Skip to content
WanderwayNZ

Privacy policy

How we look after your information.

Last updated 24 September 2026. This policy is written to meet the New Zealand Privacy Act 2020 and, for visitors from the EU and UK, the GDPR.

Who we are

Wanderway NZ Limited (company number 9452797, NZBN 9429053898180), trading as Wanderway NZ, 21 Bickerton Rise, Churton Park, Wellington 6037, New Zealand. We are the agency that collects and holds the information described here. Questions or requests: [email protected].

What we collect, and why

  • Enquiries. Name, email, phone, country, travel dates, group size and anything you write in the message — so we can reply and plan a trip. Legal basis: taking steps at your request before a contract.
  • Trip files. Once you book: passport details and scans, dates of birth, contact and emergency details, dietary and medical needs relevant to activities, insurance details, room preferences, flight details. Suppliers (hotels, operators, transport) need some of this to confirm your bookings. Legal basis: performing the contract; for health-related details, your explicit consent.
  • Payments. Invoices and receipts record who paid what and when. We do not take card details on this website; payments are by bank transfer.
  • Website analytics. Page views with an anonymised visitor code (a hash of your IP address and browser that changes monthly), the country your connection comes from, and the site or advert that referred you. No cookies, no third-party trackers, and nothing that identifies you.
  • Sign-in and security. Sign-in links, session records and, for staff, two-factor codes; audit logs of who opened or changed what.

Who we share it with

  • Travel suppliers in New Zealand — only what each booking needs (names as per passport, dates, ages, dietary or access needs).
  • Service providers that host our systems and send our email. Our servers are in a data centre operated by our hosting provider; email is delivered through our email provider. Each acts on our instructions.
  • Authorities if the law requires it.

We never sell personal information and we do not use it for advertising.

Overseas transfers

Because our travellers are outside New Zealand, your information is sent between your country and New Zealand when you contact us and when suppliers here confirm bookings. Where our providers store data outside New Zealand, we choose providers that offer protections comparable to New Zealand law.

How we protect it

  • Passports and other uploaded documents are encrypted on our servers with a key kept separately from the database.
  • Access is limited to staff who need it, protected by two-factor authentication, and every access is logged.
  • Connections to this site are encrypted (HTTPS).

How long we keep it

  • Uploaded documents are deleted automatically 12 months after your trip ends (you are told the date, and can ask for earlier deletion).
  • Enquiry and booking records are kept for 7 years to meet New Zealand tax and accounting requirements.
  • Analytics rows are deleted after 400 days.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete what we are not legally required to keep. Email [email protected]; we respond within 20 working days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner (privacy.org.nz). EU and UK residents also have the rights set out in the GDPR, including the right to complain to your local supervisory authority.

Cookies

The public website sets no tracking cookies. Signing in to a trip file or the staff console sets a session cookie that is needed to keep you signed in. Your browser may store your theme choice and saved items locally; that never leaves your device.

Changes

If this policy changes materially we will note the new date here and, for travellers with an open trip file, tell you by email.

Booking terms and conditions →