WAYMERO · LEGAL

Privacy Policy

1. About Waymero

Waymero is a travel-service marketplace project based in Europe. The person responsible for the processing described here is Mike Freedenwald (also known as Miks Frīdenvalds), operating under the Waymero brand. His contact address is Kazdangas iela 3A, Riga, Latvia. This notice explains how information is handled on our website, partner-branded marketplaces and in business partnership outreach. It does not represent a certification of GDPR compliance.

You can submit a privacy question or request through our privacy contact form or reply to an email from Waymero. You do not need to apply for a partnership to use the form.

2. Information we handle

  • Business enquiries: your name, email, company information, selected interests and any message you submit.
  • Business partnership outreach: a contact’s name, work email, employer, role, relevant company research, message history and any opt-out request. These details may come from professional contact-list providers, including Apollo, from company websites or from other publicly available business sources. We record the source when available.
  • Partner administration: branding, selected services, business contacts and partnership or settlement information provided to us.
  • Marketplace activity: the partner and service selected, a generic placement label, event time and a random click reference. Our application does not store a traveler name or email with these events.
  • Technical and security information: hosting providers receive connection information such as IP addresses. Our rate limiter uses a salted IP-address hash. Hashing does not necessarily make information anonymous.
  • Administrator access: authorized administrator account and session information.
  • Privacy requests: your reply email and the information needed to handle your request.

Please do not send passport details, payment-card information, medical information or traveler lists through our forms. Bookings and payments take place on provider websites.

3. Purposes and legal bases

We use business enquiry information to respond and discuss potential partnerships, relying on legitimate interests in answering business requests, or steps towards a contract where the individual is the prospective contracting party. Partner administration relies on contract where applicable, legitimate interests for business representatives, and legal obligations for required records.

We use relevant business-contact details to assess a potential partnership, send a limited number of tailored B2B emails where electronic-marketing law permits, manage replies and avoid contacting people who object. The basis for using named business-contact details is our legitimate interest in developing relevant business partnerships, balanced against the contact’s reasonable expectations and rights. We do not treat a public work email as blanket permission to contact anyone. You can object to this use at any time by replying to an outreach email or using our privacy form; we will stop outreach and keep the minimum information needed to respect the objection.

We use technical information for security and abuse prevention, and partner-level events to operate redirects and reconcile referrals, relying on legitimate interests where applicable. These interests must be balanced against your rights. Any processing that requires consent must have consent before it starts. We handle data-rights requests to meet legal obligations.

Submitting an enquiry does not subscribe you to marketing emails. We do not use the current application to make solely automated decisions with legal or similarly significant effects.

4. Affiliate links and providers

Service links open an affiliate network or provider website in a new tab. Supported links carry a SubID identifying the referring partner, rather than a named traveler. Waymero may receive attributed booking references, status and commission information in network reports.

The destination receives normal connection information and may use cookies or other attribution technology under its own policies and applicable consent requirements. Please review the destination’s privacy information. Your choices, browser settings and provider rules can affect attribution. We may earn commission from eligible referrals.

Partners receive their own performance and commission information. We do not need traveler contact lists to calculate their commission share.

5. Website analytics, cookies and optional scripts

The current public application does not set its own analytics or advertising cookies. Essential authentication cookies are used for administrator sessions. Hosting and security infrastructure may process technical requests.

We use Vercel Web Analytics to understand public-page visits, referral sources, approximate country, and device/browser categories and improve the website. It does not use analytics cookies. Vercel processes technical connection information to produce visitor statistics. Our integration removes query strings and fragments from tracked page URLs and excludes administrator, authentication, redirect and privacy-request pages. We do not send form contents, names or email addresses as analytics events. This measurement relies on our legitimate interest in understanding and improving the service, subject to applicable consent requirements and your rights. See Vercel’s analytics privacy information.

The optional Travelpayouts Drive script is disabled. If optional tracking is introduced, we will update the information and implement consent controls where required before enabling it. External sites reached through service links have their own cookie practices.

6. Service providers and international processing

We use Vercel for hosting and website analytics and Supabase for the application database, administrator authentication and branding storage. Google Workspace is used for business email and outreach records. Anthropic may process business names, contact first names and public company research to help prepare outreach drafts; it does not decide who is contacted or send emails. Travelpayouts and travel providers handle affiliate referrals and their own services. Information may also be handled by the communication or payment providers used for a specific enquiry or partnership, or disclosed where legally required.

Infrastructure and third-party services may process information outside the European Economic Area. Provider processing locations, contractual safeguards and retention settings are still being documented for the final notice. We do not claim that all information remains in Europe. Contact us through the privacy form for information about a specific processing activity.

7. Retention

We retain information for the purpose for which it was collected and any applicable legal or dispute-related requirements. Unanswered outreach is limited to an initial message and at most two follow-ups; records are reviewed manually when they are no longer needed for that purpose. A minimal suppression record may be kept after an objection so that we do not contact the person again. A fixed retention schedule and routine deletion process for enquiries and marketplace events have not yet been implemented; these records may currently remain stored until manually reviewed or deleted. Provider logs and backups follow the applicable provider settings, which are being reviewed.

Rate-limit windows older than 24 hours are removed when the rate limiter next runs; this is not a guaranteed 24-hour deletion deadline if there are no further requests. You may request deletion, subject to applicable exceptions.

8. Your rights and requests

Depending on the processing and applicable law, you may request access, correction, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent where consent is used. Withdrawal does not affect earlier lawful processing. Rights are subject to legal conditions.

Use the privacy contact form. We may need proportionate information to verify identity. The GDPR generally requires a response within one month; any permitted extension must be explained within that period. You may complain to a competent supervisory authority, including the authority where you live or work. Latvia’s authority is Datu valsts inspekcija.

9. Security and updates

Administrative access is restricted and technical safeguards are used to protect the service. No system is completely risk-free. We will update this page as the operating details and data practices are finalized, showing the revision date. Updating this page alone does not authorize new consent-based tracking.

← Back to Waymero