Privacy Policy and Terms of Service for WAYVA — solo travel companion app
Effective date: 31 May 2026 Last updated: 31 May 2026
This Privacy Policy explains how WAYVA (“WAYVA”, “we”, “us”, “our”) collects, uses, shares, and protects your personal information when you use our mobile and web applications, our backend services, and any related sites (collectively, the “Service”).
WAYVA is a travel companion app designed for solo travelers, with a primary focus on Southeast Asia. Because the Service is used while you travel — often across borders, on shared networks, and in safety-sensitive contexts — we treat your data with particular care. This policy is written to be specific and honest. If anything here is unclear, contact us at privacy@wayva.app.
If you are a Google Play Data Safety reviewer: the data categories disclosed on our Play Store listing are aligned with Section 4 below.
WAYVA is operated by the company or sole proprietorship identified on our App Store / Google Play listing. References below to “WAYVA” mean that legal entity. Our primary contact for privacy questions:
If you are in the European Economic Area or the United Kingdom and would like to contact our designated representative, email privacy@wayva.app and we will respond with the appropriate contact.
We collect information in three ways: you give it to us, the app collects it automatically when you use a feature, and a small amount comes from third parties (only authentication providers like Google and Apple, only with your consent).
| Category | Examples | Required? |
|---|---|---|
| Account identifiers | Email address, password (hashed), username, display name | Required to sign up |
| Profile | Home country, primary language, home currency, optional bio, optional avatar | Required (country/language); rest optional |
| Travel preferences | Travel style, interests, budget level, dietary preferences | Optional |
| Emergency contacts | Names, phone numbers, email addresses, relationship of people you nominate to be contacted in an emergency | Optional |
| Travel documents | Passport number, expiry date, document scans, visa records — all encrypted at rest with a key separate from the database | Optional |
| Posts, comments, photos, reviews, tips, warnings, trip plans, saved places, journal entries | Anything you publish or save inside WAYVA | Optional |
| Support content | The text and attachments of support tickets you file | Created when you file a ticket |
| Payment information | If you subscribe: we process payment via the App Store, Google Play, or Stripe. We never see your full card number. We retain only the subscription receipt token and the last 4 digits for billing support. | Required to subscribe |
| Category | Purpose | Granularity |
|---|---|---|
| Approximate location (IP-derived) | Country-level for currency, language, and travel advisories | Country only; not stored long-term |
| Precise location (GPS) | Only when you tap a feature that needs it — map view, nearby places, SOS, “share my live location”. Always foreground unless you opt-in to a session. | Lat/long ± device accuracy |
| Device data | Device model, operating system version, app version, screen size, language, time zone | Coarse only — no IMEI, no MAC |
| Diagnostics | Crash reports, performance traces, error stack traces (via Sentry) | Excludes message content, post bodies, and travel documents |
| App usage signals | Which screens you visit, which features you use, button taps. Aggregated and anonymized for product improvement. | Pseudonymous; not joined to your account profile in analytics |
| Network / security | IP address, request timestamps, user-agent — held only long enough to detect abuse | 30 days then aggregated |
If you sign in with Google or Apple, we receive your email and a unique provider ID. We do not request your contacts, calendar, drive files, photos, or any other data from those providers. We never receive your password.
We do not purchase personal data from data brokers, marketing platforms, or any third party.
To be explicit:
This section maps our practices to the Google Play Data Safety taxonomy.
| Data type | Collected | Shared with 3rd parties | Optional | Purpose |
|---|---|---|---|---|
| Name | Yes | No | Yes | App functionality, personalization |
| Email address | Yes | No | No | Account, support |
| User IDs | Yes | No | No | Account |
| Password (hashed) | Yes | No | No | Account |
| Photos | Yes | No | Yes | App functionality |
| Approximate location | Yes | No | Yes | App functionality |
| Precise location | Yes | No | Yes | App functionality, safety |
| Address | No | — | — | — |
| Phone number | Yes | No | Yes | Emergency contacts; phone sign-in (if used) |
| App interactions | Yes | No | No | Analytics, fraud prevention |
| Crash logs | Yes | Yes (Sentry) | No | App performance |
| Diagnostics | Yes | Yes (Sentry) | No | App performance |
| Purchase history | Yes | Yes (Stripe / App Store / Play) | No | Account, billing |
| Files & docs (visa/passport, if uploaded) | Yes | No | Yes | App functionality |
| Personal documents (travel) | Yes | No | Yes | App functionality |
| Health & fitness | No | — | — | — |
| Financial info | Limited (subscription only) | Yes (payment processor) | No | Billing |
| Contacts | No | — | — | — |
| Calendar | No | — | — | — |
| Web browsing history | No | — | — | — |
| SMS/MMS | No | — | — | — |
| Audio recordings | No | — | — | — |
| Race/ethnicity, religion, sexual orientation, political views | No | — | — | — |
Under GDPR and similar laws, we rely on the following lawful bases:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account | Performance of a contract |
| Showing you the map, nearby places, weather, currency | Performance of a contract |
| Sending you safety alerts you have enabled | Performance of a contract / vital interests |
| Storing travel documents you upload | Consent — you can delete at any time |
| Sharing your live location with emergency contacts | Explicit consent — turned off by default |
| Crash reports & diagnostics | Legitimate interests in maintaining a reliable service |
| Anonymous usage analytics | Legitimate interests, balanced against your right to opt out (Settings → Privacy) |
| Subscription billing | Performance of a contract |
| Responding to your support tickets | Performance of a contract |
| Preventing fraud, abuse, and spam | Legitimate interests |
| Complying with court orders, subpoenas, lawful requests | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
We do not sell, rent, lease, or “share” your personal data for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA. This applies worldwide.
To operate the Service we rely on a small set of trusted vendors, each bound by data-processing agreements. Current sub-processors:
| Vendor | Purpose | Data they receive | Location |
|---|---|---|---|
| Supabase | Authentication, database, file storage | Account data, user-generated content, travel documents (encrypted) | EU / US (region depends on project) |
| Sentry | Crash reporting, performance monitoring | Device data, stack traces, anonymized user ID | EU |
| Stripe | Subscription billing (when applicable) | Email, subscription tier, payment method token | US (DPF certified) / EU |
| Apple App Store / Google Play | In-app purchase processing | Apple ID / Google account at the OS level | US |
| OpenAI / Anthropic (AI features only) | Generating itinerary suggestions, translations | The text of your prompt — never your profile, posts, or documents unless you paste them | US |
| Mapbox / OpenStreetMap (map tiles) | Rendering maps | Approximate viewport coordinates | US / global |
| Resend or similar email provider | Transactional emails (verify, reset password, ticket replies) | Email address, message body of system emails | EU / US |
We will update this list when sub-processors change and notify users of material changes.
Posts, comments, reviews, photos, and warnings you mark “public” are visible to other WAYVA users and may appear in public web previews of the app. Content marked “friends only” is visible only to people you have connected with. Content marked “private” is visible only to you.
We may disclose your data when we believe in good faith that we are required to do so under applicable law, by court order, or by a valid law-enforcement request. We push back on overbroad requests and aim to publish a yearly transparency report once volume justifies it.
If WAYVA is acquired, merged, or undergoes a change of control, your data may be transferred as part of that transaction. The successor entity will be bound by this Privacy Policy (or one offering at least the same protections). You will be notified in-app before any such transfer becomes effective.
WAYVA serves travelers everywhere, but our infrastructure is hosted in specific regions (typically the EU and/or US, depending on the Supabase project). When you use WAYVA from outside those regions, your data is transferred to those regions for processing.
For EU/UK users, we rely on:
You may request a copy of the relevant transfer safeguards by emailing privacy@wayva.app.
We hold data only as long as needed for the purposes described above.
| Data | Retention |
|---|---|
| Active account data | While your account exists |
| Deleted accounts | 30-day grace period, then permanent deletion. Some backups may persist for up to 90 days but are not used and are overwritten. |
| Support tickets | 3 years after the last message, for legal and quality records |
| Crash logs and diagnostics | 90 days |
| Anonymized analytics | Indefinitely (no longer tied to your identity) |
| Subscription receipts / invoices | 7 years (tax and accounting laws) |
| Moderation records (warnings, suspensions) | As long as needed to enforce community safety, up to 3 years post-removal |
You can shorten any of these by deleting your account.
Regardless of where you live, WAYVA extends the following rights to every user:
You can exercise the access, deletion, and portability rights directly inside WAYVA:
For other rights, email privacy@wayva.app and we will respond within 30 days.
California residents have the rights above and, in addition, the right to non-discrimination for exercising them. WAYVA does not sell or “share” personal information for cross-context behavioral advertising, so there is no need to submit a “Do Not Sell or Share My Personal Information” request — but you may still email us to confirm.
You have all the rights above and may lodge a complaint with your supervisory authority.
WAYVA is not intended for users under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us their data, contact privacy@wayva.app and we will delete it.
We take security seriously:
No system is perfectly secure. If we ever experience a breach affecting your personal data, we will notify affected users as soon as reasonably possible and, where required by law, the relevant authorities.
The web version of WAYVA uses:
localStorage or SecureStorage, to keep you signed in.We do not use third-party advertising cookies. We do not use cross-site tracking pixels.
A separate Cookie Policy is available at /legal/cookies in the app.
Because travel is the heart of what WAYVA does, here are some travel-specific points we want to be explicit about:
We may update this Privacy Policy from time to time. When we make material changes:
Non-material changes (typos, clarifications) may be made without notice. Past versions of this policy are available on request.
For any privacy questions, requests, or complaints:
We aim to respond within 5 working days, and to fulfill verifiable rights requests within 30 days.
WAYVA is committed to protecting your privacy as carefully as you protect yourself on the road.