1. Who We Are
This privacy policy explains how wherewegoing? ("we", "our" or "us") collects and uses personal data when you use wherewegoing.co.uk or a wherewegoing? mobile app, contact us, subscribe to updates, use the customer portal, receive an itinerary, message us, make a payment, apply to become a partner or homeworker, use the admin platform, or receive a wherewegoing? email account.
WhereWeGoing Ltd is the data controller and is registered with the Information Commissioner's Office under registration reference ZC159227.
For questions about this policy or to exercise your rights, contact us at hello@wherewegoing.co.uk.
2. Personal Data We Collect
The data we collect depends on how you use the website and services. It may include:
- Identity and contact data: name, display name, email address, phone number, address and communication preferences.
- Travel profile data: passenger details, travel document information, preferences, notes and any assistance information you choose to provide.
- Booking and itinerary data: trip details, passengers, prices, booking terms, references, attachments and documents needed to arrange or support your trip.
- Payment data: payment amounts, due dates, payment status and payment references. Card numbers and CVV values are handled by our payment gateway and are not stored by us.
- Partner and homeworker onboarding data: enquiry details, business, tax, right-to-work, banking, insurance, evidence, signature and approval information needed to assess and manage a partner or homeworker relationship.
- Account data: login details, role or permission information, profile details, setup status and account security records.
- Internal business records: accounting, payment reconciliation, commission, audit and compliance records connected with the services we provide.
- Messages and enquiries: contact form messages, live chat messages, portal messages, email replies and related context.
- Newsletter data: email address, name, travel interests and subscription preferences.
- Technical data: IP address, device and browser information, page usage data, timestamps and approximate location derived from technical data.
- Mobile app data: an app installation identifier, device platform, app and build version, notification permission, push notification token, first and last app activity timestamps, and notification delivery status.
Some travel profile data, such as dietary requirements, accessibility needs or special assistance details, may reveal health, disability, religious or other special category information. We only ask for this where it is relevant to arranging or supporting your travel.
3. How We Use Personal Data
We use personal data to:
- respond to enquiries and manage conversations with you;
- create, send and manage quotes, itineraries, bookings, passengers and documents;
- operate customer, partner, homeworker and admin accounts;
- operate the mobile app, keep your content in sync and support secure sign-in;
- process partner and homeworker enquiries, onboarding, agreements, compliance checks and approval workflows;
- manage commission, payment reconciliation and account administration;
- send transactional emails, itinerary emails, magic links and payment reminders;
- process card payments and record payment outcomes;
- send newsletters or travel updates where you have subscribed;
- send optional app notifications in line with your device permission and notification preferences;
- protect the website, accounts and data from misuse;
- measure website performance and understand how visitors use the site; and
- comply with legal, accounting, regulatory and dispute-resolution obligations.
We do not sell personal data. We do not use customer portal or booking data for third-party advertising profiling.
4. Lawful Bases
UK data protection law requires us to have a lawful basis for each use of personal data. Depending on the context, we rely on:
- Contract: to prepare quotes, arrange travel, manage bookings, provide portal and mobile app access, take payments, administer partner or homeworker arrangements, and provide admin platform access.
- Consent: for newsletter subscriptions and where you choose to provide optional special category information for travel support.
- Legitimate interests: to respond to enquiries, protect and improve services, keep appropriate records, manage customer, partner and admin relationships, and run internal business administration.
- Legal obligation: where we must keep records for tax, accounting, regulatory, fraud-prevention, right-to-work, employment-status or travel compliance reasons.
Where we process special category data, we do so because you have provided it for travel arrangements or support, and because it is needed to deliver the services you request or to protect your vital interests during travel.
5. Payments
Card payment forms are handled by our payment gateway. We do not store your full card number or CVV. We send the information needed to process the payment, support the booking, reconcile the transaction and handle disputes.
If a payment is approved, we record that the itinerary payment is paid and store the payment date, payment reference and payment status for reconciliation, customer support, audit and dispute handling. Where applicable, payment records are reconciled against booking protection records used to help protect client money and support supplier payment.
6. Cookies, Sessions and Device Storage
We use first-party cookies and browser storage to provide essential features such as sign-in, security, preferences, live chat continuity and navigation state.
The mobile app stores essential session and security information on your device. It may also cache your account details and itinerary information, and it lets you choose to download itineraries and travel documents for offline access. Signing out removes the app's downloaded account and trip data from that device.
If you enable Face ID or Touch ID, the biometric check is handled by your device. We do not receive or store your face, fingerprint or biometric template.
We do not use customer portal or booking data for third-party advertising profiling.
7. Analytics and Security Records
We collect limited analytics to understand site usage, traffic sources, device types and approximate locations.
For the mobile app, we record authenticated app check-ins, app and build versions, notification permission and notification delivery outcomes so we can operate notifications, support customers and identify outdated or inactive installations. We do not use this information to track you across other companies' apps or websites.
We also keep security and audit records to investigate errors, unauthorised activity, disputes and compliance questions.
8. Who We Share Data With
We share personal data only where needed to operate the website and deliver travel services. Recipients may include:
- payment, booking protection and banking providers;
- email, hosting, storage, security and technology providers;
- mobile app marketplace and push notification providers, including Apple, where needed to distribute the app or deliver notifications you have enabled;
- travel suppliers, accommodation providers, cruise lines, airlines, transfer providers, insurers or other travel partners needed for your trip;
- verification, compliance, professional or business partners needed to assess partner and homeworker onboarding or ongoing account administration; and
- professional advisers, regulators, law enforcement or dispute-resolution bodies where required.
Where providers process personal data outside the UK, we use appropriate safeguards where required by law.
9. How We Protect Data
We use technical and organisational measures designed to protect personal data. These include access controls, encryption for selected sensitive data, secure authentication, audit records and staff access restrictions.
No online service can guarantee absolute security, but we work to reduce risk and limit access to people and systems with a genuine need to process the data.
10. How Long We Keep Data
We keep personal data only for as long as needed for the purpose it was collected, including service delivery, customer support, legal, accounting, audit, fraud prevention and dispute handling.
- Newsletter records are kept until you unsubscribe or ask us to delete them, subject to any suppression record needed to honour that request.
- Customer, itinerary, payment and travel records are kept for as long as needed to manage your trip and meet legal, accounting or travel compliance requirements.
- Partner and homeworker records are kept for as long as needed to assess the application, manage the relationship, pay commission, maintain compliance records, meet legal and accounting obligations, and handle disputes.
- Account, security, audit and analytics records are kept for as long as needed for security, accountability, service improvement and compliance.
- Mobile app installation and notification records are kept for as long as needed to operate the app, deliver notifications, support your account and maintain appropriate security records. Push tokens are retired when you sign out, disable notifications or the provider reports that they are no longer valid.
11. Your Rights
Depending on the circumstances, you may have the right to request access to your personal data, correction, deletion, restriction, portability, objection to processing, and withdrawal of consent where processing is based on consent.
You can unsubscribe from marketing emails using the unsubscribe link in those emails. You can manage app notifications through your device settings and, where available, your notification preferences in the app. You can also contact us at hello@wherewegoing.co.uk.
You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
12. Changes to This Policy
We may update this policy when our services, systems or legal obligations change. The latest version will always be published on this page.