Skip to main content
Demo preview · Orders and payments are not available yet.

Privacy Notice

How Wayboro collects, uses, discloses, and retains information about senders, recipients, drivers, business users, and website visitors.

Effective date and version: September 3, 2026 (2026-09-03-r1).

Policy library Privacy Notice
Jump to a section 12 sections in this document

No ad tracking

The current application has no third-party advertising tracker and does not sell personal information or share it for cross-context ads.

Details unlock by role

Eligible drivers see a masked route and structured cargo facts. Full addresses, contacts, instructions, and free text wait until assignment.

One request reference

The privacy center verifies email control, keeps an auditable reference, and still requires proportional identity or authority review.

No raw PIN storage

When recipient PIN protection is selected, the current code is derived for the active private link. The raw PIN is not stored on the order or proof.

1. Scope and controller

This Notice applies to the Wayboro website, public checkout, delivery operations, tracking links, driver and operations portals, business API, support, and claims. The entity responsible for this information is Nazar Adamovych, 31 Queens Way, Camillus, NY 13031, United States.

A business customer may provide recipient and sender information through the API. Depending on the written business agreement and applicable law, that customer may also be a controller or business responsible for its own collection and instructions.

2. Information we collect

Contact and order information

  • names, email addresses, telephone numbers, pickup and delivery addresses, units, access instructions, and special instructions;
  • shipment item categories, descriptions, quantities, approximate weights, sizes, declared values, handling flags, photographs, and prohibited-item confirmation;
  • service level, requested window, quote, fees, tax calculation, order number, status, timestamps, route, mileage estimate, and cancellation, return, dispute, or claim information; and
  • the versions and time of the legal acceptance recorded at public checkout.

Payment and transaction information

We maintain amounts, currency, payment status, provider reference, refunds, tax-calculation details, payout-account readiness, transfers, and related transaction records. When Stripe payment is enabled, card details are entered in Stripe’s hosted Payment Element and do not pass through Wayboro’s server; the application is not designed to store a full card number or security code. Checkout uses the payment experience configured for the order and keeps provider references with the transaction record.

Delivery, proof, driver, and operations information

  • pickup, delivery, and authorized-return proof photographs, the name of the person releasing or receiving the item, optional factual notes, incident reports, ratings, whether recipient PIN protection is required, and the time a required PIN is successfully verified. The raw current PIN is not stored;
  • fresh operational location coordinates, accuracy, capture time, and limited device details submitted to verify arrival or an authorized return. Successful status events retain the applicable location evidence; pickup and delivery proof uploads do not separately store a device coordinate;
  • when an assigned driver enables the route map, a current coordinate, accuracy estimate, and timestamp are used to prepare the route overview. The first accepted position, stop coordinates, returned route geometry, distance, and duration are stored with that assignment. Later location updates move the driver marker inside the open browser page and are not continuously submitted or stored by the current release;
  • driver-applicant identity and eligibility information, including date of birth, residential address, driver-license details and images, profile photo, vehicle plate and last four VIN characters, registration and insurance documents, screening result and provider reference, and the exact versions and times of driver acknowledgments;
  • driver and staff account details, role, vehicle, availability, assignment history, acceptance or release decisions, performance records, restrictions, payout-account readiness and transfer references, and audit actions; and
  • business organization, API-key metadata, webhook configuration, delivery attempts and HTTP results, durable event records, and audit actions. The current delivery worker does not read or retain the response body from a customer-controlled business webhook.

Uploaded JPEG, PNG, WebP, and PDF files are stored as the submitted file after server-side size and file-signature checks. A file can contain embedded metadata supplied by a camera, device, scanner, or editing software—including device, author, or location details. The current application does not separately extract that metadata for pricing, matching, screening, or arrival decisions, but it remains inside the stored file and may be visible to an authorized reviewer who opens or downloads it. Remove unrelated metadata before upload if you do not want to provide it, without obscuring information needed to verify an official document or claim.

Support, claim, and privacy-request information

We maintain the requester or claimant name, contact, relationship, jurisdiction where supplied, factual description, references, submitted evidence, verification and assignment state, activity history, written decision, settlement or request outcome, and notification status needed to investigate and document the workflow. Sensitive claim evidence is accepted through the private order page only when operations requests it; identity documents should not be sent through ordinary email unless an authorized reviewer provides a secure method.

A one-way duplicate-control fingerprint of a privacy-request submission is used during a short retry window so an identical retry does not create another case. The derived fingerprint is automatically cleared after 24 hours; the request reference, certification, verified case, decision, and required audit history follow the separate retention rules below.

For service notifications, the configured messaging provider receives the destination and message needed for delivery. Wayboro's internal delivery log keeps the destination, channel, subject where used, provider, status, limited error detail, and a minimized purpose description. Tracking capabilities, verification tokens, decision text, claim evidence, and ordinary contact or inquiry contents are intentionally omitted from that internal message body log and remain on their protected source record.

Business-inquiry information

A person who submits the business inquiry form provides a contact name, work email, company name, optional phone number, requested use case, estimated weekly volume, pickup area, typical destinations, and cargo and workflow descriptions. We record the time permission was given to respond to that specific inquiry, an inquiry reference, assignment and resolution activity, and related notification status. A fingerprint scoped to the submission day prevents an identical retry from creating duplicate records. This permission does not subscribe the contact to marketing.

Launch-list information

When ordering is not yet available, a visitor may choose one or more Wayboro services and provide an email address, optional ZIP code, and consent to receive launch and meaningful service-area updates. The address is added to the active launch list only after the visitor uses a time-limited verification link. We record the selected services, source, consent version and time, verification state, and whether a launch notice was sent. This choice is separate from necessary order messages and from a business inquiry.

Device, usage, and security information

Servers may receive IP address, request identifier, date and time, route requested, response status, browser or device information submitted with operational events, authentication and security events, and error logs. The signed-in driver map also uses provider-controlled browser storage for a billed map session and a rotating pseudonymous SDK identifier. Authentication and provider storage are described in the Cookie Notice. Passwords are stored as one-way hashes, not readable passwords. The current session credential is kept in secure browser cookies, and only a one-way hash of the rotating refresh credential is retained with the account.

3. Sources

We collect information:

  • directly from the person who requests, performs, receives, tracks, or supports a delivery;
  • from a sender, employer, business customer, recipient, driver, or authorized operations user;
  • automatically from browsers, devices, servers, cookies, and security controls; and
  • from service providers used for payment, tax, route or address processing, messaging, hosting, storage, and support.

4. Why we use information

  • to quote, accept, dispatch, perform, track, and document deliveries;
  • to contact senders, recipients, drivers, and business users about an active order, return, safety issue, payment, or claim;
  • to process payment and refunds and calculate, collect, report, and document tax where required;
  • to verify access, prevent fraud, protect tracking links and accounts, investigate misuse, and maintain audit records;
  • to provide support, investigate incidents and claims, enforce policies, and resolve disputes;
  • to evaluate operational fit, respond to a submitted business inquiry, and document its internal ownership and outcome without adding the contact to a marketing list;
  • to maintain, debug, measure, and improve service reliability and accessibility; and
  • to comply with law, legal process, regulatory obligations, insurance requirements, and the protection of people, rights, and property.

Automated price and marketplace rules

Customer quotes are calculated automatically from the route distance, required vehicle class, configured base and per-mile rate, service level, additional stops, selected handling charges, service fee, and configured tax result. The customer sees the quote before adding handoff contacts and chooses whether to continue; a quote by itself does not create an order or charge a payment method. The current release does not use a customer behavior profile, rating, or advertising data to personalize that quote.

The driver marketplace applies eligibility and scheduling rules before it shows an order. These include account and payout readiness, current acknowledgments and credentials, approved vehicle fit, service area, online status, active restrictions, reservation limits, and conflicts with accepted work. A driver chooses whether to accept an available offer, and the first valid acceptance is assigned atomically. Driver applications receive a human final review; the current release does not make a final approval or rejection solely from an automated score.

5. When we disclose information

  • Delivery participants. An assigned driver receives the contacts, addresses, item details, and instructions needed to complete the order. Before acceptance, an eligible online driver may see the public order number, schedule, pay and tip, route distance, pickup and drop-off street without the leading street number, and structured cargo category, quantity, weight, size, dimensions, and handling requirements. Candidate drivers do not receive contacts, units, instructions, or the customer’s free-text item description. Senders, recipients, and authorized business customers may receive status and proof information. A business customer can also receive signed lifecycle events for its organization at the webhook endpoint it configured; Wayboro records the delivery state and HTTP status, not the endpoint's response body.
  • Tracking-link holders. A person with the private tracking URL can see the information exposed on that tracking page and, after delivery, available proof while that access remains active. The link can expire, be revoked, or be replaced; access expiration does not itself delete the underlying order record. Senders must share the link only with intended participants.
  • Service providers. Vendors may process information for hosting, storage, payment, tax, address or route services, email or messaging, security, support, and professional advice. They receive only information appropriate to the contracted task. Cloudflare currently processes connection and security data at the network edge and may set a necessary bot-management cookie on protected deployments. When a complete address is not found in the local service catalog, the configured Nominatim-compatible address provider receives that address for verification. The configured OSRM-compatible route provider receives pickup and drop-off coordinates for a customer quote. Stripe receives payment contact and transaction data; Stripe Tax receives the destination address and quoted amounts; Stripe Connect receives driver payout-onboarding information directly and returns account readiness and transfer references to Wayboro. Personal data entered in Stripe-hosted payment or payout surfaces is also processed under Stripe’s Privacy Policy. Mapbox receives the three coordinates needed for the initial driver-to-pickup-to-drop-off Directions request and the browser requests needed to render visible map styles and tiles. Mapbox GL also records a billed map session and limited SDK events, such as map load, SDK version, and a rotating pseudonymous identifier; Wayboro disables optional Mapbox performance-metric collection. Mapbox handles these provider requests under its Product Privacy Policy. Later driver-marker changes are not sent as new Directions or continuous tracking requests by Wayboro; panning or recentering can still request tiles for the area the driver chooses to view. Optional Wayboro analytics, advertising pixels, and session-replay tools are not enabled in the current application.
  • Legal, safety, and rights. We may disclose information when reasonably necessary to comply with law or valid process, respond to regulators, investigate fraud or safety threats, handle insurance or claims, or protect rights and property.
  • Business transfer. Information may be reviewed or transferred in a lawful financing, merger, acquisition, reorganization, bankruptcy, or sale, subject to required notice and protections.
  • At your direction. We disclose information when you validly direct or authorize us to do so.

The current application does not sell personal information, share it for cross-context behavioral advertising, or contain third-party advertising trackers. If those practices change, this Notice and any required opt-out or consent controls must be updated before the change is enabled. We do not disclose mobile numbers or text-message consent to third parties for their marketing.

Current location boundaries

A browser location is used only for the task that requested it

  • Offer distance One driver coordinate is first requested after the driver asks to see an approximate pickup distance. If browser permission is already granted, the visible marketplace may refresh one reading without a new prompt. The coordinate is used in that request, cleared when the page is hidden, and is not saved to the profile or order by the current release.
  • Accepted route The first accepted coordinate, accuracy, time, stop coordinates, and returned geometry, distance, and duration form the one stored route snapshot. The snapshot is deleted when that assignment ends.
  • Arrival proof A fresh coordinate, accuracy, timestamp, and limited device detail may be stored with an arrival status event to verify proximity to the stop.

6. Retention

We keep information only for as long as reasonably necessary for the purposes described above, including an active delivery, proof of performance, payment and tax records, safety, fraud prevention, claims, legal limitation periods, and required records. New York sales-tax transaction records are retained for at least three years when that rule applies. Legal holds, an open claim, or another mandatory record rule may require longer retention.

A duplicate-control fingerprint for a privacy request or business inquiry is automatically cleared after its 24-hour retry window. An unverified privacy-request submission is automatically removed after 30 days. A driver route-map snapshot is deleted when its assignment is completed, canceled, released, or reassigned. Other order, business inquiry, support, claim, proof, verified privacy-request, notification, audit, and backup records are retained according to their operational, legal, tax, safety, and dispute requirements. Authorized retention actions, legal holds, and provider lifecycles determine when those records are archived or removed. This Notice does not imply that every record follows the same deletion period.

An unverified launch-list record is temporary and may be removed after its verification window and operational retry period. A verified record is kept while the person remains subscribed or as needed to document the person's consent, verification, unsubscribe choice, and required email compliance. The verification token is stored only as a one-way hash and is cleared after successful confirmation.

A business-webhook delivery record keeps its event reference, attempts, state, timing, HTTP status, and limited transport error. Wayboro does not store the customer endpoint's response body. Notification logs use the applicable operational and legal retention lifecycle described above.

When recipient PIN protection is selected, the current six-digit code is derived from the active private tracking token and a separate server secret. The raw code is shown through the private tracking page and is compared when the driver submits delivery proof, but it is not stored on the order or proof. Successful proof retains only the verification time. Rotating the private tracking token also changes the code. A retired nullable proof-PIN field remains solely so potential legacy evidence is not silently destroyed before an approved retention decision; current responses do not disclose any legacy value.

Private tracking access has a server-enforced deadline and can be revoked or rotated by authorized operations. A pending unpaid checkout uses a short configured access window; a delivered, canceled, or returned order uses the approved closed-order access window. Expiration disables the bearer link but is not represented as deletion of order, payment, proof, claim, or audit records.

7. Your choices and privacy requests

You may ask to access, correct, delete, or receive a copy of personal information, or appeal a denied request, where applicable law grants that right. We may need to verify identity and authority, and may retain or withhold information where law permits—for example, to complete a transaction, secure the service, keep required records, or preserve a claim. An authorized agent must provide evidence of authority when required.

Privacy request center

Submit, verify, and keep one auditable reference.

The structured form supports access, correction, deletion, portability, and one appeal of a denied or partially fulfilled decision. A request enters operations only after email verification. New submissions also record the requester's accuracy/authority certification; an appeal must link to an eligible earlier reference on which the currently verified email was already the requester or represented-person email.

Start a privacy request

Necessary service messages are part of an active order. A person who separately joins the verified launch list may receive launch and service-availability email for the services selected. Every such campaign must include the legally required unsubscribe method. The current application has no recurring automated text-marketing program. Browser controls can restrict cookies, but blocking necessary authentication or security cookies may prevent a portal from working.

We do not discriminate against a person for exercising an applicable privacy right. If a state law requires additional disclosures or an opt-out that applies to Wayboro’s actual processing, those rights will be honored and this Notice must be supplemented accordingly.

8. Security

The current application implements technical controls including role and object access checks, private proof storage, credential hashing, signed account tokens, request validation, sensitive-log redaction, rate limits, tracking-link rotation and expiry, and audit records. No system is perfectly secure. Protect account credentials and tracking links, and report suspected unauthorized access promptly.

9. Children

The service is not directed to children under 13, and a person placing an order must be at least 18. Do not submit a child’s information unless it is lawfully necessary for a delivery and you have the authority required by law. If we learn that information was collected unlawfully, we will take appropriate steps to delete or restrict it.

10. United States processing

The current service is designed for United States operations. Information may be processed in the United States, subject to applicable law and the safeguards described here.

11. Changes to this Notice

We will post a new effective date and version when this Notice changes. Material changes apply prospectively, and we will provide additional notice or obtain consent where law requires it.

12. Contact and appeals

Use the privacy request form for a generated reference and verified workflow. For an accessible alternative, email [email protected] or write to 31 Queens Way, Camillus, NY 13031, United States. Identify the type of request and your relationship to Wayboro, but do not email a password, private tracking link, full payment-card number, Social Security number, or unnecessary identity document.

Questions about an order? Open your private tracking link or email [email protected]. If email is needed, identify the delivery with its public WB- order number and nonsecret shipment facts—never paste the private tracking link or token.