Skip to the main content

Privacy

A short list of things we keep, and a shorter one we refuse.

This service only needs enough about you to sign you in, remember the trip you are watching, and prove we delivered an alert you asked for. Everything here is written in the same plain language as our terms.

What we hold

  • Your email address. The address you verify with a sign-in link is your account identity. We use it to sign you in and, when you select the email channel, to deliver that channel’s alerts.
  • Sign-in records. A hashed one-time sign-in token, its expiry, and when it was used, so a link cannot be replayed.
  • Your onboarding record. Your confirmation that you are 18 or older, the time zone you chose, and the exact version and timestamp of each policy you accepted.
  • Your watches. The destination, itinerary variants, dates, party size, and matching mode you configured, plus any leg you told us you had booked.
  • Delivery records. Each alert attempt, provider identifier, and safe outcome per channel, so both you and we can see the provider-reported delivery state. We do not keep rendered text-message bodies in the delivery log.
  • Text-alert permission. Where SMS is offered, we record your exact consent version and time, confirmation state, masked destination, one-way destination hash, provider contact identifier, delivery receipts, and any STOP or START event. The full number is encrypted at rest. Inbound message text is classified for STOP, HELP, or START handling and hashed for audit, but the message itself is not stored.
  • Delivery providers. We give Surge the phone number, confirmation request, and single rendered alert needed to provide SMS; we give our email provider the address and email needed for the channel you selected. Those providers return operational identifiers and delivery outcomes. We do not sell either destination or use it for advertising. Text-message opt-in data and consent are never shared for lead generation, affiliate marketing, or another party’s marketing.
  • Site measurement. When configured, Google Analytics and Meta Pixel receive public page URLs, including advertising click identifiers and campaign parameters in those URLs, browser and device signals, approximate location, referrer and campaign data, and checkout or subscription events. We also associate those click identifiers and campaign parameters with an account after sign-in so we can measure whether advertising produced a trial or payment. Raw click identifiers are removed after 90 days; campaign-level attribution remains with the account until its operational data is deleted. We suppress authenticated page views, remove the Stripe Checkout session identifier from the account return URL before either service loads, permit Google advertising storage for conversion attribution, disable advertising personalisation signals, and never send an email address, phone number, watch choice, card detail, or raw Stripe Checkout session identifier to either service.

What we never hold

  • No password. There is nothing to breach, because there is nothing to remember.
  • No Recreation.gov credentials. We never ask for them and could not use them. You complete the booking yourself.
  • No card details. When paid subscriptions open, our payment provider handles the card; we see only the subscription state we need to grant access.
  • No text-message archive. Founder tools and ordinary event records show masked destinations and categorical outcomes, never confirmation codes, inbound messages, or rendered alert bodies.

How long we keep it, and how to get it back

Delete your account and the operational data in the live service is put beyond use for 30 days so that an accidental deletion can be undone, then permanently purged. Only records we are legally required to keep, such as billing history, survive that purge.

Laravel Cloud may maintain service-level disaster-recovery copies under its infrastructure terms. They are not an account-recovery feature, and Wildchime does not create or rehearse restores against the live production database. If Laravel Cloud performs infrastructure recovery, our deletion and purge obligations still apply to the recovered active service.

Access, correction, and deletion requests

Write to the privacy mailbox below. We verify that the request really comes from the account holder before we act on it, then track it by hand until it is fulfilled — including requests made under privacy laws outside the United States. We answer against the same one business day response target as support.

Who to write to

Use the privacy mailbox for anything about your personal data. Use support for the service itself — a watch that looks wrong, an alert that did not arrive, or a billing question.

Support
support@wildchime.com
Privacy requests
privacy@wildchime.com

Both addresses are monitored role mailboxes, not personal inboxes.