Summary
- We collect account info, trip data, and basic usage analytics — nothing more.
- We do not sell or rent your personal data to advertisers, brokers, or campgrounds.
- We use trusted vendors (hosting, email, analytics) and require them to handle your data securely.
- You can download all of your data, or permanently delete your account, from the Profile page at any time.
- We respond to data requests under GDPR, CCPA, and similar laws within 30 days.
What we collect
Information you give us directly
When you create an account we collect your name, email address, and a hashed password. If you sign in with Google or Apple, we receive your name and email from that provider — no passwords are stored on our servers. When you set up a profile, you may also tell us about your RV (length, hookups, slide-outs) and your pets (name, species, breed, any access needs). All of this is optional and you can edit or remove it from the Profile page at any time.
Information we generate about your trips
When you plan a trip we store the route, the destinations, your travel dates, and the AI conversation that produced the itinerary. We use this to let you re-open and continue trips, and (in aggregated, de-identified form) to improve the planner's suggestions for everyone.
Information collected automatically
Like most web services, our servers receive standard request metadata: IP address, browser type, and timestamps. We use a privacy-respecting analytics provider to understand which features are used and where people get stuck. We do not use third-party advertising trackers or social-media pixels.
How we use your information
- To run the service: log you in, plan trips, save places, and sync between your devices.
- To send transactional email — receipts, password resets, and trip confirmations.
- To send product updates if you've opted in (you can unsubscribe in one click).
- To detect abuse, prevent fraud, and keep the service reliable for everyone.
- To improve the AI planner, using only de-identified or aggregated data.
Who we share it with
We share data only with vendors who help us run the service, and only the minimum they need to do their job. As of today that includes:
- Hosting: our application servers and database.
- Email: a transactional email provider for receipts and notifications.
- Maps: a third-party tile and geocoding provider for the maps you see in-app.
- Analytics: a privacy-respecting product analytics provider with IP anonymization enabled.
- Payments: a PCI-compliant processor; we never see or store your card number.
We do not sell, rent, or trade your personal data. We will only disclose your data to law enforcement when we receive a valid legal request and, where we're permitted to, we'll notify you first.
Cookies and similar technologies
We use a small set of first-party cookies to keep you signed in and remember your preferences. We use one analytics cookie (with IP anonymization) to measure feature usage. We do not use advertising or cross-site tracking cookies. You can disable cookies in your browser, though signing in won't work if you do.
Your rights and choices
Wherever you live, you can:
- Access a copy of the personal data we hold about you.
- Correct anything that's inaccurate from your Profile page.
- Export all of your trips and saved places as a JSON download.
- Delete your account, which removes your personal data within 30 days (anonymous, aggregated trip statistics may be retained).
- Object to any specific use of your data by emailing places@mywaggle.com.
California residents have additional rights under the CCPA, and EU/UK residents have rights under the GDPR — including the right to lodge a complaint with your local data protection authority. We'll always respond within 30 days.
How long we keep your data
We keep your account data for as long as your account is active. If you delete your account, we remove personal data within 30 days. Trip data older than 24 months is automatically rolled into anonymous, aggregate statistics. We retain billing records for 7 years to comply with tax law.
Security
Your data is encrypted in transit (TLS 1.3) and at rest. Passwords are hashed with bcrypt. Access to production systems is limited to a small group of employees, requires hardware security keys, and is logged. We run third-party security reviews annually and disclose material breaches to affected users within 72 hours.
Children
Waggle Places is not directed at children under 13, and we don't knowingly collect personal data from them. If you believe a child has signed up, contact us and we'll remove the account.
Changes to this policy
We'll post the updated date at the top of this page whenever we make material changes, and we'll email everyone with an active account at least 14 days before the change takes effect.
How to reach us about privacy
Email places@mywaggle.com with any data request, complaint, or question. Our mailing address is on the Contact page.