WAYVA Legal

Privacy Policy and Terms of Service for WAYVA — solo travel companion app

View the Project on GitHub amigoraj/wayva-legal

WAYVA Privacy Policy

Effective date: 31 May 2026 Last updated: 31 May 2026

This Privacy Policy explains how WAYVA (“WAYVA”, “we”, “us”, “our”) collects, uses, shares, and protects your personal information when you use our mobile and web applications, our backend services, and any related sites (collectively, the “Service”).

WAYVA is a travel companion app designed for solo travelers, with a primary focus on Southeast Asia. Because the Service is used while you travel — often across borders, on shared networks, and in safety-sensitive contexts — we treat your data with particular care. This policy is written to be specific and honest. If anything here is unclear, contact us at privacy@wayva.app.


1. Quick Summary (Plain English)

If you are a Google Play Data Safety reviewer: the data categories disclosed on our Play Store listing are aligned with Section 4 below.


2. Who We Are

WAYVA is operated by the company or sole proprietorship identified on our App Store / Google Play listing. References below to “WAYVA” mean that legal entity. Our primary contact for privacy questions:

If you are in the European Economic Area or the United Kingdom and would like to contact our designated representative, email privacy@wayva.app and we will respond with the appropriate contact.


3. The Data We Collect

We collect information in three ways: you give it to us, the app collects it automatically when you use a feature, and a small amount comes from third parties (only authentication providers like Google and Apple, only with your consent).

3.1 Information you give us

Category Examples Required?
Account identifiers Email address, password (hashed), username, display name Required to sign up
Profile Home country, primary language, home currency, optional bio, optional avatar Required (country/language); rest optional
Travel preferences Travel style, interests, budget level, dietary preferences Optional
Emergency contacts Names, phone numbers, email addresses, relationship of people you nominate to be contacted in an emergency Optional
Travel documents Passport number, expiry date, document scans, visa records — all encrypted at rest with a key separate from the database Optional
Posts, comments, photos, reviews, tips, warnings, trip plans, saved places, journal entries Anything you publish or save inside WAYVA Optional
Support content The text and attachments of support tickets you file Created when you file a ticket
Payment information If you subscribe: we process payment via the App Store, Google Play, or Stripe. We never see your full card number. We retain only the subscription receipt token and the last 4 digits for billing support. Required to subscribe

3.2 Information collected automatically

Category Purpose Granularity
Approximate location (IP-derived) Country-level for currency, language, and travel advisories Country only; not stored long-term
Precise location (GPS) Only when you tap a feature that needs it — map view, nearby places, SOS, “share my live location”. Always foreground unless you opt-in to a session. Lat/long ± device accuracy
Device data Device model, operating system version, app version, screen size, language, time zone Coarse only — no IMEI, no MAC
Diagnostics Crash reports, performance traces, error stack traces (via Sentry) Excludes message content, post bodies, and travel documents
App usage signals Which screens you visit, which features you use, button taps. Aggregated and anonymized for product improvement. Pseudonymous; not joined to your account profile in analytics
Network / security IP address, request timestamps, user-agent — held only long enough to detect abuse 30 days then aggregated

3.3 Information from third parties

If you sign in with Google or Apple, we receive your email and a unique provider ID. We do not request your contacts, calendar, drive files, photos, or any other data from those providers. We never receive your password.

We do not purchase personal data from data brokers, marketing platforms, or any third party.

3.4 Data we do not collect

To be explicit:


4. Google Play Data Safety Disclosure Summary

This section maps our practices to the Google Play Data Safety taxonomy.

4.1 Data collected

Data type Collected Shared with 3rd parties Optional Purpose
Name Yes No Yes App functionality, personalization
Email address Yes No No Account, support
User IDs Yes No No Account
Password (hashed) Yes No No Account
Photos Yes No Yes App functionality
Approximate location Yes No Yes App functionality
Precise location Yes No Yes App functionality, safety
Address No
Phone number Yes No Yes Emergency contacts; phone sign-in (if used)
App interactions Yes No No Analytics, fraud prevention
Crash logs Yes Yes (Sentry) No App performance
Diagnostics Yes Yes (Sentry) No App performance
Purchase history Yes Yes (Stripe / App Store / Play) No Account, billing
Files & docs (visa/passport, if uploaded) Yes No Yes App functionality
Personal documents (travel) Yes No Yes App functionality
Health & fitness No
Financial info Limited (subscription only) Yes (payment processor) No Billing
Contacts No
Calendar No
Web browsing history No
SMS/MMS No
Audio recordings No
Race/ethnicity, religion, sexual orientation, political views No

4.2 Security practices


Under GDPR and similar laws, we rely on the following lawful bases:

Purpose Legal basis
Creating and operating your account Performance of a contract
Showing you the map, nearby places, weather, currency Performance of a contract
Sending you safety alerts you have enabled Performance of a contract / vital interests
Storing travel documents you upload Consent — you can delete at any time
Sharing your live location with emergency contacts Explicit consent — turned off by default
Crash reports & diagnostics Legitimate interests in maintaining a reliable service
Anonymous usage analytics Legitimate interests, balanced against your right to opt out (Settings → Privacy)
Subscription billing Performance of a contract
Responding to your support tickets Performance of a contract
Preventing fraud, abuse, and spam Legitimate interests
Complying with court orders, subpoenas, lawful requests Legal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.


6. How We Share Your Data

6.1 We never sell your data

We do not sell, rent, lease, or “share” your personal data for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA. This applies worldwide.

6.2 Sub-processors

To operate the Service we rely on a small set of trusted vendors, each bound by data-processing agreements. Current sub-processors:

Vendor Purpose Data they receive Location
Supabase Authentication, database, file storage Account data, user-generated content, travel documents (encrypted) EU / US (region depends on project)
Sentry Crash reporting, performance monitoring Device data, stack traces, anonymized user ID EU
Stripe Subscription billing (when applicable) Email, subscription tier, payment method token US (DPF certified) / EU
Apple App Store / Google Play In-app purchase processing Apple ID / Google account at the OS level US
OpenAI / Anthropic (AI features only) Generating itinerary suggestions, translations The text of your prompt — never your profile, posts, or documents unless you paste them US
Mapbox / OpenStreetMap (map tiles) Rendering maps Approximate viewport coordinates US / global
Resend or similar email provider Transactional emails (verify, reset password, ticket replies) Email address, message body of system emails EU / US

We will update this list when sub-processors change and notify users of material changes.

6.3 Public content

Posts, comments, reviews, photos, and warnings you mark “public” are visible to other WAYVA users and may appear in public web previews of the app. Content marked “friends only” is visible only to people you have connected with. Content marked “private” is visible only to you.

We may disclose your data when we believe in good faith that we are required to do so under applicable law, by court order, or by a valid law-enforcement request. We push back on overbroad requests and aim to publish a yearly transparency report once volume justifies it.

6.5 Business transfers

If WAYVA is acquired, merged, or undergoes a change of control, your data may be transferred as part of that transaction. The successor entity will be bound by this Privacy Policy (or one offering at least the same protections). You will be notified in-app before any such transfer becomes effective.


7. International Data Transfers

WAYVA serves travelers everywhere, but our infrastructure is hosted in specific regions (typically the EU and/or US, depending on the Supabase project). When you use WAYVA from outside those regions, your data is transferred to those regions for processing.

For EU/UK users, we rely on:

You may request a copy of the relevant transfer safeguards by emailing privacy@wayva.app.


8. Data Retention

We hold data only as long as needed for the purposes described above.

Data Retention
Active account data While your account exists
Deleted accounts 30-day grace period, then permanent deletion. Some backups may persist for up to 90 days but are not used and are overwritten.
Support tickets 3 years after the last message, for legal and quality records
Crash logs and diagnostics 90 days
Anonymized analytics Indefinitely (no longer tied to your identity)
Subscription receipts / invoices 7 years (tax and accounting laws)
Moderation records (warnings, suspensions) As long as needed to enforce community safety, up to 3 years post-removal

You can shorten any of these by deleting your account.


9. Your Rights

Regardless of where you live, WAYVA extends the following rights to every user:

You can exercise the access, deletion, and portability rights directly inside WAYVA:

For other rights, email privacy@wayva.app and we will respond within 30 days.

9.1 California (CCPA / CPRA)

California residents have the rights above and, in addition, the right to non-discrimination for exercising them. WAYVA does not sell or “share” personal information for cross-context behavioral advertising, so there is no need to submit a “Do Not Sell or Share My Personal Information” request — but you may still email us to confirm.

9.2 EEA / UK (GDPR / UK GDPR)

You have all the rights above and may lodge a complaint with your supervisory authority.

9.3 Children

WAYVA is not intended for users under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us their data, contact privacy@wayva.app and we will delete it.


10. Security

We take security seriously:

No system is perfectly secure. If we ever experience a breach affecting your personal data, we will notify affected users as soon as reasonably possible and, where required by law, the relevant authorities.


11. Cookies and Similar Technologies

The web version of WAYVA uses:

We do not use third-party advertising cookies. We do not use cross-site tracking pixels.

A separate Cookie Policy is available at /legal/cookies in the app.


12. Travel-Specific Considerations

Because travel is the heart of what WAYVA does, here are some travel-specific points we want to be explicit about:


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

Non-material changes (typos, clarifications) may be made without notice. Past versions of this policy are available on request.


14. Contact Us

For any privacy questions, requests, or complaints:

We aim to respond within 5 working days, and to fulfill verifiable rights requests within 30 days.


WAYVA is committed to protecting your privacy as carefully as you protect yourself on the road.