§ 1.0Who we are
"WayHopper", "we", or "us" refers to WayHopper Inc. (Brisbane HQ), together with our wholly-owned subsidiaries in the United States (WayHopper USA Inc., Austin TX) and the European Union (WayHopper EMEA Ltd., Dublin). The data controller for your information depends on where you live; see § 12.
§ 1.1Scope of this policy
This policy covers wayhopper.com, the WayHopper operator dashboard, the WayHopper participant mobile apps (iOS / Android), embedded checkout, the marketing & sales site, and any data we receive as a processor on behalf of an organizer running an event on our platform.
§ 1.2Controller vs. processor
For the dashboard accounts of organizers, sponsors, and vendors, we act as data controller. For the participant data uploaded into an event (rider rosters, photos, scores), we act as a processor on behalf of the organizer — they decide what to collect; we hold and protect it.
§ 2.0Data we collect
We try to collect the minimum data needed to operate the platform. Below is an exhaustive list, broken out by what role you're playing on WayHopper.
| Category | Examples | Retention |
|---|---|---|
| Account | Name, email, password hash (argon2id), org affiliation, role. | Account life + 30d |
| Billing | Stripe customer ID, last-4 of card, billing address, invoices. We never see full PANs. | 7 years (tax) |
| Event roster | Participant names, emergency contacts (if organizer enabled), team affiliations. | Organizer-defined |
| Location | Checkpoint pings — coarse GPS at check-in only, never continuous tracking. | 365 days |
| Photo | Photos uploaded as event challenges. EXIF stripped before storage. | Organizer-defined |
| Telemetry | Browser, OS, IP (truncated /24), referrer, page-view counters. Aggregated. | 25 months |
| Support | Email correspondence with our team, ticket attachments. | 36 months |
We do not sell personal information. Ever. We do not use participant data to train any AI/ML models. We do not enrich your data with third-party data brokers.
§ 3.0How we use data
We use the data above only for these purposes:
- Operate the platform — sign you in, route checkpoints, score events, settle vendor payouts, send transactional email.
- Support you — when you write to [email protected] or open a chat, we can see your account.
- Improve the product — aggregate, de-identified analytics on which features get used. No individual profiling.
- Comply with law — tax invoices, KYC for vendor payouts above certain thresholds, court orders we are legally required to answer.
- Keep it safe — abuse detection on accounts, rate-limiting, fraud signals on Stripe payments.
§ 4.0Legal basis (GDPR & UK GDPR)
For users in the EU, UK, or EEA, we rely on the following legal bases under Article 6 of the GDPR:
- Contract (Art. 6(1)(b)) — operating your account, fulfilling our agreement.
- Legal obligation (Art. 6(1)(c)) — tax records, regulatory reporting.
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, product analytics. Balancing tests on file.
- Consent (Art. 6(1)(a)) — optional marketing email, non-essential cookies. You can withdraw any time.
§ 5.0Sharing & sub-processors
We use a short list of sub-processors. The full list lives at wayhopper.com/subprocessors and updates with 30 days' notice. As of this revision:
- AWS — primary hosting (Sydney AU, Frankfurt EU, Virginia US). Data residency per organizer region.
- Stripe — payments & vendor payouts. Stripe is independently controller for KYC data.
- Mapbox — map tiles and route rendering. No participant identifiers shared.
- Twilio — SMS for event-day alerts (organizer opt-in only).
- Postmark — transactional email.
- Linear, Sentry, Datadog — internal tooling. Aggregated event/error telemetry only.
§ 6.0International transfers
If you're in the EU/EEA/UK, your data is stored in EU AWS regions by default. Cross-border transfers to our US or AU entities for support purposes are covered by Standard Contractual Clauses (SCCs) and the UK IDTA where applicable. We are a participant in the EU-US Data Privacy Framework.
§ 7.0Retention
Retention durations are listed in the table in § 2. Some specifics:
- Closed accounts: a 30-day soft-delete window, then irreversible purge.
- Event archives: organizers can configure 30/90/365/forever — default is 365 days.
- Backup tapes: rolling 35-day window. Data deleted from production is removed from backups within 35 days.
§ 8.0Your rights
Depending on where you live, you may have the right to:
- Access — download a copy of your data.
- Rectify — correct anything inaccurate.
- Delete — "right to be forgotten". Subject to legal-retention exceptions (e.g. tax records).
- Port — receive your data in a portable JSON/CSV bundle.
- Object — to processing based on legitimate interest, including direct marketing.
- Withdraw consent — for anything you previously opted into.
To exercise any of these, email [email protected] or use the in-product "Privacy" pane under your account settings. We respond within 30 days.
§ 9.0Children
WayHopper is not intended for children under 16. Organizers running family-friendly events (e.g. scavenger hunts that include children) collect parental consent themselves; we surface tools to enforce this but do not collect it directly.
§ 10.0Security
We hold SOC 2 Type II (renewed annually) and ISO/IEC 27001:2022. Encryption at rest (AES-256) and in transit (TLS 1.3). MFA enforced for staff. Pen-tests twice a year by independent labs (latest report available under NDA).
§ 11.0Changes to this policy
We update this policy when the law changes, our practices change, or we find clearer wording. Material changes are emailed to active account-holders 30 days before they take effect. A complete history is in the version table below.
§ 12.0Contact & complaints
For privacy questions, write to:
WayHopper Privacy Office
[email protected]Level 4, 188 James St
Fortitude Valley QLD 4006
Australia
EU Data Protection Officer
[email protected]14 Fitzwilliam Square North
Dublin D02 X264
Ireland
If you believe we've mishandled your data, you may also lodge a complaint with your local supervisory authority (e.g. the Irish DPC, the UK ICO, the OAIC in Australia).
Privacy Policy — printable PDF
The exact text on this page, paginated and signed.
Version history
| Version | Effective | Summary of changes |
|---|---|---|
| v4.2 | 2026-05-01 | Added EU-US DPF participation, expanded sub-processor list, clarified offline-queue retention. |
| v4.1 | 2025-11-12 | Clarified controller/processor split for organizer-uploaded rosters; new section on photo EXIF. |
| v4.0 | 2025-04-01 | Major rewrite for plain-English readability. SOC 2 II + ISO 27001 added. Children's section split out. |
| v3.3 | 2024-08-15 | Added Dublin office & EU controller entity. |
| v3.2 | 2024-02-01 | Switched primary EU region from Ireland to Frankfurt for redundancy. |
| v3.0 | 2023-06-01 | GDPR realignment; added portability + objection flows. |