Privacy Policy
Last updated: 13 August 2026. This policy is drafted in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR"), Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights ("LOPDGDD"), and Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce ("LSSI-CE").
0. Identity of the data controller
The controller responsible for processing the personal data collected through the WayFy platform (hereinafter, "WayFy", "the Platform" or "the Service") is:
- Name: WayFy
- Contact email: soporte@wayfy.es
Given the nature and current volume of the Service's processing, the appointment of a Data Protection Officer (DPO) is not legally required under Article 37 GDPR. Any data protection query may be addressed to the contact address shown above.
1. Purpose and scope
This Privacy Policy is intended to inform users (hereinafter, "the User" or "Users") about WayFy's processing of their personal data when registering for and using the Platform, whether through the website, associated applications or any other channel enabled for that purpose.
Using the Service implies acceptance of this policy. If the User does not agree with its content, they must refrain from registering or providing personal data through the Platform.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (collection, recording, storage, use, disclosure, erasure, etc.).
- Processor: a third party that processes personal data on behalf of and under the instructions of the controller.
- User-generated content: reviews, photographs, trips, comments, messages and other contributions voluntarily published on the Platform.
3. Categories of data we process
WayFy processes the following categories of data, always limited to what is strictly necessary to provide the Service (data minimisation principle, Art. 5.1.c GDPR):
- Registration and identification data: first name, surname, email address and password (stored using the Argon2id hash function, never in plain text).
- Profile and accessibility data: mobility preferences and conditions selected by the User (wheelchair, crutches, walker or others), avatar and profile bio.
- Account security data: TOTP secret and backup codes when the User enables two-factor verification; one-time code sent by email when the User chooses to sign in without a password, always stored as a hash; history of failed login attempts, for the purpose of temporarily locking the account.
- Google account data when the User chooses to sign up or sign in with that provider: Google account identifier, email address, name and profile photo provided by Google itself.
- Cryptographic material for encrypted chat: the User's public key and their already-encrypted private key, together with the wrappings corresponding to each unlock method (a passkey or recovery code). WayFy holds these elements but has no key capable of opening them (see section 9).
- Notification and role preferences: alert channels enabled by the User (web and email) and, for staff with administration or moderation duties, their assigned role and permissions.
- User-generated content: accessibility reviews and photographs, places proposed for the map, trips and itineraries, comments on public trips, direct and group chat messages, and favourite-organising tags.
- Social relationship data: friend requests, friend lists and privacy preferences associated with each User (profile visibility, friends visibility, trips visibility, permission to receive messages, etc.).
- Geolocation data: if the User authorises it through their browser, WayFy briefly accesses their approximate location to centre the map and show nearby results. This data is processed on the User's device and is not stored linked to their account.
- Technical and connection data: IP address, session identifiers (cookies), connection status (online / away / offline) and technical logs necessary for the security and proper functioning of the Service.
4. Purposes of processing and legal basis
We process the above data for the following purposes, each covered by the legal basis indicated under Article 6.1 GDPR:
- Account management and authentication (email verification, sign-in, two-factor, password recovery): performance of the contract to provide the Service (Art. 6.1.b).
- Provision of the Service's features (accessibility map, trip planner, favourites, reviews, chat, friends system, notifications): performance of the contract (Art. 6.1.b).
- Moderation of community content (review of places proposed by the community before general publication): legitimate interest in ensuring the accuracy of accessibility information (Art. 6.1.f).
- Personalisation of the experience based on the indicated mobility profile: User consent (Art. 6.1.a), revocable at any time from their profile.
- Service communications (account verification, security alerts, social activity notifications the User has enabled): performance of the contract and legitimate interest in keeping the User informed (Arts. 6.1.b and 6.1.f).
- Platform security (blocking fraudulent access attempts, rate limiting, abuse prevention): legitimate interest (Art. 6.1.f) and compliance with legal obligations on information security (Art. 6.1.c).
- Custody of chat cryptographic material so the User can read their encrypted conversations from several devices: performance of the contract (Art. 6.1.b).
- Publication of public trips and public profiles and their indexing by search engines: User consent (Art. 6.1.a), given by marking the trip as public or by opening up their profile visibility, and revocable at any time (see section 10).
- Sharing content on WayFy's official profiles on Instagram and Facebook: express and separate User consent (Art. 6.1.a), given via a specific checkbox when publishing a trip or proposing a place, and revocable at any time.
- Calculating accessible routes and supporting the AI assistant based on the stops or text entered by the User: performance of the contract (Art. 6.1.b).
5. Recipients and processors
WayFy does not sell or transfer personal data to third parties for commercial or advertising purposes. In order to provide the Service, certain data is shared with the following providers, which act as processors or, where applicable, as independent controllers of the data they receive directly from the User's browser:
- Mapbox, Inc. — rendering of the interactive map. Receives the coordinates of the viewed area and the User's IP address.
- Geoapify — address autocomplete and geocoding of searches.
- OpenStreetMap (Nominatim) and Photon / Komoot GmbH — resolving addresses and points of interest from the User's searches.
- Groq, Inc. — processing of the text entered into the AI assistant. Only the conversation content is sent, without any identifying account data.
- Cloudinary Ltd. — storage and delivery of images uploaded to the Platform: profile avatars, accessibility photographs, trip covers and group avatars. Images are compressed before upload and served through WayFy's own domain.
- Google Ireland Ltd. / Google LLC — sign-in with a Google account (OAuth 2.0), when the User chooses that route, and retrieval of the cover photo for certain places via Google Places. In this second case only the place's name and coordinates are sent, never User data.
- HeiGIT gGmbH (OpenRouteService) — calculation of the accessible route between a trip day's stops. It only receives the coordinates of those stops, sent from WayFy's server, without any account identifier or the User's IP address.
- Meta Platforms Ireland Ltd. — publishing content on WayFy's official Instagram and Facebook profiles, exclusively when the User has expressly authorised it and an administrator has approved the post. The title, description, cover image and public link of the content are transmitted.
- Microsoft, Yandex and Seznam (IndexNow protocol) — automatic notice that a public trip has been published, modified or withdrawn, for indexing purposes. Only the trip's web address is shared.
Transactional emails (account verification, password recovery, sign-in code, moderation notices) are sent through mail accounts configured and managed by the controller itself, without any involvement of third-party bulk-mailing platforms.
The Service's server, database and technical cache infrastructure is hosted by [hosting provider and country, to be completed by the controller], which acts as a processor under a contract signed pursuant to Article 28 GDPR.
6. International transfers
Some of the providers listed in the previous section (Mapbox, Groq, Cloudinary, Google and Microsoft) may process data in the United States or in other territories outside the European Economic Area, which involves an international data transfer. These transfers are covered by the Standard Contractual Clauses approved by the European Commission or by the adequacy mechanism currently applicable to each provider (the EU-US Data Privacy Framework, where applicable).
Transfers to Yandex and Seznam arising from the IndexNow protocol are limited to the public web address of a trip already published by its author and do not include Users' personal data.
7. Cookies and similar technologies
WayFy exclusively uses technical or essential cookies and local storage, necessary for the Service to function and therefore exempt from the duty to obtain consent under Article 22.2 LSSI-CE:
- wayfy_access_token / wayfy_refresh_token — HttpOnly cookies that keep the session signed in. Duration: 15 minutes and 7 days respectively; deleted on sign-out.
- wayfy_csrf_token / wayfy_refresh_csrf_token — cookies protecting against cross-site request forgery (CSRF) attacks. Duration: the same as the session cookie they accompany.
- localStorage — remembers the chosen visual theme (light, dark or high contrast), the User's decision on this cookie notice itself (
wayfy_cookie_consent) and the stops marked as visited on a trip day's map. This last marker is a walking aid: it is not sent to the server or linked to the trip. Duration: persistent until the User clears their browser data. - IndexedDB (
wayfy-e2ee) — stores on the device itself the key pair that decrypts chat messages, so it doesn't need to be unlocked on every visit. Never transmitted to the server. Duration: persistent until the User resets their encrypted identity or clears their browser data.
WayFy does not use analytics, advertising or third-party tracking cookies. The cookie management panel lets you reject all, accept only essential cookies, or accept all available categories; as of this policy, the Service experience is identical under any of the three options, since there are no active non-essential cookies.
8. Retention period
- Account data is kept for as long as the User keeps their profile active on the Platform.
- Email verification tokens expire after 24 hours and password recovery tokens after 30 minutes of issuance.
- The session (access) token expires after 15 minutes and the refresh token after 7 days, after which re-authentication is required.
- Chat cryptographic material (public key, encrypted identity and unlock wrappings) is kept for as long as the User keeps encryption active, and is deleted when resetting the identity or closing the account. Once deleted, messages encrypted with that identity are unrecoverable by anyone, including WayFy.
- The technical cache of cover photos retrieved from Google Places only keeps the place identifier and the temporary link to the image, which is renewed approximately every 50 minutes. It contains no personal data.
- Notifications are kept until the User deletes them from their notification history.
- After requesting account deletion, identifying personal data is permanently erased. Content of community value (reviews, accessibility photographs and approved places) is kept dissociated from the User's identity, so as not to reduce the usefulness of the collaborative map.
- Posts already published on WayFy's Instagram and Facebook profiles remain hosted on those platforms until removed. Their removal can be requested through the contact address given in section 0.
9. End-to-end encryption of messages
Chat messages, both direct and group, are encrypted on the User's device before being sent and are only decrypted on the recipients' devices. WayFy stores the already-encrypted text and has no means whatsoever to read it.
- Each User's private key is stored on the server wrapped with a master key that is only reconstructed in the browser, from an access key (passkey) or the recovery code. Neither of those two secrets is ever transmitted to WayFy.
- As a direct consequence of the above, WayFy cannot recover the history of a User who loses all their unlock methods, hand over message content to a third party, or moderate the content of private conversations.
- The data needed to deliver messages does remain visible to the Service: who takes part in each conversation, the date and time sent, and read status, when the User has not disabled it in their privacy preferences.
10. Public content and search engines
Certain content is public by the User's own decision and is therefore accessible to anyone and liable to be indexed by search engines:
- Trips marked as public, with their title, description, itinerary, cover image and their author's name and avatar. When publishing or editing them, WayFy reports their web address to search engines that support the IndexNow protocol and includes it in its sitemap.
- The User's public profile , with the scope the User themself defines in their privacy preferences (visibility of surname, mobility profile, friends and trips).
- The reviews, accessibility photographs and approved places, together with the name of whoever contributed them, as they form part of the map's collaborative information.
When a trip's public status is withdrawn, WayFy stops showing it and notifies search engines again, although it does not control the update schedule of their indexes or any cached copies they may temporarily keep.
11. Automated decisions and profiling
WayFy does not make decisions based solely on automated processing that produce legal effects on the User or similarly significantly affect them (Art. 22 GDPR). Adapting results to the indicated mobility profile and the AI assistant's suggestions are guidance aids: they do not replace the User's decision or condition their access to the Service. Content moderation and account suspension decisions are always made by a member of the administration team.
12. Rights of Users
Under Articles 15 to 22 GDPR, the User may exercise the following rights at any time:
- Access: find out what personal data of theirs we process.
- Rectification: correct inaccurate data, directly from their profile or by written request.
- Erasure ("right to be forgotten"): request deletion of their account and associated data.
- Objection and restriction: object to specific processing or request its restriction in the cases provided for by the regulations.
- Portability: receive their trips and reviews in a structured, commonly-used format.
- Withdrawal of consent: when processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal.
A good part of these rights can be exercised directly from the User's own panel, with no need for a prior request: correcting their profile data, adjusting the visibility of their profile and trips, enabling or disabling each type of notification, removing a trip from the public listing and closing the account with double confirmation.
These rights may be exercised by writing to soporte@wayfy.es, indicating the right the User wishes to exercise and enclosing a copy of a document proving the requester's identity. WayFy will respond within a maximum of one month, extendable by a further two months in particularly complex cases.
If the User believes their data is not being processed in accordance with the applicable regulations, they have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) via www.aepd.es.
13. Security measures
WayFy applies technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:
- Password encryption using the Argon2id hash function.
- Authentication via JWT tokens served in HttpOnly cookies with CSRF protection, short-lived and with controlled renewal.
- Two-factor verification (2FA) via a TOTP app and one-time backup codes, enabled voluntarily.
- End-to-end encryption of chat messages (ECDH over the P-256 curve and AES-GCM), with the private key kept encrypted and unlockable only by its owner.
- Re-authentication with password and, where applicable, second factor before sensitive chat-encryption operations.
- Temporary account lockout after several failed login attempts.
- Database encryption of mailbox credentials and social media access tokens used by the Service.
- Content Security Policy (CSP) and security headers restricting the origins the browser can load resources from, with no dependencies on external fonts or stylesheets.
- Rate limiting per user and IP to prevent automated abuse.
- Role-based access control for staff with administration or moderation duties, restricted to what is necessary to perform their functions.
14. Minors
The Service is aimed at people over 16 years old, the minimum age to give consent to the processing of personal data under Article 8 GDPR and the first additional provision of the LOPDGDD. When registering, the User must expressly declare that they meet that age requirement or that they have their legal representative's authorisation. WayFy does not knowingly collect data from minors under that age. If it becomes aware that data has been collected from a minor without the required authorisation, it will proceed to delete it.
15. Changes to this policy
WayFy may amend this Privacy Policy to adapt it to legislative or case-law developments or to changes in the Service. Any substantial amendment will be notified to the User by email or via a prominent notice on the Platform at least 15 days before it takes effect.