Trust & Privacy

Your data,
handled with care.

This page is maintained by the Waypoint Marketing team to answer common questions about how we handle your information, payments, and privacy on waypointmkt.group. It's editable site content, not an independent certification.

Last updated: July 2026

What we collect

Only what we need to do the work.

When you fill out a contact form, request a project, or check out, we collect the details you give us — typically your name, email, phone (optional), organization name, and any notes about your project.

When you purchase, our payments provider also processes your billing details. We never see or store full card numbers ourselves.

Standard server logs (timestamp, IP, user agent) are recorded for security and abuse prevention.

How we use it

To deliver, follow up, and improve.

We use your information to deliver the services you requested, respond to questions, send order receipts and product updates, and improve how the site works.

We don't sell your data. We don't share customer lists. Marketing emails are opt-in and every message includes a one-click unsubscribe.

Subprocessors

The vendors that help us run this.

We rely on a small set of trusted vendors. Each has their own security and privacy practices:

  • Cloud hosting and database for the site and backend.
  • Stripe for payments and subscription billing.
  • An email delivery provider for transactional and opt-in emails.
  • Privacy-respecting analytics to understand site traffic.

Access & authentication

Least access, by default.

Access to customer data is limited to the people at Waypoint who need it to do their job. Admin areas of the site require authentication. Customer-facing data tables are protected with row-level access controls so visitors only see what's intended to be public.

We don't use customer chat transcripts, marketing data, or unsolicited contact lists to train third-party AI models.

Payments

Card data never touches our servers.

Checkout runs through Stripe's hosted/embedded flow. We receive a confirmation and the metadata we need to fulfill your order — never full card numbers, CVCs, or full bank details. Stripe is PCI-DSS compliant; their certifications and policies are published on stripe.com.

Retention & deletion

Keep what's useful, delete what isn't.

We keep order and customer records for as long as needed to support you and to meet tax and accounting requirements. Inquiry leads and contact-form messages are kept while they're useful for follow-up, then archived or deleted.

You can ask us to access, correct, or delete the personal information we hold about you — see "Privacy requests" below.

Cookies & analytics

Simple, not creepy.

We use the cookies needed to keep you signed in and to remember your cart, plus lightweight analytics to understand which pages are useful. We don't run third-party ad-network tracking.

Privacy requests

It's your data — just ask.

To access, update, export, or delete the personal information we hold about you, or to unsubscribe from any communication, email us and we'll take care of it. Most requests are handled within a few business days.

For security questions, suspected vulnerabilities, or anything that feels off, please reach out using the contact page and we'll respond as quickly as we can.

Shared responsibility

What's on us, and what's on you.

We take care of the site, the backend, payment integration, and the handling of the data you send us. You're responsible for keeping your account credentials safe and for any content you provide to us (for example, photos or copy you upload for a project).

This page describes our current practices and may be updated as the product evolves. It's not a contract or a certification, and it doesn't claim compliance with any specific regulatory framework unless explicitly stated.

Find your pack