Last updated June 2026
Beta pilot
Privacy policy
This policy explains what we collect when you organize or join a Waypoint beta pilot, how long we keep it, and how to ask us to delete it. The beta is a pre-release build for team outings and group events — we aim to be clear and proportionate.
Request data deletion by email
Beta / pilot processing
The sections below describe processing for the full Waypoint product. During the beta pilot, the same categories generally apply.
We may log additional technical detail on pilot builds (errors, performance, funnel steps) to fix issues quickly. Identifiers are hashed where possible.
Beta infrastructure may reset or lose data during deployments — especially on preview environments. Do not treat pilot races as long-term archives. Use the deletion process below if you need data removed.
Support and feedback emails you send during the pilot are kept to improve the product and help your race.
Who we are
Waypoint runs Waypoint, a GPS challenge race you play in your browser on your phone — solo or with other teams.
Questions about privacy: support@playwaypoint.com.
What we collect
During a race we may process:
- GPS location while the race is active — to show your position on the map, reveal nearby stops in discovery mode, and show proximity hints (honor-based; we do not block submits by GPS alone). Your browser asks permission before we read location.
- Photos and short video clips you submit as challenge evidence — compressed on your device before upload where possible.
- Device motion or orientation readings for sensor-based challenges, only while you complete that challenge and only if your browser allows it.
- Team names and participant display names you enter in the lobby.
- Organizer account email and authentication data when you create an Event or Corporate race.
- Session identifiers that keep your team signed in to a race — stored server-side and not shown to other teams.
- Technical and usage events (e.g. funnel steps, challenge completions) via privacy-oriented analytics — participant identifiers are hashed where possible.
Why we use it
We process this data to run the race you joined or organized, generate place-aware challenges, take payment for paid tiers, improve the product, and comply with law.
Legal bases under GDPR: performance of the service (Art. 6(1)(b)), legitimate interests in operating and improving Waypoint (Art. 6(1)(f)), and consent where we ask for it explicitly (e.g. optional marketing — not required to play).
Who helps us process data
We use trusted subprocessors, each under appropriate data-processing terms:
- Supabase — database, authentication, and file storage (EU-capable hosting).
- Stripe — payment processing for Pro and Event unlocks.
- OpenAI — server-side challenge text generation (Pro+ tiers); prompts may include place names near your play area, not your live GPS.
- Mapbox — map tiles and geocoding in the app.
- PostHog — product analytics (events mirrored from our database when configured).
- Google Ads — conversion measurement for paid campaigns (only if you accept cookies in our site notice).
How long we keep it
GPS traces tied to your session are kept only while relevant to an active or recently ended race, then removed or anonymized.
Challenge photos, video proofs, names, and race results are kept so teams can view results, wrap-up, and Event/Corporate recaps. Photos and videos are deleted automatically 90 days after a race ends (configurable via PHOTO_RETENTION_DAYS on our side).
Organizer account data is kept while your account is active and as required for billing and legal obligations.
Your rights
If you are in the EEA (including Lithuania), you may request access, correction, deletion, restriction, portability, or object to processing where applicable.
You may lodge a complaint with your local supervisory authority. In Lithuania: Valstybinė duomenų apsaugos inspekcija (VDAI), ada.lt.
Request deletion
Email support@playwaypoint.com with the subject "Data deletion request". Include your race link, join code, or race ID, and what you want removed (photos, names, GPS, or the full race record).
Organizers can also ask us to purge a specific race. We aim to respond within 30 days.
Security
Session tokens are server-side secrets not exposed to other teams. Photos and race data are stored in access-controlled infrastructure.
Changes
We may update this policy. The date at the top reflects the latest version. Material changes to Event/Corporate processing will be communicated to organizers where required.