Privacy Policy

Version 1.1 · Effective 9 September 2026

This Privacy Policy explains how Wentfar handles personal data in the Wentfar mobile app and on wentfar.com, including our support, abuse-report, and account-deletion pages. It applies to people who use those services from 9 September 2026, including during beta testing. This version clarifies website analytics, beta-app telemetry, and retention. You can request earlier versions from support@wentfar.com.

Controller and contact

Sokkio OÜ (registry code 17532051), registered in the Estonian Commercial Register at Tartu maakond, Tartu linn, Tartu linn, Raua tn 20-15, 50106, Estonia, is the controller of personal data processed for Wentfar. You can contact us at support@wentfar.com.

Data we handle

We may receive data that you provide, data generated while you use Wentfar, data from other users who share a trip with you, and data from sign-in providers and your device. This can include account and profile details; friendships and invitations; trips, Trip Notes and trip feeds, comments, reactions, packing lists, achievements, and expenses; photos, video, audio, and their associated metadata; precise location and travel-tracker records; notification preferences and device tokens; diagnostics; reports and moderation records; and support, abuse-report, and account-deletion form details.

Why we use it

We use this data to provide and secure your account and the features you choose to use; make trips and shared content work; show maps and place information; deliver notifications and updates; process media; provide support; prevent fraud and abuse; enforce our Community Guidelines; and meet legal obligations that apply to us. Where applicable, we rely on performing our agreement with you, our legitimate interests in security, reliability, and moderation, your consent for genuinely optional processing, or a legal obligation. Device permissions are choices in your operating system; they are not themselves the legal basis for processing.

Sharing and service providers

Content and trip details are visible to the people you choose to share them with, subject to trip roles, privacy settings, and the visibility you select. We also use trusted service providers to operate Wentfar, including providers of authentication, data hosting, media processing and storage, maps and place information, app updates, push notifications, and abuse prevention. These providers may process only the data needed to provide the relevant service. Our providers include Clerk, Convex, Cloudflare, Mux, Mapbox, Expo, Apple, Google, Sentry, and PostHog. Protected forms use Cloudflare Turnstile as an abuse-prevention provider, which may receive your IP address and browser or device signals to verify that a submission is legitimate.

Sentry is enabled for diagnostics in beta review builds. It may receive error and stack-trace information, redacted logs and breadcrumbs, app, device, operating-system and build context, pseudonymous user and session identifiers, and information you deliberately include in an optional problem report, such as a message, email address, or screenshot. Wentfar disables default personal-information collection and automatic screenshots in Sentry. Sentry is not used for advertising or cross-app tracking.

Analytics and recording in beta app builds

Some development and beta review builds use PostHog to understand app usage and improve Wentfar. Events can include the screens and features used, successful or failed actions, app and device information, and pseudonymous account and session references. Unlike website visitor references, app analytics can be linked to your Wentfar account. PostHog receives this data through its EU service. Optional feedback you send can include your written message and answers to the feedback questions.

Session recording may also be enabled in those beta builds. It records interactions and visible interface content; text inputs and images are masked, but other visible text may remain. The configured sample does not mean every session is recorded. App analytics and session recording are disabled for the planned public release. A website cookie choice or acknowledgement of this Policy does not authorize app analytics or recording.

Some providers may process personal data outside the European Economic Area. Where required, we rely on a European Commission adequacy decision or safeguards in our provider agreements, such as the European Commission's Standard Contractual Clauses. We also limit the data shared and restrict access according to its purpose. You can contact us for more information about the safeguard relevant to a transfer.

If you have questions about a recipient or transfer, contact support@wentfar.com.

Wentfar is currently free and has no advertisements, paid features, or subscriptions. We do not use your information to sell advertising.

Optional website analytics

Where we offer analytics, we use PostHog only after you choose Accept analytics. You can reject analytics and continue using every page and form. We measure visits, page types, device categories, approved campaign sources, and actions such as download clicks. Public-trip measurement uses an opaque trip reference; it does not send the sharing link, trip title, photos, itinerary, or your form entries to PostHog. Website session recording and advertising tracking are off.

We remember your choice for about six months. After acceptance, a first-party analytics cookie holds random visitor and session references for no longer than that choice lasts. These references are not linked to your Wentfar account. PostHog receives network information needed to process requests through its EU ingestion service. Country-level measurement is currently disabled; enabling it would estimate country from network information rather than precise location.

Cookie settings in the footer lets you withdraw at any time. Withdrawal stops new measurement and clears the analytics cookie; it does not delete events already received. Contact support@wentfar.com for privacy rights, including deletion where applicable. Website analytics is currently disabled. Our proposed event-retention limit is 12 months; we will confirm the period here before enabling collection. Your website choice does not grant permission for analytics or recording in the mobile app.

Permissions and location

Camera, photo-library, microphone, notification, and location permissions are optional and are requested when you use a feature that needs them. You can change them in your device settings; denying a permission can limit the related feature. The travel tracker can record location while a trip is being tracked, including when the app is not open if you allow background location. You start and stop tracking in the app. Synced trip location is available only to the people allowed to view that trip. The tracker is not an emergency service.

Retention and account deletion

We keep active account and trip data while your account remains active or until it is removed by you or an authorised trip member. Temporary upload and media-processing records expire or enter cleanup within 1 to 24 hours. Invite links expire after 7 or 30 days, depending on the type. Raw tracker points that have not become trip content are cleaned up after 30 days. Transactional email content is kept for up to 30 days, and delivery metadata for up to 180 days. Informational operation events and debug/informational audit records are kept for 30 days; warning, error, and administrator audit events are kept for 90 days. Closed safety reports are minimized after 90 days.

When you delete an account, we start the deletion process for the account and associated data. Necessary security and moderation records can enter a hold of up to 90 days. After that hold and completion of the deletion workflow, we remove the deletion-request record and the original-account link from retained shared financial history. Specific legal holds can delay this cleanup until their expiry. Shared expense history needed by other trip members and provider backups or logs may remain longer. Access to retained records is restricted. Contact us for the status of your request and the reason and period for any data that remains. Deleting the app or withdrawing analytics does not by itself remove data already held by service providers.

You can start deletion in the app or through our verified-email account-deletion page. If you own a trip with other participants, the review flow lets you remove participants in Wentfar or choose to delete the trip for everyone. Other participants’ independent content and any necessary shared financial context may not be removed with your account. We will explain any retention that applies to a particular request.

Retention also depends on the provider and the beta configuration. The PostHog review project currently reports 30-day recording retention and an event-retention setting of 84 months that is not marked as enforced. That setting is not an assurance that events are automatically deleted at that time. Website analytics remains disabled while we verify a shorter enforceable period. For provider-held data, contact support so we can assess access or deletion separately from the app's account-deletion process.

Security

We use technical and organisational measures intended to protect personal data, including authentication and access controls. No method of transmission, storage, or deletion is completely secure, and we do not claim that every copy of data on every device is encrypted or can be remotely erased.

Age

Wentfar is for people aged 13 and over and is not directed to children under 13. If optional processing requires consent, additional age or location-specific requirements may apply. If you believe a child has provided us information contrary to this Policy, contact us at support@wentfar.com.

Your privacy choices and rights

Depending on where you live and the processing involved, you may ask for access, correction, deletion, portability, restriction, or objection, or withdraw consent for optional processing. We verify requests proportionately to protect you and other people. Where applicable, we provide requested data securely through support. Read how to make a request on Privacy Choices.

Please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, +372 627 4135, or with the data-protection supervisory authority in the EEA country of your habitual residence, place of work, or the place of the alleged infringement.

Changes to this Policy

We will post the current version and effective date here. If a change is material, we will provide additional notice in the app or by another appropriate channel. Notice of a Policy change is separate from any consent required for optional processing.