Wayward Privacy Policy

    Effective: August 21, 2026 · Replaces the version of November 14, 2023

    Lost Corporation dba Wayward ("Wayward", "we", "us") operates the wayward.travel website, the Wayward operator console, and the Wayward booking pages at book.wayward.travel (together, the "Service").

    This policy explains what personal data we handle, why, and what your rights are. It is written around a distinction that matters: Wayward plays two different roles depending on who you are.

    Who you are in this Policy

    Guests. When you book a trip, join a waitlist, sign a waiver, or fill in a form with a tour operator (a "Brand") that runs its business on Wayward, we refer to you as a "Guest."

    Operators. When you create or use an account in the Wayward operator console on behalf of a Brand, we refer to you as an "Operator."

    Visitors. When you browse wayward.travel without being a Guest or an Operator, we refer to you as a "Visitor."

    The two roles we play

    When we act for ourselves (data controller). For Operators and Visitors, Wayward decides how and why personal data is processed, and this policy governs it.

    When we act for a Brand (data processor). For Guests, the Brand you booked with decides how and why your data is used. Wayward processes it on the Brand's behalf and on its instructions, under the Data Processing Terms in our Terms of Service. For questions or requests about that data, your first contact is your Brand; we give Brands the tools to answer you, and we assist directly where a processor must.

    If you are a Guest

    What we process for your Brand

    • Booking details: your name, email, phone, party members, chosen date and option, and payment status. Card details never touch our systems: payment is handled by Stripe, and we hold only a payment reference and amounts.
    • Waivers: the document you signed, your signature, and the details the waiver asked for (which can include date of birth and an emergency contact). Signing metadata (IP address, browser) is kept as evidence of signing.
    • Form answers: whatever your Brand's forms ask. We do not record your IP address or browser details on form submissions.
    • Trip communications: emails about your booking (confirmations, balance reminders, trip information links) and delivery status for them.
    • Health-related details: if your Brand collects dietary requirements or medical notes for safety on the trip, we store them with additional safeguards, including encryption, and restrict who can view them.

    What we never do with Guest data

    • We do not market to you. Wayward sends you no newsletters, promotions, or advertising; only the operational emails your booking requires.
    • We load no analytics, advertising tags, or third-party trackers on booking, waiver, or trip pages. Those pages use only the cookies strictly necessary to complete your booking, which is why they show no cookie banner.
    • We do not sell personal data, and we do not share it across Brands: each Brand sees only its own Guests.
    • Your Brand may only send you marketing email if you expressly opted in (an unticked checkbox at checkout). You can withdraw at any time via the unsubscribe link, which stops that Brand's marketing without affecting your trip emails.

    Your rights as a Guest

    The Brand you booked with is the controller of this data, so requests go to them, and the Service gives them the tools to answer, including export of your data in a machine-readable format and erasure. Two caveats, because we would rather state them than surprise you: records connected to payments may be kept in anonymized form as bookkeeping rules require, and signed waivers may be retained for the legal limitation period, as data protection law permits. If you cannot reach your Brand, contact us at privacy@wayward.travel and we will assist.

    The former Wayward mobile app

    The Wayward mobile application was discontinued in May 2026 and no longer collects any data, including location data. If you had an account on the app and would like any remaining account data deleted, contact us at privacy@wayward.travel and we will delete it.

    If you are an Operator

    For Operators, Wayward is the controller. We process your account details (name, email, password hash), role and team memberships, billing details via Stripe, and support communications. The operator console uses Google Tag Manager / Google Analytics so we can understand and improve the product; this runs only inside the logged-in console and on our marketing site, and never on your Guests' booking pages. Our lawful bases are the contract we have with you, and our legitimate interest in improving and securing the Service.

    Cookies

    • Booking and guest pages (book.wayward.travel, waiver and form links): strictly necessary cookies only (session, security, and checkout state).
    • Marketing site (wayward.travel): analytics tags load only with your consent via the cookie banner.
    • Operator console: session cookies plus product analytics for logged-in operators.

    How long we keep data

    Operational records that are no longer needed for their purpose (delivery logs, engagement counters, expired access links, abandoned checkouts) are deleted automatically on fixed schedules. Booking and Guest-relationship records are retained while the Guest relationship is active, under the Brand's own retention policy, and are always subject to your rights below. Waiver records follow the legal limitation period.

    Security

    All traffic is encrypted in transit and all stored data is encrypted at rest, with additional protection for health-related information. Access within a Brand is role-based, sensitive actions are restricted and logged, and we design for data minimisation throughout the Service.

    Sub-processors and transfers

    We process data in the United States and use a small number of sub-processors: Amazon Web Services (hosting), Stripe (payments), Mailgun (email delivery), and Google (analytics for our website and operator console only). The current list, with what each one does, is maintained in the Data Processing Terms appended to our Terms of Service. Where data of EEA/UK residents is transferred to the United States, we rely on Standard Contractual Clauses and each provider's applicable transfer mechanism.

    Children

    The Service is not directed at children, and we do not knowingly let anyone under 18 create an account. A parent or guardian booking a trip may enter details of minor participants (for example on a group booking or waiver); the Brand, as controller, is responsible for collecting that lawfully, and such details are covered by the same protections and rights described above, exercised by the parent or guardian.

    Your rights (GDPR and equivalent laws)

    You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent at any time where processing relies on it. Guests: address requests to your Brand as described above. Operators, Visitors, and former app users: contact us directly. We may need to verify your identity before acting. You also have the right to complain to your data protection authority.

    Changes and contact

    We will post changes to this policy here and update the effective date; for material changes we will notify you prominently in the Service or by email. Questions and requests: privacy@wayward.travel (or help@wayward.travel).