W

Loading your travel experience...

Privacy Policy

Last updated: September 15, 2026

1. Who we are (Data Controller)

The data controller responsible for your personal data is Andrey Sobolevsky, a sole proprietor (entreprise personne physique / eenmanszaak) trading as "Waivoo", registered in the Belgian Crossroads Bank for Enterprises (KBO/BCE) under enterprise number 0772.527.301, VAT BE 0772.527.301, with registered address at Chaussée de Tervuren 145, 1410 Waterloo, Belgium ("Waivoo", "we", "our", "us"). You can contact us at support@waivoo.com for any matter relating to your personal data.

We have not appointed a Data Protection Officer because our processing activities do not meet the mandatory thresholds set out in GDPR Art. 37(1). Any data-protection matter is handled by our privacy contact at support@waivoo.com.

2. What this policy covers

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use Waivoo's website, mobile app, and AI travel-planning service (together, the "Service"). It applies to anyone using the Service, including visitors who never create an account, to people whose email address a Waivoo user gives us so that we can invite them to a shared trip (see 3.6), and to people a Waivoo user adds by name as a guest in a trip's expenses (see 3.7).

3. Personal data we collect

3.1 Account data

  • Email address, username, first and last name
  • Optional: phone number, travel preferences (destinations, style, budget, dietary restrictions, accessibility needs)
  • Password hash (we never store the plaintext password)
  • If you sign in with Google: your Google email, Google account ID, profile picture URL, and name as returned by Google OAuth

3.2 Trip and conversation data

  • Messages you send the AI travel agent (chat content)
  • AI-generated itineraries and recommendations
  • Search parameters (destinations, dates, traveller counts)
  • Your approximate location, if your browser asks you and you allow it when you open a trip. It is used only to suggest the city you are departing from; it is not stored for tracking and not used to follow you around. You can refuse it and simply type your departure city instead
  • If you share a trip or join one shared with you: the messages in that trip are shown, with the display name of the person who wrote each one, to the trip's owner and every member — see 3.6
  • Trip expenses: the expenses, settlements and guest names that you or other people on the trip record in its expense ledger, including entries the AI records from chat messages or reads from a receipt you scan — see 3.7

3.3 Billing data

  • Stripe customer ID, subscription status (including free-trial start and end dates), plan, billing interval, renewal date, invoice history
  • We never see or store your card number, CVV, or bank credentials — those are entered directly into Stripe's hosted checkout. When you start a free trial, Stripe securely stores a token for your payment method so the subscription can convert automatically; we only see that a payment method is on file, never its details.

3.4 Technical & usage data

  • IP address (truncated to /24 after 30 days), browser user-agent, device type, operating system
  • Request timestamps, response latency, error codes
  • AI token consumption (input and output token counts per session) — needed to enforce plan limits; only output tokens, including the model's reasoning, count toward your plan's limit. In a shared trip, consumption caused by a member's prompt is counted against the owner's plan (see 3.6)
  • Feedback you send via the in-app widget, including any screenshots you choose to attach

3.5 Community content

If you post a comment on an article in our Explore section, we collect and publish:

  • the text of your comment, exactly as you wrote it
  • a public display name, taken from the first and last name on your account. We never publish your username or your email address — if you signed up with Google your username is the first part of your email address, so we deliberately never use it publicly
  • which article you commented on, and which comment you replied to
  • the date and time you posted, and of any later edit or removal
  • whether the comment was posted by a member of Waivoo staff

This category is public by design. Comments appear on a public web page: they are visible to anyone, with no account and no sign-in, and can be indexed by search engines, cached, and copied by third parties beyond our control. Please do not include personal details — yours or anyone else's — in a comment.

Internally, and not publicly, we also store the account the comment belongs to (your user ID and email address) so that you can delete your own comments and so we can act on reports, and — where staff moderate a comment — which staff member did so, when, and any internal note. We do not store your IP address with a comment.

3.6 Shared trips and invitations

If you share a trip, are invited to one, or join one, we process:

  • Invitations: the email address the trip's owner typed in — if you were invited, we got your address from that owner, not from you — plus a one-way fingerprint (hash) of the address, which trip the invitation is for, who sent it, the access offered (can plan or can view), when it was sent and when it expires, and whether it was accepted (and by which account), revoked, or has expired. When an owner sends an invitation we also check whether the address belongs to someone already on that trip, so the same person is not invited twice
  • Share links: whether the owner has turned a link on, the access it gives, who created it, and when it was created, reset, or turned off
  • Memberships: which accounts are members of a trip, the access each one has, who invited them, whether they joined through a link or an invitation, and when they joined or their access last changed. When someone leaves a trip or is removed from it, we record that (their account, the trip and when) so that a share link that existed at that moment cannot add them back
  • Who wrote each message: the account that sent each message in a trip, so the trip can show that person's display name (first name and last initial) next to it
  • Usage in shared trips: AI usage caused by a member's prompt is recorded against the owner's plan together with the member's user ID, so the right allowance is charged and we can investigate misuse

Who sees what. The owner and every member see the whole trip, including every message in it with its author's display name, and anything the AI drew from the owner's saved travel preferences when planning it (for example dietary or accessibility needs mentioned in the itinerary) — if you own a trip, review what is in it before you share it. The owner also sees the email address of each member's account and of each pending invitation; members see display names only. Travel documents uploaded to a trip are visible only to its owner. We never show members the owner's email address, plan name, usage figures, or payment details. If planning in a shared trip pauses because of the owner's plan, members see a short message that names the owner and says only whether the trip's AI budget is used up, the owner's subscription needs attention, or the owner has no active plan. We never show anyone your username.

If you received an invitation. A Waivoo user gave us your email address and asked us to send you a one-off invitation to their trip. We use your address only to send that invitation, to limit how many invitations reach the same address, and to keep only one invitation to the same trip working for that address at a time; we do not add it to any mailing list, and sending the invitation does not tell the owner whether you have a Waivoo account. See section 7 for when we erase it and section 9 for your rights, including your right to object.

3.7 Trip expenses

If you or anyone else on a trip uses its expense ledger, we process:

  • Expenses: the description, category, amount and currency, date (and trip day), an optional note, who paid and how much, who shares the cost and how it is split, the exchange rate used, where that rate came from (entered by a person, the European Central Bank, or our built-in approximate table) and its date, the converted amount, and whether the entry was typed in, recorded from a chat message, or filled in from a receipt
  • Settlements: repayments someone on the trip marks as paid — who paid whom, how much, when, and an optional note
  • People in the ledger: which accounts take part (the owner and the members of the trip are added automatically), the names of guests (see below), a colour used to show each person, and whether a person has been archived or merged into another
  • Who did what: the account that recorded and last changed each entry, and a history of the most recent changes in the trip (who added, changed, removed, or undid an entry, when, and what the entry looked like before and after)
  • Usage: AI usage caused by an expense message or a receipt scan is recorded against the trip owner's account together with the account of the person who caused it (see 3.4), and we briefly count receipt scans per account and per trip to prevent misuse

We do not collect bank-account, card, or payment-app details for trip expenses, and no money moves through Waivoo.

Who sees it. The trip's owner and, on a shared trip, every member — including members who can only view — see the whole ledger: every expense and settlement, the balances, guest names, the display names (first name and last initial) of the account holders in it, and who recorded or changed each entry. A member who leaves the trip or is removed from it stays in the entries they took part in under their display name, so the balances still add up.

Guests. A guest is someone without a Waivoo account — for example a travel companion — whom the owner or a member adds to a trip's ledger by name, or whom the AI adds when a message about an expense names them. If you are a guest, we received your name from the person who added you, not from you, together with the expenses and repayments recorded for you. We store only the name as it was typed (up to 60 characters) and those entries. We have no contact details for guests and never contact them, so this section is how we inform them. The owner and members who can plan can rename a guest (for example to initials), merge a guest into a member's account once that person has joined the trip, and remove a guest who is not part of any expense or settlement. See section 9 for guests' rights.

Expense messages and the AI. When a message in a trip may be about expenses (for example it mentions an amount, a currency, or who paid), or is sent while the trip's Expenses tab is open, it is sent to our AI provider (Google Gemini, see section 5) together with the recent conversation, the names of the people in the ledger (including guests), and the trip's recent expenses, so the AI can tell whether it is about expenses and record, change, or answer questions about them. A message that turns out not to be about expenses is then handled by the trip planner as usual. The AI only extracts what the message says; balances and splits are calculated by our own code. Those messages, and the replies confirming what was recorded (which name the people involved as they were named at the time), are part of the trip's conversation like any other (see 3.2).

Receipts you scan. If you scan a receipt, the image or PDF you upload is sent to Google's Gemini API (section 5) to read the merchant or description, the total, currency, date, and items into a draft that you check before saving. We use the file only for that reading and do not keep it: nothing from the receipt is kept unless you save the expense, and then only the details in the saved entry are kept. A receipt can show more than the purchase — for example part of a card number, a name, or a loyalty number — and a photo file can include details your camera added, such as where the photo was taken; crop or cover anything you would rather not send.

Exchange rates. To convert currencies, our servers download the European Central Bank's public daily reference rates. That request contains no personal data: the European Central Bank learns nothing about you or your trip.

We do not collect special-category data under GDPR Art. 9 (health, religion, political opinions, etc.). Please do not send such data in chat messages — if you do, we treat it as ordinary chat content and ask you to delete it via your account. Expense descriptions and notes can reveal such data too (for example a pharmacy or clinic visit): keep them general, and never record such details about someone else.

4. Why we process your data and on what legal basis

For each purpose below, we list the lawful basis under GDPR Art. 6:

  • Provide the Service (account, chat, itineraries, payment processing) — performance of a contract (Art. 6(1)(b)).
  • Authenticate you and keep the Service secure (login, fraud and abuse detection, rate-limiting) — legitimate interests (Art. 6(1)(f)) in protecting the Service and our users.
  • Bill you and prevent payment fraud — contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax and accounting record-keeping.
  • Send service emails (verification, billing receipts, free-trial and renewal reminders, security alerts, material changes to Terms / Privacy) — contract and legal obligation. We also send trip invitations a user asks us to send; their legal basis is set out below.
  • Improve the Service and our AI models using aggregated or pseudonymised conversation patterns — legitimate interests (Art. 6(1)(f)). You may object at any time (see §9).
  • Host a public discussion on our articles (publishing your comment and display name, showing them to other readers, keeping the thread readable, moderating abuse and spam, and keeping a record of moderation decisions) — performance of a contract (Art. 6(1)(b)) for publishing the comment you chose to post, and legitimate interests (Art. 6(1)(f)) in running a safe, useful, lawful public section and in being able to answer a complaint about something posted on it. You can delete any comment yourself at any time, and you may object to this processing (see §9).
  • Share trips and run shared planning (letting an owner turn on a share link or invite people, giving members the access the owner chose, showing each message with its author's display name, showing the owner who has joined and the email address of their account, keeping travel documents private to the owner, and charging AI usage in a shared trip to the owner's plan while recording which member caused it, and telling members when planning pauses because of the owner's plan, without plan names or figures) — performance of a contract (Art. 6(1)(b)) with the owner, who chose to share the trip, and with each member, who chose to join it; and legitimate interests (Art. 6(1)(f)) of the owner in knowing who uses the planning they pay for, of members in understanding why planning has paused, and of Waivoo in charging the right allowance and preventing misuse of shared allowances.
  • Send a trip invitation (using the email address an owner gives us to send one invitation, checking it against invitation limits, and keeping it for a limited time — see §7) — legitimate interests (Art. 6(1)(f)) of the owner in inviting a travel companion and of Waivoo in providing the feature the owner asked for. We limit the impact on the person invited: one email per invitation, no custom message from the owner, no reuse of the address, a cap on how many invitations any address can receive, and erasure of the address and its fingerprint within 30 days after the invitation ends. You may object at any time, and we will stop further invitations to your address (see §9).
  • Keep a trip's expense ledger (recording expenses and settlements, converting currencies, calculating balances and suggested transfers, showing the ledger and its change history to everyone on the trip, recording expenses from chat messages, and reading receipts you choose to scan) — performance of a contract (Art. 6(1)(b)) with the owner and with each member who uses the ledger; and legitimate interests (Art. 6(1)(f)) of the people on the trip in a shared, accurate record of what each of them paid and owes — which is why a member's entries stay in the ledger under their display name after they leave, and as "Former traveller" after they close their account — and of Waivoo in keeping the ledger consistent and preventing misuse.
  • Keep guests' names in a ledger (storing the name a user enters for a travel companion who has no account, with the expenses recorded for them, and showing it to everyone on the trip) — legitimate interests (Art. 6(1)(f)) of the people on the trip in sharing costs with the people they travel with, and of Waivoo in providing that feature. We limit the impact on guests: we store only a name, no contact details; we never contact guests; the people who can plan in the trip can rename a guest at any time; and a guest can object at any time (see §9). Because we have no way to reach guests, we inform them through this policy rather than individually (Art. 14(5)(b)).
  • Comply with legal requests (court orders, tax audits) — legal obligation (Art. 6(1)(c)).

We do not currently send marketing emails. If we ever do, we will ask for your separate, freely-given, opt-in consent (Art. 6(1)(a)), and you will be able to withdraw it at any time from one click in the email.

5. Who we share your data with (sub-processors)

We do not sell your personal data. We do not share it for advertising, except the consent-based partner tracking by Stay22 described below this table. We share the minimum amount needed with the following sub-processors, each of which is bound by a Data Processing Agreement compliant with GDPR Art. 28:

Sub-processorPurposeLocationTransfer mechanism
DigitalOceanApplication hosting (Kubernetes cluster) and container infrastructureEUIntra-EEA; DPA in place
Amazon Web Services (AWS)Primary database (account, trip, and conversation data) and file storage (trip documents)EU, Stockholm (eu-north-1)Intra-EEA hosting; AWS DPA with SCCs for any support access from outside the EEA
Stripe Payments Europe, Ltd.Subscription billing, invoicing, payment-fraud screeningIreland (data may flow to Stripe Inc., US)EU-US Data Privacy Framework + Standard Contractual Clauses
Google LLC (Gemini API)AI model inference for chat and itineraries, including trip-expense messages and reading receipts you choose to scan (receipt files are not stored by us)United StatesEU-US Data Privacy Framework + Standard Contractual Clauses
OpenAIAI model inference for some chat and planning featuresUnited StatesDPA with EU Standard Contractual Clauses
Google LLC (OAuth, Maps, Places, Directions)Google Sign-In; maps, places, and routing data for itinerariesUnited StatesEU-US Data Privacy Framework
Amazon Web Services (Amazon SES)Transactional email delivery (verification, password reset, service notices, and trip invitations sent at a user's request)EU, Stockholm (eu-north-1)Intra-EEA; AWS DPA with SCCs for any support access from outside the EEA
LangSmith (LangChain, Inc.)Observability and tracing of AI runs to debug and improve quality (traces can include chat content)EU data regionEU-hosted; DPA with SCCs for any US access
Travel-data providers (RateHawk / Emerging Travel Group, SerpAPI, Amadeus)Live hotel and flight availability and prices; they receive only the search parameters (destination, dates, traveller counts) — never your name, email, or account dataEU / United States (varies by provider)DPA / SCCs as applicable; pseudonymous search parameters only
Pexels GmbHDestination imagery for itineraries (receives destination search terms only)Germany (EU)Intra-EEA
Third-party booking sites (airlines, hotels, OTAs, venues)When you click a booking link, you leave Waivoo; only the search parameters needed to deep-link are passed in the URL. Exception: on Explore articles, if you allow partner tracking, the link first passes through Stay22 with a tracking identifier (see below)Varies by providerProvider's own privacy policy applies once you click through

Partner tracking on Explore articles (Stay22) — only with your consent

If, and only if, you allow Advertising and partner tracking in the cookie preferences, our Explore travel articles load a script from Stay22 Technologies Inc. It turns links to booking sites (such as Booking.com, Expedia, Hotels.com, Vrbo, Agoda, Kayak and GetYourGuide) into tracking links so that a booking can be attributed to us and earn us a commission. To do so, Stay22 receives your IP address (from which it derives an approximate location), the full address of the article page, the page you came from, the article's title and text, a fingerprint of your device, and whether you use an ad blocker or private browsing; it also stores identifiers in your browser. Stay22's privacy policy states that it shares information such as your location or region with its booking partners, receives booking details (for example whether you booked and the transaction value) back from them, and that data may be processed outside Québec and Canada, including in the United States and Europe. The script is never loaded on your trips, account, billing or any other page, and never before you consent. Refusing or withdrawing costs you nothing: booking links still work, without the tracking identifier. See our Cookie Policy for every item it stores and Stay22's privacy policy for how Stay22 handles the data.

An up-to-date list is always available on request at support@waivoo.com.

6. International data transfers

When we send personal data to sub-processors located outside the European Economic Area (notably to the United States for Google Gemini, Google OAuth/Maps, OpenAI, and Stripe's US backbone), we rely on one of the transfer mechanisms recognised by GDPR Chapter V:

  • The EU-US Data Privacy Framework, where the recipient is self-certified;
  • EU Standard Contractual Clauses (2021/914) where they are not, or as a back-up, together with a Transfer Impact Assessment we conduct annually.

You can request a copy of the relevant clauses by emailing support@waivoo.com.

7. How long we keep your data

  • Account data: for as long as your account is open. After you delete the account, we remove identifying data within 30 days, except where law requires longer retention.
  • Conversation history & saved trips you own: until you delete them or close your account. You can delete individual trips from the session interface. Messages you send in a trip someone else owns follow the Shared trips rule below.
  • Shared trips: a shared trip belongs to its owner and is kept until the owner deletes it or closes their account; everything in it, including messages members wrote, is then deleted for everyone. Messages you sent in someone else's trip stay in that trip if you leave or are removed. If you close your account, they stay in the trip but are no longer linked to your account or shown with your name, and the usage records of prompts you sent there are unlinked from you too. A membership record is kept while you are a member and deleted when you leave, are removed, or the trip is deleted. The record that you left or were removed is kept until you join that trip again, the trip is deleted, or you close your account.
  • Trip expenses: kept with the trip, and deleted with it when the owner deletes the trip or closes their account. An expense or settlement that someone deletes is permanently erased, including from the trip's change history, within 30 days; messages in the trip's conversation that mentioned it are kept like any other message. The change history otherwise keeps only the most recent changes. Receipt files are not stored at all (see 3.7). If you close your account, your entries in other people's trips stay, because the other travellers' balances depend on them, but they are no longer linked to your account and are shown as "Former traveller", and the record of which entries and changes you made is unlinked from you too. Replies already in a trip's conversation that confirmed an expense keep the names they mentioned when they were written (see §9). A guest's name is kept until someone on the trip renames or removes the guest, the guest is merged into an account, or the trip is deleted. After a rename, the previous name stays in the trip's change history (so the rename can be undone) until that change drops out of the history; removing the guest or merging them into an account also removes their name from the change history.
  • Trip invitations: invitations expire 14 days after they are sent. The invited email address, and the one-way fingerprint (hash) of it that we use only to enforce invitation limits, are erased from the invitation within 30 days after the invitation is accepted, revoked, or expires. The rest of the invitation record, which then no longer contains the address or anything derived from it, is kept until the trip is deleted. If you ask us not to send you trip invitations (see §9), we keep a one-way fingerprint of your address on a do-not-invite list for as long as your request stands. We also keep the email in which you made the request (which contains your address) for as long, and for no other purpose: if we ever have to change the security key the fingerprint is made with, it is the only way to keep honouring your request. Both are deleted when you withdraw it.
  • Comments on Explore articles: published until you delete the comment or close your account, whichever comes first. Either one immediately erases the comment text, the display name shown on it, and the link between the comment and your account, and the comment disappears from the public page at once. An empty, anonymous placeholder may remain in our database so that any replies written underneath it keep their place in the conversation — it carries no content and nothing identifying you. Copies already taken by search engines or other third parties are outside our control and may persist in their caches for a while. Where a comment was removed by our moderators, we keep the moderation record (which staff member, when, and why) for 24 months so we can answer a complaint or a legal request about it; that record does not include the comment text.
  • Billing records: 7 years after the invoice date (Belgian and EU accounting law).
  • Server & application logs: written to our cluster's log stream, which keeps a short rolling window before overwriting. IP addresses stored in our security / audit records are automatically truncated to their /24 network (IPv4) or /48 prefix (IPv6) once older than 30 days.
  • Backups: rolling 30-day retention. Deletion propagates through backups within 30 days of your request.
  • Feedback tickets: 24 months from submission, then deleted or anonymised.

8. Cookies and local storage

We ask for your consent before we load anything from a third party, such as Google Maps, or store anything on your device beyond what the Service strictly needs. Strictly necessary items — the ones that keep you signed in, remember your cookie choice, and carry out actions you start — do not require consent and are always active.

Apart from the consent-based Stay22 partner tracking on Explore articles (section 5), we do not use advertising networks, analytics, tag managers, session replay or tracking pixels.

The full list of every cookie and storage item, with its name, domain, purpose, duration and recipient, is in our Cookie Policy. You can change or withdraw your choices at any time from the Cookie preferences link in the footer of any page. Below is a summary of the main items.

NameTypePurposeLifetime
access_tokenServer-set cookie (httpOnly, api.waivoo.com)The signed JWT that authenticates each request. Not readable by page scripts.30 minutes
refresh_tokenServer-set cookie (httpOnly, api.waivoo.com)Obtains a new session token without asking you to sign in again. Single-use and replaced on every use. This is the longest-lived identifier we store on your device.30 days
access_token, token_type, isAuthenticatedFirst-party cookie (waivoo.com)Copies read by our page server to decide whether you may open a protected pageUp to 24 hours, and never longer than the token is valid
workforce_access_tokenFirst-party cookie + localStorageStaff console session. Only ever set for Waivoo staff accounts.12 hours
waivoo_consentFirst-party cookieRemembers your cookie choices180 days (identical whether you accept or refuse)
waivoo_pending_tripFirst-party cookieHolds the trip request you typed while signed out, so signing in can pick up exactly where you left off30 minutes, deleted the moment it is used
waivoo_pending_shareFirst-party cookieHolds the shared-trip invitation link you opened while signed out, so signing in can take you back to that invitation instead of losing it to the login screen. Contains only the invitation code1 day, deleted the moment it is used
access_token, token_type, isAuthenticatedlocalStorageSession token for the in-page API clientUntil you sign out or clear browser storage
search_prompt_*, initial_prompt_*sessionStorageCarries the trip request you just typed across a single redirectDeleted on first read; at most the browser tab session
new_session_*sessionStorageMarks a trip you have just started in this tab, so it opens as a new trip rather than as one you have no access to. Holds no contentDeleted once the trip is saved; at most the browser tab session
search_session_*localStorage — consent requiredKeeps a copy of trips you have opened on this device, so they load instantly and survive a brief outageUntil you withdraw consent or clear browser storage
waivoo-offline-toursIndexedDB — consent requiredHolds a guided tour you previously chose to download — text, images and audio. Guided tours have been withdrawn, so nothing new is written here, but anything saved earlier is still on your device. Can reach tens of megabytes.Until you delete it or clear site data — no automatic expiry
sid22, hip22, conMeth, visitor_id_id22 and relatedlocalStorage / sessionStorage, written by Stay22 — consent requiredStay22 partner-tracking identifiers on Explore articles (visitor/session id, IP hash, connection type, device-fingerprint id)6 hours for most; the fingerprint id has no expiry and is deleted when you withdraw consent

You can clear any of these at any time from your browser's "cookies and site data" settings, which will sign you out. The Cookie preferences panel also has a control to delete previously downloaded offline tours specifically.

9. Your rights under GDPR

If you are in the EU/EEA, the UK, or Switzerland you have the right to:

  • Access the personal data we hold about you and receive a copy (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16) — you can edit most fields from your profile;
  • Erase your data (Art. 17) — you can delete your account from your dashboard or by emailing us;
  • Restrict processing in certain cases (Art. 18);
  • Data portability — receive your data in a machine-readable JSON export (Art. 20);
  • Object to processing based on legitimate interests, including AI-model improvement (Art. 21);
  • Not be subject to a solely automated decision with legal effect (Art. 22). The Service's AI outputs are advisory — they do not by themselves produce legal or similarly significant effects;
  • Withdraw consent at any time, where consent is the legal basis (Art. 7);
  • Lodge a complaint with a supervisory authority. In Belgium that is the Autorité de protection des données / Gegevensbeschermingsautoriteit, rue de la Presse 35, 1000 Brussels, contact@apd-gba.be. You can also complain to the supervisory authority in your country of residence.

Shared trips. The JSON export in your account includes the trips other people have shared with you that you are still a member of, with each trip's title and the messages you wrote in it. Messages you wrote in a trip you have since left or been removed from stay in the owner's trip and are not in that export; email us and we will provide them as part of your access request. Erasing your account unlinks your messages in other people's trips from you and removes your name from them, but the trip belongs to its owner and stays with them; if you want the content of particular messages erased too, email us and we will do so where the law requires it. If you received a trip invitation, you can ask us at the address below to erase your email address or object to its use. If you object, we revoke any pending invitation to your address, erase the address from our invitation records, and add a one-way fingerprint of it to a do-not-invite list so that no one can send it another Waivoo trip invitation. We keep your objection email for as long as the objection stands, so that we can go on honouring it (see §7).

Trip expenses. The JSON export in your account includes the expense ledger of each trip you own, with guest names, and, for each trip shared with you that you are still a member of, the expenses you paid or share in and the settlements you are part of, with the other people in them shown only as "another traveller". For a trip you have left, email us and we will provide your entries as part of your access request. If an entry about you is wrong, anyone who can plan in the trip can correct it in the Expenses tab, or you can ask the trip's owner. Closing your account unlinks your entries in other people's trips from you and shows them as "Former traveller" (see §7); if you also want your name removed from earlier replies in those trips' conversations, email us and we will do so where the law requires it. If you are a guest in someone's trip expenses, you can email us at the address below to access what is recorded under your name, to have your name corrected or erased, or to object to its use; tell us enough (for example the trip owner's name and roughly when and where you travelled) for us to find it. If we erase your name or uphold your objection, we replace your name in that ledger, including its change history, with a neutral label, and remove it from the trip's messages where the law requires it. The amounts stay, because the other travellers' balances depend on them, but they are no longer linked to your name.

To exercise any of these rights, email support@waivoo.com. We will respond within one month (extendable by two months for complex requests, with notice to you). We may ask for proof of identity to avoid disclosing your data to the wrong person.

10. Automated decision-making and AI

Waivoo's AI generates itinerary suggestions and hotel/flight ranking based on the inputs you provide and live travel data. These outputs are recommendations only; you decide whether to act on them. The AI does not make decisions that produce legal effects (it does not grant or deny credit, employment, insurance, housing, or any regulated outcome). You can always ask for human review of an output by emailing support@waivoo.com.

11. Security

We protect your data with: HTTPS/TLS for all traffic, bcrypt-hashed passwords, principle-of-least-privilege access controls inside the team, encrypted database backups, regular dependency-vulnerability scanning, security headers (HSTS, X-Content-Type-Options, Permissions-Policy, Referrer-Policy), rate-limiting on authentication endpoints, and audit logging on administrative actions. No system is 100 % secure; we keep this list under review.

12. Personal-data breaches

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority within 72 hours of becoming aware of it, in line with GDPR Art. 33. If the risk is high we will also notify you directly without undue delay (Art. 34).

13. Children

Waivoo is not intended for users under the age of 16. We do not knowingly collect data from anyone under 16 (or the higher minimum digital-consent age set by your country of residence). If you believe a minor has created an account, contact us and we will remove it.

14. Changes to this policy

We may update this Privacy Policy from time to time. For material changes we will give registered users at least 30 days' notice by email before the change takes effect, and we will update the "Last updated" date at the top of this page.

15. Contact

For any privacy-related question, including requests to exercise your GDPR rights, contact us at support@waivoo.com or by post at Chaussee de Tervuren 145, 1410 Waterloo, Belgium.