Privacy Notice
How Wandrio processes users’ personal data in its application, web service and related support services.
| Controller | Wandrio Oy, Business ID 3546427-8 |
| Data protection contact | support@wandrio.net |
| Scope | Wandrio mobile application, Wandrio web service, Wandrio Teams and related support, communications and paid services |
| Updated | 18 August 2026 |
| Version and status | 1.1 – Published |
| In brief. Wandrio needs account information and data related to the features selected by the user in order to provide the service. Location and activity data are processed only in connection with service features. Users decide whether to connect integrations, how their activities are displayed and whether to give optional consents. Personal data is not sold. |
1. Controller and contact details
Controller: Wandrio Oy (Business ID 3546427-8)
Postal address: Tuohivirsu 2 E 19, 02130 Espoo, Finland
Data protection and rights requests: support@wandrio.net
When another organisation provides a Wandrio feature to its employees or another group and determines the purposes of processing, that organisation may act as the controller and Wandrio as its processor. Such processing is described in the organisation’s own privacy information or in a service-specific appendix.
2. Personal data we process
| Data category | Examples |
| Account and authentication data | Name, email address, user identifier, sign-in method, account status, and identifiers associated with Google or Apple sign-in. |
| Profile and community data | Display name, public user identifier, profile picture, user bio, friend and follower relationships, group and team memberships, roles and membership requests. |
| Activity and location data | Exercise activity, date and time, duration, distance, activity type, GPS route and points, elevation, speed or pace, and the visibility selected by the user. |
| Fitness metrics | For example heart rate, calories, cadence or power, if provided by a device, integration or import file selected by the user. |
| Derived data | Visited map tiles, map coverage, statistics, scores, rankings, achievements, team contributions and other summaries calculated by the service. |
| User content | Activity titles and descriptions, comments, messages, reactions, images, videos, feedback and other content added by the user to the service. |
| Usage, device and security data | Application event and view, event time, platform, application version, IP address, device or notification identifier, and session, error, log and security data. |
| Purchase and subscription data | Product, subscription or purchase identifier, transaction time, app store verification data and subscription status. Wandrio does not receive full payment card details. |
| Support and rights request data | Enquiries, messages, identifiers needed to handle the matter and measures taken in relation to the request. |
Activity and location data may reveal precise information about a user’s movements. A fitness metric may, in some circumstances, be special category personal data concerning health. Wandrio does not use this data for medical assessment, diagnosis or drawing conclusions about a user’s health.
3. Sources of personal data
- directly from the user during registration and when the user manages their profile, content, enquiries and settings
- from the user’s device and GPS location when the user starts recording and grants the necessary device permission
- from services voluntarily connected by the user, such as Strava and Garmin, and from files imported by the user
- from Google or Apple sign-in, depending on the sign-in method selected by the user
- from Apple App Store or Google Play to verify a paid product or subscription
- from use of the service, technical logs and data calculated by Wandrio
- from other users when they interact with the user’s public profile, content, team or community features.
Disconnecting an integration prevents new data from being retrieved from that service. Data previously imported into Wandrio is deleted separately using Wandrio’s deletion feature or on request, unless there is another legal basis for retaining it.
4. Purposes and legal bases of processing
| Purpose | Legal basis |
| Creating and authenticating a user account and providing the Wandrio service | Performance of a contract and steps requested by the user (Article 6(1)(b) GDPR). |
| Recording activities, selected integrations, maps, statistics, community and team features | Performance of a contract for the feature selected by the user. Device and integration permissions are requested separately. If a fitness metric constitutes health data, processing is based on the user’s explicit consent (Article 9(2)(a) GDPR). |
| Technical operation, security, prevention of misuse and troubleshooting | Wandrio’s legitimate interest in maintaining a secure and reliable service (Article 6(1)(f) GDPR). |
| Customer support, feedback and rights requests | Performance of a contract, Wandrio’s legitimate interest in managing the user relationship, or a legal obligation, depending on the nature of the request. |
| Providing purchases and subscriptions and maintaining accounting records | Performance of a contract and legal obligations (Article 6(1)(b) and (c) GDPR). |
| Optional usage analytics, personalisation or electronic marketing | Consent where processing or storage on the user’s device is not necessary for the service (Article 6(1)(a) GDPR). |
| Establishing, exercising or defending legal claims | Wandrio’s legitimate interest (Article 6(1)(f) GDPR). |
Where processing is based on legitimate interests, Wandrio assesses the necessity of the processing, the user’s reasonable expectations and the impact on the user’s rights and freedoms. Further information about the balancing test is available on request from the contact address.
5. Whether providing personal data is optional
Information required for an account and the core feature selected by the user is needed to provide the service. Without it, the account or the relevant feature may not be available. Optional profile information, external integrations, location, notifications, fitness metrics, optional analytics and marketing are selected separately. The user may withdraw a device or integration permission, but this may prevent use of the relevant feature.
6. Visibility of personal data to others
Wandrio’s community and team features may show the user’s display name, profile picture, membership, role, activities selected by the user as public and summaries calculated from those activities to other users. Visibility depends on the user’s settings and the feature being used. Before publishing, users should consider whether an activity or media item contains a location or other information they do not wish to share.
A team or content accessed through a sharing link may also be visible to people who are not members of the team. If a user accesses Wandrio as part of a service purchased by their employer, Wandrio may provide the employer with a report on use of the service. The reporting is described separately in service-specific privacy information. The report does not include names, user identifiers, raw routes or personal metrics.
7. Recipients and service providers
| Recipient or category | Purpose |
| Google Cloud and Firebase | Authentication, database, files, backend services, message queues, hosting, notifications, technical logging and maintenance. |
| Mapbox | Map tiles, map features and related technical services, and possible Mapbox service telemetry. |
| Strava and Garmin | Importing activity data through integrations voluntarily connected by the user and managing those integrations. The services process data within their own services under their own terms. |
| Google and Apple | Sign-in selected by the user, distribution of applications, verification of purchases and notification delivery for the device platform. |
| Email and support service providers | Delivering enquiries and processing support requests on Wandrio’s behalf. |
| Other users and recipients selected by the user | Displaying a profile, activity, team, message or other content selected as public or shared. |
| Public authorities and advisers | Data may be disclosed to the extent required by law or to handle a legal claim. |
| Parties to a business transaction | Data may be processed when assessing and completing a corporate transaction, subject to appropriate confidentiality and data protection measures. |
Wandrio does not sell personal data.
8. Transfers outside the European Economic Area
Some of the cloud, mapping, authentication, app store and support services used by Wandrio may process data outside the European Economic Area. Wandrio uses a transfer mechanism permitted under applicable data protection law, such as an adequacy decision of the European Commission or standard contractual clauses, and assesses any necessary supplementary safeguards. Further information about the applicable safeguards is available on request from support@wandrio.net.
9. Retention periods
| Data | Retention period or criteria |
| Account, profile, activities, location, user content and derived data | For as long as the account is active or the data is needed to provide the service selected by the user. Users may delete individual data or the entire account using the available features. |
| Temporary deletion archive related to account deletion | For no more than 30 days to complete the deletion process and recover from errors, after which the archive is deleted. |
| Restore points and soft-deleted files | Generally for no more than 7 days. Deleted data may remain in recovery protection for this period and is not restored to normal use except in a justified recovery situation. |
| Ordinary technical service logs | Generally 30 days. |
| Mandatory cloud platform administration and system logs | Generally 400 days in accordance with the service platform’s settings. |
| Purchase, accounting and tax data | For the period required by applicable accounting and tax legislation. |
| Support, rights and incident requests | For as long as needed to handle the matter, demonstrate compliance with legal obligations or deal with a potential legal claim. |
| Evidence of consent and its withdrawal | For as long as needed to demonstrate compliance with consent requirements and deal with a potential claim. |
When the retention period ends, data may be deleted or anonymised so that it can no longer be linked to a user. Anonymised statistical data may be used without the retention limitations applicable to personal data.
10. User rights
Subject to applicable law, users have the right to:
- obtain confirmation as to whether Wandrio processes their personal data and receive a copy of the data
- request correction of inaccurate or incomplete data
- request deletion of personal data
- request restriction of processing
- object to processing based on legitimate interests on grounds relating to their particular situation, and object to direct marketing at any time
- receive data they have provided in a structured, commonly used and machine-readable format and transmit it to another controller where processing is based on consent or a contract and is carried out by automated means
- withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal
- lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement.
Rights requests may be sent to support@wandrio.net. Wandrio may request additional information to verify the user’s identity. Requests are answered without undue delay and generally within one month. Exercising rights is generally free of charge. The supervisory authority in Finland is the Office of the Data Protection Ombudsman (tietosuoja.fi).
11. Deleting an account and personal data
Users may delete their account through the account settings in the Wandrio application or request deletion at support@wandrio.net. A deletion request starts the deletion or anonymisation of the account and related active personal data without undue delay. Where possible, deletion also covers integration, map, media and public data controlled by Wandrio. A reference remaining in content created by another user may be anonymised if deleting the entire conversation context is not justified.
Data may be retained after a deletion request only where necessary to comply with a legal obligation, handle a legal claim or on another basis permitted under the GDPR. Temporary deletion archives and recovery protection are removed within the periods described in section 9.
12. Automated decision-making
Wandrio does not make decisions based solely on automated processing of personal data that produce legal effects concerning the user or similarly significantly affect the user. The service may calculate scores, achievements, rankings and recommendations, but these are not significant decisions within the meaning of Article 22 GDPR.
13. Security
Wandrio protects personal data through technical and organisational measures proportionate to the risks. These include authentication, access restrictions, encrypted network connections, encryption at rest provided by cloud services, logging, recovery protection and security incident management. Access to personal data is granted only to persons and service providers who need it to perform their duties. However, no electronic service is entirely risk-free.
14. Changes to this notice
Wandrio may update this notice when the service, data processing or legislation changes. The current version is published on Wandrio’s website together with the update date. Where necessary, material changes are communicated through the service or by another appropriate method before they take effect.
15. Legal sources
1. EU General Data Protection Regulation, in particular Articles 12-22 — information for data subjects, legal bases and data subject rights
2. European Data Protection Board: Guidelines on transparency — clear, easily accessible and understandable information
3. Office of the Data Protection Ombudsman — Finnish supervisory authority and guidance on data subject rights