Skip to content
Wander

Privacy

Privacy policy

Effective 1 January 2026. Written to be read, with the detail in tables rather than buried in paragraphs.
01

Who we are

Wander Inc. is a Delaware C corporation with its principal office at 1550 Wewatta Street, Suite 200, Denver, CO 80202, United States. We operate the Wander trip-planning service at wandertrip.org. We are the data controller for the personal information described in this policy. Questions go to privacy@wandertrip.org.

02

What we collect

CategorySpecific dataWhy we collect itKept for
Account informationName, email address, password hashTo create and authenticate your accountLife of the account, then 30 days
Trip briefsDestination, dates, budget, pace, taste preferences and any notes you writeTo generate your itinerary and let you return to the planUntil you delete the trip or your account
Saved itinerariesThe day-by-day plan, stops, notes, tags and timingSo you can revisit, share and adapt your tripUntil you delete the trip or your account
Trip adjustmentsThe tweak instructions you give to rebuild a dayTo understand what changed and keep the rest of the plan intactUntil you delete the trip or your account
Billing recordsPlan, payment dates, Stripe customer IDTo manage your subscription and meet legal obligations7 years from the transaction date
Usage countsNumber of trips planned, tier, features usedTo enforce plan limits and bill accurately24 months
Form submissionsMessages sent via contact or support formsTo respond to your message24 months
Server logsIP address, request URL, timestamp, response codeSecurity, reliability and abuse prevention. Never contain trip content30 days
03

How we use your information

We use your account information to identify you, let you sign in, and send you transactional messages such as password resets and billing confirmations. We do not send marketing email without your opt-in.

We use your trip brief, including your destination, dates, budget, pace and taste preferences, to generate your itinerary. The model produces the plan. Our code validates the structure, walkability and pacing before you see it.

When you ask Wander to adapt a day, we send the existing plan, the day being rebuilt, and your tweak instruction to the model. The rest of your trip does not move.

We use aggregate, de-identified usage data to understand which features are working and to improve the service. This data cannot identify you.

04

The AI layer and model providers

Wander uses third-party language models to generate your itinerary. When you plan a trip, we send a structured payload to the model provider containing your trip brief: destination, dates, budget, pace and taste preferences. We do not send your name or email address to the model.

This happens under a business API agreement that expressly prohibits the provider from using your data to train or improve their models. Your trip data is not used for any purpose other than producing your itinerary in that session.

Wander is model-agnostic. It routes across providers based on the task. You can read about the routing logic on the how-the-AI-works page. Whichever provider handles your request, the same data-protection terms apply.

05

What we do not do

  • We do not sell your personal information or your trip data to anyone, ever.
  • We do not share your data for advertising purposes or allow advertisers to target you based on your travel preferences.
  • We do not buy personal information from data brokers.
  • We do not run advertising trackers. There are no third-party advertising cookies on this site.
  • We do not ask for your bank credentials. Wander does not connect to your bank or payment accounts.
  • We do not store payment card numbers. If you subscribe, Stripe handles the card and we receive only a token.
  • We do not use your trips to inform recommendations that benefit anyone other than you.
06

Who your information goes to

Our hosting provider stores the database and runs the application, within the United States. Our language model provider or providers receive trip briefs to produce itineraries, as described in section 4. Stripe processes payments. These are the processors we rely on, and this list is kept complete: if it changes, this section changes.

We may share information if required by law, court order or regulatory demand, and in that case we will notify you where the law permits.

If Wander is acquired or merged, your data would transfer to the acquirer, who would be bound by this policy or would obtain your consent to a new one before making any changes.

07

Storage and security

Your account information and trip data are encrypted at rest using AES-256 and in transit using TLS 1.2 or later. Access to production data is restricted by role, logged, and reviewed.

We aim to notify you within 72 hours of discovering a breach that is likely to affect your rights. Security questions go to security@wandertrip.org. Our security practices are described in more detail on the security page.

08

Retention

We keep your data for as long as your account is open and for the periods in the table in section 2. When you delete your account, we remove your trips and personal information from the active database within 30 days. Billing records are retained for 7 years as required by US tax law, stored separately and inaccessible to the application.

Server logs are deleted after 30 days. Usage counts are deleted after 24 months.

09

Your rights

You can access, correct, export and delete the personal information Wander holds about you. Most of this is self-serve: trips delete from your trips list, and the full account deletes from Settings.

For a structured export of everything we hold, email privacy@wandertrip.org and we will provide it within 30 days at no charge.

If you are in California, the California Consumer Privacy Act gives you the right to know what we collect, the right to delete it, and the right to opt out of sale. We do not sell personal information.

If the GDPR or UK GDPR applies to you, the legal bases we rely on are: performance of a contract, to deliver the service you signed up for; legitimate interests, for security, reliability and aggregate analysis; and consent, for anything optional, which you can withdraw at any time.

To exercise any right, or if you believe something has gone wrong, email privacy@wandertrip.org. We will respond within 30 days.

10

Children

Wander is not directed at anyone under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it promptly. If you believe a child's information has been submitted, contact privacy@wandertrip.org.

11

Changes to this policy

If we change this policy in a way that affects your rights or how we use your data, we will email account holders at least 30 days before the change takes effect. Continuing to use Wander after that date means you accept the updated policy. Minor clarifications will be updated without email notice.

This policy is effective 1 January 2026.

How to export or delete your data is on the your data page. Security measures and encryption are on the security page. Cookies are covered on the cookies page.