Privacy Policy
Draft · August 2026 · Effective 2 August 2026 · Counsel review pending.
way-point is run by Waypoint.io LLC, and in this policy the words “we” and “us” always mean Waypoint.io LLC. The product and the brand are spelled “way-point”, with the dash, while the company name has no dash.
This policy explains what information we collect, why we retain it, who else can see it, and how long it lives. Because we wrote it from our own data inventory rather than from a template, it describes the app exactly as it runs today.
1. Who way-point is for
way-point is built for adults, so you must be 18 or older to use it. The service is not directed to children, and we do not knowingly collect information from anyone under 18.
Because we never ask your age, we take you at your word, so if a minor has an account, write to us and we will remove it.
2. What we collect
When you sign in. You sign in through Google or Discord, so there is no password for us to see or to store anywhere. Your provider hands us your name, your email address, and a link to your picture, and we retain all three of them. We also retain an identifier that connects your account to that particular login, and we discard the provider's access tokens immediately after you sign in.
Your profile and your garage. We retain your display name, your picture, and the cars you decide to add to your garage. A build can hold power figures, engine notes, modifications, a written story, and photographs, and any service or maintenance record you keep on a car is stored here as well.
Clubs. We retain the clubs you belong to, the role you hold in each of them, and the plan tier that applies to you.
Meets. We retain the meets you create or edit, your RSVP, the car you bring, and your position on a waitlist. We also retain your check-in, which records that you turned up and how, although an arrival never records where your phone was.
Photos and files. We retain the photographs you upload, the claim that identifies a particular shot as your build, and any photographs you add to a club pool.
Follows and alerts. We retain the clubs and the people you follow, together with your alert feed, which belongs to you alone. If you enable meet alerts, we also retain the push address your browser provides and the two keys that encrypt every message.
Feedback. We retain the notes you send us from the guide, along with an email address if you have asked for a reply. Sending a note does not require an account, so you can do it while signed out.
Billing. If you pay, we retain your Stripe customer id, your subscription id, your tier, and the date on which a cancelled plan ends. Clubs and vendors that take payouts also receive a Stripe account id and a status, and card numbers never reach us at all.
Days you use the app. We record the date on which you last opened way-point while signed in: the date only, never the time, and only the most recent one. We use it to count how many people use way-point in a given week, and that figure is counted rather than listed.
Errors. Whenever something breaks, we send ourselves a report, and Section 6 describes exactly what information that report contains.
How the app gets used. We count which pages people open and which controls they click, so we can understand what actually works. Those counts are not connected to your account, and Section 6 describes everything they hold.
3. What we do not do
- We do not sell your data, and we have never sold it to anybody at any point.
- We do not run advertising, and no advertising network receives any of your information.
- We do not tell our analytics who you are, because it never receives your name, your email address, or your account id.
- We do not record your screen, and there is no session replay anywhere in the product.
- We do not store passwords, for the simple reason that the product does not have any.
- We do not store card numbers or bank account numbers, because our payment processor handles both of those.
- We keep no trail of where you drive, because each live position replaces the one before it.
- Coordinates never appear anywhere in the logs we keep.
4. Location
Location is the most sensitive information we handle, so this section sets out all of it.
Where a meet is. Every meet carries a venue name, a neighborhood, and an exact address with a map pin attached to it. A public meet displays that address to anyone, while a gated meet displays the neighborhood only. The exact spot appears the moment you RSVP, with no clock and no waiting, and it drops back out of view if you cancel that RSVP. Club managers can always see it, and parking zones and rally stops follow exactly the same rule.
Where you are. Discover can ask your browser for your position, so that it can sort nearby meets by distance. You have to allow that request, and you can withdraw the permission in your browser settings at any time. Your coordinates travel to our server so we can find the meets near you, and we do not save them.
Sharing your position live. On meet day you can share your dot with the people who are going to that meet. You turn it on yourself, every single time, on a consent screen that explains exactly what happens. Only people who hold an RSVP on that meet can see it, and each ping replaces the one before it, so we keep no trail of your drive. Your dot disappears 60 seconds after your last ping, the moment you stop sharing, and when the meet ends.
5. Who else sees your data
Other companies help us run way-point, and they handle information on our behalf and under our instructions, so here is the complete list of them.
- Render hosts the app, the API, and the database, so everything we store resides there.
- Amazon Web Services stores every photograph that you upload to way-point.
- Stripe processes payments and runs payouts, and because Checkout and the billing portal are Stripe's own pages, your card goes to Stripe rather than to us. We send Stripe your account id and the plan you selected.
- Google and Discord sign you in, so each of them sees that you signed into way-point.
- Sentry receives our error reports, and Section 6 describes exactly what it receives.
- HeyCatch counts how the app gets used, and Section 6 describes exactly what it receives, while HeyCatch itself runs on PostHog and holds its data in the United States.
- Resend delivers club email, and that channel is wired up but sends nothing today.
- Discord again, whenever a club connects a channel, and in that channel we post the meet title, the neighborhood, the time, and the RSVP link, although we never post member names or a gated address.
- Apple, Google, and Mozilla run the push services your browser uses, and they deliver an alert to your device, although each alert is encrypted, so they cannot read it.
- Mapbox draws our maps wherever we run with a Mapbox key, and without one we use CARTO for map tiles and Esri for satellite images. Your browser loads those tiles itself, so the map provider sees your IP address and the part of the map you are looking at.
- OpenStreetMap and Photon turn a typed address into a pin, so an organizer's typed venue text reaches them exactly as it is typed.
- Mapbox or the OSRM router draws a rally's driving line, and that request carries the stops rather than you.
- The National Weather Service provides the forecast for a meet, and it receives the meet's coordinates.
- NHTSA provides car makes and models, and it receives a make and a year and nothing whatever about you.
Some pictures load from wherever they happen to live, so a picture from Google or Discord loads from their servers, and so does a photograph another member linked.
We also disclose data when the law requires it: we respond to lawful requests, and we may pass on whatever a safety report requires. If the company is ever sold, your information may transfer along with it.
6. What error reporting and analytics send
When way-point breaks, we send a report to Sentry so that we can find the problem and fix it.
We strip that report before it leaves, so it carries the error, the stack, the release, and a request id, and it carries no name, no email, no account id, and no address. A page path is reduced to a pattern, so a meet page arrives as /m/:publicId, and query strings, cookies, and headers are removed entirely. Automated tests hold both halves of the application to this requirement.
One honest limit is worth stating plainly: your browser posts its report directly to Sentry, so Sentry's servers see your IP address at that moment. The report itself still says nothing at all about who you are.
Analytics. We count how our public pages get used, with a measurement service called HeyCatch. It runs on the pages you can read without signing in: the home page, pricing, sign-in, the guide, the release notes, our three articles, and these legal pages. It does not start inside the app, so your meets, your garage, your club and your rallies are not measured.
One limit worth stating. Measurement starts when a public page loads, and it keeps running while that same page session continues. So if you move from a public page straight into the app without a fresh page load, the address you move to can still be counted. Signing in loads the page afresh, which stops it, and that is the usual route into the app.
On those public pages, your browser sends the page you opened, the buttons and links you click, and the page you arrived from, together with your browser, your operating system, your device type, your screen size, and your time zone. HeyCatch also sees your IP address, which it turns into a rough location, such as a city.
We never tell HeyCatch who you are, so it receives no name, no email, and no account id. Your browser holds a random identifier instead, which allows repeat visits to count as a single person rather than several. None of the measured addresses holds an id, so nothing there points at a particular meet or at a particular member. Advertising click tags, like the ones Google and Facebook attach to a link, are stripped before anything is transmitted.
7. Cookies and what sits on your device
We set three cookies altogether, and not one of them exists for advertising.
- The sign-in cookie keeps you signed in for 14 days, renewing itself while you use the app, and scripts running on the page cannot read it.
- The club cookie remembers which of your clubs you are currently looking at, and it holds a club's short name and lasts a year.
- The analytics cookie holds a random identifier, so repeat visits count as one person instead of many, and it is not connected to your account. It lasts a year, and the same identifier also sits in your browser storage.
Your device also keeps a few things of its own: your theme pick and the last release notes you closed are stored inside the browser. way-point installs as an app as well, so it caches the pages you visit and can show them to you offline, and that cache can hold a meet page with the exact address on it. Clearing your browser data clears all of this.
8. How long we keep things
- Your account information stays for exactly as long as your account itself does.
- Ask us to delete your account and you get 30 days to change your mind, as Section 9 explains in full.
- Records of sign-ins, role changes, and venue confirmations are retained for 180 days.
- A photograph, a sponsor, or a rally route that you remove is purged from our systems 30 days later.
- A live position expires 60 seconds after the last ping we received.
- Feedback notes stay, because a note is still worth reading after you have left.
- Meets stay for good, because a meet that fifty people came to is the club's history rather than one person's data.
- We plan to thin a meet 12 months after it ends: who RSVP'd, who checked in, and any unclaimed photograph would go, while the counts would remain. That pass is built and is not switched on yet, so an older meet may still hold its full list today.
- Analytics counts sit with HeyCatch, which retains them while we remain a customer, then deletes or anonymizes them two months after we stop.
- Stripe retains its own invoice records under its own retention rules.
9. Your choices
Delete your account. Account settings has it, under Leaving, and nothing is destroyed for 30 days, so you can come back within that window and keep everything. Your account keeps working throughout the wait, and once the window passes the account is gone permanently. Your builds, RSVPs, check-ins, memberships, and uploaded photographs all go with it, while meets you helped run stay behind with your name removed. A paid plan stops at the end of the period you have already paid for, and it returns if you change your mind.
We refuse the request while a club still depends on you, and there are two reasons for that, both of which one club can carry at once. You may be its only admin, in which case it would lose the person who runs it, or you may own it, in which case it would drop back to free the day you go. The app names each club, explains which reason applies, and names who could take it on, so hand the club over and ask us again.
Turn off meet alerts. Account settings has a Meet alerts toggle, and it works per device, so turning it off on one phone leaves your other devices switched on. Your browser's own notification settings work as well.
Disconnect a login. Account settings lists the ways you sign in, and each one of them has a Disconnect button. We refuse the last one, because removing it would lock you out of your account, so add another login first and then drop the old one.
Fix your details. You can edit your name, your picture, and your builds inside the app whenever you want.
Ask us. You can write to hello@way-point.io with any question about privacy or about the information we hold.
We are a US company, and we do not claim to meet the GDPR or the CCPA today. The choices described above are the ones the product honors right now, and we have listed no others.
10. How we protect it
Plain words, and no boasting.
We take reasonable steps to protect what we hold: traffic runs over HTTPS, and access is limited to the people and the systems that genuinely need it. The values worth guarding most are encrypted where we store them, and card numbers never reach us at all, because the payment processor takes them instead.
We do not list our defences here, because naming them tells the wrong reader where to push, and it would turn a promise about today into one we might break the day we change something.
No system is perfect, and we will not pretend that ours is, so if you find a hole, write to hello@way-point.io and we will answer you.
11. Changes to this policy
We update this page as the product changes, and the date at the top records when we last did. Where a change matters to you, we will say so inside the app.
12. Contact, and the law that applies
way-point is operated by Waypoint.io LLC, and privacy questions go to hello@way-point.io.
The law of North Carolina governs this policy.