Waymorrow Community Governance

Privacy Policy

This policy explains how Wayfinder Systems collects, uses, stores, displays, and protects information associated with Waymorrow public experiences, verified accounts, and Community services.

Draft Status

Draft Policy — Not Production Effective

Privacy Policy version 1.0.0 remains a pre-release draft. It is provided for transparency and testing only and is not currently effective or enforced in production.

Final publication requires CEO review, legal review as appropriate, confirmation of production service-provider settings, an approved retention and deletion procedure, a confirmed effective date, and activation through the governed policy-version system.

1. Scope of This Policy

This Privacy Policy applies to Waymorrow websites, Waymorrow Accounts, Fellow Wayfinder profiles, Community participation, policy acceptance, and related services operated by Wayfinder Systems.

This draft describes the current Account and Community foundation. It does not yet describe subscription billing, paid-alpha entitlements, production analytics, or forum-content processing because those capabilities are not part of the reviewed implementation.

2. Information Managed Through Clerk

Wayfinder Systems uses Clerk to provide account registration, authentication, email verification, password management, session management, account recovery, and account-profile controls.

Depending on the information a member provides, Clerk may process:

  • Email address and email-verification status.
  • Username.
  • First and last name.
  • Profile image.
  • Password and authentication information.
  • Active login sessions and account-security information.
  • Account recovery information and security settings.

Passwords are managed through Clerk. The current Waymorrow Community database does not store a member’s password.

3. Information Stored by Wayfinder Systems

When a verified member opens the Account page, selected profile information is synchronized from Clerk into the Waymorrow Community database.

The current database stores:

  • A Clerk user identifier used to connect the two systems.
  • Public username or handle.
  • Public display name.
  • Profile-image URL.
  • Community role.
  • Account status.
  • Account creation and update timestamps.
  • Accepted policy type, version, and acceptance timestamp.

The verified email address is used by Clerk for identity and account management. It is not copied into the current Waymorrow Community profile table or returned by the current public-profile interface.

4. Public Profile Information

A Fellow Wayfinder profile is intended to provide a public Community identity without publicly displaying the member’s private email address.

The following information may be visible to other people:

  • Public handle.
  • Display name.
  • Profile image.
  • Community role.
  • Account status when operationally appropriate.
  • Membership date.
  • Future public topics, replies, and other Community contributions.

Members should not place private or sensitive information in their public handle, display name, profile image, or Community contributions.

5. Role Applications and Governance Records

When the role-application feature becomes available, Wayfinder Systems may collect:

  • The requested Moderator or Administrator role.
  • The applicant’s written statement.
  • Application status.
  • The reviewing member’s authorized account identifier.
  • Review notes and review timestamps.

These records support human review, accountability, permission control, and organizational governance.

6. Policy-Acceptance Records

When required policies are published, Wayfinder Systems records the member’s account identifier, the policy type, the accepted policy version, and the acceptance timestamp.

These records are used to determine whether the member may use governed interactive features and whether a new policy version must be reviewed and accepted.

7. Authentication Cookies and Session Information

Clerk uses cookies and related session technology that are necessary to register members, maintain authenticated sessions, secure accounts, and determine whether a request comes from a signed-in user.

The reviewed implementation does not include an advertising network, behavioral-advertising system, or optional analytics-cookie system. This disclosure must be revised before publication if those systems are later added.

8. How Information Is Used

Wayfinder Systems may use information to:

  • Create, authenticate, secure, and recover Waymorrow Accounts.
  • Create and maintain Fellow Wayfinder profiles.
  • Synchronize approved profile fields between Clerk and Waymorrow.
  • Display public Community identities.
  • Apply Community roles and account-status restrictions.
  • Record required policy acceptances.
  • Review future role applications and moderation matters.
  • Prevent impersonation, fraud, abuse, and unauthorized access.
  • Diagnose technical failures and protect service availability.
  • Comply with legal and organizational obligations.

9. Service Providers

Wayfinder Systems currently relies on service providers that process information to operate the Waymorrow Account and Community foundation.

  • Clerk: account registration, authentication, email verification, password management, sessions, account recovery, and profile controls.
  • Cloudflare: website delivery, serverless functions, request processing, and the Waymorrow Community database.

These providers process information under their own agreements, security practices, and privacy documentation.

10. Sale and Advertising Use

The current Waymorrow Account and Community implementation does not sell member personal information and does not use account information for behavioral advertising.

Wayfinder Systems must review and update this policy before introducing advertising technology, cross-context behavioral advertising, or a new information-sharing arrangement.

11. Paid Services and Payment Information

The reviewed implementation does not currently collect payment-card details or maintain subscription-billing records.

Before paid Waymorrow alpha access or another subscription is opened, this policy must be updated to identify the payment processor, the billing information processed, the subscription records retained by Wayfinder Systems, and the purposes for that processing.

Wayfinder Systems should not directly store complete payment-card numbers when payment processing can be handled by an authorized payment provider.

12. Data Retention

Account and profile records may be retained while an account remains active and for a reasonable period afterward when needed for account administration, security, dispute resolution, policy enforcement, legal obligations, or preservation of authorized governance records.

Policy-acceptance, moderation, security, and role-review records may need to be retained longer than ordinary profile information because they document organizational decisions and member authorization.

A final retention schedule has not yet been approved. Specific retention periods and deletion procedures must be documented before this policy is published.

13. Account Correction, Deactivation, and Deletion

Members can use Clerk’s account controls to review or update supported account information, including their name, username, profile image, password, and security settings.

A member may request account deactivation or deletion through the available account controls or the Waymorrow feedback page. Identity verification may be required before a request is completed.

The current development implementation does not yet include automatic Clerk-to-Waymorrow deletion propagation. That lifecycle must be completed and tested before production publication so that deleting an identity also produces the approved result in Community records.

Some information may be retained when reasonably required for legal compliance, security, fraud prevention, dispute resolution, or preservation of legitimate governance and moderation records.

14. Information Security

Wayfinder Systems uses authentication, server-side session verification, role restrictions, database constraints, and controlled service-provider access to reduce unauthorized access and misuse.

Secret authentication keys are intended to remain server-side. Public interfaces expose only the Clerk publishable key needed to initialize the account interface.

No technical or organizational system can guarantee absolute security. Wayfinder Systems will continue to assess risks, limit unnecessary collection, protect retained information, and establish incident and recovery procedures before production release.

15. Children’s Privacy

Waymorrow services are not directed to children under 13, and children under 13 may not create a Waymorrow Account.

If Wayfinder Systems learns that personal information was collected from a child under 13 without the legally required authorization, it will review the account and take appropriate steps consistent with applicable law.

16. Legal and Safety Disclosures

Wayfinder Systems may preserve or disclose information when reasonably necessary to comply with applicable law, respond to lawful process, investigate fraud or abuse, enforce governing policies, protect service security, or protect the rights and safety of users and others.

17. Privacy Rights and Choices

Depending on where a member lives and which laws apply, the member may have rights concerning access, correction, deletion, restriction, or other handling of personal information.

Requests may be submitted through the Waymorrow feedback page. Wayfinder Systems may need to verify the requester’s identity before providing information or changing account records.

18. Changes to This Privacy Policy

Material changes will be issued as a new policy version. When required, members must review and accept the new current version before using governed interactive features.

19. Contact

Privacy questions, requests, and concerns may be submitted through the Waymorrow feedback page.

Required Before Publication

Open Privacy Implementation Decisions

  • Approve a documented data-retention schedule.
  • Complete Clerk-to-Waymorrow deactivation and deletion handling.
  • Define data export and verified privacy-request procedures.
  • Confirm production Cloudflare and Clerk configurations.
  • Establish a production privacy and support contact channel.
  • Document security-incident response and member notification.
  • Update this policy before billing, analytics, advertising, forum storage, or additional service providers are introduced.