Privacy Policy – Werr
Welcome to Werr, the short-form video guide that lets travellers swipe through local clips and book hotels, restaurants, and experiences in seconds.
This Privacy Policy explains:
- What personal data we collect
- How we use it
- Who we share it with
- Your choices and rights
If any capitalized term is not defined here, it has the meaning given in our [Terms of Service].
1. Definitions
- Personal Information: Any data that identifies or can reasonably be linked to a living individual.
- Creators: Users who upload or license videos via Werr Pro.
- Travelers / Audience: Users who browse or book through the Werr app or on werr.app.
- Partners: Hotels, restaurants, affiliate networks (e.g., Booking.com), channel managers, and third-party service providers.
- Services: Our websites, mobile apps, APIs, widgets, and any other related products.
2. What We Collect & Why
(Includes lawful basis under GDPR and other regulations)
We collect personal information to:
- Provide and improve our services
- Enable bookings and transactions
- Support creator payouts
- Monitor performance and security
- Conduct marketing (only if you opt in)
3. How We Collect Your Data
We collect information:
- Directly from you: When you sign up, upload content, contact support, or enter promotions.
- Automatically: Through cookies, SDKs, and server logs when you use the app or website.
- From social media: If you connect TikTok or Instagram, we may access your public profile and authorized embed IDs.
- From partners: Such as anonymized booking confirmations from affiliate networks or payout status from payment processors.
4. How We Use Your Information
We use your data to:
- Operate Werr: Stream videos, preload content, recommend experiences.
- Facilitate bookings: Generate affiliate deep links, show pricing, and autofill booking forms.
- Pay creators: Calculate commissions and process payouts via Stripe Connect.
- Conduct analytics: Monitor trends, conversions, and platform performance.
- Run marketing (optional): Send newsletters, push notifications, and serve lookalike ads on TikTok or Meta (only with consent).
- Ensure security & compliance: Detect fraud, process DMCA takedowns, and fulfill regulatory duties.
Note: We never use sensitive demographic data for ad targeting unless you make it public in your profile.
5. Cookies & Similar Technologies
We use:
- Essential cookies: For login, fraud prevention, and session continuity
- Analytics pixels: Including Firebase, TikTok Events API, and Google Analytics 4
- Advertising tags: Only with your consent
You can manage your preferences anytime via the “Cookie Settings” link in our footer. We honor Global Privacy Control (GPC) signals.
6. When We Share Data
We do not sell your personal data for money.
We may share it with trusted partners for:
- Booking fulfillment
- Payment processing
- Analytics and product improvement
- Security and legal compliance
7. International Data Transfers
- Our servers are hosted in AWS eu-west-1 (Ireland) and us-east-1 (Virginia).
- For EU/UK residents, we rely on Standard Contractual Clauses (SCCs) and ISO 27001-certified vendors.
- For U.S. residents, see Section 10 for details per CCPA/CPRA and other state laws.
8. Your Rights
Depending on your country or state, you may have the right to:
- Access or correct your data
- Delete your account
- Object to certain processing
- Withdraw consent
- File a complaint with a regulator
We aim to respond within 30 days or as required by law.
9. Security Measures
We take data security seriously:
- Encryption: HTTPS in transit; AES-256 at rest
- Access control: Role-based IAM with regular audits
- Bug bounty: Coordinated disclosure via HackerOne; see
security.txt
No system is 100% secure — please use a strong, unique password and keep your device updated.
10. Regional Notices
California (CCPA/CPRA)
We may disclose identifiers, internet activity, geolocation, and inferences for business purposes under Cal. Civ. Code §1798.140(v).
We do not sell personal data for money, but some analytics or advertising activities may qualify as “sharing.”
You can opt out using the “Do Not Sell or Share My Info” link.
EEA / UK / Switzerland
Our GDPR representative is PrivacyWorks GmbH, Germany.
Complaints may be directed to your local DPA or the Irish Data Protection Commission.
Brazil (LGPD)
Legal bases include:
- Article 7(I): Consent
- Article 7(V): Contract
Regulator: ANPD (Autoridade Nacional de Proteção de Dados)
(Add UAE, KSA, or other regions if applicable)
11. Data Retention
- Account data: Retained until deletion + 90 days
- Booking & commission records: Retained for 7 years (for tax purposes)
- Analytics data: Retained for 24 months, then aggregated
- Uploaded videos: Stored for the license period or until you revoke it
12. Children’s Privacy
Werr is not intended for users under:
- 13 years old (global)
- 16 years old (EEA)
We delete any underage accounts we identify.
13. Changes to This Policy
We will:
- Update the “Last updated” date, and
- Notify users by email or in-app 30 days before material changes take effect.
14. Contact Us
Werr Ltd.
Attn: Privacy Team
140 Fenchurch St, London, EC3M 6BL, United Kingdom
📧 hello@werr.app