Privacy policy

What WholeAway stores, where it stores it, and how to get it back or delete it.

This is an operational draft. It describes the product accurately, but it has not yet been reviewed by qualified legal counsel, and the controller's registered identity and contact address are still to be confirmed. Both are required before public release.

The short version

WholeAway works without an account. If you never sign in, your searches, saved trips and plans stay on your device. There is no advertising network in the product, and no third-party analytics or crash-reporting vendor is enabled.

What stays on your device

Personalisation can be switched off, and history can be deleted item by item or all at once, from Settings. Passport and residence details are deliberately excluded from search history.

What reaches the server

Searches are executed on our backend because provider credentials must not live on a phone. A search request contains the trip parameters — origin, budget, dates, party composition, preferences — and either your installation identifier or, when signed in, your account identifier.

If you create an account, we store the identifier, e-mail address and any display name your provider returns. If you enable price alerts we store the watch, your consent time and a device token so the alert can reach you.

Processors we use

Provider requests are made from our servers. Your e-mail address is not shared with travel providers.

Getting your data back, and deleting it

The app can export everything it holds as a JSON file, including the local records, and can delete your account and its server-side records. Remote deletion must succeed before the local copy is cleared, so a failure cannot leave you with nothing.

Legal bases and retention

Search and planning data is processed to provide the service you asked for. Price alerts and push notifications are processed on your explicit consent and stop when you withdraw it. Records tied to an installation identifier are removed on the retention schedule documented in the repository, and account records are removed on request.

Contact

Data-protection requests will be handled through the support address published on this site before release.