Privacy & Trust

Privacy Policy

How we respect your personal data, secure your travel preferences, and uphold your privacy rights with quiet discretion.

Last Updated: August 2026Effective: August 2026
Privacy Commitments

We Never Sell Your Data

Your travel style, destinations, and personal notes are strictly yours. We do not monetize or sell your information to advertisers.

Protected AI Prompts

Your journey prompts sent to our AI models (Claude) are protected under enterprise confidentiality and never used to train public models.

Bank-Grade Stripe Security

We never store your raw credit card numbers. All billing and card storage is handled by PCI-DSS certified Stripe infrastructure.

Complete Data Control

You have full rights under GDPR and CCPA to export your entire travel history or permanently delete your account at any time.

01.

Our Privacy Philosophy

At Wayheld, we believe intentional travel requires trust. Just as we advocate for gentle, respectful interaction with the destinations you visit, we hold ourselves to the highest standards of discretion and security when handling your personal information.

This Privacy Policy explains what data we collect when you visit wayheld.com and use our travel companion platform, how we utilize that data to tailor your slow travel journeys, and the rigorous safeguards we implement to keep your information secure.

02.

Information We Collect

We collect only the information necessary to provide, refine, and secure our services:

1. Account & Profile Data

When you register, we collect your name, email address, password hash, home city/country, and linked OAuth account identifiers (e.g., Google Sign-In).

2. Travel Preferences & Onboarding Answers

Your pace choices (e.g. One Place Deeply), transport bias (e.g. Rail-first), budget tier, cultural interests, and avoid-crowd preferences.

3. Journeys, Notes & Saved Places

Itineraries you compose, custom stops, bookmarked places, lodging recommendations, and personal travel notes.

4. Billing & Transaction Records

When you purchase a plan or points, payment is handled by Stripe. We receive tokenized customer identifiers (`cus_...`), subscription statuses, and invoice records, but never your full payment card number or CVV.

5. Technical & Device Logs

IP address, browser type, device information, and interaction events logged for security auditing, rate limiting, and performance diagnostics.

03.

How We Use Your Data

We process your information for the following legitimate purposes:

  • Journey Composition: Generating nuanced, multi-day slow itineraries matching your pacing and geographic preferences.
  • Personalized Discovery: Suggesting quiet accommodations, cultural artisans, and heritage experiences tailored to your profile.
  • Billing & Account Management: Provisioning point balances, processing renewals, and maintaining your subscription status.
  • Platform Security: Detecting bot abuse, preventing fraudulent transactions, and enforcing rate limits.
  • Member Communication: Sending essential service notifications, journey export summaries, and security alerts.
04.

Artificial Intelligence & Claude Model Protection

Wayheld utilizes Anthropic’s Claude API to assist with route design, stop curation, and travel recommendations. We maintain strict data protections regarding AI integration:

  • No Model Training: Your private prompts, personal journey notes, and profile details sent via our API integrations are never used by Anthropic or third parties to train public AI foundation models.
  • Data Minimization: We send only the parameters strictly required to generate your itinerary (such as destination, season, pace, and interests).
  • Audit Trail: Prompt logs and token metadata are securely stored in your private database ledger to allow journey version history and refinement rollbacks.
05.

Trusted Third-Party Service Providers

We partner only with industry-leading infrastructure providers that adhere to rigorous data protection standards:

Stripe

Payment processing, recurring subscription management, and PCI-DSS compliance.

Anthropic (Claude)

Secure AI model generation via zero-retention enterprise API endpoints.

Google Maps Platform

Geocoding, place verification, and interactive map displays.

Supabase & PostgreSQL

Encrypted relational cloud database storage and authentication session caching.

06.

Your Rights & Controls (GDPR / CCPA)

Regardless of where you reside, Wayheld honors comprehensive data privacy rights under GDPR, UK-GDPR, and the California Consumer Privacy Act (CCPA):

  • Right of Access: You may request a complete copy of the personal data we hold about you.
  • Right to Rectification: You can edit your profile, preferences, and details directly within your Settings dashboard.
  • Right to Erasure (“Right to be Forgotten”): You may delete your account and all associated journeys and prompt logs at any time.
  • Right to Data Portability: You can export your journey itineraries and saved places in structured digital formats.

To exercise any of these rights, you can use your account settings or email our Data Protection team at privacy@wayheld.com.

07.

Data Retention & Security

We employ industry-standard administrative, technical, and physical safeguards designed to protect your information against unauthorized access, loss, or alteration. All web communications are encrypted via Transport Layer Security (TLS 1.3), and sensitive fields are encrypted at rest.

We retain your information only for as long as your account remains active or as needed to comply with our statutory tax, accounting, and legal obligations.

08.

Contact Our Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or how your personal information is managed, please contact:

Wayheld Privacy & Data Governance
Email: privacy@wayheld.com
Support: Contact Help Centre

Questions regarding our terms or policies?

We believe in radical clarity. Reach out to our concierge or compliance team anytime.

Contact Support