Wayamigo

Privacy Policy

16 July 2026

This policy explains what personal data Wayamigo (the data controller) collects, why, and what rights you have. We collect as little as we can, and we do not sell personal data or run advertising trackers.

1. Data we collect

We process the following categories of data:

  • Account data — e-mail address, optional name and your sign-in credentials. Sign-in is operated by our authentication provider Clerk: passwords are stored by Clerk only in hashed form (never in plain text), and if you sign in with Google we receive your name and e-mail address from Google.
  • Trip inputs and guides — what you enter to create a guide (origin, destination, dates, budget, travelers, interests, language) and the generated guide itself, stored so you can access it again.
  • Photos and notes — content you upload to your gallery and travel map.
  • Purchase records — which token pack you bought, when, and its status. Payment card data is collected and processed by Dodo Payments (merchant of record); we never receive your full card details.
  • Technical data — server logs (IP address, time, requested page) kept for security and troubleshooting.

2. Why we process it (legal bases)

  • To provide the service you signed up for — accounts, guide generation, gallery, e-mail delivery of your guides (performance of contract).
  • To process purchases, prevent fraud and keep required accounting records (contract and legal obligation).
  • To keep the service secure and diagnose problems (legitimate interest).
  • To send you product e-mails you asked for, like “your guide is ready” or a gift-code delivery (performance of contract). We currently send no marketing e-mails.

3. Cookies

Functional cookies (always on, no consent needed): a session cookie that keeps you signed in, a language cookie, a theme (light/dark) cookie, and a cookie remembering your analytics choice.

Analytics cookies (only with your consent): if you press “Accept analytics” in the cookie banner, Google Analytics sets statistics cookies so we can see how the site is used (pages visited, where visitors come from). If you decline, no analytics runs at all — the site works exactly the same. You can change your mind anytime by clearing this site's cookies in your browser, which brings the banner back. We use no advertising cookies.

4. Who we share data with (processors)

We share data only with service providers needed to run Wayamigo, under their data-processing terms:

  • Clerk — account creation and sign-in (authentication). Clerk stores your e-mail address and hashed password (or your Google sign-in identity) on our behalf.
  • Dodo Payments — checkout and payment processing (merchant of record).
  • Anthropic — AI generation of guide text. Trip parameters (destination, dates, budget, interests) are sent to generate your guide; your name, e-mail and account identity are not.
  • Resend — transactional e-mail delivery (guide-ready, purchase confirmations, gift codes).
  • Google (Google Analytics) — aggregated usage statistics, loaded ONLY after you accept analytics in the cookie banner. We do not send Google your name or e-mail address.
  • Flight and places data providers (e.g. SerpApi for flight prices, OpenStreetMap services for verified places) receive trip search parameters, never your identity.
  • Cloudflare and other hosting/infrastructure providers — domain and content delivery, file storage, and privacy-friendly aggregate visit statistics (cookie-less, no personal data, no cross-site tracking).

5. Retention

Your account data, guides and photos are kept while your account exists, so your travel history stays available to you. If you delete your account, they are deleted with it (except records we must keep by law, e.g. accounting records of purchases). Server logs are kept for a short rolling window.

6. Your rights

You can delete your account and ALL data tied to it (guides, PDFs, photos, map data, notes, tokens) yourself at any time — on your profile page under “Danger zone”. Deletion is immediate, permanent and also removes your sign-in identity at our authentication provider (Clerk).

For everything else — access, correction, export, restriction of or objection to processing — write to [email protected] and we will respond within the legally required time. You can also lodge a complaint with your data-protection authority.

7. International transfers

Some processors listed above operate infrastructure outside your country (including the United States). Where required, transfers rely on recognized safeguards such as the EU Standard Contractual Clauses or an adequacy framework the processor participates in.

8. Children

The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

9. Changes and contact

We will announce material changes to this policy by e-mail or on the site. Privacy questions: [email protected].

Questions about this document? [email protected]