Effective Date: February 17, 2026 | Version: 1.0 | Governing Law: Republic of Lithuania
Platform Operator: MB "Wewander", Company code: 307580758, Kalvarijų g. 149-52, LT-08352 Vilnius, Lithuania
This Privacy Policy explains how WeWander collects, uses, stores, and protects your personal data when you use our marketplace platform. Please review this document carefully.
Key point: WeWander is fully GDPR-compliant. We collect only the personal data necessary to process bookings, facilitate communication, and improve our platform. We never sell your data to third parties. Payment card details are processed by Stripe and PayPal — never stored on WeWander servers.
WeWander operates an online marketplace connecting travelers with local tour operators and activity providers. We take your privacy seriously and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
This Privacy Policy explains:
By using the WeWander Platform, you agree to the collection and use of your personal data as described in this Privacy Policy.
Data Controller:
MB "Wewander"
Company code: 307580758
Address: Kalvarijų g. 149-52, LT-08352 Vilnius, Lithuania
Contact:
Email: info@wewander.tours
Website: wewander.tours
Data Protection Officer:
For privacy-related questions or to exercise your rights, contact us at: info@wewander.tours
This Privacy Policy applies to:
Important: When you book an activity, the Operator providing that activity acts as an independent data controller for the personal data they receive from you. Their processing of your data is subject to their own privacy practices, not this Privacy Policy. WeWander acts solely as an intermediary connecting you with Operators.
Key point: WeWander collects account information (name, email, phone), booking details, payment confirmation data, communications, and technical data (IP, browser, device). Full payment card details are handled exclusively by Stripe and PayPal and are never stored on WeWander servers.
Account Information (if you register):
Booking Information:
Payment Information:
Communication Data:
Technical Data:
Registration Information:
Verification Information:
Activity Listings:
Financial Data:
Communication Data:
Technical Data:
Cookies and Tracking Technologies:
See Section 9 for detailed information about cookies.
Under GDPR, we must have a legal basis for processing your personal data. We process your data under the following legal grounds:
We process your data to:
We process your data for our legitimate business interests:
We always balance our interests against your rights and freedoms.
We process your data to:
We ask for your explicit consent to:
You can withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
With your consent:
With your consent:
WeWander does not sell your personal data to third parties. We share your data only in the following circumstances:
When you book an activity, we share necessary booking information with the Operator:
Important: Operators are independent data controllers. They process your data according to their own privacy policies to provide you with the booked activity.
We do not share your full personal details with travelers until a booking is confirmed. After confirmation, travelers receive:
We share data with trusted third-party service providers who help us operate the platform:
Payment Processors:
These processors handle your payment card details. WeWander never stores full card numbers.
Email Services:
Analytics Providers:
Customer Support:
All service providers are contractually required to:
We may disclose your data when required by law:
If WeWander is involved in a merger, acquisition, or sale of assets, your personal data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Key point: WeWander retains transaction and booking records for 5 years (tax/accounting compliance). Traveler account data is deleted 30 days after account deletion. Operator account data is retained for 3 years after closure (statute of limitations). Marketing data is deleted within 30 days of consent withdrawal.
We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy.
While your account is active, we retain your data to provide our services.
For Travelers:
For Operators:
For All Users:
We may retain data longer if required by law, for legal proceedings, or to establish, exercise, or defend legal claims.
After retention periods expire, we securely delete or anonymize your personal data so it can no longer identify you.
Cookies are small text files placed on your device when you visit our website. They help us provide you with a better experience and allow certain features to function.
Strictly Necessary Cookies:
Functional Cookies:
Analytics Cookies:
Advertising Cookies (if applicable):
On First Visit:
You will see a cookie banner asking for your consent to non-essential cookies. You can accept or reject these cookies.
Anytime:
Third-Party Cookies:
Some cookies are placed by third-party services (like Google Analytics). These services have their own privacy policies.
Our website does not currently respond to "Do Not Track" signals from browsers.
Key point: Under GDPR, you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. To exercise any right, email info@wewander.tours. WeWander responds within 30 days. You may also lodge a complaint with your national data protection authority.
Under GDPR and EU data protection laws, you have the following rights regarding your personal data:
You have the right to request:
You can request correction of inaccurate or incomplete personal data.
You can request deletion of your personal data when:
Exceptions: We may refuse deletion if we need the data to:
You can request that we limit how we use your data while we:
You can request a copy of your data in a structured, commonly used, machine-readable format, and you can request that we transfer it to another service provider where technically feasible.
Applies to:
You can object to processing based on legitimate interests or for direct marketing purposes.
Direct Marketing: You can opt out at any time using the unsubscribe link in emails or by contacting us.
Legitimate Interests: We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
If you believe we have violated your privacy rights, you can lodge a complaint with:
To exercise any of these rights:
Email us at: info@wewander.tours
Include:
Response Time: We will respond to your request within 30 days (may be extended by 2 months for complex requests).
Key point: WeWander protects your data with SSL/TLS encryption in transit, encryption at rest for sensitive data, hashed and salted passwords, firewalls, intrusion detection, and access controls. In the event of a data breach, WeWander notifies the supervisory authority within 72 hours and affected individuals without undue delay.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
Technical Measures:
Organizational Measures:
In the event of a data breach that poses a risk to your rights and freedoms, we will:
Travelers & Operators:
Operators:
While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work continuously to protect your data.
WeWander is based in Lithuania (European Union). We primarily process data within the European Economic Area (EEA).
Some of our service providers may be located outside the EEA. When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
Standard Contractual Clauses (SCCs):
We use EU-approved Standard Contractual Clauses with service providers in third countries.
Adequacy Decisions:
We may transfer data to countries that the European Commission has deemed to provide adequate data protection (e.g., UK, Switzerland).
Specific Services:
You have the right to obtain information about the safeguards we have in place for international transfers. Contact us at info@wewander.tours for details.
WeWander's services are not intended for children under 16 years of age.
We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at info@wewander.tours, and we will delete that information.
Activities involving minors:
When booking activities for children, the adult making the booking is responsible for providing accurate information and ensuring proper supervision during the activity.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.
Material Changes:
If we make significant changes that affect your rights, we will notify you by:
Minor Changes:
For minor updates, we will post the revised policy on our website with a new "Last Updated" date.
Your continued use of the WeWander Platform after changes become effective constitutes acceptance of the updated Privacy Policy.
If you do not agree with the updated policy, you should stop using our services and contact us to close your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. The latest version is always available at: wewander.tours/privacy
Our website may contain links to third-party websites, services, or applications (e.g., social media platforms, payment processors, external tour booking systems).
We are not responsible for:
Before providing personal data to third parties:
WeWander does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We use automated tools to detect potentially fraudulent transactions or activities. These tools flag suspicious behavior for manual review by our team. No automated decisions are made that would deny you service without human intervention.
If you write reviews or post content on our platform:
Messages sent through our platform may be monitored for:
We do not use the content of your private messages for marketing purposes.
Operators must:
Travelers:
If an Operator contacts you for purposes other than your booking, or if you have privacy concerns about how an Operator handles your data, please contact us at info@wewander.tours.
We will only send you marketing communications if:
With your consent, we may send:
You can unsubscribe from marketing communications at any time:
After opting out:
WeWander collects account information (name, email, phone number), booking details (dates, participants, special requirements), payment confirmation data (transaction amount and status — full card details are handled by Stripe and PayPal), communications through the platform, and technical data (IP address, browser, device type). WeWander never stores full payment card numbers on its servers.
No. WeWander does not sell personal data to third parties. Data is shared only with operators (to fulfill bookings), payment processors (Stripe, PayPal), analytics providers (Google Analytics), and legal authorities when required by law. All service providers are contractually bound to GDPR compliance.
Under GDPR, WeWander users have the right to access, rectify, erase ("right to be forgotten"), restrict, port, and object to the processing of their personal data. You can also withdraw consent at any time and lodge a complaint with your national data protection authority. To exercise any right, email info@wewander.tours — WeWander responds within 30 days.
Transaction and booking records are retained for 5 years (tax and accounting compliance). Traveler account data is deleted within 30 days of account deletion. Operator account data is retained for 3 years after closure (statute of limitations). Marketing consent records are deleted within 30 days of consent withdrawal.
WeWander uses four types of cookies: strictly necessary cookies (login sessions, essential features — cannot be disabled), functional cookies (language and preference settings), analytics cookies (Google Analytics — requires consent), and advertising cookies (if applicable — requires consent). You can manage cookie preferences via the cookie banner on first visit or through browser settings at any time.
To delete your account and personal data, email info@wewander.tours with the subject line "Data Request." Include your full name and the email address associated with your account. WeWander will process the deletion within 30 days. Some data (transaction records) may be retained longer where required by law.
In the event of a data breach posing a risk to your rights and freedoms, WeWander notifies the relevant supervisory authority within 72 hours and affected individuals without undue delay. WeWander implements SSL/TLS encryption, firewalls, intrusion detection systems, and access controls to minimize breach risk.
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data:
MB "Wewander"
Company code: 307580758
Address: Kalvarijų g. 149-52, LT-08352 Vilnius, Lithuania
Email: info@wewander.tours
Website: wewander.tours
Subject Line: Include "Privacy Inquiry" or "Data Request" for faster processing.
Response Time: We aim to respond to all inquiries within 5 business days and to data subject requests within 30 days.
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your privacy rights.
Lithuania (where WeWander is based):
State Data Protection Inspectorate
Website: https://vdai.lrv.lt
Your country:
You may also contact the supervisory authority in your EU member state. Find your local authority at: edpb.europa.eu