1. Controller
Binoron, LLC, 1111B S Governors Ave # 47095, Dover, DE 19904, United States, is responsible for the Waywoven processing described in this notice.
Privacy requests can be sent to hello@waywoventravel.com. The website contact form is disabled and transmits no entries.
2. Scope and current product status
This notice covers the public information and journal website at waywoventravel.com, the protected travel app at app.waywoventravel.com, and the related account, payment, support, email, and affiliate boundaries. Private journeys, bookings, and family details are not transferred to the public website.
When registration is open, new accounts are created only for adults through the enabled Google or Apple sign-in routes. Passwordless email remains limited to existing accounts. A Waywoven subscription is purchased only after sign-in inside the protected app through Stripe. The optional four-part planning series and Travelpayouts features apply only when the relevant feature is actually enabled and visibly offered; the sections below explain each boundary.
The free long-trip planning check processes selected answers and the calculated result only temporarily in browser memory. The check does not transmit these details to a Waywoven server, store them in cookies or local storage, or add them to a URL. Switching language, reloading or closing the page removes the answers and result. A deliberate click on copy or print passes the visible output to the device clipboard or print function. Optionally, you can save up to three selected fixed task titles and IDs as a file on your device. The file contains no answers or scores. Selected titles are saved as journey tasks only after you open the file in your signed-in journey, review it and confirm adding the tasks.
3. Technical delivery
The website and protected app are technically hosted on Vercel. A page request may involve technically necessary log data such as IP address, time, requested URL, browser information, and security events. The purposes are delivery, stability, and security.
Accounts, permissions, and private journey content are stored in Waywoven's Supabase project in Frankfurt. Supabase provides authentication, database storage, and server-side access controls. For sign-in, the selected provider, Google or Apple, processes the account, device, security, and OAuth data it needs under its own notices. Waywoven requests minimal sign-in scopes and never stores provider passwords.
The planner map loads tiles for the visible area from tile.openstreetmap.org. OpenStreetMap receives ordinary network and browser data, the referrer, and requested tile coordinates, from which the approximate visible map area may be inferred. Waywoven does not send a complete route, stop list, booking data, or live location as application data to OpenStreetMap.
4. Manual contact email
We use Binoron, LLC’s business Google Workspace mailbox to receive and manually handle messages sent to hello@waywoventravel.com. We send manual replies through Google Workspace using hello@waywoventravel.com as the sender. Google and the participating email providers process sender and recipient details, headers, subject, content, attachments, and delivery and security data.
Please do not send passport or identity copies, full payment details, health information, live locations, or unnecessary child and family information by email. Ordinary correspondence is deleted or reviewed for continued necessity no later than twelve months after the last substantive handling, with longer retention only where needed for legal claims, security, or statutory duties.
4a. Public cancellation and withdrawal declarations
The public cancellation and withdrawal forms work without signing in. To receive and acknowledge a declaration, we process the name, receipt email address, contract information, language and declaration type; cancellations also include the cancellation type and any optional reason and requested date. We store the submitted content with a receipt reference, server-recorded receipt time and receipt version, together with delivery status and necessary handling and review notes. Please do not enter payment, identity-document, health or unnecessary family information.
The data is held in a private Supabase area. Only authorised operators can view the worklist and record how a declaration was handled. The acknowledgement contains your declaration and is sent through Resend to the address provided; Resend and the receiving email provider process the address, message content and delivery data for this purpose. You can also download the receipt directly after storage is confirmed. This process does not subscribe you to marketing or automatically change a subscription or issue a refund.
We process these details to handle your contractual declaration, document its receipt and, where applicable, meet legal obligations. Abuse prevention and necessary evidence also rely on our legitimate interest in a secure and traceable process. Abuse limits use secret-keyed fingerprints of the email address and request source; this record does not contain a raw IP address. The request-source fingerprint becomes due for removal after 48 hours. Removal takes place during a successful run of the configured delivery process and may be delayed by operational failures.
Continued retention of the receipt and handling notes is first reviewed twelve months after receipt and again no later than twelve months after documented resolution. This review is not automatic deletion or a statutory twelve-month retention period. Further retention is considered individually only for a documented continuing purpose, legal claims or statutory duties; without such a purpose, the data is to be deleted. Deleting an account or workspace does not automatically remove these separate contract records. For access or deletion, contact hello@waywoventravel.com; we check secure attribution and any retention obligations. Copies held by participating email providers and in backups are considered separately.
4b. Purchase details and durable contract copy
When you choose a paid plan and confirm the displayed purchase details, we record the offered terms, language, service, price, billing period and declaration actually made, together with its time. We also store the necessary purchaser and workspace references and confirmation address. These details are linked to the specific checkout; a prepared order does not establish that payment occurred. Stripe payment, invoice and subscription references and their verified status are added separately. Full card or bank details and private journey content are not part of this record.
The original version is retained in a private Supabase area and is not overwritten by later text changes. After a paid contract is confirmed, we provide a contract copy you can save and send it through Resend to the address recorded for that purchase. Delivery status and necessary retry and failure records are stored separately; handing a message to the provider does not establish actual inbox receipt. This contractual message does not enrol you in marketing. No additional copy is sent to the manual support mailbox for this purpose.
This processing serves contract administration, provision of the contract copy, applicable legal evidence duties and our legitimate interest in traceable purchase and error handling. Necessary records are retained for as long as required for the contract, its administration, legal claims or statutory duties. Uncompleted orders and resolved matters must be reviewed for continued necessity and deleted when no purpose remains; blanket indefinite retention is not intended. Account or workspace deletion does not automatically remove these separate records. Access and deletion requests are handled after secure attribution and consideration of remaining duties; Stripe, Resend and backup copies are considered separately.
5. Optional email continuation
After the complete check result is visible, and at the end of editorial articles, visitors may be offered an optional four-part planning series over ten days. The check and every article remain available without an email address. Consent covers only this finite series and does not automatically enrol the person in a general newsletter.
For a voluntary request, Waywoven processes the email address, language, explicit consent choice, consent version, and fixed public source page. An empty field hidden from human visitors acts as a bot trap. Check answers, planning score, profile, proposed actions, and trip, family, or child details are not sent. The address and double-opt-in/delivery state are held in a private Supabase area in Frankfurt. Browser roles and the narrowly scoped email-automation role have no direct table access; only named server-side RPCs can process the records required for DOI, delivery, unsubscribe, suppression, and deletion. For abuse control, the IP address and normalized email address are converted only into secret-keyed HMAC values; the raw IP is not stored in the limiter.
The prepared delivery path uses Resend with a durable private Supabase queue. Exactly four messages begin only after a deliberate confirmation step behind an encrypted, purpose-bound, generation-bound, expiring link; an automated link fetch does not confirm. Every message provides a visible and standards-based one-click unsubscribe path. Signed provider events stop the remaining series after a bounce, complaint, or suppression. Open and click tracking remain disabled. Resend may process the address, language, message content, and delivery, unsubscribe, bounce, and complaint events.
Unconfirmed records are deleted seven days after the 48-hour link expires; confirmed series that never complete are deleted 30 days after confirmation, and completed series 30 days after completion. After unsubscribe or provider suppression, the clear address is removed after 30 days while a secret-keyed value retains the necessary suppression state. When the feature is not visibly offered, the endpoint accepts no addresses and sends no series.
6. Optional affiliate features with Travelpayouts Drive and direct links
Travelpayouts Drive is optional affiliate and monetisation technology for expressly reviewed, static, link-free journal articles. The provider is Go Travel Un Limited, a company registered in Hong Kong under number 1658681 with registered office stated in the Travelpayouts Privacy Policy at 4007 Central Plaza, 18 Harbour Road, Wanchai, Hong Kong, operating under the Travelpayouts brand. Under the release described here, only Content Analytics is used after consent. The provider may process visible public article content and DOM structure, page URL and referrer, page views, link destinations, clicks, hover, scroll, media and other content interactions, and browser and device characteristics for fraud and bot detection. Binoron, LLC may receive a commission from a separately labelled affiliate placement after a later booking.
Travelpayouts Drive is not loaded on the journal index, articles with direct affiliate links or interactive tools, or the long-trip planning check and its result pages, even after consent.
Drive is not loaded in the protected app, on sign-in, authentication, or admin pages, or inside private journeys. This does not exclude separately selected, clearly labelled affiliate cards rendered by Waywoven inside the app. Those cards do not load Drive and do not send private journey, family, booking, or user data to Travelpayouts before an intentional outbound click. Waywoven does not send workspace, journey, child, booking, or user identifiers as affiliate parameters. This technical separation does not prevent Travelpayouts from processing information visible on an expressly enabled public journal page and in the visitor's browser.
Individual editorial articles may also contain clearly labelled direct affiliate links. No request to Travelpayouts or the booking provider occurs before a deliberate click. The link carries only a fixed, non-personal SubID for language, article, travel category, and placement. It contains no check answer, score, profile, or user, journey, family, child, or booking identifier. After the click, Travelpayouts and the selected provider process ordinary URL, referrer, browser, attribution, and any booking data under their own terms.
This processing occurs only when the relevant placement is actually enabled. Drive additionally requires active consent. Under this release, automatic link changes, switching other affiliate networks, automatic selection of all connected brands, keyword links, recommendation blocks, smart previews, and Targeted Offers including background tabs remain disabled. Enabling any of these features later would be a new product and data flow requiring a fresh privacy, consent, and presentation review first.
7. Protected app and Stripe payments
The protected app processes account details, private journeys, travellers, stages, booking metadata, tasks, invitations, and permissions in Supabase. Details about children, locations, and bookings are not sent to Stripe.
When a user deliberately begins checkout, Stripe processes information such as email, billing and payment details, tax IDs where supplied, and transaction, invoice, and subscription data. Waywoven does not store card or bank details. Internally it stores only the necessary workspace-to-customer mapping, subscription status, price ID, term, and minimal signature-verified webhook receipts.
7a. Private document files and downloads
When you deliberately upload a document file to a protected journey, Waywoven stores the original file in private Supabase storage alongside its document metadata. Supported formats are PDF, JPEG, PNG, and WebP. Processing covers the file content, name, type, and size, its necessary journey association, and technical verification and deletion records. This provides the shared access to journey documents that you request; original files are not automatically sent to OpenAI, Stripe, or the public website.
Only people with current permission can request a new, short-lived download link. Anyone holding such a link can use it until it expires. Waywoven cannot recall an already downloaded file. The JSON account export includes permitted document metadata but no original files; download any originals you need separately from the journey while you have permission. A journey report is also not a complete file archive.
After file removal or loss of access, Waywoven does not issue new authorised downloads for it. Removal in the planner and physical deletion at the storage provider are separate steps. Server-side cleanup must successfully confirm removal at the provider; failures are retried. Previously issued links, existing downloads, and time-limited provider backups are separate considerations. The restrictions on identity, health, and child details in the Children and families section also apply to uploads.
7b. Encrypted offline travel pass and device copies
You explicitly save the offline travel pass on the device you use. It contains selected journey information such as routes, stops, tasks, providers, and booking references; you may optionally add local addresses, emergency contacts, and ticket files. These additionally selected details and files, and your separate device passphrase, are not sent to Waywoven for this offline feature. The pass and its ticket files are encrypted with your chosen passphrase in local browser storage and the local browser database. Waywoven cannot recover the passphrase.
You choose an expiry date. After expiry, the app refuses to open the pass and removes expired encrypted data when the app or offline page is next opened. This is not guaranteed scheduled deletion on a powered-off device. Signing out, losing workspace membership, or deleting an account cannot remotely wipe an already saved offline copy. Remove it on each affected device through the offline feature or browser data settings. Previously exported, copied, printed, or otherwise saved content and device backups may remain outside Waywoven.
7c. Calendar files and private calendar subscriptions
When you download a calendar file or deliberately open a private calendar link in a calendar app, you give the included journey data to your selected app and, where applicable, its calendar or cloud provider. The subscription includes journey titles, dates, providers, programmes, and payment and cancellation deadlines; it excludes booking references, amounts, private notes, and traveller profiles. Your selected calendar provider may store the link, repeatedly fetch the included data, and process it under its own notices, including outside the EU/EEA.
The private calendar link is an access key: anyone holding it can fetch the limited calendar data without signing in to Waywoven. To manage the subscription, Waywoven stores a secret-bound verification hash instead of the complete link, together with status, version, and access time. Replacing or revoking a link blocks new fetches through the previous link. It does not remove previously imported or cached events from calendar apps, their backups, or exported calendar files. Remove these copies with the relevant provider if needed; its refresh and deletion behaviour is outside Waywoven's control.
8. Optional AI journey planner and speech-to-text
Waywoven uses artificial intelligence only when a signed-in person deliberately invokes the visibly offered AI feature. For a text request, the Waywoven server sends the entered text, chat context needed to continue the exchange, necessary structural constraints, and the minimized journey-planning context described below to the OpenAI API. Text-generation requests are sent with store: false and without tools or web access. The AI does not make a booking or payment, send a message, or take any other external action. The processor for text generation and transcription is OpenAI OpCo, LLC, United States. OpenAI processes submitted customer content as a processor under the applicable Services Agreement and Data Processing Addendum; subprocessors and international transfer mechanisms follow the then-current DPA and OpenAI subprocessor list.
For text requests, OpenAI receives a compact overview of the workspace's non-deleted journeys so the AI can take the journey timeline into account and should not plan a silent parallel journey. When an existing journey is selected, the browser sends only its identifier; the Waywoven server checks workspace access and editing permission, loads the planning data itself, and adds the more detailed ordinary planning state of that target journey: title, status, dates and currency, countries and stops, and each journey item's type, title, dates, association, and ordinary planning notes. A proposal may modify only the selected journey. An AI thread stays bound to its mode and target journey and never silently switches that target.
Speech input is not a live conversation: Waywoven sends only the deliberately completed recording to the OpenAI API for one transcription request, and AI replies are text only. Waywoven does not store the audio file. The returned transcript remains editable before submission and is saved as part of the AI conversation only when the person expressly submits it. The feature makes no solely automated decision producing legal or similarly significant effects. A draft becomes part of a journey only after the person expressly reviews and applies it.
Structured traveller profiles and names, booking references, provider, source and booking-status fields, amounts and payment deadlines, participant assignments, raw import data, the stored free-text starting place, and exact coordinates are not included in AI context loaded from stored journeys. Ordinary free-text planning notes from the selected journey are included and may contain content a person entered. Passports or identity details, health information, exact private addresses or live location, booking references, full payment details, and unnecessary information about children must therefore not be entered in free-text fields or AI requests. Accounts are for adults only.
Waywoven stores submitted AI threads, messages, and change proposals in the private Supabase area so that drafts can be continued, reviewed, accepted, discarded, exported, and deleted with the account or workspace data. For changes to existing journeys, Waywoven also stores the target journey, expected versions and state fingerprints, and the minimal apply and undo receipt. These records support conflict-protected, atomic changes and prevent a journey that was subsequently changed manually from being silently overwritten or reverted.
Waywoven also stores server-side operational and allowance metadata: user and workspace association, request and operation identifiers, a secret-keyed HMAC fingerprint instead of plaintext in the cost ledger, model identifier, status and timestamps, and reserved and actual usage units. This supports safe retries, cost and abuse limits, troubleshooting, export, and deletion. Plaintext prompts, transcripts, and audio are not stored in the cost ledger or Waywoven operational logs; messages and drafts are nevertheless stored in the private workspace as described above.
OpenAI does not use API inputs and outputs to train its models by default unless the customer expressly opts in. As of this notice’s effective date, sharing API inputs and outputs for training and API-call logging are disabled in Binoron, LLC’s OpenAI organization; text requests additionally use store: false. Depending on the endpoint, OpenAI’s default abuse monitoring may retain content for up to 30 days; legal or security exceptions may apply. The project is configured for global rather than EU-only data residency. OpenAI and its subprocessors may process data in the United States, EU/EEA, or other countries; Waywoven does not guarantee EU-only storage or processing.
AI output is an editable draft and may be wrong, incomplete, or out of date. It is not a confirmed booking or evidence of price, schedule, availability, visa or entry requirements, or safety conditions. Before applying or relying on a proposal, the person must review it and verify important details against current primary sources.
9. Purposes, legal bases, and international transfers
Accounts, the planner, expressly invoked AI and transcription features, support, and billing are processed to take steps at a user's request or provide the requested service. Security, abuse prevention, and necessary operational logs rely, where applicable, on legitimate interests in a secure and functioning service. Statutory retention duties remain unaffected. Where enabled, the email planning series and Travelpayouts Drive are used only after voluntary consent.
Binoron, LLC is based in the United States. Providers may process data in the United States, EU/EEA, or other countries. Depending on the provider, transfers rely on the provider's applicable transfer terms, Standard Contractual Clauses, an adequacy decision, or another permitted mechanism. Data Privacy Framework participation is not claimed without provider-specific verification.
Vendor roles depend on the data category, product, and governing contract. Vercel, Supabase, Resend, and OpenAI typically process customer content for Waywoven to the contractually agreed extent, while they may determine their own purposes for account, usage, security, or service data. Stripe may act as a processor and/or independent controller depending on the payment function. Go Travel Un Limited and an external booking provider also process data under their own terms after an intentional click-out or, for Drive, consent.
Google processes message content in our business Google Workspace mailbox as a processor under the applicable Google Workspace agreement and its Data Processing Addendum.
When Drive is enabled, the browser sends the described public usage and device data to Go Travel Un Limited in Hong Kong; its notices allow for further processing in other countries. Waywoven does not claim an adequacy decision for Hong Kong or this provider's participation in the Data Privacy Framework. The applicable vendor role, contractual transfer safeguards, and data-subject-rights handling remain part of the qualified contract and privacy review required before an official customer launch.
10. Rights, export, and deletion
Depending on applicable law, people may have rights to access, correct, delete, restrict, port, or object to processing, withdraw consent, and complain to a supervisory authority.
Signed-in users can export their account, workspace, and journey data, including stored AI threads, messages, change proposals, target bindings, and apply/undo receipts and their AI operations with IDs, status, model, reserved and actual units, cost-catalog version, and timestamps, from the app as JSON. The self-service export excludes both the secret HMAC key and the input fingerprint; further privacy requests may be sent to hello@waywoventravel.com. Account and workspace deletion requests have a 30-day recovery window; final cleanup becomes due afterwards and completes only after successful safety and provider checks. Failures can delay completion; active subscriptions and other members must first be resolved or ownership transferred. After the window, a service-only process first reconciles the technical Stripe Customer and deletes it only when no non-terminal subscription or open Checkout remains. A second step removes the local Customer mapping and due app, AI, and Auth data only after that provider proof. Legally retained invoices and payment evidence at Stripe, and time-limited provider backups, are handled separately.
Requests about these rights can be sent to hello@waywoventravel.com. An activated email series can be stopped through the link in every message. The local affiliate choice can be changed through the affiliate and cookie settings; withdrawing reloads the page so active third-party code is stopped.
11. Retention and security
Incomplete new Auth accounts without completed setup become due for cleanup after 30 days. Account and workspace deletion requests have a 30-day recovery window. Stored AI conversations, drafts, and operational and allowance data are currently deleted together with the associated account or workspace and are included in its export and deletion; an individual AI conversation cannot currently be deleted separately. Non-personal aggregate totals may remain. Waywoven does not store speech-input audio files. Short-lived affiliate abuse records are removed after 24 hours and non-personal click aggregates after 90 days. Payment and invoice data remains with Stripe for as long as contractual, tax, or statutory evidence duties require. Provider backups, OpenAI abuse-monitoring logs, and security logs expire under their applicable configured or contractual periods.
For recovery, we store encrypted backup copies of the Waywoven database and associated artwork files in Google Drive within Google Workspace and in a separate Google Drive account outside Google Workspace. Decryption keys are kept separately. Backup retention and deletion are considered separately from the active service.
Waywoven stores no server-side copy of Drive Content Analytics. Data already sent to Go Travel Un Limited is retained under its applicable notices, contract, and legal duties; Waywoven cannot currently promise its own fixed deletion period for that provider data. Withdrawal and deactivation prevent future Drive loads but do not retroactively delete data already received by the provider. Privacy requests may be sent to Waywoven and, where required, to the provider.
Waywoven uses tenant-bound access rules, server-side authorisation checks, encrypted transport, minimal vendor permissions, and separated public and private systems. No internet service can guarantee absolute security.
12. Children and families
Waywoven is a planning tool for responsible adults and is not directed to children. Accounts may be created only by adults. An adult may enter minimal information about travelling children only when the adult has parental responsibility or other lawful authority; passport numbers, identity documents, health information, exact private addresses, live location, and unnecessary child details do not belong in Waywoven or AI requests. Children do not receive their own accounts in the current product. Travelpayouts Drive receives no access to protected family journeys or child profiles.
