Legal

Cookie Policy


Wayora uses very few cookies. This page lists every one of them, the third-party services our pages load, and how long each lasts. The list is short because the reality is short: no analytics, no advertising, no tracking.

1. Essential cookies (always active)

These cookies are required for the platform to function. They cannot be disabled.

  • Authentication session: keeps you signed in. Set by Supabase, the service that runs our database and sign-in.
  • Language preference (NEXT_LOCALE): remembers your selected language.

2. Third-party services loaded by our pages

Some parts of Wayora are built on services run by other companies. When a page that uses one of them opens in your browser, your browser connects to that company directly. This means it receives your IP address and, in some cases, sets its own cookies. Each service below is listed with what it does, where it appears, and what it stores.

These services are loaded because a feature you asked for depends on them: a map needs a map provider, a payment needs a payment processor. None of them are used for advertising or profiling.

  • Google Maps (maps.googleapis.com): draws the map of your trip stops and the route between them. It loads only on the itinerary planning pages, which require you to be signed in; it is not present on our public pages. Google may set its own cookies and receives your IP address. Category: functional, part of the planning feature.

  • Stripe (js.stripe.com): processes your payment and checks for fraudulent transactions. It loads only on the checkout pages. Stripe sets the cookies __stripe_mid and __stripe_sid, which it uses to recognise the browser making a payment. Category: functional, part of the payment feature.

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com): supplies the Onest typeface inside the payment module, which runs in a frame provided by our payment processor. Only there does your browser contact Google, which therefore receives your IP address. Our own pages serve the typeface from our servers and do not contact Google. Category: functional, payment module typography.

  • Wikimedia Commons (upload.wikimedia.org): is a fallback source for activity photographs. Wayora normally copies the photograph to its own storage, and your browser loads it from Supabase. If that copy fails, your browser may instead load the image directly from Wikimedia, which then receives your IP address. Category: functional, fallback activity imagery.

  • Supabase (*.supabase.co): runs our database, sign-in and file storage. Its cookies are the session cookies described in section 1. Category: essential.

3. No analytics

Wayora currently uses no analytics or product-measurement tools. There is no Google Analytics, no session recording and no product-analytics SDK in the site. If we add one, we will update this page and ask for your consent first.

4. Functional local storage

These entries store choices in your browser between visits. Some of their values are sent to Wayora when you use the related feature, for example when you generate an itinerary with your saved departure airports.

  • Cookie choice (wayora_cookie_consent): records the choice you made in the cookie banner.

  • Departure airports (wayora_departure_airports): remembers your preferred departure airports.

  • Trip checklist (wayora.checklist.<booking>): remembers which items you have ticked in your Trip Kit packing checklist.

  • Interface hints (wayora_carousel_hint_seen): remembers that you have already seen a one-time interface hint.

  • Booking selection (wayora_booking_selection, sessionStorage): stores a room selection within a single browser session; it is cleared when the tab closes.

  • Traveller details in progress (wayora_traveler_draft_<itinerary>): keeps the traveller details you are entering at checkout — names, dates of birth, contact details, nationality and country of residence, including those of any children travelling with you — so that reloading the page does not lose them. This copy stays in your browser and is never sent to our servers; the details reach us only if you complete the booking. Passport details are never kept here. They are deleted when the booking is completed, when you sign out, and in any case 24 hours after you entered them.

  • Trip planning conversation in progress (wayora_intake_conversation): keeps only an identifier for the conversation you are having with the assistant, so that reloading the page does not make you start over. No message is kept in your browser: the conversation stays on our servers and is returned only to you. It is deleted when you sign out, when the conversation produces an itinerary, and in any case 24 hours later.

5. How long they last

  • Language preference (NEXT_LOCALE): for the browser session when the language is detected automatically; stored for 1 year when you actively choose a language.

  • Authentication session: our sign-in provider manages its duration and may refresh it automatically while you use Wayora. It ends when you sign out or when the session is otherwise invalidated.

  • Stripe cookies: __stripe_mid lasts about one year, __stripe_sid about 30 minutes, as documented by our payment provider.

  • Local storage: most entries in section 4 have no expiry date: they stay until you clear your browser data. Three are the exception: the booking selection lasts for the session only and is cleared when the tab closes, the traveller details in progress are deleted 24 hours after they are entered, when you sign out or when the booking is completed, and the planning conversation identifier is deleted 24 hours later, when you sign out or when the conversation produces an itinerary.

6. What we don't use

We do NOT use advertising cookies, tracking pixels, or retargeting technologies. We do not share your browsing data with ad networks.

7. Our public site (wayora.ai)

Everything above describes app.wayora.ai, where you plan and book. Our public site wayora.ai works differently in one respect, and it is the reason this section exists: it uses Google Analytics 4 to understand how the site is used.

Google Analytics loads only after you accept it. Until you choose, and if you choose "Necessary only", the script is never loaded and no request is sent to Google: it is not a matter of cookies being blocked, it is that nothing is loaded at all. Your choice is remembered on that site, and you can change it by clearing your browser data for wayora.ai.

The public site uses no other analytics tool and no advertising cookies.

8. Managing your preferences

Essential cookies cannot be disabled: the site does not work without them. The third-party services in section 2 load as part of the feature they belong to: the map on the planning pages, the payment form at checkout and its typeface, and, as a fallback, activity photographs.

Wayora does not currently offer a cookie settings panel, because there is no optional category to manage: everything we load is either essential or part of a feature you are using. Your browser lets you block cookies or scripts per site, though doing so may stop the related feature from working. To remove what is stored in your browser, delete this site's data in your browser settings.

For any question or request about cookies: privacy@wayora.ai.

9. Contact

Questions about our cookie use: privacy@wayora.ai