Privacy Policy
Last Updated: July 12, 2026
At Wayly, we value your trust above all else. This Privacy Policy describes how Wayly Inc. ("we", "us", or "our") collects, uses, processes, and discloses information in connection with our mobile application (the "App"), our website, and all associated services (collectively, the "Services").
We limit data collection to the minimum required to facilitate secure transactions, fulfill flights, hotels, and activities bookings, comply with our legal and auditing obligations, and provide direct customer support. By using our Services, you consent to the data practices described in this Policy.
1. Information We Collect
To provide the travel search and booking experience, we collect the following types of information, which may constitute Personal Data or Personally Identifiable Information (PII) under various jurisdictions:
- Identity & Contact Data: Full legal name, email address, phone number, physical address, date of birth, and gender.
- Travel Documents: For international travel bookings, passenger passport details (passport number, country of issuance, expiry date, and nationality). These details are strictly required by government agencies and travel carriers for ticketing.
- Booking Details: Flight itineraries, passenger names, hotel reservations, lodging choices, dates of travel, and companion information.
- Payment Logs: Cryptocurrency transaction hashes, blockchain wallet network addresses, invoice amounts, and transaction status. Note: We never collect, access, or store your private keys, seed phrases, or login credentials to external digital asset wallets.
- Technical & Device Information: IP address, unique device identifiers, operating system version, app crash logs, request timings, and API interactions.
2. How We Use and Process Your Information
We process your personal information based on the following legal grounds (including contract performance, legal compliance, and legitimate interests):
- Fulfillment of Contracts: To execute travel availability checks, verify pricing, and issue tickets/bookings with our airline, hotel, and activity providers.
- Payment Verification: To monitor and validate cryptocurrency payment completion on public blockchains before triggering final booking actions.
- Customer Service & Communications: To deliver booking confirmations, e-tickets, hotel vouchers, push notifications, and support assistance via Telegram or email.
- Security & Fraud Prevention: To detect, investigate, and prevent malicious, deceptive, or illegal activity, and secure our system APIs.
- Legal Compliance: To comply with financial auditing, tax reporting requirements, transport safety regulations, and legal warrants.
3. Information Sharing and Supplier Integrations
We do not sell, rent, or trade your personal data. To ticket and fulfill your requested bookings, we share passenger data with third-party travel suppliers and platform partners strictly as necessary:
- Travel Suppliers: Passenger details (including passport data where applicable) are transmitted to booking providers such as Duffel (flights), Mystifly (flights), RateHawk / ETG (hotels), and Viator (activities) to secure reservations. These entities process your data in accordance with their respective privacy policies.
- Payment Gateways: We integrate with Payfall to generate transaction invoices and verify token transfer statuses.
- Regulatory and Legal Authorities: We may disclose data if legally required to do so under subpoena, court order, or to satisfy civil aviation/border security authorities (e.g., flight passenger manifests).
4. Data Security, Isolation, and Signatures
We implement comprehensive organizational and technical security measures to safeguard your personal data:
- All network communications are strictly encrypted using Transport Layer Security (TLS/HTTPS).
- Server-side databases housing sensitive traveler records are isolated from direct public internet routing.
- We enforce strict signature validation checks on all incoming webhooks (e.g., Payfall) to verify authenticity and prevent tampering.
While we take rigorous precautions, no transmission method over the internet or database storage is 100% secure. We cannot guarantee absolute security against unauthorized access or breaches.
5. Data Retention Policy
We retain your Personal Data only as long as necessary to perform the booking contract, comply with tax and auditing laws, and resolve billing disputes. Passport records collected for international travel are retained exclusively to complete the ticketing process and will be securely deleted or anonymized once the travel contract is fulfilled or no longer subject to dispute.
6. International Data Transfers and Regional Rights (GDPR & CCPA)
As a global travel booking intermediary, your personal information may be transferred to and processed in countries outside your residence, where data protection standards may differ.
If you reside in the European Economic Area (EEA), United Kingdom, or California, you are entitled to specific rights under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), including:
- The right to access, update, correct, or retrieve a copy of your Personal Data.
- The right to restrict or object to certain processing activities.
- The right to request the complete deletion of your data ("Right to be Forgotten").
- The right to opt-out of data collection/sharing for commercial marketing (we do not sell your data).
To exercise any of these rights, please submit an request to support@wayly.ai. We will respond within the statutory timeframe.
If you have questions regarding this policy or our data safety practices, you can chat with a live representative in our official Telegram bot or email our legal compliance team at support@wayly.ai.