Legal

Privacy Policy

Effective April 8, 2026

1. Introduction

Way Back Tours (“we,” “our,” or “us”) operates the Way Back Tours mobile application (Android and iOS) and the website at waybacktours.com(collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account we collect your email address and a password. You may optionally provide a display name and profile photo. We use Supabase as our authentication and database provider.

2.2 Location Data

With your permission, we access your device’s GPS to provide real-time flight tracking and in-flight entertainment features. Location data (latitude, longitude, altitude, speed, and heading) is collected only while the app is in active use and is used to:

  • Track your position along a flight route
  • Trigger location-based content (points of interest, stories)
  • Record states and cities visited for your personal travel stats

GPS works offline via your device hardware and does not require an internet connection. You can revoke location permission at any time through your device settings.

2.3 User-Created Content

We store content you create within the Service, including:

  • Saved places— name, city, state, notes, visit status, and optional coordinates
  • Trips— trip names, descriptions, stops, and route information
  • Photos— images you capture or upload for your saved places (stored in Supabase Storage)
  • Ratings and notes— reviews you add to places

2.4 Usage and Activity Data

We record aggregated activity statistics tied to your account, such as total flights completed, total distance traveled, and unique destinations visited. This data powers your personal dashboard and is not shared with third parties.

2.5 Device and Technical Data

We may collect basic technical information needed to operate the Service, including device platform (iOS/Android/Web), network connectivity status, and app version. We do not use third-party analytics SDKs (such as Firebase Analytics, Mixpanel, or Segment).

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Authenticate your identity and secure your account
  • Deliver in-flight entertainment content based on your location
  • Sync your saved places, trips, and photos across devices
  • Display your personal travel statistics
  • Generate shareable content (e.g., place cards and trip summaries) when you choose to share
  • Send transactional emails (password reset, account verification)

4. Sharing and Public Content

When you use the sharing feature, a unique URL is generated for your saved place or trip. Anyone with that URL can view a public landing page for the shared item. You can revoke sharing at any time, which immediately makes the content private again.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5. Data Storage and Security

Your data is stored on servers operated by Supabase (hosted on AWS infrastructure). We use industry-standard security measures including:

  • Encrypted data transmission (HTTPS/TLS)
  • Row-level security (RLS) policies on all database tables
  • Secure password hashing via Supabase Auth
  • Scoped API keys with minimal privileges

The app also stores data locally on your device for offline functionality. This local data remains on your device until you sign out, at which point it is cleared.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law.

7. Your Rights and Choices

You have the right to:

  • Access your personal data through your account dashboard
  • Update or correct your account information at any time
  • Delete your account and associated data by contacting us
  • Revoke location permissions through your device settings
  • Revoke sharing of any place or trip at any time
  • Export your data by contacting us

8. Children’s Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal data, please contact us.

9. Third-Party Services

We use the following third-party services to operate the platform:

We do not use third-party advertising networks or sell data to advertisers.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Way Back Tours
Email: privacy@waybacktours.com