Privacy Policy
1. Introduction
Welcome to WeiFinders ("we", "us", "our"). Your privacy is important to us. This Privacy Policy explains how we collect, use, and safeguard your information when you visit or use our website and services worldwide, with UK and EU data-protection requirements as our primary framework and applicable United States privacy laws. Your rights depend on where you live and which laws apply.
2. Data We Collect
- Identity & Account Information:Email address, username, display name, profile picture (including from Google if you sign in via Google Login).
- User-Generated Content & Interactions:Guides, itineraries, custom places, images, videos, comments, and links that you publish, and actions such as likes, dislikes, bookmarks, and ratings. Published guides and public itineraries may remain visible after account deletion under “Deleted User”.
- Usage & Diagnostic Data:Server logs including IP address, pages viewed, features used, timestamps, error logs, and other technical information generated as you navigate our site. With analytics consent, we also measure how long itinerary generation, application, and loading take. These itinerary-performance records contain fixed event and stage names with timings, not account or session identifiers, itinerary or destination identifiers, prompts, content, URLs, or precise locations. Used to maintain, secure, and improve the platform.
- Cookies & Tracking Technologies:We use strictly-necessary cookies to enable core site functionality, analytics cookies (e.g. Google Analytics) for aggregated statistics, and marketing cookies (e.g. affiliate-tracking IDs) to attribute bookings made via our partners. Non-essential cookies are set only with your consent via our cookie banner.
- Preference & Profiling Data:Your saved content, search filters, and personalization settings used to tailor recommendations.
- Communications Data:Messages you send via support forms, in-app chat, or feedback surveys, with metadata.
- Chatbot Interaction Data:Transcripts of your questions, our responses, and related metadata used to power and improve our AI chat service.
- Optional Current Location:When you open Explore and allow browser location access, or open an itinerary map with location permission already granted, your browser provides coordinates, accuracy and a timestamp. Itinerary maps use that fix to show your position; Explore uses rounded coordinates to find a broad area and uses the named area as starting context for Explore AI suggestions when browser location access is allowed. See Optional location below. Precise geolocation is treated as sensitive personal information where applicable US state law requires it.
- Consent & Preference History:Your opt-in/opt-out records for cookies and marketing, stored with a timestamp for audit purposes.
- Payment Information:We do not store payment details. All transactions are handled by Stripe; see Stripe’s Privacy Policy for details.
3. How We Use Your Data
- To manage your account and personalise travel recommendations.
- With your consent, to show your position on an itinerary map or use your approximate area for Explore suggestions.
- For subscription management, billing, and payment processing via Stripe.
- To send updates, promotions, and marketing communications (with consent).
- To analyse behaviour and improve our services.
- To support site functionality and security.
- For affiliate tracking via cookies and similar technologies (with consent).
4. Sharing Your Information
We do not sell your personal data. We may share your information with:
- Service providers (payment processors, hosting, analytics).
- Affiliate programme partners (e.g. GetYourGuide) when you click a labelled “Ad” or “Paid link”; shared data is limited to a booking reference or hashed click ID required to attribute commission.
- Law enforcement or regulators when required by law.
- Parties in mergers, acquisitions, or asset transfers (with safeguards).
5. Data Security
We implement encryption and access controls to protect your data. In the event of a breach, we will notify authorities and affected users as required.
6. Data Retention and Breach Notification
Account Information: Retained while your account is active. When you confirm account deletion, we immediately disable the old account and remove its email, username, login provider, and Stripe customer reference from the active user record. The old internal user ID remains only as a pseudonymous ownership and audit reference. A later account created with the same email is a separate account and does not regain the old account’s content.
User-Generated Content & Interactions: Private guides, private itineraries, drafts, saved items, likes, ratings, preferences, feedback, and chatbot transcripts are removed from the active service when account deletion is confirmed. Published guides and public itineraries may remain available under “Deleted User” so existing public pages and links continue to work. Contact us if you want retained public content reviewed for removal.
Custom Places: Private custom places that are not used anywhere else are deleted when you delete your account. Public or reused custom places may be archived so existing itineraries keep working, and any direct ownership attribution is removed.
Custom Place Images: User-owned custom place images are removed when you delete your account. If a place is archived to preserve an existing itinerary reference, the structured place entry may remain without those images.
Usage & Diagnostic Data: General usage and diagnostic data is retained for up to 360 days. Detailed consented itinerary-performance events are retained for 90 days. We may retain daily itinerary-performance aggregates for up to 24 months; these contain only fixed event categories, result, sample count, median, and 95th-percentile timings, exclude account, session, itinerary, destination, place, prompt, content, URL, and precise-location identifiers, and are not retained for groups with fewer than five samples.
System Logs: Retained up to 90 days in Google Cloud Logging.
Cookies & Tracking: Session cookies deleted on browser close. Google Analytics cookies retained 13 months; affiliate cookies such as gyg_partner_id retained 31 days. All non-essential cookies require consent.
Communications & Chatbot Data: Account-linked feedback and chatbot transcripts are deleted from the active service when account deletion is confirmed. Support correspondence held outside the product may be retained only while needed to resolve the request or establish legal claims.
Optional Current Location: Browser location state expires after ten minutes and is cleared when you clear Explore results, revoke browser permission, leave the page, change itineraries or accounts, or reload. A temporary area reference in an Explore job is removed when the job finishes or fails, or by scheduled expiry cleanup. Expiry stops new use immediately; database cleanup can occur later if a worker is unavailable. Location-use notice version and time, without coordinates or the area name, remain with the ordinary job record for up to 90 days. Chatbot content also follows our 90-day content retention and account-deletion rules. Replies may naturally mention the area. Provider retention is separate from our ten-minute browser expiry.
Consent Logs: Direct network and device identifiers are removed on account deletion. The remaining consent record is retained for up to 24 months after deletion for compliance audits.
Billing Records: Payment-card details are held by Stripe, not WeiFinders. Subscription and transaction records may be retained for up to seven years where needed for tax, accounting, fraud, or legal-claims purposes.
Deletion Processing: Firebase authentication, private media, custom-place, and contributed-photo deletion is attempted immediately after the database deletion completes. If a provider or storage service is temporarily unavailable, a daily reconciliation process retries the cleanup. Data may remain in encrypted backups until those backups rotate under the applicable backup schedule and is not restored to the active service.
Breach Notification: We will notify the ICO within 72 hours of discovering a breach and inform affected users if there is a high risk to their rights.
Optional location
Explore requests a one-time location through your browser when the page opens; you can decline the browser prompt. Itinerary maps can show a position when browser location permission is already granted. For users in the UK and EEA, we rely on consent for these optional location uses. Declining or withdrawing does not prevent ordinary browsing or planning. The same opt-in controls are offered to US users. Neither accepting our terms nor allowing analytics or marketing cookies enables location.
Itinerary view and edit: If your browser already grants location access, opening the map requests one fix and displays a simple marker on Google Maps. Otherwise no marker is shown unless you enable location using the location control in the itinerary header, which requests browser permission. We keep the fix in page memory until you leave or it expires after ten minutes. We do not save it as an itinerary stop, send it to itinerary AI, or share the marker with other viewers. It does not continuously update as you walk. The marker does not move or zoom the map. Turn off the header location control to hide it, or revoke browser location permission to clear it.
AI Explore: When browser location access is allowed, Explore sends coordinates rounded to one decimal place to our server to identify a broad area. We do not store those lookup coordinates. After you allow browser location access, the named approximate area is included in subsequent Explore AI requests while the location remains fresh. The “Use my location” switch inside the search box controls whether that area is included. Turn it off to hide the Explore map marker and omit location from subsequent AI requests. The fresh fix stays only in page memory until expiry so you can turn it back on without another lookup. When no usable area is available, the switch stays off, and turning it on requests browser access again. The AI receives the area name, not the browser’s precise coordinates. You can instead write a starting point in your request, which is then ordinary chatbot content.
Your choices: Turn off “Use my location” in Explore to stop future AI location sharing. Revoke location permission in your browser’s site settings to stop browser location use. Leaving or reloading the page clears the current fix. Explore uses the permission for its map marker and approximate starting-area context; itinerary maps never send the fix to AI. Stopping cannot recall requests already submitted or automatically erase an area mentioned in earlier replies; contact us about your data rights. Withdrawal does not affect processing that was lawful before it was withdrawn.
Limited use: We do not use location collected through these controls for advertising, sell it, share it for cross-context behavioural advertising, or add it to analytics, account preferences or collaboration messages. We retain the location-use notice version and acquisition time; map-only use follows browser permission, without creating an account or tracking identity for a viewer.
8. International Data Transfers
Our hosting, map and AI providers may process data outside the UK or EEA, including in the United States. Where required, transfers must be covered by an applicable adequacy decision or contractual safeguards, such as the EU Standard Contractual Clauses with a UK Addendum, or the UK International Data Transfer Agreement. Contact us for information about the safeguards applicable to your data. Using a location feature is not a waiver of your transfer protections.
9. Your Rights
If you are a resident of the UK or EU, you have the right to access, correct, delete, or port your data, and to restrict or object to processing. To exercise these rights, please contact us using the details below. Where we rely on consent, you can withdraw it at any time. You may complain to the UK Information Commissioner or your local EEA supervisory authority.
United States privacy rights
Depending on your state and whether its privacy law applies, you may have rights to access or know about your personal information, obtain a portable copy, correct it, request deletion, and opt out of sale, targeted advertising or certain profiling. California residents may also have a right to limit certain uses of sensitive personal information, including precise geolocation. Our optional location features use it only to provide the service you request, as explained above.
Send requests to [email protected]; you may use an authorised agent where permitted. We may need proportionate information to verify your identity or the agent’s authority. We will respond within applicable legal deadlines and will not discriminate against you for exercising your rights. If we decline a request, we will explain why and how to appeal where your state provides that right. You can submit an appeal to the same address with “Privacy appeal” in the subject and contact your state regulator where applicable.
10. Children's Privacy
Our services are intended for users aged 18 and over. We do not knowingly collect data from individuals under 18.
11. Updates to This Policy
We may update this Privacy Policy and its date to reflect changes in our service or data handling. We will draw material changes to your attention where required. An updated notice or continued use does not give consent for new optional processing; we will ask separately when consent is needed.
12. Accessibility
We are committed to ensuring our website is accessible to everyone. If you encounter any issues, please contact us at [email protected].
13. Data Controller & Contact Information
WeiFinders is the data controller. For questions, requests, or concerns, contact us:
- Email: [email protected]
- Address: WeiFinders, 124 City Road, London, EC1V 2NX
- Contact Page: Contact Us