Privacy Policy
Last updated: 29 August 2026
1. Who we are
Waylo Go operates the peer-to-peer parcel delivery marketplace at waylogodelivery.com. Waylo Go is the data controller for the personal data described here. For privacy questions, data-rights requests or complaints, contact privacy@waylogodelivery.com (general support: support@waylogodelivery.com). We respond to verified requests within 30 days.
2. What we collect
- Account data: name, email address, phone number, password hash, chosen role (sender / traveler), language and notification preferences.
- Identity verification: government ID document and selfie check, processed by Stripe Identity. We store only the verification result and a reference, not your ID images.
- Listing and delivery data: trips, parcels, routes, dates, declared contents and value, recipient first name and contact detail supplied by the sender, handoff photos, delivery-code events, ratings and reviews.
- Messages: in-app chat between matched users and attachments.
- Payment data: escrow and payout records. Card details are handled by Stripe and never reach Waylo servers.
- Technical data: IP address, device and browser type, timestamps, error diagnostics, and (only with your consent) analytics events.
We do not knowingly collect data from anyone under 18. Waylo Go is an adults-only service; accounts found to belong to minors are deleted.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create your account and run the marketplace | Contract |
| Match senders with travelers and rank matches | Contract |
| Hold and release escrow, pay travelers | Contract; legal obligation |
| Verify identity and phone; prevent fraud and prohibited items | Legal obligation; legitimate interests (platform safety) |
| Resolve disputes using photos, messages and code records | Contract; legitimate interests |
| Service emails, SMS and push notifications about your deliveries | Contract |
| Marketing or pilot-update emails | Consent (withdraw at any time) |
| Analytics cookies | Consent |
| Security logging, abuse prevention, accounting records | Legitimate interests; legal obligation |
We do not use your data for automated decisions that produce legal effects. Match ranking and trust levels are computed automatically, but account suspension, dispute outcomes and verification rejections always involve human review, and you may contest them by writing to privacy@waylogodelivery.com.
4. What other users can see
Other users see your first name, avatar, verification badges, trust level, rating and review count, and the public details of listings you post. Your email address is never shown. Your phone number is only revealed to a matched counterparty at handoff time, and only in part. Chat messages automatically mask phone-number-like text to keep contact exchange inside the platform.
5. Who we share data with
We never sell or rent personal data, and we do not share it for cross-context behavioural advertising. We use these processors under written data-processing terms:
- Supabase: database, authentication and file storage.
- Stripe (Payments, Identity, Connect): payments, escrow, payouts and ID verification.
- Twilio: phone verification (SMS one-time codes).
- Resend: transactional email delivery.
- Sentry: error monitoring and diagnostics.
- Google Analytics: only if you accept analytics cookies.
We may also disclose data to law enforcement, customs or regulators where legally required, and to a successor entity in a merger or acquisition (you will be notified).
6. International transfers
Waylo Go operates corridors between Ethiopia, the United States, Europe, the Gulf and beyond, so your data necessarily crosses borders. Our infrastructure and processors are primarily located in the United States and the European Union. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) together with technical safeguards including encryption in transit and at rest, and access restricted through row-level security. Copies of the relevant transfer terms are available on request.
7. How long we keep it
- Account and profile data: while your account is active.
- Delivery, escrow and dispute records: up to 7 years after completion, to meet financial, tax and anti-fraud obligations.
- Chat messages and handoff photos: 24 months after the delivery closes.
- Identity-verification results: 5 years (anti-money-laundering practice).
- Security and access logs: 12 months.
- Analytics data: 14 months.
When you delete your account we remove your profile, listings and preferences immediately and anonymise the remaining transaction records we are required to keep.
8. Your rights
Wherever you live, you can export all of your data or permanently delete your account yourself from Profile → Privacy. We never charge for a rights request and never discriminate against you for making one.
EEA, UK and Switzerland (GDPR / UK GDPR)
You have the right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time (withdrawal does not affect prior processing). You may lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office.
United States (CCPA / CPRA and state privacy laws)
California, Colorado, Connecticut, Virginia, Texas and other state residents may request to know, access, correct, delete and port personal information, and may appeal a refused request by replying to our decision email. In the past 12 months we have not sold or shared personal information as those terms are defined under the CPRA, and we do not process sensitive personal information for inferring characteristics: so there is nothing to opt out of, but you may still email us to confirm. We honour Global Privacy Control signals as an opt-out of analytics cookies.
Ethiopia, Nigeria, Kenya, South Africa and other African jurisdictions
We apply the same access, correction, deletion and objection rights to all users, consistent with Ethiopia's Personal Data Protection Proclamation, Nigeria's Data Protection Act, Kenya's Data Protection Act and South Africa's POPIA. Ethiopian, Nigerian and Kenyan users may also complain to their national data-protection authority.
Canada, Brazil, and the rest of the world
PIPEDA, LGPD and comparable regimes are honoured through the same self-service export and deletion tools and the contact address above.
9. Cookies
Essential cookies keep you signed in and remember your preferences. Analytics cookies load only after you accept them. You can review the full list and change or withdraw your choice at any time on our cookie policy page.
10. Security
Data is encrypted in transit (TLS) and at rest. Access is enforced per-row in the database so users can only reach their own records; parcel photos and dispute evidence are stored in private buckets served through short-lived signed URLs. Optional two-factor authentication is available in your profile. If a breach affects your rights, we will notify you and the competent authority within 72 hours of becoming aware.
11. Changes to this policy
We will post any update here with a new “last updated” date, and email you before material changes take effect.