Controller and contact
The controller is Tobias Wetzel, Löhrgasse 8, 1150 Wien, Austria, trading as SteadyGo. Privacy requests can be sent to contact@steadygo.app.
Data Wheee! processes
- Account and profile data, such as email address, authentication identifier, display name, profile picture, sign-in provider, and security information.
- Trip content, including destinations, dates, travellers, budgets, itineraries, saved places, routes, preferences, assistant messages, group proposals, polls, memberships, and invitations.
- Location data when you grant device permission. It is used to show your position and nearby context. A location becomes server-side trip content only when you choose to use it in a saved plan or assistant request.
- Subscription and entitlement information, such as product, purchase status, store, renewal or expiry state, and the pseudonymous identifiers needed to connect a store purchase to a Wheee! account. Wheee! does not receive full card details.
- Support messages, feedback, AI-response reports, and the information you include when asking for help.
- Technical, security, crash, performance, device, app-version, and network information needed to operate and protect the service.
- Optional product analytics and interaction telemetry only after the relevant consent is given. This choice can be changed in Settings.
Why the data is used
Data is used to create and secure accounts, generate and save trips, provide collaboration and notifications, answer support requests, manage entitlements, prevent abuse, diagnose errors, and improve the service. Processing is based on performing the service requested by you, legitimate interests in secure and reliable operation, consent for optional analytics and AI processing where requested, and legal obligations where applicable.
AI and travel providers
When you use the trip assistant, the prompt, relevant trip context, tool results, and necessary account context are sent to the configured AI service to produce the response. Do not include passport numbers, payment-card details, health information, or other sensitive personal information in prompts. Travel-search and route features may send the destination, dates, occupancy, route points, currency, and other necessary request fields to the selected travel, routing, place, map, or weather provider. Partner credentials remain server-side.
Booking.com live inventory is not currently integrated. If that integration is approved and enabled, this notice will be updated before Booking.com data is used in production.
Service providers and recipients
Depending on the feature and production configuration, recipients can include Supabase for authentication and EU-hosted application data; Cloudflare for website delivery, DNS, security, and network data; TensorX and its configured model provider for text-based AI; RevenueCat, Apple, and Google for mobile subscriptions; Sentry for essential error monitoring; PostHog and Microsoft Clarity for consent-based analytics; Resend for transactional email; and the map, place, routing, weather, activity, flight, or accommodation provider selected for a request. Provider privacy terms also apply when you open an external provider link.
Sharing and collaboration
A trip is private unless you create an invitation or share it. People who receive a valid link can receive the view or edit access chosen by the trip owner. Group-chat proposals and poll answers are visible to the trip group as indicated in the app. Private traveller preferences and private assistant context are not made group-visible merely because a trip is shared.
Retention and deletion
Account and trip data is retained while the account or relevant shared trip remains active. Operational logs, support records, usage records, and security events are kept only for the period reasonably needed for their stated purpose. You can delete the account in the app or follow the account-deletion instructions. Limited billing, fraud, dispute, legal, and backup records may remain for their applicable retention periods.
International transfers
Some providers may process data outside Austria or the European Economic Area. Where required, transfers are protected through an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism. Core account and application data is configured for EU hosting where supported.
Your rights
Subject to the conditions of applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing, and may withdraw consent without affecting earlier lawful processing. You may also complain to the Austrian Data Protection Authority. Contact contact@steadygo.app to exercise a right.
Security and children
Wheee! uses transport encryption, access controls, row-level database security, managed secrets, and monitoring intended to protect the service. No online service can guarantee absolute security. Wheee! is a general-audience travel-planning product and is not directed to children. A person who cannot lawfully consent to data processing in their country should use it only with the involvement of a parent or guardian.
Changes
Material changes will be reflected on this page and, where required, communicated in the app. The date at the top shows the latest update.