Legal

Privacy Policy

Version 1.1 — Last updated 3 June 2026

Wildara AS is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and what rights you have — in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

1. Data Controller

The data controller for personal data processed through the Wildara platform is:

Wildara AS
Norway
Email: personvern@wildara.no

If you have any questions about how we process your personal data, or if you wish to exercise your rights, please contact us at the address above.

2. Data We Collect

2.1 Account registration

When you create an account, we collect:

  • Full name
  • Email address
  • Password (stored as a secure hash — we never store your plaintext password)
  • Country of residence
  • Phone number (optional)
  • Profile photo (optional)

2.2 Booking and transactions

When you make or receive a booking, we collect:

  • Booking details: experience, dates, number of guests, price
  • Communication between Buyer and Provider through the in-platform messaging system

Wildara currently operates on a request-based booking flow. Online payment processing is not yet active. When payment functionality is introduced, payment card data will be handled exclusively by our payment provider; Wildara will not store full card numbers or CVV codes.

2.3 Compliance documents

Where required by law or requested by the Provider, we may ask you to upload compliance documents, including:

  • Norwegian hunting licence (jegeravgiftskortet)
  • Salmon fishing licence (fiskeravgift)
  • Firearms licence or other permits relevant to the experience

2.4 Provider information

If you register as a Provider, we additionally collect:

  • Company name and organisation number
  • Bank account details for payouts
  • Listing content: descriptions, photos, pricing, availability
  • Terms acceptance records, including timestamp, IP address, and browser user-agent

2.5 Usage data

We collect limited technical data to operate and improve the platform:

  • IP address (processed as a one-way hash for view counting; not stored in readable form)
  • Browser type and operating system (user-agent string)
  • Pages visited and time spent, via server-side logging

We do not use third-party advertising trackers or behavioural profiling cookies.

3. Purposes and Legal Basis

We process your personal data only for specified, explicit purposes and always on the basis of a lawful ground under GDPR Article 6.

PurposeData usedLegal basis
Creating and managing your accountName, email, passwordContract — Art. 6(1)(b)
Processing and fulfilling bookingsBooking details, payment info, messagesContract — Art. 6(1)(b)
Compliance verification (hunting/fishing permits)Compliance documentsLegal obligation — Art. 6(1)(c)
Accounting and tax reportingTransaction records, billing dataLegal obligation — Art. 6(1)(c)
Provider terms acceptance audit trailTimestamp, IP hash, user-agentLegal obligation — Art. 6(1)(c)
Customer support and dispute resolutionAccount data, booking data, messagesLegitimate interest — Art. 6(1)(f)
Platform security and fraud preventionUsage data, IP hashLegitimate interest — Art. 6(1)(f)
Transactional emails (booking confirmations, receipts)Email address, booking detailsContract — Art. 6(1)(b)

4. Data Retention

4.1 Booking and financial records

Booking data and associated financial records are retained for 5 yearsfrom the date of the transaction in order to satisfy Norwegian accounting obligations under the Bookkeeping Act (bokføringsloven). After this period they are securely deleted.

4.2 Compliance documents

Compliance documents uploaded by Buyers (hunting licences, fishing licences, etc.) are retained only for the duration of the relevant season and are securely deleted thereafter, unless a longer retention period is required by law.

4.3 Account data

Account data is retained for as long as your account is active. If you request deletion of your account, we will delete your personal data within 30 days, subject to any retention obligations described above.

4.4 Platform messages

Messages exchanged between Buyers and Providers through the platform are retained for the duration of the booking plus 12 months, to facilitate dispute resolution.

5. Data Processors and Third Parties

We use the following third-party data processors to operate the platform. Each has entered into a Data Processing Agreement (DPA) with Wildara and processes data only on our documented instructions.

5.1 Supabase

Role: Relational database hosting for all platform data.
Location: European Union (Frankfurt, Germany).
Data transferred: All structured personal data stored on the platform (accounts, bookings, messages, provider profiles).

5.2 Vercel

Role: Application hosting, content delivery, and image storage (Vercel Blob).
Location: European Union (primary region).
Data transferred: Server-side request logs including IP addresses (retained by Vercel per their own data retention policy); listing images uploaded by Providers.

5.3 Resend

Role: Transactional email delivery (booking confirmations, notifications, password resets).
Location: United States (subject to appropriate transfer safeguards — see §6).
Data transferred: Recipient email address, name, and booking details included in each email.

5.4 Upstash

Role: In-memory data store used for rate limiting and abuse prevention.
Location: European Union (EU region configured).
Data transferred: Hashed IP addresses, used to enforce request rate limits. No personal data is retained beyond the rate-limit window.

5.5 Google (OAuth)

Role: Optional sign-in via Google account.
Location: Global (Google LLC, subject to SCCs).
Data transferred: If you choose to sign in with Google, your name, email address, and profile picture are received from Google and stored in our database. Google’s own privacy policy governs how Google processes your data during authentication.

5.6 Payment processing

Online payment processing is not yet active on the platform. When payment functionality is introduced, this section will be updated to name the payment provider and the data they process on our behalf. Wildara will not store full card numbers or CVV codes.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

6. International Transfers

We process your data primarily within the European Economic Area (EEA). Where any transfer outside the EEA is required, it will be subject to appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Your Rights

Under GDPR, you have the following rights with respect to your personal data:

  • Right of access (Art. 15): You may request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): You may ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): You may request deletion of your personal data, subject to any legal retention obligations.
  • Right to restriction of processing (Art. 18): You may ask us to restrict how we use your data in certain circumstances.
  • Right to data portability (Art. 20): You may request your data in a structured, machine-readable format.
  • Right to object (Art. 21): You may object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at personvern@wildara.no. We will respond within 30 days. We may ask you to verify your identity before processing your request.

8. Cookies

Wildara uses only strictly necessary cookies required to operate the platform, including session authentication cookies. We do not use advertising cookies, tracking pixels, or third-party analytics scripts that process personal data.

9. Security

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include encrypted data transmission (TLS), hashed passwords, and role-based access controls. We review our security practices regularly.

10. Complaints

If you believe we are processing your personal data in breach of applicable law, you have the right to lodge a complaint with the Norwegian Data Protection Authority:

Datatilsynet
Website: datatilsynet.no
Phone: +47 22 39 69 00
Email: postkasse@datatilsynet.no

We encourage you to contact us first at personvern@wildara.no so that we have an opportunity to address your concern directly.

11. Changes to This Policy

We may update this Privacy Policy periodically. Where changes are material, we will notify registered users by email before the changes take effect. The date at the top of this page always reflects when the policy was last updated.

12. Contact

For all privacy-related enquiries:

Wildara AS
Email: personvern@wildara.no
Norway