← Wistbound

Privacy Policy

Effective date: July 19, 2026 · Version 1.0
Operated by [YOUR LLC NAME] ("Wistbound," "we," "us," or "our"), the data controller for personal information processed through wistbound.com and its subpages (the "Service").
Contact for all privacy matters: [CONTACT EMAIL]

Note: This is our Privacy Policy. Our Terms & Conditions are a separate document that governs your use of Wistbound.

1. Scope and roles

This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use the Service. It applies worldwide. Where the EU/UK General Data Protection Regulation ("GDPR") applies, we act as the data controller; our service providers listed in §5 act as processors on our documented instructions. Where the California Consumer Privacy Act as amended by the CPRA ("CCPA") applies, we act as the business and those providers act as service providers.

2. Information we collect

CategoryExamplesSourcePurpose
Trip inputsDestination, dates, group composition, vibe, budget, dietary and transport preferences, free-text requestsYouGenerating and refining your itinerary
Contact dataEmail addressYouWaitlist updates you requested; delivering itineraries you asked us to email; one-time sign-in links and retrieval codes
Saved tripsYour most recent itinerary, linked to your emailGenerated for youLetting you retrieve your trip on any device (kept until you save a new trip or request deletion)
Device-stored dataPreferences, trip history, consent choice, stored in your own browser (localStorage)You / your browserSame-device convenience; never transmitted to us as a profile
Usage dataPages viewed, interactions (e.g., "generated itinerary"), approximate location (country/city), device and browser typeGoogle Analytics, subject to §7 consent rulesProduct improvement and aggregate statistics only
Server logsIP address, timestamps, requested resources, processed transiently by our host for delivery and securityAutomaticOperating and securing the Service

We do not collect: names (not requested), payment data (nothing is sold), precise geolocation, government identifiers, biometric data, or any special-category/sensitive data as defined by GDPR Art. 9 — except that dietary preferences you voluntarily enter could indirectly suggest religious or health information; we use them solely to generate your itinerary, never to profile you, and you may simply omit them.

3. Purposes and legal bases (GDPR Art. 6)

4. What we never do

5. Processors / service providers

ProviderFunctionData handled
Anthropic, PBC (US)AI itinerary generationTrip inputs. Per Anthropic's commercial API terms, API inputs/outputs are not used to train their models by default.
Netlify, Inc. (US)Hosting, serverless functions, edge country lookup for §7Server logs; request payloads in transit
Formspree, Inc. (US)Waitlist storageEmail; associated trip summary
Resend (US)Transactional emailEmail; itinerary content you asked us to send; sign-in links and retrieval codes
Upstash (US)Temporary trip storageEmail-keyed saved itinerary (kept until overwritten or deleted on request); sign-in links and codes with 10-minute expiry
Google LLC (US)Analytics (consent-governed)Usage data per §7

Each provider is bound by data-processing terms limiting use of your data to providing services to us. We disclose personal information otherwise only: (a) to comply with law or valid legal process; (b) to protect the rights, safety, or property of users, the public, or Wistbound; or (c) in a merger, acquisition, or asset sale, in which case this Policy continues to apply and you will be notified of any successor.

6. International transfers

We are US-based and our providers process data in the United States. Where GDPR applies to transfers from the EEA/UK/Switzerland, we rely on providers' participation in the EU–US Data Privacy Framework and/or Standard Contractual Clauses, together with supplementary technical measures (encryption in transit, minimization, short retention).

7. Cookies, analytics, and consent

8. Retention

DataRetention
Trip inputs sent for generationProcessed transiently; not stored by us after your itinerary is returned (except as a saved trip if you email it to yourself)
Saved trips (cloud)Until you save a new trip (which replaces it) or request deletion
Sign-in links & retrieval codes10 minutes; single use
Waitlist emailsUntil launch communications conclude or you request deletion, whichever is sooner
Transactional email recordsPer Resend's standard log retention, then deleted
AnalyticsLimited retention configured in Google Analytics (target: 2 months)
Device-stored dataUnder your control; clear via browser settings anytime

9. Your rights

Everyone, everywhere: as a matter of policy we extend these rights globally — access, correction, deletion, portability, restriction, objection, and withdrawal of consent — exercisable by emailing [CONTACT EMAIL]. We will verify requests using the email address associated with your data, respond within 30 days (45 where law allows extension, with notice), and will not discriminate against you for exercising any right.

EEA/UK: you additionally have the right to lodge a complaint with your supervisory authority (in the UK, the ICO).

California: you have the rights to know/access, delete, correct, portability, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not use any for inferring characteristics), and to non-discrimination. You may designate an authorized agent; we will verify agent authority. Metrics available on request.

Other US states (Virginia, Colorado, Connecticut, Utah, and similar): equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising (we serve none); appeals may be submitted by replying to our response, and will be reviewed by a different reviewer within statutory timelines.

Self-service deletion: device-stored data — clear this site's data in your browser. Cloud-saved trips — email us for deletion at any time.

10. Security

All traffic is encrypted in transit (TLS/HTTPS). API credentials are held server-side only and never exposed to browsers. AI-generated content is sanitized before display. Trip retrieval requires an emailed one-time sign-in link or code; both expire in 10 minutes, are single-use, and are rate-limited; retrieval responses never confirm whether an email has saved data. Access to provider dashboards is restricted and credentialed. No method of transmission or storage is 100% secure; if we learn of a breach creating risk to you, we will notify affected users and regulators as required by applicable law (including GDPR Arts. 33–34 and US state breach statutes) without undue delay.

11. Do Not Track

We honor Global Privacy Control (§7). Legacy "Do Not Track" browser signals have no settled standard; where received, we treat them equivalently to a GPC opt-out for analytics.

12. Children

The Service is a general-audience service not directed at children. We do not knowingly collect personal information from children under 13 (or under 16 where the GDPR sets that threshold). If you believe a child provided us personal information, contact us and we will delete it promptly.

13. Changes to this Policy

We may update this Policy. Material changes will be posted here with a new effective date, and — where we hold your email for an active purpose — notified by email. Continued use after the effective date constitutes acceptance; where consent is legally required for a new processing purpose, we will seek it.

14. Contact

Privacy questions, requests, complaints: [CONTACT EMAIL] · [YOUR LLC NAME], [MAILING ADDRESS — add when available].

Terms of Service

Our Terms of Service are a separate document. Please read the Terms & Conditions, which govern your use of Wistbound.

© 2026 [YOUR LLC NAME]. All rights reserved. · Home · Terms & Conditions · Unsubscribe · Delete account