that the address has an account. Otherwise the gift is added to the account of whoever first opens the gift link while signed in — except you: opening your own link shows you what the recipient will see and does not accept it. Anyone else you pass the link to can accept it, so share it only with the person it is for.

No app or browser reads the gift record directly; Avatar Walk's servers read it and send each of you only your side of it. You are sent the tour, the minutes, the amount paid, the email address you typed, your note, the gift's status, any refund reason and its dates, and the gift link until someone accepts it. The recipient is sent the tour, the minutes, the amount paid, your name, your note, your brief for the Avatar, the status, any refund reason and the dates. Neither of you is sent the other's account identifier, and the recipient is not sent the email address you typed, the link's code, the Stripe identifiers or the commission rates.

When the gift is booked, the booking stores your name and your brief — it does not record who paid, and no older booking does either — and the Avatar is shown your name and your brief. Your name and brief on the booking can be read by everyone who can read that booking: the recipient, the Avatar and any friends the recipient invites to a watch party (section 9). The recipient can see your brief too before booking: it is sent to them from the moment the gift reaches them, and it is shown to them when they choose a time, so they can ask the Avatar for something different. If you start paying for a gift and do not finish, the gift record — with the recipient's email address, your name and your notes — is kept, although the gift is never sent. While you fill in the gift form, what you have typed — including the recipient's email address and your notes — is kept only in that browser tab, so it survives signing in. It is cleared when you go on to payment, and gone when the tab (or, in the app, the app itself) is closed.

Gifts when you delete your account. On gifts you bought, your name, your note, your brief for the Avatar and the recipient's email address are removed. A gift you had started paying for and not finished is cancelled with Stripe, so it can never be charged, and its email address is removed at once; if you had paid but the gift had not yet reached the recipient, the email address is kept only until it does — it is how the gift finds them — and removed then. On gifts you received, your email address is removed. On every booking a gift of yours paid for, including cancelled ones, your name and brief are removed. What stays, so that a gift you sent before leaving can still be accepted, booked, refunded or expire as normal: both people's account identifiers on the gift record (which, as above, neither person is sent), the link's code, the amounts and commission rates, the Stripe identifiers, the status and the dates. Stripe keeps its own record of the purchase, including your account identifier and the billing details you gave it, under its own policy. Notifications and emails already sent — such as the one telling the recipient who the gift is from — are not changed. If Avatar Walk cannot reach Stripe while deleting your account, the deletion stops before any gift is changed and can be tried again.

Card details are entered directly into Stripe and never reach Avatar Walk's servers or database. On Stripe's checkout page you also give Stripe your email address and billing details; Stripe includes them in the payment confirmation it sends Avatar Walk, but Avatar Walk does not store them. Avatar Walk gives Stripe your account identifier and what you are paying for; for a tip it also gives Stripe your account email address, so the checkout page is filled in, and your display name. Avatar Walk stores the Stripe payment identifiers so a charge, refund or payout can be matched to a booking or a gift. What Stripe does with your payment information is governed by Stripe's own privacy policy.

Avatars who take payouts connect a Stripe account. Stripe collects the identity and bank details it needs to pay them and to meet its own legal obligations; Avatar Walk stores the resulting account identifier, the payout status, and its own ledger of earnings, payouts and fees.

8. Messages, reviews, reports and support

Private conversations. Messages between a guest and an Avatar are stored and readable by the two participants. Once sent, a message cannot be edited or deleted by either party — money changes hands on this marketplace and the record of what was agreed has to stay trustworthy for disputes.

Live chat. Chat during a live walk is visible to everyone watching that walk and is stored with your account identifier, display name and profile photo.

Reviews. A review stores your star rating, any category scores, your written text, and your display name and profile photo copied at the time of writing. Reviews are public.

Reports. If you report a profile, Avatar Walk stores who you reported, the reason, any detail you wrote, and your identity as the reporter. Reports are readable by administrators and are not shown to the person reported.

Support chats. A support chat stores your messages and Support's replies, the topic and the walk you attach, and your display name copied at the time of writing. It is readable by you and by Avatar Walk administrators, and by nobody else. Tickets sent before support chats existed (which stored your name and email address) were copied into your chat.

9. Watch parties

A guest who has booked a walk can invite up to four friends to watch it with them, free. This section covers what that means for the guest who invites, for the friends who join, and for the Avatar.

The invitation. Only the guest who booked can invite, from the time the booking is made until the walk ends. There is one link per booking. Avatar Walk does not send it to anyone: the guest shares it themselves, through their phone's share sheet, by opening Messages, WhatsApp or email with the link already written in, or by copying it. A friend has to sign in to an Avatar Walk account to accept — the same 18-and-over accounts as everyone else (section 14). Anyone holding the link can accept while places remain; no one approves each person. The guest can reset the link, after which the old one admits nobody new (friends already in stay in), and can remove any friend. Before accepting, someone signed in with the link is shown the Avatar's name and photo, the inviting guest's first name, the walk's status and scheduled time, and how many friends have joined. The Avatar cannot join the watch party for their own walk.

The link's preview. When the link is pasted into a messaging app, the app fetches a short preview from Avatar Walk: the inviting guest's first name, the tour's photo and city, and its date, time and length. Messaging apps that show the preview may keep their own copy of it. Once the link is reset or the walk is over, the preview no longer names anyone. The link itself reads like avatarwalk.com/party/sophia-madrid-7kq2xv9mwpt4h: the Avatar's first name and the tour's city, then a private code. Those words stay in the link wherever it has been sent, after a reset too.

What is stored about each friend. When a friend accepts, the booking keeps a record of them: their account identifier, their display name and profile photo as they were at that moment (“Guest” if they had no name), when they accepted, and when they were removed, if they were. The booking also keeps a count of how many friends are in, which the Avatar can see. The link's code is kept where only Avatar Walk's servers can read it. The guest who invited can read each friend's record: their account identifier, name and photo, and when they accepted or were removed. None of this is deleted when the walk ends, and deleting a friend's account does not remove it: the record, with the name and photo copied when they accepted, stays on the booking indefinitely, and messages they posted in the walk's chat keep the name and photo they were posted with (sections 12 and 13).

What friends can see. A friend who has been let in can read the whole booking record — including the guest's note to the Avatar, the price, the guest's rating, the guest's and the Avatar's account identifiers, any gift giver's name and brief (section 7) and, while the walk is live, the destination pin — and can read and post in the walk's chat. That access does not end when the walk ends; it lasts until the guest removes them. Friends are not given the Avatar's position: Avatar Walk's servers refuse it to them (section 4). They cannot read the other friends' records; inside the party they see the inviting guest's first name, and everyone else is labelled “Friend”. Anything a friend posts in the walk's chat carries their account identifier, display name and profile photo and is visible to everyone in the walk, the Avatar included (section 8).

Camera and microphone. During a live walk, joining the party turns on your camera and microphone — the microphone starts on — and sends them, through Agora, to the inviting guest and the other friends who have joined, and to nobody else. The Avatar does not see or hear the party call; from it they learn only how many friends there are, although anything a friend posts in the walk's chat reaches them as described above. A camera or microphone you switch off before joining is not sent. The camera preview shown before you join stays on your device. If you choose to watch only, or refuse the camera or microphone permission and then watch only, you are not in the party call at all and nothing of yours is sent.

Not recorded, and not watched by staff. The party call is not recorded, and staff monitoring (section 5) does not reach it. The walk itself is still subject to staff monitoring. The walk's chat, friends' posts included, is stored like any live chat (section 8).

Notification. When the walk starts, each friend who is in the party is sent one “Your watch party is live” notification — in the app, and by push and email subject to their own notification settings (section 10). Friends are not notified when they are removed or when the walk is cancelled.

Removal. When the guest removes a friend, the friend loses access to the booking and the chat at once, and is cut off from the party call within about ten minutes at most. The app stops showing them the walk at once, and Avatar Walk's servers refuse them any new access to its video, but video access already issued to them runs out only within 24 hours. A removed friend cannot rejoin that party, and can still see their own record, which says they were removed.

Availability. Avatar Walk can switch watch parties off, for everyone or for a particular guest. Doing so stops new invitations, the party call and the notification, but friends already let in keep their access to the booking and the chat until they are removed.

10. Notifications

Avatar Walk sends in-app notifications about your bookings, payments, reviews, messages and equipment application, and about a watch party you are in going live (section 9). Email notifications are on by default and can be turned off in your settings; browser push notifications are off until you enable them and grant your browser's permission.

Enabling push stores a device registration token and your browser's user-agent string, so a stale registration can be identified. Turning push off deletes the registration.

11. Who your information is shared with

Avatar Walk does not sell your information. It is shared with:

  • Stripe — payments, refunds and Avatar payouts. Stripe receives your payment details directly and, for Avatars taking payouts, the identity and bank information it requires.
  • Google (Firebase) — authentication, the database that holds everything described above, file storage for photos, and push delivery. Google Maps renders the maps in the app, and while a guest's destination is set during a walk, the Avatar's current position and that destination are sent to Google — again each time the Avatar has walked about 75 metres — to work out the walking route.
  • Agora — the live video and audio transport. Your camera and microphone feed passes through Agora to reach viewers, and in a watch party it passes through Agora to the others in the party call (section 9).
  • Resend — sending notification emails, which means Resend handles your email address and the contents of those emails.
  • Upstash — the scheduling service that fires timed callbacks for booking expiry and session end. It carries booking identifiers, not personal details.
  • Law enforcement or regulators — where Avatar Walk is legally required to disclose, or where disclosure is necessary to address fraud, safety or a legal claim.

Other users see what the product shows them: your display name and profile photo, your public profile and tours if you host (with your phone model and gimbal, as described in section 3), your reviews, and messages you send. While you host a live walk, the guest who booked it also sees your exact position on the walk's map (section 4). If you buy someone a tour, the recipient sees your name, your note, the amount you paid and your brief, and the Avatar sees your name and your brief (section 7). If someone buys you a tour, they see the email address they typed, whether the gift has been added to an account — straight away if that address is yours — and whether it has been booked and taken. Neither of you is given the other's account identifier by the gift. If it goes unused for 90 days they are told it was refunded, and any refund on the walk — for minutes not used, or the whole amount if the Avatar does not turn up — goes back to their card.

If you join a watch party, the guest who invited you sees your account identifier, display name and profile photo, and the people in the party call see and hear you while your camera and microphone are on. The Avatar is not in the party call and is told only how many friends are in the party, but sees your name and photo on anything you post in the walk's chat (section 9).

12. How long information is kept

Live location is deleted when the session ends, and Avatar Walk holds only the latest position at any moment before that. The guest's map keeps the recent path on their screen only while the walk is open. A destination pin is deleted from the booking when the walk ends, and in any case within about a day of the walk's scheduled end (sections 4 and 7).

Staff monitoring produces no recording, so there is no session footage to retain (section 6). Two records around it are kept: your acknowledgement of the pre-session monitoring notice, and the internal audit record written each time a member of staff is given access to watch. Both are kept as part of the session's history rather than deleted when the session ends, because a record of who watched what is only useful if it outlives the thing it describes.

Everything else — your account, bookings, gifts (the giver's name and both notes stay on the gift record, and the giver's name and brief on every booking it paid for, after the gift is used or refunded, until the giver deletes their account; the recipient's email address stays until either person deletes theirs; a gift that was started and never paid for is kept with the same details; section 7 sets out what deleting an account removes), payment records, messages, reviews, equipment application, reports and support chats (and the tickets sent before them) — is kept for as long as your account exists, and afterwards where a record is needed for accounting, tax, fraud or dispute purposes. Avatar Walk does not currently run an automatic deletion schedule for these records; deletion happens when you ask for it under section 13.

Watch-party records — each friend's record on a booking, with the name and photo copied when they accepted — are kept with the booking indefinitely, including after the friend deletes their account (section 9).

13. Your rights and how to use them

You can see and change most of your own information in the app: your profile and photo, your notification settings, your tours and availability if you host, your bookings, and your equipment application status.

You can delete your account yourself, from Profile. It asks you to confirm first, because it cannot be undone. To ask for a copy of your information or a correction — or for help with a deletion that did not complete — email Info@avatarwalk.com from the address on your account. Avatar Walk will confirm your identity before acting on a request made by email, since these requests are also the shape a takeover attempt takes.

Some things cannot be deleted on request. Messages are immutable once sent, so a conversation cannot be edited after the fact. A watch-party record — your account identifier, name and photo as they were when you accepted — stays on the booking of a walk you were invited to, and deleting your account does not remove it (section 9). Payment and payout records are kept where accounting, tax or anti-fraud obligations require them. Where a request cannot be met in full, Avatar Walk will say which part it could not do and why.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to or restrict certain processing and the right to complain to your local data protection authority. Use the same address to exercise them.

14. Children

Avatar Walk is for adults. You must be at least 18 years old to use it, as a guest or as an Avatar, and the platform is not directed at children. Avatar Walk does not knowingly collect information from anyone under 18. If you believe a child has created an account, email Info@avatarwalk.com and the account and its information will be removed.

15. Security

Access is enforced in the database itself rather than only in the interface: a user can read their own account, their own bookings, their own tickets and the conversations they are part of, and the collections holding payment ledgers, tours, notifications and live locations cannot be written by any client at all. Administrator status is granted out of band and cannot be self-assigned.

No system is perfectly secure, and Avatar Walk does not claim otherwise. If you find a problem, report it to Info@avatarwalk.com.

16. Changes to this policy

This policy describes what the platform does today. When the platform's behaviour changes — including if session monitoring, live location handling, or recording ever change — this policy is updated to match, and the effective date at the top changes with it. A policy that promises something the code does not do is worse than no policy.

17. Contact

Questions about this policy, or about anything in it, go to Info@avatarwalk.com.