Wildpost What it doesLive mapPrivacy policy
Sign inStart free
Legal

Privacy policy

What Wildpost records, what it deliberately does not, and what you can ask us to do about it.

Last updated 10 August 2026

The short version
  • Scanning a poster records the country, the city and a one-way hash of the browser's user agent. No IP address, no visitor location.
  • A print's GPS coordinates come from a team member choosing to register that spot — never from a visitor.
  • Uploaded artwork and spot photos sit in private storage and are served through short-lived signed links.
  • No advertising, no profiling, no selling data.
  • Google Analytics runs on this site only if you accept it. Decline and nothing loads.

1. Who this is about

Wildpost is operated by Flint Port (Jildert Venema), Van Brakelplein 40A, Groningen, the Netherlands. In data-protection terms we are the controller for the account data described below, and a processor for the campaign content a workspace puts into the service.

This policy covers the Wildpost web app, the scan redirect at /s/…, the printed codes that lead to it, and the public marketing pages.

2. Data we hold

Account data

  • Your email address and display name, from signing up or from your Google account if you use Google sign-in.
  • Your workspace memberships and the role you hold in each.
  • Authentication records held by our auth provider: password hashes, sign-in timestamps, session and refresh tokens. We never see your password in readable form.

Workspace content

  • Campaigns: name, format, destination URL, status, and the artwork you upload.
  • Codes: the serial number and the unguessable slug printed in the QR code.
  • Placements: latitude, longitude, reported accuracy, your spot label, the surface type, an optional photo, who registered it and when.
  • Invites: the invited email address, the intended role, and the invite token.

Scan events

When somebody scans a printed code, we write a single row containing:

  • which code was scanned, and the time;
  • the country and city our edge network reports for the request;
  • a SHA-256 hash of the browser's user-agent string, used only to avoid counting the same device twice inside a 60-second window;
  • a flag marking scans made by your own team while registering a placement, so they are excluded from your statistics.

3. What we deliberately do not collect

These are constraints in the code, not preferences:

  • No IP addresses are stored against scans.
  • No visitor location. A person who scans a poster is never asked for, and never has recorded, their own coordinates. The only coordinates in the system are the ones a team member entered for the print itself.
  • No advertising identifiers, no fingerprinting, no cross-site or cross-device tracking, and no data sold or shared for anyone else's marketing.
  • No analytics on the app itself. Google Analytics, described in section 5, is limited to the public marketing pages and only runs with your consent — it never observes your campaigns, placements or team.
  • No special-category data. Do not put health, political, religious or similar personal information into campaign names, spot labels or photos.

Our hosting provider and our database provider keep their own short-lived operational logs, which can include IP addresses, for security and abuse handling. Those are theirs, they are not joined to your campaign data, and they age out on their schedules.

4. Cookies and browser storage

Wildpost sets no advertising cookies. What it does use:

NamePurposeLife
sb-…-auth-tokenKeeps you signed in (local storage, set by our auth provider)Until sign-out
wp_member Flags this device as belonging to a team member, so scanning an unplaced code opens the registration screen instead of the campaign's destination. Carries no identity. 180 days
wildpost.workspaceRemembers which workspace you last had openUntil cleared
wildpost.pendingInviteCarries an invite token across a sign-in redirectThe browser session

All of these are strictly necessary to operate the service, so we do not ask for consent. Analytics cookies are a separate matter and are covered next.

5. Analytics, and your choice about it

We use Google Analytics 4 to understand which pages people use. It is off until you say yes: the Google script is not present in the page, and no request reaches Google, until you accept the banner. Decline and the script is never loaded at all — not even in a cookieless mode.

If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as a refusal and never ask.

Accepting lets Google Analytics set these cookies:

NamePurposeLife
_gaDistinguishes one browser from another so repeat visits are not counted as new people2 years
_ga_<id>Keeps session state for the same purpose2 years

Google receives the pages you viewed, approximate location derived from your IP, and device and browser characteristics. IP anonymisation is enabled, and Google Signals, advertising features and ad personalisation are all switched off. Google acts as our processor for this and is a recipient outside the EEA, covered by its standard contractual clauses.

Changing your mind: use the Analytics preferences button at the foot of this page. Withdrawing clears the _ga cookies and stops any further collection. The legal basis is your consent, and withdrawing it costs you nothing — every part of Wildpost works identically either way.

6. The map on the home page

The home page shows a sample map centred on your approximate area. It is worked out from the IP address of your request by our own network edge — no third-party geolocation service is involved, and your browser is never asked for GPS on that page.

The coordinates are rounded to two decimal places, roughly a kilometre, before they ever leave the server, and nothing is stored: the response is calculated per request and kept nowhere. The pins on that map are invented sample data, labelled as such, not other customers' placements.

The map tiles themselves are served by the OpenStreetMap Foundation, so your browser requests them directly and OpenStreetMap sees those requests. Nothing loads until you scroll the map into view.

7. Location permission in the app

Registering a placement asks your browser for a location fix. That is your explicit choice each time, you can decline, and you can drag the map pin to correct or coarsen what gets saved. The coordinates describe where a poster is, not where you are — but they are captured while you stand next to it, so treat them accordingly. Your browser or operating system controls the permission and you can revoke it at any time.

8. Why we are allowed to hold it

  • Performing our contract with you — running your account, your campaigns and the scan redirect.
  • Our legitimate interests — keeping the service secure, preventing abuse, and producing the aggregate scan counts that are the point of the product.
  • Your consent — the browser location permission, which you grant per use and can withdraw, and analytics cookies, which are off until you accept them.
  • Legal obligation — where we have to keep or disclose something by law.

9. Who processes it with us

  • Supabase — database, authentication and file storage.
  • Cloudflare — application hosting and the scan redirect at the network edge.
  • OpenStreetMap Foundation — map tiles, and the optional address lookup that suggests a spot label. Your browser requests tiles directly, so OpenStreetMap sees those requests. We send it the coordinates of the placement being registered and nothing else.
  • Google — in two separate, optional roles. If you choose Google sign-in, Google confirms your identity and we receive your email address, name and profile picture URL. If you accept the analytics banner, Google Analytics also processes the page-view data described in section 5. Neither happens unless you choose it.

We do not sell personal data and we do not share it for anyone else's marketing.

10. Where it lives

Data is stored in the region chosen for the workspace's project. Our providers operate global networks, so some processing — request routing and edge caching in particular — happens outside that region. Where personal data leaves the EEA or the UK, our providers' standard contractual clauses cover the transfer.

11. How long we keep it

  • Account and workspace data: for as long as the account exists.
  • Campaigns, codes, placements and uploads: until you delete them, or until the workspace is deleted.
  • Scan events: retained while the campaign exists, because they are the campaign's own history.
  • Deleting a workspace cascades: its campaigns, codes, placements, scan rows and stored files go with it.
  • Backups roll off within 30 days of deletion.
  • Google Analytics data is retained for 14 months, Google's shortest available setting.

12. Your rights

Subject to local law, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable form. You can also withdraw the location permission at any time in your browser.

Email support@wildpost.app and we will respond within 30 days. If you are unhappy with the outcome you can complain to your local data-protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

If your data is in a workspace somebody else owns, they decide what happens to the campaign content. Ask the workspace owner first, and tell us if they do not respond.

13. Security

Every table is protected by row-level security, so a query can only ever reach workspaces you are a member of. The storage buckets are private and files are served through signed links that expire within the hour. The privileged key that can bypass those rules exists only in server-side secrets and is never sent to a browser. No system is perfect; if you find a weakness, please tell us at support@wildpost.app before telling anyone else.

14. Children

Wildpost is a tool for people running poster campaigns and is not intended for anyone under 16. We do not knowingly collect their data.

15. Changes

If we change this policy we will update the date at the top, and we will tell account holders by email before anything material takes effect.

16. Contact

Flint Port (Jildert Venema)
Van Brakelplein 40A, Groningen, the Netherlands
support@wildpost.app

Questions? support@wildpost.appPrivacyTerms