Privacy Policy

Last updated 9 September 2026

This policy explains what personal data Wave Horizon Solutions Ltd, trading as Goiaba ("Goiaba", "we"), collects, why, and what your rights are. It covers two groups of people: operators who use Goiaba to run their business, and guests who book a tour on a website powered by Goiaba.

1. If you are an operator (our customer)

We are the controller of the data we hold about you.

  • What we collect: name, email, phone, company name and address, site settings, login activity, and billing details (plan, invoices, billing address, VAT number). Card details go directly to Stripe; we only store a customer reference.
  • Why: to provide the service and support (contract), to bill you and keep tax records (legal obligation), to send service emails about your account (contract), and to keep the service secure and improve it (legitimate interest). We do not sell your data and do not send marketing without your consent.
  • How long: for the life of your account and 90 days after closure, except invoices and tax records, which we keep as long as the law requires.

2. If you are a guest booking a tour

The operator whose site you booked on is the controller of your booking data; Goiaba processes it on their behalf as a processor. Their own privacy notice applies. In short:

  • What is collected: the details on the booking form (name, email, phone, participants, pickup point, special requests, answers to the operator's questions), your booking and payment status, and the emails sent about your booking.
  • Payment: card payments are handled by Stripe, PayPal or Revolut on the operator's own account under their privacy policies. Goiaba never sees full card numbers.
  • Your rights: to see, correct or delete your data, contact the operator first; they can do it from their admin. If you cannot reach them, email us and we will help.

3. Cookies

Goiaba's own site and admin use only strictly necessary cookies: a session cookie to keep you logged in and a token that protects forms against forgery. We do not run advertising or tracking cookies. Operator websites show a cookie notice and may add their own analytics.

4. Who we share data with

Only service providers we need to run Goiaba, under contracts that bind them to protect it: hosting and backup providers, Stripe for our own billing and for operators' connected payments, PayPal and Revolut when an operator uses them, email delivery providers for transactional emails, and an error-monitoring service that receives technical logs. We share data with authorities only when the law requires it.

5. International transfers

Goiaba is operated by a company established in the United Kingdom. Personal data of people in the EU is transferred to the UK under the European Commission's adequacy decision for the United Kingdom. Where a provider processes data outside the UK and the European Economic Area (for example Stripe or the error-monitoring service), we rely on standard contractual clauses or an adequacy decision.

6. Security

Connections are encrypted (TLS), passwords are hashed, mail-server credentials are encrypted at rest, access to production is limited to the people who operate it, and we keep daily backups. No system is perfectly secure; if a breach affects you we will tell you and, where required, the supervisory authority.

7. Your rights

Under the UK GDPR and the EU GDPR you can ask for access to your data, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Write to [email protected]; we answer within one month. You can also complain to your national data-protection authority, or to the UK Information Commissioner's Office.

8. Changes

We post changes here and, for material changes affecting operators, email account owners in advance.

Contact

Wave Horizon Solutions Ltd (trading as Goiaba), company no. 15529395, 128 City Road, London, EC1V 2NX, United Kingdom. Email [email protected].