The short version
- We collect what we need to run your account, your trips and your bookings — and, for providers, to verify who you are before money moves.
- Your questions, answers, articles, reviews and public profile are public. Your messages, drafts, documents and payout details are not.
- SerendAI sends your messages to AI providers outside Sri Lanka to produce an answer. They do not use them to train their general models.
- We never see your full card number, and we never sell your personal data.
- You have enforceable rights under Sri Lanka’s Personal Data Protection Act — see section 17.
1.Who we are
OneCeylon (Private) Limited (registration number PV-00260243), of 14 Sir Baron Jayathilake Mawatha, Colombo 00100, Sri Lanka, operates OneCeylon at oneceylon.space.
For the purposes of the Personal Data Protection Act, No. 9 of 2022 (the “PDPA”), we are the controller of the personal data described here: we decide why and how it is processed, and we are accountable for it.
Our contact point for all data-protection matters is privacy@oneceylon.space.
2.What this policy covers
This policy applies to oneceylon.space, our progressive web and mobile applications, our embeddable assistant on partner websites, and the emails, notifications and messages we send. It covers travellers, providers, community members and visitors who are not signed in.
It does not cover: what a provider does with your details after we pass them on for a booking (they are a separate controller with their own obligations); external websites we link to; or a partner’s own website that happens to embed our assistant.
3.Personal data we collect
3.1 Account and profile
- Email address, username and display name
- Password, stored only as a one-way hash — we cannot read it
- Profile picture, biography, location, website and social links, where you add them
- Your stated travel interests and what you told us you came here to do
- Language and display preferences, and notification settings
- Where you sign in with a third-party account, the identifier, name and email that provider returns
3.2 Content you create
- Questions, answers, comments, articles, tags and suggested edits
- Reviews and ratings you leave
- Scam reports, safety reports and crowd reports
- Itineraries, trip plans, stops, notes, packing lists and budget entries
- Photographs and images you upload, including any location data embedded in the file
- Messages you send in Crews and in booking threads
- Fare and price reports you contribute
- Votes, bookmarks, saved items, collections and follows
- Flags and reports you submit about other users or content
3.3 Bookings and marketplace
- Booking details: service, dates, party size, and the requirements you give the provider
- Special requirements you choose to disclose, which may include health, mobility, dietary or religious information — see the note in section 3.8
- Correspondence with a provider about a booking
- Payment records: amount, currency, status, a payment reference from our processor, fees and refunds
- Cancellation, dispute and chargeback records, and any evidence submitted
- Invoices and receipts
3.4 Provider identity and payout data
Collected only if you offer services (see section 9):
- Phone number, and the record of its verification
- National Identity Card number and an image of the document
- A photograph of your face, used to check it against the document
- Business registrations, licences, permits and insurance certificates you upload
- Bank name, branch, account holder name and account number for payouts
- Taxpayer Identification Number where required
3.5 SerendAI
- The text of your messages, and the answers generated
- Images you upload for analysis
- Voice recordings, where you use voice input or the translator
- Trip context you supply — destination, dates, budget, party
- Short preference notes the assistant keeps to personalise later answers, which you can view and delete
- Feedback ratings you give on an answer
- A session identifier, and a hashed form of your IP address used for rate limiting
3.6 Location
Precise location from your device, only when you grant browser or device permission, and only for the feature you asked for. See section 7.
3.7 Technical and usage data
- IP address, and an approximate location derived from it
- Browser type and version, operating system, device type, screen size and language
- Pages viewed, features used, referring page, and timestamps
- Search queries you run on the site
- Cookies and similar technologies — see our Cookie Policy
- Push notification subscription identifiers, where you enable notifications
- Diagnostic and error logs
3.8 Special categories of personal data
Please think before you share
Some data attracts stronger protection under the PDPA — including data revealing health, race, religion or belief, political opinion, and biometric data. We do not ask for it as a matter of course. It can nonetheless reach us when you tell a provider about a medical condition, dietary or accessibility need; when you mention health in a question or to SerendAI; or through the identity photograph in section 3.4.
Where you supply it, we process it on the basis of your explicit consent, or where it is necessary to protect your vital interests in an emergency. Please share only what the situation actually requires, and never post health information about someone else.
4.Where we get it from
- From you — when you register, complete a profile, post content, book, verify your identity, or use a feature.
- From your device — automatically, as you use the Service.
- From other users — when someone books you, invites you to a crew or itinerary, reviews you, mentions you, or reports you.
- From service providers — our payment processor confirms whether a payment succeeded; a sign-in provider confirms your identity; a messaging provider confirms delivery.
- From public sources — publicly available business and place information used to build listings and guides.
5.Why we use it, and our lawful basis
The PDPA requires us to have a lawful basis for every use of your personal data. Ours are set out below.
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and run your account; authenticate you; keep you signed in | Account and profile, technical | Performance of a contract with you |
| Publish your questions, answers, articles, reviews and public profile | Content you create, profile | Performance of a contract; your consent for optional profile fields |
| Take booking requests, process payment, pass details to the provider, issue invoices and refunds | Booking, payment, contact | Performance of a contract |
| Answer your questions through SerendAI, including images, voice and translation | SerendAI data, trip context, location where shared | Performance of a contract; consent for images, voice and location |
| Verify a provider's identity, licences and payout account | Identity and payout data | Legal obligation (anti-money-laundering and financial transaction reporting); performance of a contract |
| Prevent fraud, abuse, spam and vote manipulation; enforce fair-use limits; keep the platform safe | Technical, usage, hashed IP, content | Our legitimate interests in protecting the Service and its users |
| Moderate content and screen reports before publication | Content you create | Our legitimate interests; legal obligation where a takedown notice applies |
| Send service messages about your account, bookings, security and policy changes | Contact details, booking data | Performance of a contract |
| Send marketing emails and product news | Contact details, interests | Your consent — withdrawable at any time |
| Send an emergency alert to a contact you have nominated | Location, contact details you supplied | Your consent; protection of vital interests |
| Understand how the Service is used and improve it; measure activation and performance | Usage, technical, aggregated analytics | Our legitimate interests; consent where analytics cookies require it |
| Keep accounting and tax records; respond to lawful requests; establish or defend legal claims | Booking, payment, identity, correspondence | Legal obligation; our legitimate interests |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that the processing is proportionate and would be reasonably expected. You may object — see section 17. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.
We do not sell your personal data, and we do not share it with third parties for their own advertising.
6.SerendAI and AI processing
6.1 What happens to a message
When you send a message to SerendAI, it is transmitted to our AI providers — currently Anthropic and Google — which run it through a large language model and return an answer. Depending on your question, we may first retrieve supporting information from Google Maps and Places, the Google Directions service, the Open-Meteo weather service, and our own community content, and include it in what is sent.
Under our agreements with these providers, your content is not used to train their general-purpose models. They process it to return a response and may retain it briefly for abuse monitoring under their own terms.
6.2 Images and voice
Images you upload are processed to generate an answer and are not stored permanently by us. Where we cache an answer to avoid re-processing, the cache is keyed by a hash of the image, not by the image itself. Voice recordings are transcribed and the audio is discarded once transcription completes; the resulting text is treated like any other message.
6.3 Conversation history and memory
Conversations are stored so you can return to them, so we can serve a cached answer to a repeated question, and so we can investigate abuse and improve quality. Where you are signed in, SerendAI may keep short preference notes — for example that you travel with children, or avoid meat. You can view and delete these from within the assistant. Where you are not signed in, an anonymous profile of this kind is held in your own browser and never leaves it unless you sign in.
6.4 What not to send
Do not send SerendAI your identity documents, bank or card details, passwords, medical records, or anyone else’s personal data.
7.Location data
We ask for your device location only for a feature that needs it, and only after you grant permission — for example to show weather where you actually are, to find places near you, to work out whether you are about to arrive somewhere, or to include your position in an emergency alert.
- You can refuse, and the Service continues to work with reduced precision.
- You can withdraw the permission at any time in your browser or device settings.
- We do not track your location in the background, and we do not build a movement history for advertising.
- We derive an approximate, city-level location from your IP address for regional content and fraud prevention; this happens whether or not you grant device permission.
- Photographs you upload may contain embedded location data. Where an image becomes public, strip it first if that matters to you.
8.Data about other people
Sometimes you give us personal data about someone else. When you do, you are responsible for having a proper basis to share it — usually their consent — and for telling them how it will be used.
- Emergency contacts. If you nominate someone, we store their name and phone number and may send them a message containing your location and a request to contact you. Ask them first.
- Fellow travellers. Names and ages you give a provider for a booking are passed to that provider so the service can be supplied.
- Photographs and posts. Do not upload identifiable images of other people, or post their contact details, location or identity numbers, without their agreement.
If someone has shared data about you and you want it removed, write to privacy@oneceylon.space and we will deal with it.
9.Identity verification and payout data
Providers must verify their identity before receiving bookings and payouts. This is how a traveller in another country can reasonably trust a stranger with a deposit, and it is also required of us under the Financial Transactions Reporting Act, No. 6 of 2006 and the Prevention of Money Laundering Act, No. 5 of 2006.
- Identity documents and photographs are stored with access restricted to the small number of staff who review them, and are used only for verification, fraud prevention, and responding to a lawful request.
- They are never shown to travellers or to other providers. A traveller sees only a verification badge.
- Bank account numbers are stored to make payment; only the last four digits are displayed back in the interface.
- We may be required to report a suspicious transaction to the Financial Intelligence Unit, and we are prohibited by law from telling you if we do.
- Identity and financial records are retained after your account closes for the period the law requires — see section 14.
10.Payment data
Card payments are handled by our third-party payment processor. Your card number never reaches our servers and we cannot see it. The processor is a separate controller of the payment data it holds and applies its own privacy policy.
What we store is the payment reference, the amount, the currency, the status, the fees, and the refund or dispute history — enough to run the booking, produce an invoice, resolve a dispute, and keep proper accounts.
11.What is public, and what is not
| Visible to anyone on the internet | Kept private |
|---|---|
|
|
Public means public: search engines index it, AI systems read it, and other people copy it. Content posted publicly may persist in caches and archives we do not control even after you delete it here.
13.Sending data outside Sri Lanka
Some of the processors in section 12.2 are located outside Sri Lanka, so running the Service necessarily involves cross-border transfers — principally to the United States and the European Union.
The PDPA permits such a transfer where the receiving jurisdiction provides an adequate level of protection, or where we have put appropriate safeguards in place. We rely on written data-processing agreements imposing confidentiality, security and purpose limitation; on standard contractual protections offered by our processors; and, for data you supply to SerendAI, on your consent to the processing being carried out abroad.
You may ask us for details of the safeguards applying to a particular transfer by writing to privacy@oneceylon.space.
14.How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then deleted or anonymised after the closure process in section 18 |
| Public content — questions, answers, articles, reviews, scam reports | Retained indefinitely, but anonymised on account closure so the record other users rely on stays intact |
| Crew and booking messages | Retained while relevant to the trip or booking and any dispute period, then deleted |
| SerendAI conversations | Retained for service quality and abuse investigation, then deleted or anonymised; you can delete preference notes at any time |
| Uploaded images sent to SerendAI | Not stored — processed and discarded |
| Voice recordings | Discarded once transcribed |
| Booking, payment, invoice and tax records | At least 6 years, as required by Sri Lankan tax and anti-money-laundering law |
| Identity verification documents | Retained for the statutory record-keeping period after the business relationship ends — generally 6 years |
| Payout bank details | Until replaced or the account closes, then subject to the financial-records period above |
| Fraud, abuse, moderation and ban records | Retained as long as necessary to keep the platform safe, including after account closure |
| Server, security and error logs | Typically up to 12 months |
| Marketing consent records | Until you withdraw consent, plus a record of the withdrawal |
15.Automated decisions and profiling
We use automated systems in a small number of places where a decision may affect you:
- Content screening — reports, questions and messages are screened automatically for harmful or defamatory material, and may be held back from publication.
- Abuse and rate limiting — unusual patterns of use may trigger a temporary block.
- Payout risk checks — a payout may be held for human release, based on factors such as it being a provider’s first payout, its size, or a prior dispute.
- Anomaly holds — an unusual community price submission may be held for review.
- Personalisation — recommended content and follows are based on your stated interests and activity.
These are safeguards, not final determinations: none of them closes your account or refuses your money on its own. The PDPA gives you the right to object to a decision produced solely by automated processing that significantly affects you. Write to privacy@oneceylon.space or trust@oneceylon.space and a person will review it, explain the reason, and take your representations into account.
16.How we protect your data
- Passwords are stored only as a salted one-way hash and cannot be recovered or read by us.
- All traffic is encrypted in transit using HTTPS.
- Access to identity documents, payout details and payment records is restricted to staff who need it for their role.
- Card data never reaches our systems.
- Authentication, password reset and sensitive endpoints are rate limited to resist automated attack.
- User-generated content is sanitised, and a content security policy limits what can execute in your browser.
- Emergency contact alerts and verification codes expire quickly.
- We keep audit trails for administrative actions on bookings and payouts.
No system is perfectly secure. We cannot guarantee absolute security, and you play a part too: use a strong, unique password, do not reuse it elsewhere, sign out on shared devices, and never share a verification code with anyone — including anyone claiming to be from OneCeylon.
17.Your rights under the PDPA
The Personal Data Protection Act, No. 9 of 2022 gives you the following rights over your personal data. They apply whatever your nationality or where you are.
| Right | What it means |
|---|---|
| Access | Ask whether we process your personal data, and get a copy of it along with information about how it is used. |
| Rectification | Have inaccurate data corrected, and incomplete data completed. |
| Erasure | Ask us to delete your personal data where there is no longer a good reason for us to keep it. |
| Withdraw consent | Withdraw consent at any time where our basis for processing is consent — for example marketing, location, or voice input. |
| Object to processing | Object to processing based on our legitimate interests, and to a decision produced solely by automated means that significantly affects you. |
| Restrict processing | Ask us to pause using your data while a dispute about its accuracy or our basis is resolved. |
| Appeal | If you are not satisfied with our response, appeal to us — and then complain to the Data Protection Authority. |
17.1 How to exercise them
Many of these you can do yourself: edit your profile, change notification settings, delete SerendAI preference notes, export your data, or close your account, all from your settings. Otherwise, write to privacy@oneceylon.space from the email address on your account, telling us what you want.
We will respond within 21 days of receiving your request, as the PDPA requires. If a request is complex and we need the further period the Act allows, we will tell you within that time and explain why. We may ask you to confirm your identity first — we are not going to hand your data to someone claiming to be you. There is no charge, unless a request is manifestly unfounded or repetitive.
17.2 When we may refuse, in whole or in part
Some rights are qualified. We may decline a request, and will tell you why, where complying would:
- require us to delete a record we must keep by law — a payment, tax or anti-money-laundering record, for instance;
- interfere with the detection or prevention of fraud or crime, or with a moderation or ban record needed to keep others safe;
- reveal another person’s personal data, or the identity of someone who reported content in confidence;
- prejudice a legal claim; or
- be impossible — we cannot recall a public post someone else has already copied or that a search engine has cached.
17.3 Appeals and complaints
If you are unhappy with our answer, reply and ask for it to be reviewed; a different person will look at it. If you remain dissatisfied, you have the right to complain to the Data Protection Authority of Sri Lanka, established under the PDPA. We would appreciate the chance to put it right first.
18.Closing your account
You can request deletion from your settings. The request takes effect after a 30-day grace period, during which signing in cancels it. You cannot close an account while a booking is in progress or a dispute is open.
When the deletion runs:
| Removed | Kept, with your identity stripped |
|---|---|
|
|
Backups are overwritten on a rolling cycle, so a copy may persist in backup storage for a short period after the purge before it is expunged.
19.Children
The Service is for adults. You must be at least 18 to hold an account, and we do not knowingly collect personal data from anyone younger. The PDPA treats a person under 18 as a child whose data requires the consent of a parent or guardian.
Where a booking includes a child, the adult making it supplies only what the provider needs — typically a first name and age. If you believe a child has given us personal data, write to privacy@oneceylon.space and we will delete it promptly.
21.If something goes wrong
If a personal data breach occurs, we will investigate immediately, contain it, and notify the Data Protection Authority without undue delay as the PDPA requires. Where the breach is likely to result in harm to you, we will notify you directly, tell you what happened, what data was involved, what we have done, and what you should do.
If you think you have found a security vulnerability, please report it responsibly to trust@oneceylon.space rather than disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith and does not access, alter or exfiltrate other people’s data.
22.Visitors from the EEA and the UK
Most of our travellers come from outside Sri Lanka. Where the General Data Protection Regulation or the UK GDPR applies to our processing of your data, you have rights equivalent to those in section 17 — access, rectification, erasure, restriction, objection, portability, and withdrawal of consent — and the right to lodge a complaint with your national supervisory authority.
We handle such requests through the same channel: privacy@oneceylon.space. Where those laws require a shorter response period than the PDPA’s, we will meet the shorter one.
23.Changes to this policy
We will update this policy as the Service and the law change. The effective date at the top always reflects the current version. Where a change materially affects how we use your personal data, we will tell you by email or by a prominent notice in the Service before it takes effect, and where the law requires it we will ask for your consent again.
24.Contact and complaints
- Controller
- OneCeylon (Private) Limited (PV-00260243)
- Registered office
- 14 Sir Baron Jayathilake Mawatha, Colombo 00100, Sri Lanka
- Data protection contact
- privacy@oneceylon.space
- Privacy questions
- privacy@oneceylon.space
- Trust and safety
- trust@oneceylon.space
- Online
- oneceylon.space/contact
- Regulator
- Data Protection Authority of Sri Lanka, established under the Personal Data Protection Act, No. 9 of 2022
See also our Terms of Service and Cookie Policy.