Privacy Policy
Last updated 8 September 2026
The short version
WhereWise exists to tell you whether you are meeting your own office attendance policy. It is a personal tool, not a reporting line. Everything below follows from that.
Your location is never shared with your employer, your manager, or anyone else. There is no employer dashboard, no manager view, and no way for an organisation to be given access to your account. This is a design decision, not a setting.
Who is responsible for your data
WhereWise is operated by Preston Dale Ferguson as an individual. For any question about your data, or to exercise any right described here, email preston.ferguson@icloud.com.
What is collected
Account details. Your email address and a hashed, salted version of your password — the password itself is never stored and cannot be recovered, only reset. Optionally a display name and your timezone. The timezone is not decoration: attendance is counted in calendar days, and without it the wrong days get counted.
Your office areas. The coordinates and radius of the places you choose to count as “the office”. You place these yourself.
Attendance records. The times you arrived at and left one of your office areas, and days you marked by hand as attended, planned, PTO, working from home, or a holiday.
Phone status. If you use the mobile app, it reports whether it has background location permission and how many office areas it is watching, so the site can warn you when automatic tracking has quietly stopped.
Password reset and confirmation links. When you ask to reset your password or confirm your address, a random token is emailed to you and only its hash is stored — the link itself is never kept, so a copy of the database could not be used to take an account. Reset links last 30 minutes, work once, and are destroyed when used.
Failed sign-in attempts. To limit password guessing, failed sign-ins are counted against your email address and against the requesting IP address for fifteen minutes, then deleted. A successful sign-in erases them immediately.
What is not collected
No trail of your location is stored — not for a day, not for an hour. Ever.
When your phone reports a position, the server compares it to your office areas, decides whether you have arrived or left, and writes down only that: an arrival time, and later a departure time. The coordinates themselves are discarded in the same request. They are never written to the database and never logged. The only coordinates stored anywhere are the office areas you placed yourself.
This means WhereWise cannot show you where you were last Tuesday afternoon, and that is deliberate. Nobody needs to know where you are between the office and home — only whether you arrived.
There is also no analytics, no advertising, no tracking pixels, no behavioural profiling, and no third-party marketing scripts of any kind. Your data is not sold, rented, or shared for anyone else’s commercial purposes, and it never will be.
Cookies
WhereWise sets exactly one cookie: a session cookie that keeps you signed in. It contains a random token and nothing else — no personal details are stored in it. It is marked httpOnly so page scripts cannot read it, and sameSite=lax so it is not sent from other sites. Signing out deletes it, and it expires on its own.
There is no cookie consent banner on this site, and that is not an oversight. Under the ePrivacy rules, consent is required for cookies that are not strictly necessary — analytics, advertising, tracking. A cookie that exists solely to keep you signed in is exempt. Since WhereWise sets no other cookies, there is nothing to ask you to consent to, and a banner would be a box to dismiss rather than a choice to make. If that ever changes, you will be asked properly before anything is set.
Who else your data touches
Running a website means other companies are involved. These are all of them:
Vercel hosts the site and Neon hosts the database. Both process your data on WhereWise’s behalf in order to run the service. Their servers are located in the United States.
Fonts. None. The typefaces this site uses are served from its own domain. They were previously loaded from Google’s servers, which disclosed your IP address to Google on every page load — including on this one. They are now self-hosted, so that request no longer happens at all.
OpenStreetMap. When you view the map to place an office area, map tiles are requested from OpenStreetMap’s servers. Those requests disclose your IP address and, by which tiles are requested, the approximate area you are looking at. A map cannot work without a tile server, so this one is disclosed rather than removed.
Resend. Sends the emails the service needs to send you — password reset links and address confirmation. Your email address and the contents of those messages pass through Resend to deliver them. Nothing is sent to you for marketing, and your address is not added to any mailing list.
Sentry. The mobile app sends crash and error reports so failures can be found and fixed. Reports are configured to strip IP addresses and to drop any diagnostic data containing coordinates, so location does not travel inside an error report.
How long it is kept
Account details, office areas and attendance records are kept for as long as your account exists, because they are the thing the service is for — an attendance history that is deleted is an attendance history that cannot answer the question you came with.
Sessions expire on their own. Failed sign-in records are deleted within a day. Delete your account and everything belonging to it is removed from the database.
Your rights
You can ask for a copy of everything held about you, ask for anything inaccurate to be corrected, or ask for your account and all its data to be deleted. Depending on where you live, you may also have rights to restrict or object to processing, and to complain to a data protection authority.
Two of those you can do yourself, immediately, without asking anyone. Under Settings → Your data you can download everything held about you as a JSON file, and permanently delete your account and all of its records. Deletion is immediate and cannot be undone — there is no backup to restore from, which is the honest consequence of not keeping copies of your history.
For anything else — a correction, a restriction, a question about what a field means — email preston.ferguson@icloud.com.
Security
Passwords are hashed and salted. Traffic is encrypted in transit. Sign-in endpoints are rate limited against password guessing. Session tokens are random, expire, and can be revoked by signing out.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If you find a vulnerability in WhereWise, please report it to the address above rather than disclosing it publicly, and it will be taken seriously.
Children
WhereWise is a workplace tool and is not intended for anyone under 16. Accounts are not knowingly created for children, and any such account found will be deleted.
Changes to this policy
If this policy changes in a way that materially affects what is collected or who it is shared with, you will be told before the change takes effect — not by a silently updated date at the top of a page.