Wanderoon How it works Why Wanderoon Join the waitlist
Legal

Privacy Policy

Last updated: 6 September 2026

This Privacy Policy explains how Wanderoon (referred to here as “we”, “us” or “our”) collects, uses, shares and protects personal data, and the rights you have under the privacy laws that may apply to you. These include the EU General Data Protection Regulation (GDPR), the UK GDPR, United States state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the CCPA) and comparable laws in other states, and Canadian privacy laws including the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Law 25. Rights that are specific to your region are set out in the notices below. Wanderoon is a platform that lets travel organisers build, sell and manage group trips, and lets travellers browse and book those trips.

  • 1. Who we are and our role
  • 2. Personal data we collect
  • 3. How we use your data and our legal bases
  • 4. Cookies and local storage
  • 5. Who we share data with
  • 6. International data transfers
  • 7. How long we keep your data
  • 8. Your rights under the GDPR
  • 9. Automated processing and the AI assistant
  • 10. Marketing communications
  • 11. How we keep data secure
  • 12. Children
  • 13. Notice for United States residents
  • 14. Notice for Canadian residents
  • 15. Changes to this policy
  • 16. Contact us and complaints

1. Who we are and our role

The data controller for the personal data described in this policy is Wanderoon. You can reach us with any privacy question at [email protected].

Wanderoon serves two kinds of people, and our role differs for each:

  • Organisers and visitors. When you create an organiser account, contact us, join our waitlist or visit our marketing site, we act as the controller of your personal data and decide how it is used.
  • Travellers and booking data. When an organiser uses Wanderoon to run their trips, the organiser is the controller of the traveller and booking data they collect, and we act as a processor that handles that data on the organiser’s instructions under a data processing agreement. This same role is described as a service provider under United States state privacy laws, and as handling personal information on the organisation’s behalf under Canadian law. If you are a traveller, please also read the privacy notice of the organiser you booked with, and direct requests about your booking to them in the first instance.

2. Personal data we collect

Depending on how you use Wanderoon, we may process the following categories of personal data:

  • Account and identity data: name, email address, password credentials (managed by our identity provider), organisation name and role, and preferences such as language and currency.
  • Booking and traveller data: traveller names, email addresses, phone numbers, trip and departure selections, room and pricing choices, participant form answers and waiver acknowledgements, and messages exchanged through the platform.
  • Payment data: transaction amounts, currency, status, and limited non sensitive card details (such as the card brand and the last four digits). Full card numbers are handled directly by our payment providers and are not stored by us.
  • Support and communications data: the content of messages, emails and notifications you send or receive through the platform.
  • Usage and technical data: IP address, device and browser information, pages viewed, actions taken, and diagnostic logs, collected to operate and secure the service.
  • Marketing data: your email address and preferences when you join a waitlist or subscribe to updates.

We do not seek to collect special categories of data (such as health or biometric data). Please do not enter such data into free text fields unless an organiser has asked for it and has a lawful basis to process it.

3. How we use your data and our legal bases

Where we act as controller, we rely on the following legal bases under Article 6 of the GDPR:

  • Performance of a contract: to create and manage your account, provide the platform, process bookings and payments, and provide support.
  • Legitimate interests: to secure and improve the service, prevent fraud and abuse, understand how the platform is used, and carry out limited business to business marketing. We balance these interests against your rights, and you can object at any time.
  • Consent: for optional cookies and analytics, and for marketing emails where consent is required. You can withdraw consent at any time without affecting processing carried out before withdrawal.
  • Legal obligation: to meet accounting, tax, and other legal requirements, and to respond to lawful requests from authorities.

Where we act as a processor on behalf of an organiser, we process traveller data only on that organiser’s documented instructions.

4. Cookies and local storage

We use cookies and similar technologies, including browser local storage, for the following purposes:

  • Strictly necessary: to sign you in, keep your session secure, and remember essential settings. These are required for the service to work.
  • Preferences: to remember choices such as your language, active organisation, and table or panel layouts.
  • Analytics, where enabled: to understand usage in aggregate. These are set only with your consent where consent is required.

You can control non essential cookies through your browser settings. We also honour recognised opt out signals such as the Global Privacy Control. Blocking strictly necessary cookies may stop parts of the service from working.

5. Who we share data with

We share personal data only as needed to run the service, and we require our providers to protect it under written agreements. Recipients include:

  • Payment providers (for example Stripe and Paystack) to process payments, payouts, refunds and disputes.
  • Identity and authentication providers to sign you in, including optional social sign in where you choose to use it.
  • Email and messaging providers to send transactional and, where applicable, marketing messages.
  • Cloud hosting and file storage providers that host the service and store uploaded files such as images and evidence documents.
  • Artificial intelligence providers that power the in product assistant. Traveller identities are pseudonymised before content is sent to these providers (see section 9).
  • Organisers, who receive the booking and traveller data relating to their own trips.
  • Professional advisers, authorities and acquirers where required by law, to enforce our terms, or in connection with a business transfer.

A current list of our sub processors is available on request at [email protected]. We do not sell your personal data.

6. International data transfers

Some of our providers may process data outside the European Economic Area or the United Kingdom. Where they do, we put appropriate safeguards in place, such as an adequacy decision, the European Commission Standard Contractual Clauses, or the UK International Data Transfer Agreement, together with any additional measures needed to protect your data. You can ask us for a copy of the relevant safeguards at [email protected].

7. How long we keep your data

We keep personal data only for as long as we need it for the purposes described in this policy. Account data is kept while your account is active and for a reasonable period afterwards. Booking and payment records are kept for as long as required to meet legal, accounting and tax obligations. Where we act as a processor, we retain traveller data according to the organiser’s instructions and our agreement with them. When data is no longer needed, we delete or anonymise it.

8. Your rights under the GDPR

Subject to the conditions in the law, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure of your data in certain circumstances (the right to be forgotten).
  • Restriction of processing in certain circumstances.
  • Data portability, to receive your data in a structured, commonly used, machine readable format and to have it transmitted to another controller where technically feasible.
  • Object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent at any time where we rely on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Lodge a complaint with a supervisory authority (see section 16).

To exercise any of these rights, contact us at [email protected]. We will respond within one month, and we may need to verify your identity first. If your request relates to a booking, the relevant organiser may be the controller, and we will help route your request to them.

9. Automated processing and the AI assistant

Wanderoon includes an AI assistant that helps organisers draft content and understand their data. Before any traveller content is sent to a third party AI provider, traveller identities are pseudonymised (names are replaced with stable labels and direct contact details are removed), and the results are mapped back only within the organiser’s own dashboard. The assistant produces drafts and suggestions for a human to review. We do not use it to make decisions about you that produce legal or similarly significant effects without human involvement.

10. Marketing communications

Where you have joined our waitlist or agreed to receive updates, we may send you marketing emails about Wanderoon. Every marketing email includes an unsubscribe link, and you can opt out at any time by using that link or by contacting us at [email protected]. Opting out of marketing does not stop essential service messages, such as booking confirmations and security notices.

11. How we keep data secure

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, tenant isolation, least privilege data access, and monitoring. Payment card data is handled by PCI compliant payment providers. No system can be guaranteed to be completely secure, so we also ask you to keep your account credentials confidential and to tell us promptly if you suspect any unauthorised use.

12. Children

Wanderoon is intended for use by adults. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.

13. Notice for United States residents

This notice applies if you are a resident of the United States. It supplements the rest of this policy and describes rights under US state privacy laws, including the CCPA and comparable laws in states such as Virginia, Colorado, Connecticut, Utah, Texas and others as they take effect.

We collect the following categories of personal information, as those categories are defined under the CCPA: identifiers (such as name, email address and IP address); customer records (such as contact and billing details); commercial information (such as trips booked and transaction history); internet or network activity (such as usage and interactions with the service); approximate geolocation derived from IP address; and inferences drawn to provide and improve the service. We may collect a limited amount of sensitive personal information, such as account log in credentials, which we use only to provide and secure the service and not to infer characteristics about you. The sources, purposes and recipients are described in sections 2, 3 and 5.

We do not sell your personal information, and we do not share it for cross context behavioural advertising, as those terms are defined under the CCPA. This includes the personal information of consumers we know to be under 16.

Subject to the conditions in the law, you have the right to:

  • Know and access the personal information we hold about you and how we use and disclose it.
  • Correct inaccurate personal information.
  • Delete personal information we hold about you.
  • Opt out of any sale or sharing of personal information (we do not sell or share, so there is nothing to opt out of).
  • Limit the use of sensitive personal information to what is necessary to provide the service.
  • Data portability and to opt out of targeted advertising or certain profiling, where your state grants those rights.
  • Not be discriminated against for exercising any of these rights.

To make a request, contact us at [email protected]. We will verify your request using the information associated with your account, and an authorised agent may submit a request on your behalf with proof of authorisation. Where the law allows, you may appeal a decision by replying to our response, and you may also contact your state Attorney General. Where required, we honour recognised opt out preference signals such as the Global Privacy Control. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing purposes.

14. Notice for Canadian residents

This notice applies if you are in Canada. We handle personal information in accordance with PIPEDA and applicable provincial privacy laws, including Quebec’s Law 25. Our privacy officer can be reached at [email protected].

We collect, use and disclose personal information with your consent (which may be express or implied depending on the sensitivity of the information and the circumstances), or as otherwise permitted or required by law, for the purposes described in sections 2 and 3. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, although this may limit our ability to provide the service.

You have the right to access the personal information we hold about you and to request corrections, and to ask about how we handle your information. In Quebec you also have the right to data portability and to be informed about decisions based solely on automated processing.

Your personal information may be processed by service providers located outside of Canada, including in the United States and the European Economic Area, where it may be accessible to courts, law enforcement and national authorities under the laws of those jurisdictions. We use contractual and other safeguards to protect it, as described in section 6.

15. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you. Please review this page periodically to stay informed.

16. Contact us and complaints

If you have questions about this policy or how we handle your data, contact us at [email protected]. We would appreciate the chance to resolve any concern first, so please do consider contacting us before making a complaint to a regulator.

If you believe we have not adequately addressed your concern, you may contact the relevant authority for your region:

  • In the European Economic Area or the United Kingdom, your local data protection supervisory authority.
  • In the United States, your state Attorney General, and in California the California Privacy Protection Agency.
  • In Canada, the Office of the Privacy Commissioner of Canada, and in Quebec the Commission d’accès à l’information du Québec.

← Back to Wanderoon

Wanderoon
© Wanderoon · Home · Why Wanderoon · Terms · Privacy · Refunds