Legal

Privacy Policy

Effective date: 14 August 2026 · Last updated: 14 August 2026

Go Wild Booking ("we", "our", or "us") respects your privacy and is committed to protecting personal data. This privacy policy explains how we collect, use, share, and safeguard information when you use our website at gowildbooking.com, our booking and management platform, and related services. Those services include operational customer notifications sent through the WhatsApp Business Platform (provided by Meta Platforms, Inc.).

This policy is intended to be clear enough for guests, business clients, and platform reviewers (including Meta / WhatsApp) to understand what data we handle, in which role, and why. Related documents: Terms of Service, Data Processing Agreement, and data deletion instructions.

1. Who we are and our role

Go Wild Booking is the trading name of Go Wild Booking Ltd (company number 16414166), which provides online booking and operations software for outdoor adventure and hire businesses, such as canoe hire, guided activities, and similar experiences.

Under UK GDPR we act in two different roles, depending on whose personal data is involved. That distinction matters: it determines who decides why the data is collected, and who you should contact to exercise your rights.

Where we are the data controller

We are the data controller only for personal data we collect for our own business purposes. That is:

  • Website visitors. Information collected on this marketing website (for example analytics data).
  • Business clients. The adventure or hire operators we sell the platform to. We keep their name, email address, and related account or support details so we can provide the service, bill them, and contact them.

Where we are the data processor

We are a data processor for personal data that guests and other end-customers provide in connection with a booking. That data is collected for the business client, not for Go Wild Booking.

The adventure or hire business the guest booked with is the data controller of that booking information. They decide what to collect and why. We host, store, and transmit it on their instructions solely so the booking platform can run — for example to hold a reservation, show it in the operator's diary, or send a confirmation.

We do not own End User booking data. We do not use it for our own marketing, advertising, profiling, or product promotion, and we do not sell it. We do not decide the purposes of that processing.

Business clients are responsible for giving their own customers a privacy notice — at checkout, before or when guest data is collected — and for having a lawful basis to collect and use that data. Our processing of End User data is governed by the Terms of Service and the Data Processing Agreement, which is the Article 28 UK GDPR contract between the operator (controller) and us (processor).

2. Information we collect

Business-client information (we are the controller)

When an operator enquires, registers, or uses the platform, we collect the information we need to run that commercial relationship. This typically includes:

  • Name and business name
  • Email address
  • Phone number, billing details, and account credentials, where provided
  • Records of our correspondence (for example support or onboarding emails)

We use this to create and administer the account, provide support, send service notices, and keep our own business records.

Guest booking information (we are the processor)

To run reservations for a business client we process booking details that the guest or the operator enters. That may include the activity or hire selected, date and time, party size, customer name, email address, phone number, and any notes needed to deliver the experience safely.

That information belongs to the booking relationship between the guest and the operator. We process it only to provide the platform to that operator. We do not use it as our own customer list.

Messaging data (we are the processor)

If a guest receives operational notifications (for example booking confirmations, schedule updates, or reminders), we process the contact details used to deliver those messages and related delivery metadata. This includes WhatsApp, as described in section 3. Those messages are sent on behalf of the business client.

Technical and usage data

When you use our website we automatically collect standard log and device data, such as IP address, browser type, operating system, pages visited, referring URL, and approximate timestamps. We are the controller of that marketing-site data.

When the booking platform is used, similar technical logs may be created so we can operate, secure, and troubleshoot the service. Where those logs relate to a guest booking, we treat them as processor data for the relevant business client. Where they relate to a business-client account, we treat them as controller data for security and service administration.

3. WhatsApp messaging data

We use the WhatsApp Business Platform (also known as the WhatsApp Business API / Cloud API), operated by Meta Platforms, Inc. and its affiliates ("Meta"), to send operational messages on behalf of our business clients. For this data we act as a processor; the business client is the controller.

What we collect and process

In connection with WhatsApp messaging we may process:

  • The guest's mobile phone number and, where provided by WhatsApp, related identifiers needed to route the message.
  • The guest's name and booking details included in a message (for example activity name, date, time, meeting point, or booking reference).
  • Message content we send, typically using approved WhatsApp message templates for confirmations, updates, and reminders.
  • Inbound replies a guest sends to a WhatsApp conversation, if the business uses our platform to receive them.
  • Delivery metadata, such as message status (sent, delivered, read, or failed), timestamps, and error codes returned by the WhatsApp Business Platform.

Why we use WhatsApp

We use this data solely to:

  • Deliver booking-related notifications requested by the adventure or hire business the guest booked with.
  • Confirm that messages were sent successfully and troubleshoot failures.
  • Comply with WhatsApp / Meta platform rules and applicable law.

We do not sell WhatsApp messaging data. We do not use WhatsApp contacts or message content to build our own marketing audiences, sell advertising, or contact people about Go Wild Booking products.

Opt-in

WhatsApp messages are sent only where the guest has provided a phone number in connection with a booking or enquiry and the business client has a legitimate operational reason to message them. Business clients are responsible for collecting a valid opt-in and for telling guests that they may receive booking updates on WhatsApp.

Opt-out and stopping messages

Guests can stop WhatsApp messages at any time by:

  • Replying with a standard opt-out keyword such as STOP, where supported; or
  • Asking the business they booked with to update or remove their contact number; or
  • Contacting us at [email protected] using the steps on our data deletion instructions page, and we will pass the request to the relevant business client (the controller) so it can be actioned.

Meta's role

To deliver WhatsApp messages we must share the relevant phone number and message content with Meta. Meta processes that information as the provider of the WhatsApp Business Platform, in accordance with Meta's terms and privacy notices. We do not control Meta's independent processing of WhatsApp service data.

4. How we use your information

Data we control

We use business-client and website-visitor personal data to:

  • Create and administer business-client accounts and provide customer support.
  • Contact business clients about their account, billing, onboarding, and the service.
  • Maintain platform security, prevent fraud and abuse, and troubleshoot technical issues.
  • Comply with legal, accounting, and tax obligations.
  • Understand how our public website is used, using aggregated or similarly limited analytics.

Data we process for business clients

We process guest booking, contact, and messaging data only to provide the booking platform to the relevant business client, including to:

  • Store and display reservations, schedules, and related operational records for that business.
  • Send operational notifications, confirmations, and service updates by email, SMS, or WhatsApp on that business's behalf.
  • Take or record payments through the business client's payment provider, where they use that feature.
  • Help the business client meet a guest's data-protection request, when they ask us to assist.

We do not use guest personal data to market Go Wild Booking, to build independent profiles of guests, or for any purpose of our own.

6. Data sharing and third-party services

We do not sell personal data. We share information only with trusted service providers who help us operate the platform, and only as needed to deliver our services.

Where we are the controller (business-client and website data), those providers act as our processors. Where we are the processor (guest booking and messaging data), those providers act as our subprocessors on behalf of the business client.

Typical categories include:

  • Secure cloud hosting and infrastructure providers.
  • Communications providers, including Meta / WhatsApp for message delivery and email or SMS delivery services.
  • Payment processors, where a business client takes payment through the platform. Guest card payments are taken through the business client's payment provider, not as Go Wild Booking's own sales.
  • Analytics providers used on this website (see cookies below).

These providers are permitted to use personal data only to perform services for us (or, for guest data, for the relevant business client), under appropriate contractual protections. We may also disclose information if required by law, to protect our rights or users, or in connection with a genuine business transfer (for example a merger), in which case we will take reasonable steps to keep the data protected.

7. Cookies and analytics

Our public website uses Google Analytics to understand traffic and improve the site. Google Analytics may set cookies or similar technologies and collect technical information such as IP address, device/browser details, and pages visited. Google processes this information in accordance with its own privacy policy. We are the controller of this marketing-site analytics data.

You can control cookies through your browser settings and, where available, Google's analytics opt-out tools. Disabling cookies may affect some site functionality.

8. International transfers

Some of our service providers, including Meta (WhatsApp) and Google, may process data outside the United Kingdom or European Economic Area. Where we transfer personal data internationally, we use appropriate safeguards recognised by applicable law, such as standard contractual clauses or an equivalent transfer mechanism, together with any supplementary measures that are reasonably required.

9. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. That applies both to data we control and to guest data we process for business clients. No method of transmission or storage is completely secure, but we work to reduce risk through access controls, encryption in transit where appropriate, and least-privilege access to production systems.

10. Data retention

Business-client and website data

We keep personal data we control only for as long as needed for the purposes in this policy, including providing the service, resolving disputes, enforcing agreements, and meeting legal, tax, and accounting requirements.

Guest booking and messaging data

Booking and messaging records are retained for the period the business client needs them to run their operation and meet their own legal duties, as set out in our contract with them. When they close their account, or when they instruct us to delete guest data, we delete or anonymise it after any short grace period needed to unwind the service, unless we must keep a limited copy to meet a legal obligation (for example tax or to defend a claim).

Website analytics data is kept in identifiable form only for a limited period.

11. Your rights

Depending on your location, you may have the right to access, correct, delete, or restrict use of your personal data, to object to certain processing, to withdraw consent, and to receive a copy of data you provided in a portable format. You may also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO).

To ask us to delete personal data, including WhatsApp / Meta platform data, follow the steps on our data deletion instructions page. In short: email [email protected] with the subject line "Data deletion request".

  • Guests who booked an activity or hire. The business you booked with is the data controller. To update or delete booking data, contact them first. You can also email [email protected] and we will help the relevant business client action a valid request. We cannot treat guest booking data as our own, and we will not use it except as their processor.
  • Business clients and website visitors. We are the controller of your account, contact, and website data. Contact [email protected] to exercise your rights.

We may need to verify your identity before fulfilling a request, and some rights are subject to legal exceptions (for example where we must keep a record). For guest data, we may need to refer the request to the business client so they can confirm it and instruct us.

12. Children

Our platform is designed for business operators and adult customers making bookings. We do not knowingly collect personal data directly from children as a controller.

A booking held for a business client may include a child's name or age if an adult provides it as part of a reservation. In that case we process it only as the operator's processor. Parents or guardians who believe a child's data has been collected in error should contact the business they booked with, or contact us and we will help that business delete it where they instruct us to do so.

13. Changes to this policy

We may update this privacy policy from time to time. The current version will always be posted on this page with an updated effective date. If we make a material change, we will take additional steps that are reasonable in the circumstances, such as a notice on our website or an email to business clients.

14. Contact us

If you have questions about this privacy policy, our data practices, or WhatsApp messaging sent through our platform, please contact us:

Go Wild Booking Ltd
Company number 16414166
Registered office: Orchard Bank, Bishopswood, Ross-On-Wye, United Kingdom, HR9 5QX
Not registered for VAT.
Privacy: [email protected]
Cancellations: [email protected]
General: [email protected]
Website: https://gowildbooking.com

If you are a guest asking about a specific booking, please also contact the operator you booked with. They are the controller of that data.