Overview
Waypoint is a travel planner from Rimu Apps in New Zealand.
Rimu Apps is responsible for the personal information described in this policy. Waypoint requires a verified account and a completed account profile before you can plan trips or claim a shared-trip viewer link. After a successful verified sign-in and profile setup, the mobile apps cache member trip access so members can continue planning offline. Read-only viewer trips are online-only and are not added to the mobile offline trip database.
Waypoint contains no advertising. Rimu Apps does not sell personal information or share it for cross-context behavioural advertising, and does not use trip content to advertise to you. In this policy, “share” means disclosing information to the service providers and people described below; it does not mean selling it.
Mobile apps keep a private local copy of member trip data for offline use. New Android trips created online connect to cloud sync automatically; trips created offline remain local until sync can be established. Existing local-only Android trips remain on the device unless connected to sync. Trips created or opened in the web portal are cloud synced. A trip claimed through a viewer link is fetched only while online, kept in memory while displayed and removed when connectivity is lost. Cloud trips, gallery photos, attachments and billing records are handled by Rimu Apps and the providers identified below.
Information we handle
What Waypoint may access or collect
Account and profile
Email address, display name, optional home country and home currency, Firebase user identifier, sign-in provider, email-verification state, onboarding state, account and entitlement status.
Trips and collaboration
Trip names and descriptions; destinations and time zones; scheduled, placeholder and unscheduled events; routes; dates and times; venues, addresses, notes, links and booking references; visa-planning answers; costs, currencies, expense participants and balances; memberships, roles, invitations, viewer grants and shared-trip activity. A shared-trip owner can see a viewer’s display name, verified email address, claim state and access state. Owners may enter another person’s email address or a placeholder name.
Documents and attachments
Files you select or share, including travel documents, images, email or calendar files and expense receipts; file names, types, sizes, checksums, upload state and storage references; and fields suggested from a document when you request analysis.
Trip gallery photos
Photos a trip owner or editor deliberately adds to an event or location gallery, their event or location tags, uploader identity, checksums, processing and storage state, dimensions and storage amounts. Waypoint corrects orientation, converts the image to JPEG, limits its long edge to 2560 pixels, creates a 480-pixel thumbnail and strips EXIF and GPS metadata. The selected source is not retained after processing. Existing attachments, booking files and receipts are never exposed as gallery photos automatically.
Billing and usage
Plan, offer, platform and storefront; Stripe customer, checkout, subscription and webhook references; subscription status and dates; purchase, refund, dispute or payment-failure state; promotion-code use; cloud-storage amounts, selected files to keep, analysis allowances and server-maintained usage counters. Authorised Rimu Apps administrators can view account metadata, subscription state and content-free usage totals and can apply manual entitlement corrections. They cannot use the admin portal to read trip names, destinations, notes, receipts, documents or other trip content. Stripe receives the payment and billing details entered at checkout. Rimu Apps does not receive your full card number or card security code.
Maps, searches and live travel
Place-search text and selected results; saved place identifiers, addresses, coordinates and time zones; flight number, travel date and airport codes; provider flight status and progress; route start and destination coordinates, scheduled departure time, expected duration, distance and route line.
Notifications
Notification permission state, Firebase Cloud Messaging registration token, platform, account and trip or item identifiers, delivery state and limited notification text needed to tell you about collaboration or an expiring plan.
App use and diagnostics
On Android, iOS and the authenticated web portal while online, Firebase Analytics may collect app interactions, screen journeys, feature outcomes, platform and app version, app-instance or installation identifiers and approximate regional information under Google’s terms. Android Firebase Crashlytics may collect crash, ANR, device, operating-system, installation identifier and bounded diagnostic context. Server-maintained counters record cloud AI, Places, storage and canonical cloud-operation totals against an account so quotas, support and estimated service costs can be managed. Analytics events and counters exclude trip and document content, names, addresses, email addresses, filenames, URLs and trip identifiers.
Technical and support information
IP address, browser or device type, app and operating-system version, request time and security or attestation signals produced when the website or an online service is used. If you contact Rimu Apps, the contact details, message and attachments you provide are also handled.
Waypoint does not request your device’s GPS location, contacts or calendar. Places and routes come from information you enter, select or search for. Waypoint does not intentionally collect advertising identifiers; Android advertising-ID collection is disabled.
Where information comes from
You, collaborators, devices and travel services
- Directly from you: when you create an account or profile, enter trip content, select a file, search for a place, request analysis, make a purchase or contact Rimu Apps.
- From trip owners, editors and viewers: when a collaborator adds you, enters an invitation email or placeholder name, assigns you to an event or expense, adds a gallery photo, creates shared-trip activity involving you, or claims a viewer link. Before a viewer confirms access, Waypoint identifies the categories the owner has chosen to disclose and explains that the owner will see the viewer’s identity.
- From selected documents and public links: when you ask Waypoint to extract travel or receipt details or retrieve public metadata for a link.
- From service providers: when Firebase returns account and delivery state, Stripe returns billing state, mapping services return place or route data, or a flight provider returns operational information.
- Automatically from the app, browser or hosting service: limited usage, diagnostic, request and security information described above.
Account details are required to authenticate you and provide cloud features. A trip needs enough information to perform the feature you request. Optional profile details, documents, receipts, notifications, link analysis, cloud analysis, purchases and collaborator invitations can be omitted, but the related feature will not work or may need manual entry.
Uses and legal bases
Why Rimu Apps processes information
- Provide Waypoint and perform the user agreement: authenticate accounts; save, sync, share and export trips; build owner-controlled redacted viewer itineraries; process gallery photos; show maps and schedules; manage collaboration, viewers, documents, expenses and notifications; perform requested analysis and live travel lookups; process purchases and provide paid entitlements.
- Act on your request or consent: access a selected file, send a notification after platform permission, analyse a document, receipt or link, or hand content to another app. Where processing relies on consent, you may withdraw it for the future.
- Meet Rimu Apps’ legitimate interests: secure the service, enforce roles and quotas, prevent fraud or abuse, diagnose faults, understand privacy-limited feature use, support users and improve reliability. Where applicable, you may object to processing based on legitimate interests.
- Comply with law and protect rights: keep required accounting or transaction records, respond to lawful requests, resolve disputes and enforce legal rights.
Waypoint does not make decisions that produce legal or similarly significant effects using solely automated processing. Document, receipt and link suggestions are review-first and are not saved as trip events or expenses until an authorised user confirms them.
Service providers and disclosures
Who may receive information
Rimu Apps discloses only the information reasonably needed for the purposes below. Service providers must protect information consistently with their contracts, this policy and applicable law. Rimu Apps may also disclose information where reasonably necessary to comply with law, protect a person, investigate fraud or security incidents, or establish and defend legal claims.
Google and Firebase
Waypoint uses Firebase Authentication for email/password, Google and Apple provider sign-in; Cloud Firestore, Cloud Functions and Cloud Storage for accounts, trip sync, collaboration, viewer grants, server-redacted shared itineraries, billing state, attachments and processed gallery photos; Cloud Messaging for notifications; Firebase Analytics on Android, iOS and the authenticated web portal; and Android Crashlytics for diagnostics. Google may receive account, trip, file, device, request and diagnostic information needed to provide those services.
Waypoint integrates Firebase App Check to help distinguish supported app or portal requests. Android may use Google Play Integrity, iOS may use Apple App Attest or DeviceCheck, and web uses a reCAPTCHA Enterprise provider. Those providers may process device, app, browser, network and attestation signals for service integrity; they do not give Rimu Apps your device passcode or biometric data.
Apple and Google platform services
On iOS, Apple processes sign-in information when you choose Sign in with Apple. Apple Maps and MapKit receive place-search text, an optional saved destination area used to bias a search, visible map areas and ordinary device or network information. When you select a result, Waypoint saves its name, address, coordinates and available time-zone or country information with the trip.
On Android and web, Google Maps receives visible map areas and ordinary request information such as IP address. Waypoint does not add trip names, event titles or addresses to map-tile requests. On supported Android installations, Google Play may process app version, device, account and network information to check for and present native app updates.
Google Places, Geocoding, Time Zone and Routes
Android and web place search sends the search text through Firebase to Google Places. The text and transient predictions are not written to Waypoint’s database. Selecting a result saves the returned place identifier, address or context, coordinates and time zone as trip content. Waypoint may also send an item title, venue or address, saved destination context and an existing Google place identifier to Google Geocoding to locate a trip item.
For an eligible online Pro car or taxi event, Waypoint sends the start and destination coordinates and scheduled departure time through Firebase to Google Routes. Google returns a traffic-aware duration, distance and route line. Trip names, event titles and account identifiers are not included in the Routes request.
On-device analysis and Google AI services
On supported Android devices, an on-device option processes a selected document through Gemini Nano/AICore; Android may download the model and maintain platform diagnostics. If you choose cloud analysis, Waypoint sends a temporary processing copy of the selected document or retained receipt through Firebase to Google Vertex AI. For public-link analysis, it sends the URL, public page metadata and saved destination context through Firebase to Vertex AI. The service returns suggestions for review.
Stripe
Where a purchase is offered, Stripe hosts checkout and the customer billing portal and processes your payment method, billing contact, transaction, tax, promotion, subscription, refund, dispute and fraud-prevention information. Rimu Apps sends Stripe your Waypoint account identifier, email, display name, selected offer, platform, storefront and, for a Trip Pro purchase, the relevant trip identifier. Stripe returns identifiers and status needed to record the purchase and entitlement. Stripe may place or read its own cookies and similar storage on Stripe-hosted pages.
Live flight providers
For an online Pro flight opened from 24 hours before its scheduled start until 24 hours after its scheduled end, Waypoint sends the IATA flight number and local departure date through RapidAPI to AeroDataBox. Airport codes may be used to choose the matching service. AeroDataBox may return status, estimated or actual times, terminals, gates, delays and available aircraft position, altitude, speed and heading. AirLabs is a configured alternative and receives the flight number; Waypoint validates its result against the travel date and available airport codes. Waypoint does not send the trip name, traveller name or account identifier to either flight provider.
Currency rates and external actions
Frankfurter receives only source and trip-base currency codes when Waypoint requests a daily reference rate. It does not receive the account, trip, expense amount, receipt or personal details. The selected multiplier is saved with the expense and is informational, not a bank or transaction rate.
When you open a link, attachment, booking shortcut, calendar file, exported trip or print job, the app or service you select receives that content under its own privacy terms. Owners and editors receive member details and activity their role permits. An authenticated viewer receives only the server-redacted itinerary categories selected by the owner. Waypoint never includes booking references, documents, ordinary attachments, visas, ideas, app shortcuts, member email addresses or identifiers, raw expense records, payers, splits, receipts, rates or settlements in that viewer response. If expense sharing is enabled, it is limited to trip and event totals in the trip base currency.
Permanent viewer links and owner controls
A viewer link is permanent for the life of its trip and cannot be disabled or rotated. Its secret is placed after the # in the address so it is not sent in ordinary web requests, and Waypoint removes it from browser history after a successful claim. Anyone who receives the link can use another verified Waypoint account to claim access until the trip is deleted, subject to the 100-active-viewer limit. The owner can change one disclosure policy for all viewers, revoke or restore an account, and see viewer identities. A revoked account cannot reclaim the link; a viewer who removes the trip voluntarily can claim it again later.
Owners can control exact addresses, flight numbers, live travel cards, expense totals, notes and public links, participant names, galleries and whether Waypoint presents an explicit photo save action. Hiding the save action is a user-interface control, not digital rights management: a displayed image can still be captured or extracted. Live flight and drive-route cards use the viewer’s own eligible Pro entitlement.
Provider information: Google Privacy Policy, Firebase privacy and security, Apple Privacy Policy, Stripe Privacy Policy, RapidAPI Privacy Policy, AeroDataBox Privacy Policy and AirLabs Privacy Policy.
Overseas processing
Information may be processed outside New Zealand
Rimu Apps operates from New Zealand. Waypoint’s Firebase and Cloud Functions services are currently configured in the United States, and Google, Apple, Stripe, RapidAPI, AeroDataBox, AirLabs and their subprocessors may process information in the United States or other countries where they operate. Those countries may have different privacy laws.
Where required, Rimu Apps relies on providers that are subject to applicable privacy law or uses provider agreements and contractual or other safeguards intended to preserve protections comparable to New Zealand law and, where applicable, recognised international transfer safeguards. You may contact Rimu Apps for more information about the safeguard relevant to your information.
Retention and deletion
How long information is kept
- Local app information remains until you delete it, clear app storage or uninstall. Mobile account-access caches are removed on sign-out or account deletion. Android automatic backup and device-transfer restoration are disabled. iOS app files are excluded from iCloud backup. Manual exports remain where you save them.
- Accounts and cloud trips remain while the account or shared trip exists. Deleting an owned cloud trip deletes its cloud records, attachments, gallery photos, viewer grants and private invitation or notification records. Leaving as a member removes your membership. Removing a viewer trip marks the grant as left and removes its library reference; owner revocation retains the minimum grant state needed to prevent that account reclaiming the permanent link. A shared history may retain a non-identifying “Deleted user” marker after account deletion.
- Invitations and notifications remain until accepted, revoked, expired or the related trip is deleted. Invitation links expire after seven days and can be used once. Push tokens remain while current, are removed after certain failed deliveries, on account deletion, or for the current device on sign-out.
- Selected source documents, receipts and gallery photos: documents and receipts remain as trip files until an authorised user deletes them or the trip is deleted. A gallery upload source reservation expires after 30 minutes; the source is deleted after normalization or a failed validation. The normalized display image and thumbnail remain until an editor removes the photo, its event or location is deleted, the trip is deleted, or paid-plan retention requires purge. Temporary cloud-AI processing copies and job records are deleted after each attempt. Pending review data stays in private app or browser storage until completed or cleared.
- Paid-plan lifecycle: after a paid entitlement expires, affected cloud storage can enter a 30-day read-only grace period. At the end of grace, files above the free allowance that were not selected to keep may move to a restricted support backup for up to 90 further days so they can be restored after an eligible upgrade. The file content is then permanently purged; a metadata placeholder may remain in the trip to explain the missing file.
- Billing records such as Stripe customer or subscription references, transaction status, entitlements, refunds, disputes, usage and webhook processing records are kept for account administration and for the period reasonably needed for accounting, tax, fraud prevention, disputes and legal obligations. Stripe applies its own retention obligations to payment records. Deleting Waypoint does not itself delete records Stripe must retain.
- Place and travel data: transient Google place predictions are not stored. One-way-hashed autocomplete quota records have a three-day expiry. The geocoding cache uses hashed query values and may keep returned place data for up to 30 days; Google-sourced coordinates have a 30-day expiry and may be refreshed for an upcoming event. Flight responses are cached for up to five minutes while airborne, 30 minutes while scheduled or delayed, and 24 hours once completed or cancelled. A scheduled drive route may be reused until the day before departure; when viewed on the departure day it can refresh hourly or on manual refresh. Related quota records contain hashes, counters and expiry metadata.
- Other operational records: currency cache entries are refreshed after 24 hours; each completed expense keeps its chosen multiplier. Aggregate Firebase Analytics reporting is configured for 14-month retention. Account-linked server usage counters are removed through account deletion; immutable administrator audit and subscription history, and finance records, are retained for security, accounting, tax, fraud prevention and legal obligations. Other diagnostic, security, support and hosting records are kept only as long as reasonably needed for their purpose, subject to provider settings and legal obligations.
Deletion may take a reasonable period to propagate through active systems and provider processes. Information may be retained longer when required by law, needed to complete a transaction, resolve a dispute, prevent fraud or protect legal rights, and is then restricted to that purpose.
Your choices and rights
Control over your information
- Edit or delete trip details, events, ideas, expenses, documents, attachments and gallery photos; leave a member trip; remove a trip from Shared with you; manage collaborators or viewers if authorised; change the owner’s viewer disclosure policy; export a trip; or choose local/offline workflows where available.
- Skip optional profile fields, documents, receipts, online place search, cloud or link analysis, purchases and notifications. Manual entry remains available for core planning and expenses.
- Manage a Stripe subscription through Usage & plans. Cancel any active subscription before deleting your Waypoint account so future Stripe renewals stop.
- Delete your account in Settings → Account → Delete account, or use the secure web deletion page. A fresh sign-in is required. Account deletion removes the Firebase account, profile, pending AI files, push registrations and trip memberships; owned cloud trips must be transferred or deleted. Minimum billing or security records may remain for the reasons above.
- Ask Rimu Apps for access to or correction of personal information it holds about you. Depending on the law that applies, you may also request deletion, restriction or portability, object to certain processing, withdraw consent for the future, or complain to a privacy regulator. Rimu Apps may need to verify your identity and consider legal exceptions.
Right to object: where applicable, you may object at any time to processing based on Rimu Apps’ legitimate interests. Rimu Apps does not sell personal information or use it for targeted advertising, so there is no sale or advertising opt-out to operate.
New Zealand users may complain to the Office of the Privacy Commissioner. Users elsewhere may contact their local data-protection or privacy authority. Contact Rimu Apps first if you can, so there is an opportunity to resolve the concern.
Security and children
How information is protected
Waypoint uses encrypted HTTPS connections, private app storage and file protection, verified authentication, role-based trip access, restricted cloud-storage paths, backend validation, integrity checks, quotas and supported platform attestation. No method is completely secure, but Rimu Apps uses reasonable technical and organisational safeguards appropriate to the information handled.
Waypoint is a general travel-planning service and is not designed for children to use without a parent or guardian. Rimu Apps does not knowingly use children’s information for advertising or profiling. If you believe a child has provided personal information inappropriately, contact Rimu Apps so it can be reviewed and, where required, deleted.
This website
A public website and secure trip portal
The public marketing and privacy pages do not use advertising or application analytics. Firebase Hosting may process ordinary request logs to deliver and protect them. The authenticated portal uses Firebase Analytics for content-free screen and product-action reporting when its analytics configuration is present. It does not send account identifiers, email addresses, trip identifiers, names, locations, notes, URLs, filenames or document content in custom analytics events. The portal uses browser storage to remember authentication until sign-out and to keep limited onboarding, trip-creation and pending document-review state. Firestore uses memory rather than a persistent browser cache, while selected document-review state may use IndexedDB. Files are downloaded only when you open or export them.
The portal uses Firebase Authentication, Firestore, Functions and Storage and can initialise Firebase App Check with reCAPTCHA Enterprise. A Stripe checkout or billing-portal link opens a Stripe-hosted page with Stripe’s own cookies or similar technologies. Waypoint does not use advertising cookies.
Changes to this policy
Keeping this page current
Rimu Apps reviews this policy when Waypoint’s features, providers or legal obligations change. The effective date will change when an update is published. Rimu Apps will give additional notice, and seek authorisation where required, before a material new use that users would not reasonably expect.
Contact
Rimu Apps privacy contact
Rimu Apps is the developer responsible for Waypoint’s privacy practices. Its postal address is 1/17 Islington Ave, New Lynn, Auckland 0600, New Zealand. Email the privacy contact at jamesstevenrutledge@gmail.com. Include enough detail to identify the account and request, but do not email passwords or full payment-card details. You can also use the verified developer contact shown in Waypoint’s Google Play listing.
Request account deletion