Privacy policy
Effective date: July 25, 2026
This policy explains what Waylead ("we," "us") collects when you use the Waylead service (the "Service"), how we use it, and who receives it. It reflects how the Service actually behaves.
What we collect
- Account: your email address; an optional display name and avatar (an avatar may be filled in automatically from a social sign-in, or you can set your own); sign-in metadata (last login; session tokens, stored hashed). If you use social sign-in, the verified email and a provider account id (we never receive your provider password). If you add a backup recovery email, we store that too.
- Ride content you create: routes (from GPX you upload), plans, stops, bail-outs, and any leader/rider details you enter (names, phone numbers, roles).
- Saved places (precise location): the labels and coordinates you save to a workspace's address book (e.g. home, clubhouse, a favorite fuel stop), and the coordinates of the routes you upload. These stay within your workspace and are never shown on a public ride link.
- AI route assistant: if you use the optional Route Architect, the messages you send it and the route/plan content of that conversation are sent to a third-party AI model provider to generate suggestions, and the conversation is stored in your workspace. Under our agreement with the provider, your conversations are not used to train its models.
- Operational logs: request/job/provider events for reliability. Sign-in links and leader tokens are redacted from logs; rider PII is not logged.
- We do not use third-party advertising or tracking cookies. We set a first-party session cookie, a short-lived sign-in cookie for social login, and use a CSRF header — all necessary for the Service. Your IP address is used only briefly, in memory, to rate-limit abuse (for example, sign-in requests); it is not stored in our database or written to our logs.
How we use it
To operate the Service: analyze routes, compute group logistics, render briefings, generate AI route suggestions when you ask for them, and share them at your direction. To send the magic-link sign-in email and service notifications. To keep the Service secure and reliable. We do not use your information for advertising, and we do not sell or share it.
Information about other people
When you plan a ride you may enter details about other riders — names, roles, and phone numbers. Those people are usually not Waylead users. You are responsible for having any consent they require, for telling them how their information is used, and for honoring their requests. If someone asks to have their information removed from a ride, you (the ride organizer) can remove it, or you can contact us for help. A public ride link strips rider PII; a leader link exposes it only to people holding the unlisted token.
Sharing and third parties
Plans you choose to share are reachable via the share/leader links you enable, at the privacy tier you select. We do not sell or rent your personal information, and we do not "share" it for cross-context behavioral advertising.
To run the Service we rely on a small set of third-party service providers, each receiving only what its function needs and bound by a contract to use it only to provide the service to us:
- an email provider that delivers sign-in and notification messages (receives recipient email addresses);
- an AI model provider that powers the optional Route Architect (receives your assistant conversation and its route/plan content);
- a web-search provider the Route Architect may query while researching roads, stops, and conditions (receives the search terms it generates, which can include place or route names);
- weather and wildfire data services we query by route location (receive route coordinates/areas, not your identity);
- an address-search (geocoding) service, used when you add a stop by typing an address (receives the address text you enter).
Our maps, routing, and error diagnostics run on our own infrastructure; diagnostics have personal details scrubbed before anything is recorded.
Sub-processors
The named providers we currently use to run the Service, each bound by contract to use your information only to provide their service to us:
- Cloudflare, Inc. (USA) — content delivery, DNS, TLS ingress, and sign-up bot protection; receives IP addresses and HTTP request metadata for traffic to the Service.
- Railsware Products Studio ("Mailtrap") — delivery of sign-in and notification email; receives recipient email addresses and message content.
- Google LLC (USA) — "Sign in with Google" authentication; receives your Google account email, name, and profile identifier.
- Anthropic, PBC (USA) — the AI model behind the optional Route Architect; receives your assistant conversation and its route/plan content, only when you use the Architect.
Weather, wildfire, geocoding, maps, routing, and error diagnostics either receive only route locations (not your identity) or run on our own infrastructure. This list is current as of the effective date above; we will keep it updated here and give notice of material changes before a new sub-processor begins processing your information.
Your rights (access / deletion / portability)
You can export your plans and routes at any time (Account → export), and delete your account and everything it owns (Account → delete) — both are self-service in the app. When you delete your account it is deactivated immediately (you're signed out), then permanently erased after a 7-day grace period. Change your mind within that window? Just sign back in and your deletion is cancelled and your data restored (our staff can also restore it on request). Depending on where you live you may have additional rights — see the California and international sections below, or contact us.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to access and delete it, to correct it, and not to be discriminated against for exercising these rights.
- Categories we collect: identifiers (email, account id, IP for rate-limiting); customer records (display name, phone numbers you enter); commercial information (subscription status, if any); internet/network activity (operational logs); and precise geolocation (saved addresses and route coordinates).
- Sources: you, your uploads, and your social sign-in provider (if used).
- Purposes: to provide, secure, and improve the Service, as described above.
- Recipients: the service providers listed under "Sharing and third parties," each for the stated purpose only.
- Sensitive personal information: precise geolocation is "sensitive personal information" under California law. We use it only to provide the Service (analyzing and displaying your routes and places); we do not use it to infer characteristics about you, and we do not sell or share it — so no "Limit the Use of My Sensitive Personal Information" action is needed.
- No sale or sharing: we do not sell or share personal information, and we do not process it for cross-context behavioral advertising. Because we do not sell or share, we do not need to act on Global Privacy Control signals for that purpose, and no "Do Not Sell or Share My Personal Information" link is required.
- Exercising your rights: use the in-app export and delete tools, or email [email protected]. We verify your request using your account and respond within 45 days. You may use an authorized agent, with proof of authorization.
Users outside the United States
We operate the Service in the United States, and your information is processed and stored there. If you use the Service from the European Economic Area, the United Kingdom, or another region with data protection laws, we process your information to provide the Service you request (contract) and to run it securely (legitimate interests), and you may have rights of access, correction, deletion, and portability. Contact [email protected] to exercise them.
Retention
We keep plans and routes while your account is active. Post-ride, leader/rider PII is scrubbed and plans are eventually deleted on a schedule (defaults: PII at ~18 months after the ride date, plans at ~7 years; routes no longer referenced by any plan within 14 days). A GPX file you upload is kept with the route it produces — so we can re-analyze it if our routing engine improves — and is removed when that route is deleted; only the temporary upload copy is discarded right after analysis. Deleting your account deactivates it at once and hard-erases your data after the 7-day grace period described above.
Security
We use reasonable technical and organizational measures to protect your information, including hashing of session tokens and scrubbing of sensitive values from logs and diagnostics. No system is perfectly secure. If a breach affects your personal information, we will notify you as required by law.
Children
The Service is intended for adults. You must be at least 18 to use it, and it is not directed to children.
Changes
We may update this policy. If we make material changes, we will provide notice (for example, by email or in the app) and update the effective date above.
Contact
Waylead [email protected]