Draft: not yet reviewed by a lawyer. Details in [brackets] still need to be filled in.
Privacy Policy
Effective [effective date] · Version 2026-09-29
This policy explains what We Were Here collects, what’s shown publicly, and the choices you have. [operator’s legal name] ([postal address], [contact email]) is responsible for your data (the “controller”).
The short version: we keep your email to run your account, we don’t keep your name or photo from Google, and we don’t store your birth date. Your signature shows your country, not your location. City, age, message and photos are hidden unless you turn them on. We don’t sell data, show ads, or use tracking cookies.
What we collect
| Data | Details |
|---|---|
| Account | Your email address and your Google account ID, received when you sign in with Google. Google also sends your name and profile photo; we delete those automatically and don’t keep them. |
| Age check | You enter your birth month and year and whether you live in the EU, EEA or UK. We use these only to check the minimum age and don’t store them. We store that you passed, when, and which minimum applied (13 or 16). |
| Your signature | Signature text, display name, style, and optionally a one-line message and a birth year (used only to show your age, if you choose). |
| Location | The area you choose (country, and optionally region or city) and a random point inside it where your signature is placed. We never ask for or record your actual location. If you pick a city, its name is stored but only shown if you turn on “Show my city”. |
| Photos (Plus and Premium) | Up to 3 photos. Before storing them we remove all embedded metadata (including GPS location, camera details and timestamps) and re-compress them. They’re kept in private storage and shown only if you turn on “Show my photos”, blurred until a visitor clicks them. |
| Payments | Stripe handles your card details; we never see or store them. We store the tier, amount, payment status and Stripe reference numbers, plus the time you gave the checkout consent and which version of our terms applied. We share your email with Stripe so it can send your receipt. |
| Reports | If you report a signature, we store the reason, any note you add, and your account, to review it and prevent abuse. Reports aren’t public. |
| Technical data | Our hosting and database providers keep standard server logs (such as IP address, browser type and request times) for security and troubleshooting. [Confirm log retention with your hosting provider.] |
What’s public
- Always: your signature text and style, display name, country, signing number, and the (randomized) point on the globe.
- Only if you turn them on: your city, your age (not your birth year), your message, and your photos.
- In private mode, visitors see only your display name, whatever else is on.
- Never: your email, your account ID, your payment details, or anything from the age check.
You can change these settings at any time from your signature’s page. The number of people online is counted anonymously (see “Cookies and local storage”).
Why we use your data
- To provide what you bought (your account, placing and showing your signature, taking payment): necessary for our contract with you.
- To keep the site safe (age check, offensive-language filter, reports, removing violations, preventing payment fraud): our legitimate interest, and our legal obligations toward young people.
- To meet legal obligations, such as keeping payment and tax records.
Who we share it with
We don’t sell your data or share it for advertising. We use these service providers:
- Supabase: database, sign-in, photo storage and live updates. Data is stored in the United States.
- Stripe: payments and fraud prevention.
- Google: sign-in.
- [hosting provider, e.g. Vercel]: website hosting.
- Vercel Speed Insights: measures how fast pages load (for example load times, the page visited, and general device and browser type) so we can keep the site quick. It uses no cookies and isn’t linked to your account.
Because these providers store data in the United States, data about people in the EU, EEA or UK is transferred there, under the European Commission’s Standard Contractual Clauses (and the UK equivalent) or another lawful transfer mechanism.
How long we keep it
- Signatures stay forever unless you request removal. On your signature’s page, “Remove my info” deletes your city, birth year, message and photos straight away while keeping the signature, and “Delete my signature” removes the signature and everything attached to it.
- Your account is kept until you delete it from your Account page (or ask us to). That deletes your email address, all your signatures and photos, and reports you’ve filed, straight away.
- Payment records (tier, amount, date, Stripe reference numbers, and your checkout consent) are kept for [7] years, or as long as tax law requires, even after you delete your signature or account. When you delete your account they’re no longer linked to you, and the signature text saved with them is erased. Stripe keeps its own records of your payment, including your email address, under its privacy policy.
- Reports are kept for [2] years after they’re resolved.
Your rights
Depending on where you live (including under the GDPR and UK GDPR), you can ask to access, correct, delete or export your data, or to restrict or object to how we use it. You can delete your signatures and your account yourself at any time from the site. For anything else, email [contact email] from the address you sign in with. We’ll reply within one month. You can also complain to your local data protection authority. We don’t sell or “share” personal data as defined by US state privacy laws.
Children
We Were Here is not for children under 13, or under 16 in the EU, EEA or UK. If we learn that someone younger has signed up, we delete their account and signatures. Parents can contact us at [contact email].
Cookies and local storage
We only use what the site needs to work. There are no analytics or advertising cookies, and page speed measurement (Vercel Speed Insights) works without cookies.
| Name | Purpose | Lasts |
|---|---|---|
| sb-…-auth-token | Keeps you signed in (set by Supabase). | Until you sign out |
| ww_theme | Remembers dark or light mode. | 1 year |
| ww_age_blocked | Set only if the age check isn’t passed, to prevent immediate retries. | 24 hours |
| ww_presence_key (local storage) | A random ID used to count people online. It isn’t linked to your account. | Until cleared |
Stripe’s checkout page sets its own cookies, covered by Stripe’s privacy policy.
Security
Data is sent over HTTPS. Database access is restricted so people can only read public signature details and change their own. Photos are stored privately and served through short-lived links.
Changes
We’ll post updates here with a new version and effective date, and announce significant changes on the site. See also our Terms of Service.