This policy explains how Wihemi Travel handles personal information. Wihemi Travel is software, and it is a product of Neat Ledger. This policy covers the Wihemi Travel website and platform only. It does not cover Neat Ledger's finance and accounting services, which are governed by a separate policy at neatledger.co.
Using our software does not make you a client of Neat Ledger's finance services, and nothing in this policy creates that relationship. The two are separate, and your data is not shared between them.
1. Two different relationships
Almost every privacy question about Wihemi Travel depends on which of these you are.
| If you are | Then |
|---|---|
| A website visitor You are reading wihemi.com or requesting a demo. |
We are the controller of the small amount of information you give us. We decide what to collect and why. |
| A platform customer Your agency uses the Wihemi Travel application. |
You are the controller of your bookings, clients, and payment records. We are the processor. We hold that data and process it on your instructions. It is yours. |
2. What we collect from website visitors
When you request a demo
The form asks for your first and last name, email address, job title, company name, phone number, what you would like help with, and any additional context you choose to write. You provide all of it voluntarily. We use it to contact you about a demo and about Wihemi Travel. We do not sell it and we do not add you to a marketing list you did not ask for.
Automatically, when you browse
Our hosting provider records standard server logs, including IP address, browser type, pages requested, and timestamps. These are used to operate and secure the site.
Analytics and advertising trackers
We may use the Meta Pixel and the LinkedIn Insight Tag to understand which pages people read and whether our advertising reaches the right audience. These tools set cookies and report activity to Meta and LinkedIn. If you would rather not be tracked, you can block these through your browser settings or an ad blocker, and the site will work normally.
Error monitoring
We use Sentry to record application errors. When something breaks, Sentry captures technical details about the failure. It may incidentally include an IP address or a user identifier. We use this only to fix problems.
3. What we hold on behalf of platform customers
When an agency uses Wihemi Travel, the application stores the records the agency enters. That typically includes:
- Booking records: reference numbers, dates, trip details, passenger names, destinations
- Client payments and refunds, including amounts, dates, and payment method descriptions
- Supplier costs, invoices, and payments
- Commission rates, margins, and balances
- Agency and agent contact details
- User accounts for the agency's own staff, and an audit log of who changed what and when
We call all of this Customer Data. It belongs to the agency. We do not own it, we do not sell it, and we do not use it to build products, train models, or market to anyone.
We never take custody of money. Wihemi Travel records payments; it does not process, hold, or transfer funds. We do not store full credit card numbers or bank account credentials.
Passenger and client information
Agencies record the names of their own travellers. If you are a traveller and want to know what an agency holds about you, contact the agency. They are the controller of that record. We will support them in responding to you.
4. What we never do
- We do not sell personal information, and we have never done so.
- We do not share Customer Data with other customers. Each company's data is isolated at the database level.
- We do not use Customer Data for advertising, or to train machine learning models.
- We do not access an agency's data except when they ask us to, when it is necessary to fix a fault or maintain security, or when the law requires it.
- We do not serve advertising on the platform.
5. Who processes data for us
We use a small number of service providers. Each is bound to protect the data they handle.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website hosting | United States |
| Railway | Application hosting and database | United States |
| Resend | Transactional email (activation, notifications) | United States |
| Sentry | Error monitoring | United States |
| Meta, LinkedIn | Website analytics and advertising measurement | United States |
| Search Console, fonts | United States |
We will update this list when it changes. If a customer requires notice of new sub-processors, tell us and we will arrange it.
6. Where your data is held
Wihemi Travel is operated from the United States, and Customer Data is stored on servers in the United States. If you use the platform from outside the US, you are sending your data to the US, and you consent to that by using it.
7. How we protect it
- Data is encrypted in transit. The database is encrypted at rest by our hosting provider.
- Each company's data is isolated, and that isolation is enforced by the database itself rather than only by the application.
- Accounts support two-factor authentication, and an agency owner can require it for every user.
- Repeated failed sign-ins lock an account. Security events are logged.
- Every modification, cancellation, and refund is recorded with the user who made it and when.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly and tell you what we know.
8. How long we keep it
- Demo requests: kept while we are in contact and for a reasonable period afterwards. Ask us to delete yours and we will.
- Customer Data: kept for as long as the agency's subscription is active. On termination, we make it available for export for thirty days, then delete it.
- Audit logs and security events: retained while the account is active, because their purpose is to be available later.
- Backups: deleted data may persist in backups for a limited period before being overwritten.
9. Your rights
Depending on where you live, you may have the right to know what personal information we hold, to obtain a copy, to correct it, to delete it, and to object to certain uses. California residents have these rights under the CCPA as amended by the CPRA, including the right not to be discriminated against for exercising them.
We have never sold personal information and we do not share it for cross-context behavioural advertising in the sense the CPRA defines, other than through the analytics and advertising tools described above, which you can block.
To exercise any right, email will.h@neatledger.co. We will verify who you are before we act, and we will respond within the time the law allows.
If your data sits inside an agency's Wihemi Travel account, your request belongs with that agency. We will help them answer it.
10. Children
Wihemi Travel is business software. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. An agency may record a minor's name as a passenger on a booking; that record belongs to the agency, and the agency is responsible for having a lawful basis to hold it.
11. Changes to this policy
We will update this page when our practices change, and we will move the "last updated" date. If a change is material, we will tell active customers by email rather than relying on you to notice.
12. Contact
Wihemi Travel, a product of Neat Ledger
Concord, California, United States
will.h@neatledger.co
See also our Terms of Service.