Legal
Privacy Policy
This policy covers both app.wayora.ai, where you plan and book your trips, and wayora.ai, our public site. The data controller is the same for both; where the two differ, this policy says so.
1. Who is responsible for your data
The data controller is Wayora S.r.l., Via Altinate 125, 35121 Padova, Italy, VAT IT05799040281.
For anything related to your personal data, write to privacy@wayora.ai.
2. What data we collect
Account data. Your email address and name. You sign in with a one-time code we send to your email; there is no password to create, remember or store.
Traveller details. When you book a trip, we ask for each traveller: title, first and last name, date of birth, gender, phone number and country of residence, plus the email address of the lead traveller. We need these to issue bookings in each traveller's name.
Passport details. Only when a fare in your trip requires them: passport number, issuing country and expiry date. If no service in your trip requires them, we do not ask for them.
Travellers other than you. If you book for other people, you provide their details on their behalf. Please make sure they know about this policy; it covers their data too, and the rights below belong to them as well.
Payment. Payments are handled by our payment infrastructure. We never see or store your full card number.
Trip and conversation data. Your itineraries, travel preferences, bookings, and the messages you write in the planning chat.
Technical data. Your IP address at the moment of booking (an anti-fraud requirement of one of our accommodation suppliers), your language and basic referral parameters if you reached us through a link or campaign.
When you contact us or ask for access. Messages you send through the contact form and support requests; your email address if you ask for early access; and, if someone invites you to a group trip, the name and email address used for the invitation.
We do not use analytics or tracking tools, so there is no "usage data" category in this policy. What we don't collect, we don't have to protect.
3. Why we use your data
- To plan, book and manage your trip, including your account, your Wayora Miles balance, your booking confirmation and your Trip Kit: performance of the contract with you.
- To meet legal obligations: invoicing, accounting and tax rules require us to keep certain booking records.
- To keep the service secure and prevent fraud: including sharing your IP address at booking where a supplier requires it: our legitimate interest in running a safe service, and the defence of legal claims.
- Where we ask for your consent: such as the consent box at checkout, the processing described there. You can withdraw consent at any time.
4. Who receives your data
We share personal data only with the parties needed to deliver your trip:
-
Travel providers: the airlines, hotels and other suppliers that fulfil your bookings receive the traveller details needed to issue them (bookings and tickets are nominative).
-
Our payment processor: to handle payments.
-
Our database and hosting providers: to store and serve your data.
-
Our AI provider: the messages you write in the planning chat are processed to build your itinerary. They are not used to train the provider's models.
-
Our email provider: to send transactional emails such as booking confirmations.
We never sell your personal data.
One detail worth knowing: the booking confirmation email is sent to the lead traveller's email address, which may not be the account that paid for the trip.
5. Where your data is processed
Our database runs on servers in the European Union. However, when you book a trip, the traveller details needed to issue your bookings go to the travel providers that fulfil them, wherever your destination requires. For destinations outside the EEA, this transfer is necessary to perform your contract; where safeguards such as Standard Contractual Clauses apply, we rely on them.
6. How long we keep your data
Booking and payment records are kept for as long as invoicing, accounting and tax law requires.
You can ask us to delete your data at any time by writing to privacy@wayora.ai. We will delete everything we are not legally required to keep, and tell you what we kept and why.
7. Your rights
You have the right to:
- access the data we hold about you;
- rectify it if it is wrong;
- erase it ("right to be forgotten"), within the legal limits above;
- receive it in a portable format;
- restrict or object to processing based on our legitimate interest;
- withdraw your consent at any time, where processing is based on consent;
- complain to a supervisory authority: in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or the authority of your country of residence.
To exercise any of these rights, write to privacy@wayora.ai.
8. Minors
Wayora accounts are for adults: you must be at least 18 to use the service. Minors can be travellers on a booking made by an adult; in that case the adult provides the minor's details, and only what is needed to issue the booking.
9. How we protect your data
Data travels encrypted (HTTPS/TLS). Personal data is stored with qualified infrastructure providers that apply industry-standard security measures, and access is limited to what is needed to operate the service.
10. Cookies
Cookies and similar technologies have their own page: see our Cookie Policy.
11. If you apply for a job with us
When you apply we ask for your first and last name, your email address, the position, your LinkedIn profile and your CV as a PDF. A phone number, other links and a few lines about yourself are optional. Some positions also ask for work references: the company and the person there who can vouch for your work, and their contact details only if you want to leave them.
We process all of this to read and evaluate your application, at your own request and before any contract exists between us.
Naming a reference means handing us another person's data, so we contact them only after telling you.
We keep an application for twenty-four months, and then it deletes itself, your CV included. If you would rather we deleted it sooner, write to privacy@wayora.ai.
Your application is read only by the people at Wayora who evaluate applications; as with everything else, the data sits on the infrastructure providers listed in section 4. Your CV is not publicly reachable — it opens from our internal panel, by an authorised person, and every time it is opened stays on record.
The rights described in section 7 apply here too.
12. Changes to this policy
We may update this policy. The current version and its publication date are shown on this page.