Legal

Privacy Policy

Last updated: April 2026  ·  Effective immediately

Contents
  1. Who we are
  2. Data we collect
  3. How we use it
  4. Legal basis (UK GDPR)
  5. Third-party providers
  6. Data retention
  7. Your rights
  8. Location data
  9. Children's privacy
  10. Cookies & storage
  11. Security
  12. Contact & complaints
01

Who we are

Wonda is a local discovery platform that helps people find activities, events, and experiences near them across the UK. We connect consumers with local businesses and event organisers ("hosts") through our consumer app and host portal.

For the purposes of UK data protection law, [COMPANY NAME] (trading as Wonda) is the data controller responsible for your personal information. Registered address: [COMPANY ADDRESS]. Website: wondaful.app. If you have any questions about how we handle your data, please contact us at hello@wondaful.app.

02

Data we collect

We collect different information depending on whether you use Wonda as a consumer or as a host.

Consumer app users

Data Why we collect it
Location (GPS coordinates) To show listings and events near you. Only used in-session; not stored on our servers.
Device identifier To remember your saved favourites and preferences between sessions, without requiring an account.
Saved favourites The listings you heart, stored locally on your device and optionally synced if you create an account.
Search & filter activity Anonymised usage patterns used to improve recommendations and app performance.

Host portal users

Data Why we collect it
Name & email address To create and manage your account and send you service communications.
Password (hashed) To authenticate you securely. We never store your plain-text password.
Business details (name, type, city, phone) To create your host profile and display accurate listing information to consumers.
Listing content Titles, descriptions, prices, addresses, images, and event details you submit for publication.
Payment details Processed securely via Stripe. We do not store card numbers or CVVs.
Subscription & billing history To manage your plan, process payments, and provide invoices.
03

How we use your information

We do not use your personal information for advertising profiling, and we do not sell your data to third parties.

05

Third-party providers

We use the following trusted third-party services to operate Wonda. Each is contractually bound to protect your data and only process it on our behalf.

Supabase
Our database and authentication provider. Stores host accounts, listings, and app data. Hosted in the EU. Privacy policy →
Vercel
Our hosting and deployment platform. Serves the app and API globally via edge infrastructure. Privacy policy →
Stripe
Payment processing for host subscriptions. Stripe handles all card data — we never see or store your full card details. Privacy policy →
Anthropic
AI content moderation. Listing titles and descriptions are sent to Anthropic's API to check for prohibited content before publication. Data is not used to train AI models. Privacy policy →
OpenStreetMap / Nominatim
Geocoding service used to convert city names into map coordinates for listings. Only the city name or search query is sent — no personal data. Privacy policy →

We will notify you if we add any new third-party providers that process personal data.

06

Data retention

Data type Retention period
Host account data Held for the duration of your account. Deleted within 30 days of account closure on request.
Listing content Retained while the listing is active. Removed within 14 days of deletion by the host.
Payment & billing records 7 years, as required by HMRC financial record-keeping rules.
Consumer location data Not stored on our servers. Used only for the duration of your app session.
Consumer device identifier Stored locally on your device. Cleared when you clear your browser data or uninstall the app.
Anonymised analytics Up to 2 years, after which data is aggregated or deleted.
07

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights. You can exercise any of them by contacting hello@wondaful.app. We will respond within 30 days.

Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data.
Right to erasure
Request deletion of your personal data ("right to be forgotten"), where no legal obligation requires us to retain it.
Right to restriction
Ask us to pause processing your data in certain circumstances.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests, including profiling.
Withdraw consent
Withdraw consent for location access at any time via your device settings.
Automated decisions
Request human review of decisions made solely by automated processing (e.g. AI content moderation).
08

Location data

Wonda requests access to your device's precise location to show you activities and events nearby. Here is exactly how we handle it:

09

Children's privacy

Wonda is not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13.

Our host portal requires users to be 18 or over to enter into a contract with us. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@wondaful.app and we will delete that information promptly.

10

Cookies & local storage

Wonda uses minimal browser storage to provide a working experience. We do not use third-party advertising cookies or tracking pixels.

Storage type What it stores Duration
LocalStorage Your saved favourites, filter preferences, and anonymous device identifier Until you clear browser data
Session cookie Your host portal login session token Until you sign out or the session expires
Supabase auth cookie Authentication token for host portal access Up to 7 days (refresh token)

You can clear all locally stored data at any time via your browser's settings. Doing so will sign you out of the host portal and clear your saved favourites.

11

Security

We take the security of your data seriously and implement the following measures:

Despite these measures, no system is completely immune to security incidents. If you suspect your account has been compromised, please contact hello@wondaful.app immediately.

12

Contact & complaints

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Get in touch

We aim to respond to all data-related requests within 30 days.
[COMPANY NAME] (trading as Wonda), [COMPANY ADDRESS]

✉ hello@wondaful.app

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent authority for data protection:

We would, however, appreciate the chance to address your concerns before you contact the ICO, so please reach out to us first.