Wayside is the self-guided audio walking tour app published by Small Works Lab, LLC, a Delaware limited liability company with its principal place of business at 2810 N Church St STE 89444, Wilmington, DE 19802 (“Wayside”, “we”, “us”). We are the data controller for the personal data described in this policy. This policy covers the Wayside mobile app and the wayside.tours website. The website’s data is limited to the website analytics in section 4C and the map and photograph embeds in section 5; the rest of this policy concerns the app.
1. Who we are and how to reach us
- Controller: Small Works Lab, LLC, 2810 N Church St STE 89444, Wilmington, DE 19802, United States.
- Privacy contact: privacy@wayside.tours. We answer every request ourselves and aim to respond within one month.
- Person in charge of the protection of personal information (for Quebec residents, under Law 25): the person exercising the highest authority within Small Works Lab, LLC, reachable at privacy@wayside.tours.
We have not appointed a Data Protection Officer; we are not required to, given the limited scale and nature of our processing.
2. The data we handle
Your Wayside identity is anonymous. When you first open the app we create an account for you automatically using Firebase Anonymous Authentication: a random identifier (a “UID”) with no name, email, password, or social login attached. Everything below is stored under that UID.
Data you create in the app
- Your library: tours you save or bookmark, tours you’ve taken, and simple completion stats (which stops and tours you finished).
- Personalized tours: if you generate a personalized tour, it is stored privately under your UID. Personalized tours cannot be shared or seen by other users.
- Preferences: your interests, language, notification and communication toggles (all off by default), and cities you follow for alerts.
- Push token: if you turn notifications on, the device push token needed to deliver them (Apple/Google push services).
Data collected automatically
- Location: see section 3. Precise location is processed on your device and is not uploaded to our servers.
- Photographs from Unsplash: tour and city screens show photographs from Unsplash, loaded directly from Unsplash’s own servers. Loading them exposes your device’s IP address to Unsplash. Downloading a tour for offline use also saves a copy of its Unsplash photographs to your device.
- App updates from Expo: on launch the app checks Expo’s update service for a newer JavaScript bundle for this app, and may download one to apply on the next launch. That check exposes your device’s IP address to Expo, along with technical app and device metadata needed to select a compatible update. A downloaded bundle is stored on your device until it is replaced or the app is removed.
- Crash and error diagnostics: if the app crashes or hits an error, a technical report (device model, OS version, app version, stack trace, and recent in-app technical events) is sent to our monitoring providers, Sentry and Firebase Crashlytics. Reports are tagged with your UID and nothing else, so we can count affected users without identifying anyone.
- Usage analytics: if analytics is on (see section 4A), we record how you use the app: screens viewed, onboarding completion, city searches (the place name you type, trimmed and capped), tours started, completed, rated, and shared, paywall views and dismissals, plan selection and purchase completion (which pass, never payment details), and feedback submissions, together with two session properties (free/Plus membership and app language) and standard technical context the analytics service adds automatically (device type, OS, coarse region, session counts). It is keyed to your anonymous UID, and carries no advertising identifiers and no precise location. Our analytics processor is Google, through Google Analytics for Firebase (GA4).
- Ads measurement: if ads measurement is on (see section 4B), we share data with our advertising partners to improve the ads we run, for example refining our creatives and discontinuing low-performing campaigns. On Android this means collecting the device advertising ID (Google Advertising ID) and reporting purchase-conversion events (which pass, plus its value and currency) to Google Ads. On iOS we collect no advertising identifier; Apple’s AdServices provides campaign-level install attribution. We build no advertising profile, run no remarketing, and use this data only to measure and improve the campaigns described in section 4B.
- Purchase data: if you buy a pass or membership, Apple or Google processes the payment. We and our subscription provider, RevenueCat, receive a receipt and entitlement status (which product, when, which store), never your name or card details.
Data you send us directly
- Support email: if you email us, we receive your email address and whatever you include in the message. We use it only to help you and keep it only as long as needed to do so.
When you send us feedback
If you send feedback from inside the app, we collect:
- What: your message text; an optional email address, only if you provide one, used solely to reply to you (leave it blank and the feedback stays anonymous under your UID); the kind of feedback (bug, idea, or other); and the technical context that rides along: app version and build, platform and OS version, device model, and app language. When you send feedback from a tour — while you are walking it or once it is finished — or from an error screen, we also attach that tour’s reference, the reference and name of the stop you are reporting about, or the error’s event id, so we can place your report.
- Why: to answer you and to fix and improve the product.
- Where: it is stored in Firestore under your UID, where we read it.
- Retention: we keep it until the feedback is handled, and it is deleted when you delete your account (it is part of the deletion purge).
The email field is optional and never pre-filled.
What we do not collect
On iOS the app uses no advertising identifier and requests no App Tracking Transparency permission. The app does no cross-app tracking and builds no advertising profile on any platform. On Android it collects the device advertising ID solely for the consent-gated ad conversion measurement in section 4B.
On the website (wayside.tours)
The website processes the following, none of it tied to your anonymous app account:
- Visit analytics: we count visits and basic interactions (which pages are viewed, whether a download button is tapped) with Umami, a cookieless tool that stores nothing on your device and keeps no identifier that could single you out. See section 4C.
- Map tiles: each tour page shows an interactive route map whose images (tiles) are served by CARTO, using OpenStreetMap data. Loading them exposes your device’s IP address to CARTO. See section 5.
- Photographs: some photographs on tour and city pages come from a third-party provider, Unsplash, using their own image URLs. Loading them exposes your device’s IP address to Unsplash. See section 5.
- Theme preference: if you switch light/dark mode, that choice is saved in your browser’s local storage on your device; it never reaches our servers.
See the cookies & trackers notice for exactly what the website and app store on, or read from, your device.
3. Location, specifically
Location is what makes Wayside work, so here is exactly how it is used:
- The app asks for “while using the app” location permission the first time a feature needs it: finding tours around you, and guiding you along a live tour. We never request “always” access.
- During an active tour, location keeps updating with the screen locked or the app in the background, using the platform’s in-tour mechanisms (an iOS background mode, an Android foreground service with a visible notification), so narration can trigger at the right stop hands-free. This stops when the tour ends.
- Your precise coordinates are processed on the device. They drive the map, the route line, and stop auto-advance locally. We do not store your movement history on our servers. What our servers see is the city you browse tours for.
- You can revoke location access at any time in your device settings. The app still works for browsing, reading, and listening; only live location-triggered guidance needs the permission.
4. Why we process data, and on what legal basis
For readers in the EEA and UK, the GDPR requires us to name a legal basis for each purpose:
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the app: your library, preferences, personalized tours, sync | UID, library, preferences | Performance of a contract (Art. 6(1)(b)) |
| Guide you on a live tour | Location (on-device) | Performance of a contract (Art. 6(1)(b)) |
| Process purchases and unlock membership | Receipt and entitlement data | Performance of a contract (Art. 6(1)(b)) |
| Send notifications you turned on | Push token, city alerts | Consent (Art. 6(1)(a)), withdrawable in the app or device settings |
| Fix crashes and keep the app reliable | Crash and error diagnostics | Legitimate interest (Art. 6(1)(f)): running a stable, secure service |
| Measure how the app is used (product analytics) | Usage events, membership and language properties, device/session context | Consent (Art. 6(1)(a)), withdrawable in You → Privacy |
| Measure how the website is used (website analytics) | Cookieless visit and interaction counts; IP used only momentarily | Legitimate interest (Art. 6(1)(f)): measuring and improving the website |
| Measure ad-campaign effectiveness (ads measurement) | Android advertising ID and purchase-conversion events; iOS AdServices campaign token | Consent (Art. 6(1)(a)) for the Android advertising ID and conversion signals, withdrawable in You → Privacy; legitimate interest (Art. 6(1)(f)) for campaign-level Apple AdServices attribution |
| Answer support requests | Your email and message | Legitimate interest (Art. 6(1)(f)): helping users who contact us |
| Answer and act on in-app feedback | Your message, optional email, feedback kind, app/device context, tour, stop, or error reference | Legitimate interest (Art. 6(1)(f)): improving the product and replying to users who write in |
| Comply with legal obligations | Purchase records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have checked that the processing is minimal, expected, and doesn’t override your rights; you can object at any time (section 8). We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not profile you.
4A. Usage analytics, specifically
To understand what works in the app and what to fix, we measure how it is used. This is the one place we use product analytics, and here is exactly how it works:
- What we collect. Usage events only: the screens you view, when you finish onboarding, city searches (the place name you type, trimmed, lowercased, and length-capped, never free-form text beyond a place name), tours you start, complete, rate (thumbs up or down), and share, how far you get through a walk and how long it takes, paywall views and dismissals, which plan you select, when a purchase completes (which pass, never payment details), and feedback submissions. Alongside these we record two properties about your session (whether you are on the free or Plus plan, and your app language) and the analytics service adds standard technical context automatically: device type, operating system, an approximate region inferred from your IP address (never precise location or coordinates), and session counts.
- What analytics does not collect. No precise location or coordinates (the only place signal is the city you browse), and no advertising identifiers. Analytics is keyed to your anonymous UID and nothing else.
- Purpose. Product analytics for activation (do installs reach a first tour?), monetization (where does the paywall funnel leak?), and retention (do people come back?).
- Processor. Our analytics processor is Google, through Google Analytics for Firebase (GA4), acting on our behalf under a data-processing agreement.
- Your choice. In the EU, EEA, and UK analytics is off until you turn it on: we ask during onboarding and rely on your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time. Everywhere else it is on by default, with a one-tap opt-out. Either way the control is a single “Usage analytics” switch in You → Privacy, and turning it off is as easy as leaving it on.
- Retention. Analytics data is retained for 14 months, then deleted automatically.
- Deletion. Turning analytics off resets the analytics identifiers on your device. Deleting your account additionally issues a user-deletion request to Google Analytics for the data keyed to your UID (see section 7 and the account & data deletion page).
4B. Ads measurement, specifically
We run ads to promote Wayside. To measure whether they work, we attribute installs and purchases to the campaign that led to them. This is separate from product analytics (section 4A) and runs under its own consent. It works differently on each platform.
- Purpose. We report conversion data to our advertising partners to improve the ads we run, for example refining our creatives and discontinuing campaigns that don’t perform. This is measurement of our own campaigns: we build no advertising profile, run no remarketing, and do not personalize ads.
- On Android. The app collects the device advertising ID (Google Advertising ID) and reports conversion events, including when a purchase completes and its value and currency, to Google Ads for conversion measurement. This happens only while ads measurement is on.
- On iOS. The app collects no advertising identifier and shows no App Tracking Transparency prompt. Attribution runs through Apple’s AdServices framework, via our subscription provider RevenueCat: a campaign-level attribution token that carries no IDFA and no cross-app identifier, which Apple does not count as tracking.
- Partners. Google Ads receives the Android advertising ID and purchase-conversion events. Apple receives the AdServices attribution token on iOS. Neither receives your data for any purpose beyond measuring the campaigns described here.
- Legal basis. In the EU, EEA, and UK the Android advertising ID and conversion signals rely on your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time; everywhere else they are on by default with a one-tap opt-out. Apple’s campaign-level AdServices attribution relies on legitimate interest (Art. 6(1)(f)): measuring our campaigns with a signal that identifies no individual.
- Your choice. The control is a single “Ads measurement” switch in You → Privacy. In the EU, EEA, and UK it is off until you turn it on; everywhere else it is on by default and one tap turns it off. Turning it off stops the Android advertising ID and the conversion signals.
- No sale, no remarketing. We do not sell your personal data, and we do not use it to retarget you with ads or to personalize advertising.
4C. Website analytics, specifically
To see what works on the wayside.tours website, we measure how it is used. This is the website’s only analytics and it is separate from the app’s usage analytics in section 4A:
- What we collect. Visits and basic interactions only: which pages are viewed and whether a download button is tapped.
- How. Our tool is Umami, and it is cookieless: it sets no cookie and stores nothing on your device, uses your IP address only momentarily to count the visit without keeping it, keeps no identifier that could single you out, produces only aggregate statistics, and does not track you across other websites.
- Purpose. To understand which pages are useful and improve the site.
- Processor. Umami (Umami Cloud), which hosts the data in the EU.
- Legal basis. In the EEA and UK, our legitimate interest (GDPR Art. 6(1)(f)) in measuring and improving the site.
5. Who we share data with
We do not sell personal data. We share it with the processors that run the service, and, while ads measurement is on, with the ad partners named below, under data-processing agreements where they apply:
| Provider | Role | Where |
|---|---|---|
| Google (Firebase) | Authentication, database, hosting, push delivery, crash reporting (Crashlytics), product analytics (Google Analytics for Firebase) | EU and US |
| Umami (Umami Cloud) | Cookieless website analytics (visit and interaction counts) | EU |
| Sentry | App error and crash monitoring | US |
| RevenueCat | Purchase validation and membership status; Apple AdServices attribution token collection on iOS | US |
| Expo | Over-the-air delivery of JavaScript app updates (EAS Update) | US |
| Google Ads | Android ad conversion measurement: receives the device advertising ID and purchase-conversion events, only while ads measurement is on (section 4B) | US |
| Apple (AdServices) | iOS campaign-level install attribution, no IDFA and no cross-app identifier (section 4B) | Per their policies |
| Apple / Google | App distribution, payment processing (as independent controllers) | Per their policies |
Website analytics (Umami). The wayside.tours website’s cookieless visit analytics runs on Umami (Umami Cloud), described in full in section 4C. It is separate from the app’s usage analytics in section 4A.
Photographs from Unsplash. Tour and city screens in the app, and tour and city pages on the website, show photographs from Unsplash. We do not download or host these images: the app and your browser fetch them directly from Unsplash’s own servers when a photograph loads, which means Unsplash receives your device’s IP address, as it would for any image a web page or app asks your device to load. See Unsplash’s privacy policy.
App updates (Expo). The Wayside app uses Expo’s EAS Update service to deliver JavaScript fixes without a full store resubmission. On launch the app contacts Expo to check for an update and may download a bundle to store on the device. Expo receives your device’s IP address and technical metadata about the app build (platform, runtime version, and related update-selection fields). See Expo’s privacy policy.
Interactive map on the wayside.tours website. Each tour page on the website shows an interactive map so you can preview the route. The map images (tiles) are served by CARTO, using map data from OpenStreetMap. The map is loaded only on a tour page, and only once you scroll it into view. When it loads, your browser fetches the tiles directly from CARTO’s servers, which means CARTO (and the OpenStreetMap infrastructure behind it) receives your device’s IP address, as it would for any image or resource a web page asks your browser to load. See CARTO’s privacy policy and the OpenStreetMap Foundation privacy policy.
We may also disclose data if the law genuinely requires it, or as part of a merger or acquisition, in which case this policy continues to apply and we will notify you of any change of controller.
6. International transfers
We are a US company, so the data described in this policy is processed in the United States, by us and by our processors (Google, Sentry, RevenueCat, Expo). For users in the EEA, UK, and Switzerland, transfers to the US are protected by our self-certification under the EU-US Data Privacy Framework and its UK Extension and Swiss annex; our US processors are themselves DPF-certified or bound by Standard Contractual Clauses. You can request a copy of the relevant safeguards via privacy@wayside.tours. Our website analytics processor, Umami, hosts its data in the EU, so website-analytics data is not transferred to the US.
7. How long we keep data
| Data | Kept for |
|---|---|
| Your UID, library, preferences, personalized tours, push tokens | Until you delete your account; then removed from live systems immediately |
| Residual copies (backups, logs) | Deleted or expired within 90 days of account deletion |
| Crash and error diagnostics | 90 days on our monitoring providers, then deleted automatically |
| Usage analytics (only if on) | 14 months on Google Analytics, then deleted automatically; turning analytics off resets the on-device identifiers, and deleting your account issues a Google Analytics user-deletion request |
| Website analytics (Umami) | Kept as aggregate, cookieless site statistics only; no identifier that could single you out is stored |
| Purchase and entitlement records | As long as required for accounting, tax, and fraud-prevention obligations |
| Support emails | Up to 24 months after your request is resolved |
| In-app feedback (message, optional email, context) | Until the feedback is handled, and deleted when you delete your account |
Because your account is anonymous and lives on your device, uninstalling the app orphans the account; deleting your account in the app (You tab → Delete account & data) is the clean way to remove everything. See the account & data deletion page for the exact steps and inventory of what is removed.
8. Your rights
Wherever you live, you can ask us to access, correct, delete, or export the data we hold about you, object to or restrict certain processing, and withdraw any consent (like notifications) at any time without affecting past processing.
- In the app: delete everything via You tab → Delete account & data; turn notifications and alerts off in Preferences; revoke location in device settings.
- By email: privacy@wayside.tours. Because accounts are anonymous, we may ask you to make a small in-app action to prove which UID is yours; we never ask for more identity than needed.
You also have the right to complain to a supervisory authority: in France the CNIL (cnil.fr), in the UK the ICO (ico.org.uk), in Canada the Office of the Privacy Commissioner (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information (cai.gouv.qc.ca), or the authority of your country of residence.
9. Regional notices
European Economic Area and France. The legal bases in section 4, the transfer safeguards in section 6, and all the rights in section 8 (including access, rectification, erasure, restriction, portability, and objection under GDPR Arts. 15 to 21) apply to you. Under French law you may also set directives for the handling of your data after death (Loi Informatique et Libertés, Art. 85). You may complain to the supervisory authority of your country; in France that is the CNIL.
United Kingdom. The UK GDPR and Data Protection Act 2018 give you the same rights as described above, exercised the same way. The supervisory authority is the ICO.
United States (including California). We do not sell personal information and we do not share it for cross-context behavioral advertising, and we haven’t in the preceding 12 months; there is accordingly no “Do Not Sell or Share” choice to offer. Because there is no sale or sharing for a signal to opt you out of, we do not respond to Do Not Track or Global Privacy Control signals. The categories of personal information we collect are set out in section 2 (identifiers: an anonymous UID and push token; internet/activity: crash diagnostics, if enabled the app’s usage analytics, and cookieless website visit counts; commercial information: purchase receipts; geolocation: processed on-device only). California residents (and residents of other states with privacy laws, such as Virginia, Colorado, Connecticut, and Texas) may exercise the rights in section 8, including through an authorized agent, and have the right not to be discriminated against for doing so. The “Last updated” date above is this policy’s effective date.
Canada. We comply with PIPEDA and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25. Our defaults are privacy-protective: no marketing, no advertising or cross-context tracking, notifications off. The technology described in section 3 can locate you; it is active only with your permission and can be deactivated in your device settings at any time. Quebec residents can address the person in charge of personal information (section 1) and complain to the CAI. A French version of this policy is available, with the French version at least as prominent as the English one.
10. Children
Wayside is not directed to children. You must be at least 13 to use it, or older where your local law sets a higher age for consenting to data processing (15 in France, 14 in Quebec, up to 16 in some EEA countries), in which case a parent or guardian must consent. We do not knowingly collect personal data from children below these ages; if you believe a child has used Wayside, contact us and we will delete the data.
11. Changes to this policy
When we change this policy we update the date at the top.
12. Contact
privacy@wayside.tours, or by post: Small Works Lab, LLC, 2810 N Church St STE 89444, Wilmington, DE 19802, United States.