Last updated 17 September 2026
What personal data we hold, why, how long, and your rights over it.
Controller
The controller of your personal data is [to be supplied by the operator], [to be supplied by the operator]. Data protection contact: [to be supplied by the operator].
What we collect and why
Account data — email address and authentication identifiers — to let you sign in and to keep your saved trips separate from everyone else's. Legal basis: performance of a contract.
Trip data — origins, destinations, dates, the number of travellers and the ages of children, traveller names, contact details and notes you send with a request — to plan the journey and to act on your request. Ages of children are needed because carriers price and carry by age.
Assistant conversations — the questions you ask the travel assistant and the plan they refer to — to answer them. The assistant receives only the figures our engine calculated for the plan in front of you.
Technical data — error reports and basic request information — to keep the service working. Legal basis: legitimate interests.
Recent searches are stored in your own browser and are not sent to us.
Special category and children's data
We do not ask for health, religious or biometric data. Please do not send it in free-text notes; if a requirement affects your travel, describe it in practical terms.
Waypoint Travel is not directed at children. We hold the age of a travelling child only because carriers require it, and it is provided by the adult making the request.
Who we share it with
We share personal data only with processors acting on our instructions: our hosting and database provider, and the AI provider that powers the travel assistant. We do not sell personal data and we do not share it for advertising.
When booking becomes available, the traveller details needed to issue travel will be passed to the relevant carrier, accommodation provider or transfer operator, who will then act as their own controller.
International transfers are protected by the transfer mechanisms permitted under applicable law, including standard contractual clauses. Current hosting region: [to be supplied by the operator].
How long we keep it
Account and trip data are kept while your account is open, and deleted when you close it. Withdrawn trip requests are kept while the account exists so you retain a record of what you asked for. Technical error reports are kept for a short diagnostic period.
Your rights
You can ask for a copy of your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Where the law gives you the right, you may also complain to your data protection authority.
If you are in California, you may exercise equivalent rights to know, delete, correct and opt out of sale or sharing — we do not sell or share personal data as those terms are defined there.
To exercise any right, contact us through the contact page. We reply within the period the law allows.
Security
Access to your data is restricted at the database level so that only your account can read or change your saved trips and requests. Passwords are handled by our authentication provider and are never visible to us.
Anywhere this document says “[to be supplied by the operator]”, the detail depends on the registered company, its address and its jurisdiction, and must be filled in by the owner before publication. We will not invent a company identity or a regulator registration.