legal

Privacy Policy

Last updated: 26 July 2026

WhorlID provides device identification for fraud prevention and account security. This policy explains what data the service processes, why it is lawful, how long it is kept, and what rights you have. It covers both this website (including the customer dashboard) and the identification service our customers embed on their own sites.

Who we are

WhorlID is WhorlID, an independent operator based in Ireland, subject to the EU General Data Protection Regulation (GDPR) and the ePrivacy rules. Contact for all privacy matters: [email protected].

Note on our legal identity. WhorlID is currently run by an independent operator rather than a registered company, and the full legal name and postal address are being finalised. We would rather say that plainly here than imply a corporate form we do not have. If you need the contracting party in writing before you integrate, email the address above and we will provide it.

Two roles, two kinds of data

1. Data we control (this website and dashboard). When you create an account we process your name, email address, and a hashed password, plus billing information handled by our payment provider. We use this to provide the service, send service messages, and bill subscriptions. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

2. Data we process for our customers (the identification service). When a website that uses WhorlID loads our script, we collect technical characteristics of the browser and device and compute a visitor identifier for that customer. For this data we act as a processor; the customer operating the website is the controller and is responsible for informing their users and choosing the legal basis. We require customers, by contract, to use the service only for fraud prevention, account security, and abuse detection, not for cross-site advertising or tracking.

What the identification service collects

The script collects technical signals only. These include: browser and platform identifiers (user agent, vendor), screen properties (resolution, color depth, pixel ratio), hardware characteristics (CPU core count, device memory, touch support), installed font detection, graphics rendering characteristics (canvas and WebGL output, supported extensions), audio processing characteristics, language and timezone settings, and math rounding behavior. In addition, our servers observe the IP address and user agent of each request.

From that IP address we also derive the network operator (its autonomous system number and organisation name) and whether it belongs to hosting or cloud infrastructure or to a published Tor exit node. This uses datasets we hold locally, built from public sources; the IP is not sent to any third party to answer this.

The service does not collect names, email addresses, page contents, browsing history, form input, or anything the user typed. It does not read or set advertising cookies. The signals are used to answer one question for the customer whose key made the request: is this the same device we have seen before on this same customer's site?

Legal basis for the identification service

Customers deploy WhorlID to prevent fraud, secure accounts, and detect abuse (for example: blocking credential-stuffing, spotting multi-account abuse, protecting checkouts). Recital 47 GDPR recognizes fraud prevention as a legitimate interest (Article 6(1)(f)). Each customer remains responsible for their own legitimate-interest assessment and for meeting ePrivacy requirements in the jurisdictions where they operate, including disclosure in their own privacy notice.

Device fingerprinting is in scope for the ePrivacy consent rules even though we set no cookies, so avoiding cookies does not remove a customer's consent obligations. We explain what that means in practice, and how to deploy the service lawfully, in GDPR and device fingerprinting. The processor terms that apply to every account are in our Data Processing Agreement.

Data retention

Retention is short and enforced automatically in the production database:

Closing your account and deleting everything

You can delete any project yourself from the dashboard, which erases its devices, events, keys, and webhooks immediately. To close the account entirely, email [email protected] from the address on the account. We verify the request against that address, then delete your login and sessions, your organization and its memberships, every project with all of its devices, events, API keys, and webhook configuration, and your contact messages. Billing records are handed to the retention required by tax law and the customer record with our payment provider is closed. We complete deletion within 30 days, normally within a few working days, and email you confirmation of what was removed. Backups age out on their own cycle. Say so in your email if you also want an export of your data before it is deleted.

Tenant isolation

Visitor identifiers are scoped to a single customer project. The same physical device visiting two different customers' websites receives two unrelated identifiers, and no customer can query another customer's data. We do not build cross-site profiles.

Sub-processors

We use a small number of infrastructure providers to run the service: hosting of the API and database, and Stripe as our payment processor (Stripe processes billing data as an independent controller, under its own terms). We are the seller and merchant of record for every subscription, so your contract for the service is with us and not with a reseller. Card details are entered directly into Stripe and never reach our servers. We do not sell data and we do not share identification data with advertisers or data brokers.

How network information is derived

Country, hosting classification, and network operator (ASN) are derived from the IP address using databases held on our own servers. No IP address is sent to a third party for this: there is no per-request lookup service in the path, which is both a latency decision and the reason identification data never leaves the EU.

The databases and their licences:

Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. For dashboard accounts, contact us directly. For data collected on a customer's website, contact that website's operator (the controller); we assist customers in fulfilling such requests. You also have the right to lodge a complaint with a supervisory authority; in Ireland this is the Data Protection Commission (dataprotection.ie).

Security

Data is encrypted in transit. Secret API keys are stored only as cryptographic hashes. Access to production data is limited to what is needed to operate the service.

Changes

We will update this page when the service or the law changes and adjust the date above. Material changes affecting customers will be announced by email.

Back to home

Privacy Policy | WhorlID