Privacy Policy
This policy explains how WanderlyMe handles your personal information. It is written to align with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Last updated 2026-10-01
1. Who we are
WanderlyMe is operated by Gurman Soni, a sole trader based in Sydney, Australia (ABN {{ABN}}). In this policy, "we", "us" and "our" refer to WanderlyMe. You can contact us about privacy at hello@wanderlyme.com.
2. What we collect
We collect only what we need to run the service:
- Account details: your name (if provided) and email address, plus a securely hashed password. We never store your password in plain text.
- Trip inputs: destination or country, travel dates and year, number of days, group size, budget, interests, origin airport or country, seat class, and any free-text instructions you give the planning assistant.
- Generated content and edits: the itineraries, budgets, comments, votes and suggestions you or your collaborators create and save.
- Contact messages: name, email, subject and message when you use the contact form or email us.
- Payment information: if you purchase a paid plan, payments are processed entirely by Stripe. We receive confirmation of payment, the plan purchased, the amount and a Stripe payment reference. WanderlyMe never receives or stores your card number, expiry or security code.
- Usage analytics and technical data: pages visited, approximate location derived from IP address, device and browser type, referring pages and interaction events, collected via Google Analytics and our server logs.
3. Why we collect it
- To generate, save, edit and share your trip plans.
- To create and secure your account, and to send account emails (welcome, password reset, saved-trip copies, collaboration notifications).
- To verify venues, calculate routes and travel times, and estimate budgets and flight costs.
- To process payments and deliver paid plans, and to handle refunds.
- To respond to your messages and support requests.
- To understand how the service is used so we can fix problems and improve it.
- To comply with legal obligations and enforce our Terms of Service.
4. Internal customer records
To run the service and support you, WanderlyMe keeps internal records that link your account to the trips you create, the enquiries and contact messages you send, any paid-plan orders you place, and a log of the emails we have sent you. The email log holds metadata only — the type of email, the recipient address, the time it was sent and its delivery status (sent, delivered, bounced or failed) as reported by our email provider. We do not store the contents of those emails in the log.
When you ask us to fulfil a paid plan or respond to an enquiry, we may record short internal notes against your customer record (for example, preferences you have told us about, or the status of your request). These notes are used only for that purpose, are visible only to the operator, and are never shared with other users or third parties except where the law requires.
Access to these records is restricted to the operator's own account and is checked on every request on our servers.
5. Third-party processors
We rely on a small number of service providers to operate WanderlyMe. Each receives only the data necessary for its function:
- AI model provider (Anthropic Claude, accessed through our infrastructure provider): receives your trip inputs, assistant messages and existing itinerary content to draft and edit plans.
- Google Places API: receives venue names and destination coordinates so we can verify places, opening hours, ratings and photos.
- Mapbox: receives place coordinates to calculate routes and travel times.
- Stripe: processes payments for paid plans and handles all card data under its own privacy policy. Card details never touch WanderlyMe's servers.
- Email provider (Resend): delivers transactional emails such as welcome messages, password resets, itinerary copies and collaboration notifications.
- Google Analytics: collects aggregated usage analytics.
- Cloud hosting and database providers: store your account and trip data.
6. Trip prompts are sent to a third-party AI provider
To build your itinerary, the details you enter — destination, dates, budget, interests, group size and any instructions you type to the assistant — are transmitted to a third-party AI model provider. We do not send your password, and we avoid sending your email address or name in prompts unless you include them yourself in free-text fields. Please don't enter sensitive information (health conditions, passport numbers, payment details) into trip prompts.
7. Overseas processing
Some of the providers listed above store or process data outside Australia, including in the United States and the European Union. By using WanderlyMe you acknowledge that your personal information may be disclosed to overseas recipients. We take reasonable steps to ensure those recipients handle information in a manner consistent with the APPs, including relying on their contractual and security commitments.
8. Data retention
- Account and saved trips: kept while your account is active. If you delete a trip it moves to Trash and is permanently removed when you empty it or delete your account.
- Enquiries and contact messages: kept for 24 months after our last contact with you about them, then deleted or de-identified.
- Orders for paid plans: kept for 7 years from the date of the order to meet Australian tax and record-keeping obligations; internal notes attached to an order are deleted with it.
- Email log (metadata only): kept for 24 months after the last email sent to you, then deleted.
- Deleted accounts: personal data is deleted or de-identified within 30 days of a verified deletion request, except where we must retain records for legal, tax or dispute purposes (typically up to 7 years for payment records).
- Password-reset tokens and temporary generation jobs: expire automatically within hours.
- Analytics data: retained according to Google Analytics settings (currently 14 months).
9. Cookies and analytics
We use a strictly necessary authentication cookie (and a browser-stored token) to keep you signed in. We use Google Analytics, which sets cookies to distinguish users and measure usage. You can block or delete cookies in your browser settings; the site will still work but you may need to sign in more often. You can also opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on.
10. Security
We use encrypted connections (HTTPS), hashed passwords, access-controlled databases and time-limited tokens. No system is perfectly secure, so we can't guarantee absolute security, but we will notify affected users and the Office of the Australian Information Commissioner (OAIC) of any eligible data breach as required by law.
11. Access, correction and deletion
You can request a copy of the personal information we hold about you — including your account details, trips, enquiries, contact messages, orders, the email log and any internal notes — ask us to correct it, or ask us to delete it, by emailing hello@wanderlyme.com from the address you registered with. We will respond within 30 days. There is no charge for making a request. If we must refuse part of a request (for example, where tax law requires us to keep an order record), we will tell you which records are affected and why.
12. Complaints
If you believe we have mishandled your personal information, please contact us first at hello@wanderlyme.com and we will investigate and respond within 30 days. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Changes to this policy
We may update this policy as the service or the law changes. The "last updated" date at the top of this page will change when we do, and material changes will be highlighted in the app or by email. Questions about this policy can be sent to hello@wanderlyme.com.