Not production legal advice. Bracketed review notes have been turned into visible counsel notes so launch owners can see what remains unresolved.
1. Scope and controller
This notice is intended to cover the Waystone website, customer account, checkout, eSIM management, support, and partner inquiry experiences.
Before production, identify the legal entity responsible for personal data, its address, privacy contact, and applicable representatives.
2. Information you provide
Depending on the feature you use, Waystone may receive contact and account details, order and payment references, destination and device information, support messages, and partner inquiry details. Payment-card data should be entered directly into the configured payment provider’s secure interface rather than stored by Waystone.
- Account: name, email, and authentication records.
- Orders: selected plan, destination, price, payment status, and fulfillment references.
- Support: device, destination, order reference, diagnostic answers, and your description.
- Partners: professional contact, organization, partnership type, and inquiry details.
3. Information created by the service
Waystone may create session records, security and audit events, order status, eSIM installation state, provider references, and data-usage snapshots needed to operate the product.
Provider-neutral analytics are designed to remain off unless configured and should not include directly identifying information in event properties.
4. Why information is used
Information should be used only for defined purposes such as providing the requested service, securing accounts, processing and fulfilling orders, diagnosing support issues, responding to inquiries, meeting legal duties, and improving the product with properly configured analytics.
Counsel must map each purpose to an appropriate legal basis in every launch market.
5. Service providers and network partners
Waystone may need to share limited information with configured infrastructure, authentication, payment, email, telecom, analytics, and support providers. Each integration should receive only what it needs for its role.
Waystone does not treat a provider name or integration as live until it has been configured and verified.
6. Retention and security
Records should be retained only as long as needed for their stated purpose, security, dispute handling, accounting, and legal obligations. Security controls should include access restrictions, secure sessions, encryption in transit, validation, audit logging, and responsible secret management.
Add an approved retention schedule and incident-notification process before production.
7. Choices and rights
Depending on location, people may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Requests must be verified without collecting unnecessary identity data. Nonessential cookies and analytics should remain disabled unless a valid choice enables them.
Counsel must tailor rights, response timelines, appeals, and regulator contact information to launch markets.
8. International processing and children
Travel services can involve providers in multiple countries. Any international transfer mechanism must be documented before live processing begins.
Waystone is not designed to knowingly collect children’s data independently of a properly structured and reviewed program.
Define age thresholds, parental-consent rules, and approved transfer safeguards.
9. Contact and updates
The production notice must provide a monitored privacy contact, a clear effective date, and an explanation of material changes.