Sign in

Where

Privacy Notice

Version 2 October 2026

EnglishNorsk

This notice explains how Where uses personal data. It is information we owe you under the GDPR and the Norwegian Personal Data Act (personopplysningsloven). It is not a contract, and it is not a request that you consent to every use described here. The English text is the reference text. If you live in Norway, you may rely on the Norwegian text.

  1. Who is responsible
  2. What we use
  3. Why we use it
  4. Who receives it
  5. Transfers out of the EEA
  6. How long we keep it
  7. Your rights
  8. Children
  9. Cookies
  10. Changes to this notice
  11. Contact

Who is responsible

Where is offered at https://where.ltd by the operator of that site, established in Norway. Email: [email protected]. The registered name, organisation number, and postal address belong in this section under the Norwegian Electronic Commerce Act (ehandelsloven). Write to [email protected] and we will send those details and add them here. We are the controller for the personal data this notice describes.

We have not appointed a data protection officer. The law does not require one for this service. Write to us at the email above. You can write in English or Norwegian.

What we use

We use the personal data you give us and the data the service creates while you use it:

  • Account: name, email, handle, bio, profile photo, language, time zone, city, and coordinates if you choose “use my location”.
  • Login: an email link, or the identifier Google, Facebook, or Apple sends if you choose that login. We do not receive the password you use with those providers.
  • Session: IP address and browser type, so the session can stay signed in and so we can protect the account.
  • Events: events you host or join, chat, invites, and photos you add. A photo can include a place and a time if the file or the event has them.
  • People: follows, and the name you use inside an event.
  • Taste: the kinds of events you pick, and whether you want friends, public events, or both.
  • Where+: whether it is active, how long it lasts, and a Stripe customer id. Stripe handles the card number. We do not store it.
  • AI pictures: the prompt and the images you send when you ask us to draw a picture.
  • Campaigns: if you open a link with a campaign code, we store that the account came from that code.
  • Guest session: before you finish signup we create a temporary technical address for that session. It is not a mailbox you can read.

We do not ask for special categories of data, such as health, religion, or biometric data used to identify you. Do not put that into Where unless you choose to. If you do, we process it only to host what you posted, and you can delete it.

Why we use it

We use personal data for these purposes, on these legal bases in GDPR Article 6:

  • To create the account, show events near you, run events, chat, photos, and Where+. The basis is the contract, Article 6(1)(b). Before the account exists, the basis is the steps you asked for so you can enter the contract.
  • To take payment, avoid charging you twice, and keep accounting records. The basis is the contract and a legal obligation, Article 6(1)(b) and (c). Norwegian bookkeeping rules can require us to keep payment records for five years.
  • To send a sign-in link, an invite, or a notice about an event you are in. The basis is the contract.
  • To keep Where secure, limit abuse, and order the feed. The basis is legitimate interests, Article 6(1)(f). The interest is a safe and useful service. You can object, as the rights section explains.
  • To sign you in with Google, Facebook, or Apple when you choose that. The basis is the contract.
  • To draw an AI picture you asked for. The basis is the contract. We send the prompt to the image provider for that request. We do not use your content to train our own models.

Ordering the feed does not produce a legal effect or a similarly significant effect on you. It is not a solely automated decision under GDPR Article 22. The parameters are described in the Terms of Service.

We do not send marketing email. Messages are about the account, an invite, or an event.

Who receives it

We share personal data with:

  • Resend, to send email.
  • Stripe, to take payment and run a subscription. Stripe is also a controller for its own payment service.
  • Google, Meta, or Apple, only if you use that login. They are controllers for their own login service.
  • The OpenStreetMap Nominatim service, to look up a city or a place you search for. The query can include a place name or coordinates.
  • OpenRouter, and the model provider it uses, to draw an AI picture you request.
  • The provider that hosts the application, the database, and stored photos.
  • People the product shows the content to. That includes guests of an event and, for a public event, people who can see the listing. A host can export the photos from their own event.
  • Authorities, when the law requires us to disclose.

We do not sell personal data.

Transfers out of the EEA

Some providers are outside the EEA, including in the United States. Where we transfer personal data out of the EEA, we use an adequacy decision or the European Commission’s standard contractual clauses, and extra measures where the transfer needs them. You can ask us for a copy of the safeguards we use, or for where they are published.

How long we keep it

  • Account data: for as long as the account is open.
  • After you close the account: we delete or anonymise it within 30 days, except what we must keep.
  • Payment and accounting records: up to five years after the end of the year of the payment.
  • Session and security logs: up to 12 months.
  • Backups: overwritten on a shorter cycle. After deletion we do not use a backup to restore a closed account, except where we must restore the service after an incident and the backup still contains the data.
  • Photos and chat: until you or the host deletes them, or the event is deleted, and then for the backup period.
  • A file a host has already downloaded is their copy. We do not control it after the download.

Your rights

You can ask for access, correction, erasure, and restriction. You can ask for a copy of the data you provided, in a portable form. You can object to processing based on legitimate interests. Where a use relies on consent, you can withdraw that consent. Withdrawal does not affect processing that already happened.

Write to [email protected]. We answer within one month. We may ask you to show that you hold the account. If we refuse a request, we explain why and how you can complain.

You can complain to Datatilsynet, the Norwegian Data Protection Authority, at https://www.datatilsynet.no. If you live elsewhere in the EEA, you can complain to the authority in your country.

Children

Where is not for anyone under 13. If you believe a child under 13 has an account, write to [email protected]. We will close it and delete the personal data, unless we must keep some of it.

Cookies

We use cookies and similar storage that are needed to sign you in and to remember settings you choose, such as language, time zone, and theme. We do not use advertising cookies. We do not use third-party analytics cookies.

These cookies are exempt from the consent requirement. You can block cookies in the browser. Sign-in and saved settings will then not work.

Changes to this notice

If we change this notice in a way that matters, we tell you in the product or by email before the change applies. The date at the top is the current version. The current text is at https://where.ltd/privacy.

Contact

Email: [email protected]

Privacy notice: https://where.ltd/privacy

Terms of Service: https://where.ltd/terms