WayBurb Privacy Policy
Effective date: 23 September 2026
Last updated: 27 September 2026
1. About this Privacy Policy
This Privacy Policy explains how WayBurb collects, uses, stores, discloses and protects personal information when you use the WayBurb mobile application, the website at wayburb.com (https://wayburb.com), and related support, account, map, subscription, advertising and social services (together, the Services).
WayBurb is operated in Australia by Jaxon Adrian Stone, an individual and sole trader trading as WayBurb, ABN 54 788 904 455, based in Queensland 4510, Australia (WayBurb, we, us or our).
This policy describes our practices under applicable privacy requirements, including the Australian Privacy Act 1988 and Australian Privacy Principles where applicable, New Zealand's Privacy Act 2020, and Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486).
By using the Services, you acknowledge that you have read this Privacy Policy. Where consent is legally required, such as before accessing device location or photos or for certain advertising uses, we ask for it separately.
2. Who may use WayBurb
WayBurb is intended only for people aged 16 years or older. You must not create or use a WayBurb account if you are under 16.
We do not currently collect a date of birth solely to verify every user's age. If we reasonably learn that an account belongs to someone under 16, we may suspend or delete the account and take reasonable steps to remove the associated personal information. A parent, guardian or other person may report a potentially underage account by emailing support@wayburb.com.
We will not assume a person's age solely from an email address, username or another unreliable indicator.
3. Information we collect
The information we collect depends on the features you use.
3.1 Account and authentication information
We may collect and hold:
- your email address;
- your Firebase user identifier and other internal account identifiers;
- authentication status, account creation date, last sign-in information and email-verification status;
- an identifier and, if you choose to provide them through the provider, a name or email address supplied through Sign in with Apple or Google Sign-In; and
- security information used to authenticate your account and prevent unauthorised access.
Passwords and third-party sign-in credentials are handled by Firebase Authentication, Apple or Google as applicable. WayBurb does not receive your Apple or Google account password.
3.2 Profile and user-generated content
We may collect:
- your display name or username;
- a profile image you upload;
- place photos and comments you submit;
- profile customisations, badges, flairs, colours, borders and gradients;
- your profile and discovery-sharing preferences;
- content you submit through feedback, reports, support forms or other interactive features; and
- automated and human moderation results and limited records needed to review or enforce content and safety rules.
Do not use a display name, image, comment or other submission that reveals sensitive or unnecessary personal information about you or another person.
3.3 Location, map and discovery information
Location is central to WayBurb's suburb-discovery features. If you grant location permission and actively use a location-based feature, we may process:
- your device's precise latitude and longitude at the time of a discovery, photo submission or location refresh;
- location accuracy and related information supplied by the operating system;
- an address, place label, postcode, suburb, district, state, region or country derived from your location;
- an official geographic boundary code and boundary type, such as an Australian suburb or locality, a New Zealand Statistical Area 2, or a Hong Kong Tertiary Planning Unit;
- the date and time of a discovery;
- an official suburb or boundary centre point;
- your discovery and missing-discovery request history; and
- rewards, XP, streak, rank or Passport bonus information associated with a discovery.
For a successful discovery, WayBurb uses the precise coordinate to identify and verify the official geographic boundary. After the backend boundary and land-XP process succeeds, WayBurb is designed to replace the precise coordinate stored in the relevant discovery record with an official boundary centre or another representative boundary point. WayBurb may retain the suburb or district name, derived address or place label, postcode, country, boundary identity, representative point and discovery time.
If processing is interrupted, fails or has not yet completed, a precise coordinate may remain temporarily until the process is retried or the record is sanitised or deleted. Some older discovery records may also require migration. We take reasonable steps to minimise this retention.
When you submit a place photo, a current upload coordinate may be held briefly as unverified context for automated review. It is not treated as proof of where the photo was taken and is deleted after assessment or expiry.
When you ask WayBurb to restore a missed discovery, we may compare the requested suburb and estimated date with nearby entries in your discovery history. A limited summary may include surrounding suburb names, day and distance differences, discovery counts and an evidence score.
WayBurb may send a coordinate to operating-system geocoding services and official Australian, New Zealand or Hong Kong geospatial services to determine the correct address or boundary. Those providers may receive the coordinate and ordinary request information such as an IP address.
You can deny or withdraw location permission through your device settings. Without location access, core discovery and live-location map features may not function.
3.4 Social and visibility information
If you use WayBurb's social features, we may process:
- friend requests and friend relationships;
- the users who are permitted to see a discovery;
- social-feed records connected to your discoveries;
- your display name, profile image and selected profile customisations as presented to other users;
- your suburb or district discovery, rank, level, streak, discovery count and related progress information; and
- reports, blocks, moderation actions and other safety-related interactions.
When you first access the global discovery feature, WayBurb offers a choice about sharing discoveries globally. If global sharing is disabled, your discoveries are not intended to appear in the global discovery feed. Friends you add may still be able to see friend-visible discoveries. You can change global-sharing preferences in Settings.
The app may display an approximate relative time such as “Recently” instead of an exact time. This display choice does not delay publication and does not mean that the underlying system timestamp has been removed.
3.5 Gameplay and virtual-economy information
We may collect and generate information about your use of WayBurb features, including:
- XP, levels, ranks, coins, Pins, Star Shards, Energy and other virtual balances;
- streaks, rewards and reward-claim timestamps;
- shop rolls, rerolls, purchases, inventory, equipped items and wishlisted items;
- challenge, bonus-suburb and Progress activity; and
- entitlement information for paid features such as WayBurb Passport.
WayBurb virtual items and balances are app records and are not bank accounts or government-issued currency.
3.6 Purchase and subscription information
When you make or restore an in-app purchase or subscription, Apple, Google and RevenueCat may process information such as:
- an App User ID or anonymous purchase identifier;
- purchase receipts or Google purchase tokens;
- the product purchased, purchase and renewal dates, subscription status and entitlement status;
- transaction identifiers, storefront or transaction country, and limited device or technical information; and
- refund, cancellation, billing-issue or restore status.
WayBurb does not receive or store your full debit-card, credit-card or bank-account number. Payments are processed by the applicable app store or payment platform.
3.7 Advertising information
WayBurb may offer an optional rewarded advertisement that you choose to watch in exchange for an in-app reward. The Google Mobile Ads SDK and participating advertising providers may process:
- advertising or app-instance identifiers;
- IP address and approximate location derived from it;
- device, operating-system, app-version and language information;
- ad requests, impressions, interactions, reward events and diagnostic information; and
- consent and advertising-choice signals.
Advertising providers may use this information to deliver, limit, measure and prevent fraud involving ads and, where permitted by your settings and applicable consent, to personalise advertising. You can decline to watch a rewarded ad and continue using the rest of WayBurb. Where available, you can revisit advertising choices through Manage ad privacy choices on the Privacy Policy page.
3.8 Support, privacy and deletion requests
If you contact us or submit a Google Form, we may collect your email address, WayBurb account details, the contents of your request, attachments you choose to provide, and our correspondence with you. Please do not send passwords, payment-card numbers or unnecessary precise-location information in a support request.
Public in-app feedback: text submitted through the Report/Feedback form may be automatically published in WayBurb’s public GitHub issue tracker. The exported report includes the feedback text, Apple or Android/other platform, submission time and a report reference. Your account email and Firebase user ID are not automatically included in that export. However, personal information you type into the feedback can still become public; automated redaction is imperfect and is not a guarantee of anonymity. Anyone may read, index or copy public issues. For private account, safety or privacy matters, email support@wayburb.com instead. Account deletion does not automatically remove public GitHub issues or copies made by others. Contact support@wayburb.com if a report needs review or removal; third-party copies may remain outside our control. GitHub processes information under its privacy statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement.
3.9 Technical, notification and security information
WayBurb and its infrastructure providers may automatically process limited technical data needed to deliver, measure and secure the Services, such as:
- IP address;
- device type, operating system, app version, language and user-agent information;
- app-start, screen-rendering and network-performance measurements;
- request times, authentication events, security tokens, service logs and diagnostic information;
- a push-notification token, notification permission and delivery information if notifications are enabled; and
- information needed to detect abuse, fraud, outages or unauthorised access.
WayBurb currently uses Firebase Performance Monitoring for operational performance measurements. It does not currently use Firebase Analytics or Firebase Crashlytics. Advertising, mapping, hosting, authentication and app-store providers may collect their own operational, measurement and security data as described in this policy and their policies.
4. How we collect information
We collect information:
- directly from you when you register, edit your profile, upload or submit content, contact us, request a missing discovery or choose settings;
- from your device when you grant a permission or use a feature that requires location, photos, notifications, storage or network access;
- automatically when necessary to authenticate you, operate or measure a requested feature, deliver an ad, protect the Services or maintain virtual balances and progress;
- from other users when they add you, report content, or interact with a shared feature; and
- from service providers, app stores, advertising providers and official geographic-data services used to operate WayBurb.
5. Why we use information
We use personal information for purposes including to:
- register, authenticate and manage accounts;
- provide maps, identify official geographic boundaries and record or restore discoveries;
- calculate Progress, XP, ranks, streaks, rewards and virtual balances;
- operate profiles, friendships, sharing choices and social feeds;
- provide and verify purchases, subscriptions and Passport entitlements;
- review display names, profile images, place photos, comments and reports for safety and policy compliance;
- provide optional rewarded ads and verify reward events;
- answer support, privacy, access, correction and deletion requests;
- prevent fraud, cheating, harassment, abuse, unauthorised access and other misuse;
- investigate technical problems and maintain the security, performance and reliability of the Services;
- generate and maintain general suburb guides and other geographic content;
- enforce our Terms of Service and protect users, WayBurb and the public;
- comply with legal obligations and respond to valid legal requests; and
- improve existing features and design new features using aggregated or appropriately de-identified information where reasonably possible.
We will not use personal information for a materially unrelated purpose unless we have permission or are otherwise permitted or required by law.
6. Artificial intelligence and automated moderation
WayBurb uses automated services for limited moderation, restoration review and content-generation tasks:
- Display names: a proposed display name may be checked locally and sent to OpenAI's API for moderation. The result may approve the name, reject it or suggest a safe replacement.
- Profile images: the uploaded image bytes may be processed using Google Cloud Vision SafeSearch to assess categories such as adult, racy or violent content.
- Place photos: an uploaded place photo is sent to OpenAI for image-safety moderation and scene-plausibility review. The review may also receive the named suburb, state or region, boundary identifiers and, when still available, an optional unverified upload coordinate. The photo may be approved, rejected or held privately for review by an authorised human moderator.
- Comments: submitted comment text is sent to OpenAI for safety moderation before publication. A flagged comment, or one that cannot be checked, is not published.
- Missing discoveries: a limited structured summary of the requested suburb, estimated date and surrounding discovery history may be sent to OpenAI to recommend approval or denial. The summary does not include your email address or raw discovery coordinates. The result affects whether the requested discovery is restored.
- Suburb guides: general suburb names, state or region information, postcodes, boundary identifiers and other non-user-specific geographic information may be sent to OpenAI to generate visitor-guide content.
These checks can be imperfect. If you believe content or a missing-discovery request was incorrectly rejected or restricted, contact support@wayburb.com and request a review.
WayBurb does not use these AI systems to make decisions about employment, credit, insurance, housing, education, healthcare or similarly significant matters. OpenAI states that API inputs and outputs are not used to train its models by default unless its customer opts in. OpenAI may retain API abuse-monitoring logs containing customer content for up to 30 days by default, unless a longer period is required by law or reasonably necessary to prevent harm. OpenAI's Moderations endpoint is documented as having no abuse-monitoring or application-state retention. Provider practices remain subject to current settings, terms and legal requirements.
7. When information is visible to other users
Information may be disclosed to other users when you use social or sharing features. Depending on your settings and relationship with the viewer, this may include your display name, profile image, selected cosmetics, approved place photos or comments, rank, streak, discovery count, suburb or district discovery, approximate discovery time and other progress information.
Global discovery sharing is optional. Friend visibility is separate from global visibility. Review both your global-sharing setting and your friend list when deciding who may see discoveries.
Other users may take screenshots or otherwise copy information that was visible to them. WayBurb cannot control copies made outside the Services. Do not upload or share information that you do not want the relevant audience to see.
8. When we disclose information to service providers and others
We do not sell or rent personal information. We may disclose or make information available to:
- Google Firebase and Google Cloud for authentication, databases, Cloud Storage, backend functions, hosting, push notifications, operational security, performance monitoring and profile-image moderation;
- Google AdMob and participating advertising providers to request, deliver, limit, measure and protect optional rewarded ads and, where permitted, personalise them;
- Mapbox to display maps and location-related features. The SDK sends de-identified location and usage telemetry by default when the app causes it to be gathered. The clickable Mapbox attribution control on WayBurb maps provides Mapbox's telemetry opt-out;
- OpenAI for display-name and comment moderation, place-photo safety and plausibility review, missing-discovery review, and generation of general suburb-guide content;
- RevenueCat for purchase validation, subscription status and entitlement management;
- Apple for Sign in with Apple, app distribution, purchases, subscriptions and platform services;
- Google for Google Sign-In, Google Play distribution, purchases, native geocoding and related platform services;
- Google Forms and Google Sites when you use a WayBurb support, privacy or deletion form or view a hosted policy page;
- official government and open geospatial services in Australia, New Zealand and Hong Kong when WayBurb queries a coordinate or boundary identity to resolve a discovery;
- professional advisers or contractors who reasonably need access and are subject to confidentiality or privacy obligations;
- law-enforcement agencies, regulators, courts or other persons when disclosure is required or authorised by law, or reasonably necessary to protect safety, rights and security; and
- a successor or prospective successor in connection with a genuine sale, transfer, merger or restructure of WayBurb, subject to appropriate confidentiality and privacy protections.
WayBurb may promote the app through public social-media posts, including TikTok. WayBurb does not currently include a TikTok advertising or tracking SDK in the app. We will not intentionally feature identifiable private user content in WayBurb-controlled promotional material without permission. Content a user has independently made public may be reshared only in accordance with applicable law, platform rules and reasonable user expectations.
Third-party services may also process information for their own platform, security, legal, measurement, advertising or billing purposes under their privacy policies. Their practices may change independently of WayBurb.
Provider information is available at:
- Firebase Privacy and Security (https://firebase.google.com/support/privacy/)
- Google Privacy Policy (https://policies.google.com/privacy)
- Google advertising technologies (https://policies.google.com/technologies/ads)
- Mapbox Privacy Policy (https://www.mapbox.com/legal/privacy)
- OpenAI Privacy Policy (https://openai.com/policies/privacy-policy/)
- OpenAI API data controls (https://developers.openai.com/api/docs/guides/your-data)
- RevenueCat Privacy Policy (https://www.revenuecat.com/privacy-policy)
- Apple Privacy Policy (https://www.apple.com/legal/privacy/)
9. International storage and processing
WayBurb is operated from Australia, but providers may process or store information in Australia, the United States and other countries where they or their subprocessors operate. Firebase Authentication is operated from United States data centres, while other Firebase and Google Cloud services may use selected or global infrastructure. RevenueCat states that customer data is stored using Amazon Web Services infrastructure in the United States. OpenAI, Google, Mapbox, Apple and their subprocessors may process information in other countries according to their services, settings and terms.
Privacy protections in another country may differ from those in your home jurisdiction. Where reasonably available and required, we use provider terms, contractual protections, security measures and other safeguards intended to protect information disclosed overseas. For users in New Zealand, we take reasonable steps to use recipients subject to the New Zealand Privacy Act 2020, comparable safeguards, or another arrangement permitted by Information Privacy Principle 12. We do not rely on this Privacy Policy as blanket consent to an otherwise unlawful overseas disclosure.
10. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide an active account, maintain security, resolve disputes, comply with legal obligations and enforce agreements.
In general:
- account, profile, gameplay, discovery and social information may be retained while your account remains active;
- precise discovery coordinates are intended to be retained only long enough to resolve and verify the official boundary, after which the stored coordinate is replaced with a representative boundary point following successful processing;
- short-lived private location context associated with a place-photo review is deleted after assessment or expiry;
- moderation and security information may be retained for as long as reasonably needed to prevent repeated abuse, respond to an appeal or protect the Services;
- support and privacy-request records may be retained for a reasonable period to resolve the request and demonstrate that it was handled;
- transaction, ad-reward and subscription records may be retained for the period required for accounting, tax, fraud prevention, dispute and legal purposes; and
- de-identified or aggregated information that no longer reasonably identifies a person may be retained for research, statistics and service improvement.
After a verified account-deletion request, we will remove or de-identify associated personal information from active WayBurb systems within 30 days unless a longer period is required or permitted by law. This process includes user-owned Firestore records, profile images and user uploads in Cloud Storage, social-feed entries and discovery references, and RevenueCat customer information where appropriate. The Firebase Authentication account is deleted after the associated WayBurb data has been processed.
Provider backups, security logs and disaster-recovery copies may persist for a limited period before being overwritten or deleted. Firebase states that some authentication and installation data is removed from live and backup systems within 180 days after deletion is initiated.
WayBurb retains an anonymous completion receipt for a finished account deletion. We may also retain a minimal Firebase user-ID deletion marker and hashed or de-identified anti-fraud records to prevent a deleted account from being silently recreated, to stop repeat reward or purchase redemption, and to establish that a deletion or security action occurred. These records do not contain the deleted profile, email address, user content or location history and are restricted from ordinary use.
We may retain limited information where reasonably necessary to comply with law, complete financial records, resolve payment disputes, prevent fraud or abuse, enforce our agreements, protect safety, or establish or defend legal claims. Where possible, retained information will be restricted from ordinary use.
11. Security and privacy incidents
We take reasonable technical and organisational steps to protect personal information against loss, misuse, interference and unauthorised access, modification, disclosure or deletion. These measures may include authenticated access, database and storage rules, restricted administrative access, encrypted network connections, provider encryption at rest, secret management and review of access permissions.
No online service can guarantee absolute security. You are responsible for protecting access to your email account, device and WayBurb sign-in method and for notifying us if you suspect unauthorised access.
If a privacy or security incident is likely to cause serious harm or otherwise requires notification, we will investigate and notify affected individuals and relevant regulators as required by applicable law.
12. Your choices and rights
Depending on where you live, you may have rights to:
- know whether we hold personal information about you;
- request access to personal information we hold about you;
- request correction of inaccurate, incomplete, outdated or misleading information;
- withdraw a permission or consent where processing depends on it;
- change global-discovery sharing and other privacy settings;
- revisit available advertising choices;
- use Mapbox's telemetry opt-out through the clickable attribution control on a WayBurb map;
- request deletion of your account and associated personal information;
- object to or ask questions about a use or disclosure of your information; and
- make a privacy complaint without being treated unfairly for doing so.
You may update some profile and sharing information directly in the app. You can disable device-location, photo or notification permissions through your device settings, although doing so may disable related features. You can decline to watch an optional rewarded ad.
To request access, correction or another privacy action, email support@wayburb.com. We may ask for reasonable information to verify that you control the relevant account. We will respond within the timeframe required by applicable law and will explain any lawful reason why a request cannot be completed in full.
13. Account deletion
You can initiate account deletion:
1. in the WayBurb app by opening your Profile page and using the account-deletion option at the bottom of the page;
2. through WayBurb's published web account-deletion request form; or
3. by emailing support@wayburb.com if the in-app or web method is unavailable.
After receiving an in-app or web deletion request and verifying the account where necessary, WayBurb will complete the following steps within 30 days unless a longer period is required or permitted by law:
- delete or anonymise user-owned Firestore records;
- delete profile images and other user uploads from Cloud Storage;
- delete or anonymise social-feed entries and discovery references associated with the account;
- request removal of RevenueCat customer information where appropriate, subject to transaction records that RevenueCat, Apple, Google or WayBurb must retain for legal, accounting, fraud-prevention, refund or dispute purposes;
- delete the Firebase Authentication account after the associated data has been processed; and
- retain only the limited deletion, anti-fraud and legal records described in section 10.
These steps are subject to the limited retention grounds described in this policy. Information that other users copied outside WayBurb, or that was lawfully published to a third-party service at your direction, may remain outside our control.
Deleting your WayBurb account does not automatically cancel an Apple App Store or Google Play subscription. You must separately cancel an active subscription through the subscription settings of the store through which you purchased it. Deleting WayBurb or revoking Sign in with Apple or Google access does not necessarily cancel billing.
Account deletion is permanent once completed. Virtual currency, inventory, discoveries, streaks, ranks and other account progress cannot ordinarily be recovered afterward.
14. Complaints
If you believe WayBurb has mishandled your personal information, contact:
WayBurb Privacy Contact
Jaxon Adrian Stone, Sole Trader
ABN 54 788 904 455
Queensland 4510, Australia
support@wayburb.com
Fallback: wayburb@gmail.com
Please describe what happened, the account involved, what outcome you are seeking and any relevant dates. Do not send your password. We may request proof that you control the account. We will acknowledge and investigate the complaint and aim to provide a substantive response within 30 days, or within another period required by law.
If you are not satisfied, you may contact the regulator relevant to you:
- Australia: Office of the Australian Information Commissioner (https://www.oaic.gov.au/privacy/privacy-complaints)
- New Zealand: Office of the Privacy Commissioner (https://www.privacy.org.nz/your-rights/making-a-complaint/)
- Hong Kong: Office of the Privacy Commissioner for Personal Data (https://www.pcpd.org.hk/english/complaints/how_complaint/complaint/complaint.html)
15. External links and third-party platforms
WayBurb may link to websites, app stores, government data services or social-media platforms that we do not control. Their privacy practices are governed by their own policies. Review those policies before providing information directly to them.
16. Changes to this Privacy Policy
We may update this Privacy Policy when our features, providers, practices or legal obligations change. The latest version will be made available through wayburb.com (https://wayburb.com) or the app and will show its effective date.
If a change materially affects how we use or disclose personal information, we will provide reasonable notice through the app, website, email or another appropriate method. Where new consent is legally required, we will request it before the relevant processing begins.
17. Contact us
For privacy questions, access or correction requests, account-deletion assistance or complaints, contact:
WayBurb Privacy Contact
Jaxon Adrian Stone
ABN 54 788 904 455
Queensland 4510, Australia
support@wayburb.com
Fallback: wayburb@gmail.com
Website: wayburb.com (https://wayburb.com)