At Wayfinder ("we," "us," or "our"), we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, including our coaching programs, courses, booking and scheduling tools, text (SMS) and email communications, payment processing systems, and user-authorized AI connectors.
This Privacy Policy also governs personal information collected by the businesses and organizations that use the Wayfinder Collective platform to operate their services and that link to this policy from their own websites (each, a "Platform Business"). Where a Platform Business links to this policy, references to "we," "us," or "our" include that Platform Business with respect to information collected through its own services and communications. This does not limit or reduce the commitments made under this policy by Wayfinder or by any Platform Business.
By using our services, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use our services.
1. Information We Collect
Personal Information
We may collect personal information that you voluntarily provide, including but not limited to:
Full name and contact information (email address, phone number)
Billing and payment information (processed securely via Stripe)
Account credentials
Communication preferences
AI connector authorization, scope, use, and operation audit information
Any information you provide during coaching sessions or program enrollment
Automatically Collected Information
When you access our services, we may automatically collect:
Device information (browser type, operating system)
IP address and general location data
Usage data and interaction with our platform
Cookies and similar tracking technologies
2. How We Use Your Information
We use the information we collect to:
Provide, operate, and maintain our coaching services and programs
Process transactions and send related information (receipts, confirmations)
Send administrative information, updates, and marketing communications
Respond to inquiries and provide customer support
Personalize and improve your experience
Provide business data and perform authorized actions through an AI connector you choose to connect
Analyze usage patterns to improve our services
Protect against fraudulent transactions and ensure security
Comply with legal obligations
3. Payment Processing & Security
All payment transactions are processed through Stripe, a PCI-DSS Level 1 certified payment processor. We do not store your complete credit card information on our servers. Your payment details are:
Encrypted using industry-standard 256-bit SSL encryption
Protected by 3D Secure (3DS) authentication when required
Stored securely by Stripe in compliance with PCI-DSS standards
Never accessible to our team in full form (only last 4 digits are visible)
For more information about Stripe's security practices, please visit Stripe's Privacy Policy.
4. Google Calendar Integration
When you connect your Google Calendar to Wayfinder, we access the following data through Google's API:
What We Access
Your calendar events (titles, times, descriptions, locations, attendees)
Your free/busy availability status
Your calendar list (to identify which calendar to sync with)
How We Use This Data
Display your Google Calendar events alongside Wayfinder events on your scheduling dashboard
Check your availability when prospects book meetings through your booking page
Create calendar events in your Google Calendar when new bookings are confirmed
Sync event updates (reschedules, cancellations) between Wayfinder and Google Calendar
How We Store This Data
Calendar event data is stored in our database (hosted by Convex, encrypted at rest) to enable real-time availability checking and two-way sync
Google OAuth tokens (used to maintain your calendar connection) are stored securely in our database
Data is retained only while your Google Calendar is connected; disconnecting removes synced data
What We Do NOT Do
We do not sell, share, or disclose your Google Calendar data to third parties
We do not use your calendar data for advertising or marketing purposes
We do not allow third-party access to your Google Calendar data unless you explicitly connect that service and request a feature that uses it
How to Revoke Access
Disconnect Google Calendar from your Wayfinder booking page settings at any time
Or revoke access directly in your Google Account at myaccount.google.com → Security → Third-party apps with account access
When you connect your Gmail account to Wayfinder, we access the following data through Google's Gmail API:
What We Access
Read access to your Gmail messages and threads (subject, body, sender, recipient, headers, timestamps, labels)
The ability to send email on your behalf from your connected Gmail account
Your email address (via Google's basic profile scope) to identify the connected mailbox
How We Use This Data
Display your Gmail conversations in Wayfinder's unified inbox alongside SMS, calls, and other channels
Thread incoming messages against the matching CRM contact or deal so coaches see relevant context
Send replies and new messages from inside Wayfinder via your Gmail account, preserving thread headers so recipients see the message in the correct Gmail thread
Reflect your read/archive/delete actions back to Gmail so your mailbox stays in sync
How We Store This Data
Synced email content is stored in our database (hosted by Convex, encrypted at rest) with row-level multi-tenancy isolation per organization
Google OAuth tokens (used to maintain your Gmail connection) are stored securely in our database
Data is retained only while your Gmail account is connected; disconnecting triggers a full cleanup of synced messages and conversations from Wayfinder
What We Do NOT Do
We do not sell, share, or disclose your Gmail data to third parties
We do not use your Gmail data for advertising or marketing purposes
We do not allow third-party access to your Gmail data unless you explicitly connect that service and request a feature that uses it
We do not use your Gmail data to train AI or machine learning models, ours or anyone else's
We do not read your Gmail data for any purpose other than the features described above
How to Revoke Access
Disconnect Gmail from your Wayfinder Inbox Settings at any time — this triggers a full cleanup of synced messages and conversations
Or revoke access directly in your Google Account at myaccount.google.com → Security → Third-party apps with account access
When an organization connects a YouTube channel, Wayfinder uses YouTube API Services to access channel and video metadata and read-only analytics, including video titles, thumbnails, publish dates, views, watch metrics, impressions, click-through rates, engagement, and subscriber gains.
How We Use and Store This Data
We use the data to show video performance beside Wayfinder funnel attribution for the connected organization.
Synced channel, catalog, and analytics data is stored in our database with organization-level access controls and encryption at rest.
Google OAuth credentials are stored in encrypted form and are used only to maintain the requested YouTube connection.
We do not sell YouTube API data or use it for advertising. We disclose it to a connected AI service only when an authorized user requests a feature that needs it.
Retention and Revocation
We re-verify authorization during successful syncs. If authorization cannot be verified for more than 30 days, we delete the synced YouTube data for that connection. Disconnecting the integration deletes its synced data and attempts to revoke its tokens immediately. You can also revoke Wayfinder's access at any time in your Google Account security settings.
If you connect Wayfinder to an AI service such as ChatGPT, Codex, or Claude, that service may request Wayfinder records and actions in response to your prompts. Depending on your permissions and request, returned data may include CRM contacts and deals, inbox and email content, calendar events, meetings and transcripts, orders and payment status, marketing activity, reports, team information, and organization settings.
The connector uses OAuth and your current Wayfinder permissions. It does not provide the AI service with your Wayfinder password, MFA code, personal access token, payment credentials, or provider secrets.
Public directory connectors exclude dedicated medical operations and must not be used to send payment-card data, protected health information, or government identifiers to an AI service.
Wayfinder receives operation requests and returns only the data needed for those operations. Wayfinder does not receive your full AI chat history unless information from that chat is included in a specific operation request.
Wayfinder stores connection identity, authorization scope, use timestamps, and operation audit records. We do not store the raw connector OAuth access token in the Wayfinder application database.
Data returned to the AI service is processed under that service's terms and privacy policy. Its retention practices may differ from Wayfinder's.
Removing Wayfinder from the AI service's connected-app settings stops future connector access. Information already included in an AI conversation remains subject to that service's retention and deletion controls.
Wayfinder does not use connector data to train its own general-purpose AI models.
6. Sharing Your Information
We do not sell, trade, or rent your personal information to third parties. We may share your information with:
Service Providers: Third-party vendors who assist us in operating our business (payment processing, email delivery, hosting)
Advertising & Analytics Partners: Limited information about your visit, shared with Google, Meta, and OpenAI to measure advertising performance, as described in the Cookies & Tracking section below
User-Authorized AI Services: Wayfinder data requested through an OAuth-connected AI service, such as OpenAI or Anthropic, only after an authorized user connects and uses that service
Coaches & Instructors: Information necessary for delivering coaching services you've enrolled in
Legal Requirements: When required by law, court order, or governmental authority
Business Transfers: In connection with a merger, acquisition, or sale of assets
With Your Consent: When you explicitly authorize us to share your information
7. SMS & Text Messaging
When you provide your mobile phone number and give consent through one of our (or a Platform Business's) forms, you may receive text (SMS) messages such as appointment reminders, booking confirmations, account updates, application or booking follow-ups, and, where you have separately consented, promotional messages.
SMS consent is collected through an optional checkbox and is never required to submit a form or to purchase our services.
Message frequency varies. Message and data rates may apply.
You can opt out at any time by replying STOP (or UNSUBSCRIBE, QUIT, CANCEL, or END) to any message, and reply HELP for assistance.
Your consent to receive text messages is specific to the business you provided it to and is not transferred to any other business.
Your mobile information will not be sold or shared with third parties for promotional or marketing purposes. Mobile opt-in data and consent are not shared with any third parties, except the service providers (such as our messaging carrier) that are strictly necessary to deliver the messages you have requested.
8. Your Rights (GDPR & CCPA)
If you are a resident of the European Economic Area (EEA), United Kingdom, or California, you have certain data protection rights:
Right to Access: Request a copy of the personal data we hold about you
Right to Rectification: Request correction of inaccurate or incomplete data
Right to Erasure: Request deletion of your personal data ("right to be forgotten")
Right to Restrict Processing: Request limitation of how we use your data
Right to Data Portability: Receive your data in a structured, machine-readable format
Right to Object: Object to processing of your personal data for marketing purposes
Right to Opt Out of Sale or Sharing: California residents may opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising, including the advertising cookies and pixels described in the Cookies & Tracking section
Right to Withdraw Consent: Withdraw consent at any time where we rely on consent
To exercise any of these rights, please contact us at support@wayfindercollective.io. We will respond to your request within 30 days.
9. Data Retention
We retain your personal information for as long as necessary to:
Provide our services and fulfill our contractual obligations
Comply with legal, accounting, and reporting requirements
Resolve disputes and enforce our agreements
Transaction records are retained for a minimum of 7 years for tax and legal purposes. You may request deletion of your account and personal data at any time, subject to legal retention requirements.
Connector authorization and operation audit records are retained as needed for account security, access control, abuse prevention, troubleshooting, and legal obligations. Disconnecting an AI service prevents new access but does not control copies already retained by that service.
10. Cookies & Tracking
We use cookies and similar tracking technologies to:
Remember your preferences and settings
Authenticate your account and maintain session security
Analyze website traffic and usage patterns
Improve our services based on user behavior
You can control cookies through your browser settings. Disabling cookies may affect the functionality of our services.
Advertising & Analytics Partners
We use advertising and analytics technologies from Google, Meta, and OpenAI, including cookies and tracking pixels, to measure the performance of our advertising and to show relevant ads. These partners may set cookies and receive information about your visit, including pages viewed and actions taken. Where required, this is subject to your consent, which you can withdraw at any time.
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place, including:
Standard Contractual Clauses approved by the European Commission
Data processing agreements with all third-party service providers
Encryption of data in transit and at rest
12. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately so we can delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
Posting the updated policy on this page with a new "Last Updated" date
Sending an email notification for significant changes
Displaying a notice on our platform
Your continued use of our services after any changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
This Privacy Policy is provided for informational purposes and does not constitute legal advice. We recommend consulting with a qualified legal professional for specific compliance requirements in your jurisdiction.