legal
Privacy Policy
Last updated: 20 July 2026
WhorlID provides device identification for fraud prevention and account security. This policy explains what data the service processes, why it is lawful, how long it is kept, and what rights you have. It covers both this website (including the customer dashboard) and the identification service our customers embed on their own sites.
Who we are
The service is operated from Ireland and is subject to the EU General Data Protection Regulation (GDPR) and the ePrivacy rules. Contact for all privacy matters: [email protected].
Two roles, two kinds of data
1. Data we control (this website and dashboard). When you create an account we process your name, email address, and a hashed password, plus billing information handled by our payment provider. We use this to provide the service, send service messages, and bill subscriptions. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
2. Data we process for our customers (the identification service). When a website that uses WhorlID loads our script, we collect technical characteristics of the browser and device and compute a visitor identifier for that customer. For this data we act as a processor; the customer operating the website is the controller and is responsible for informing their users and choosing the legal basis. We require customers, by contract, to use the service only for fraud prevention, account security, and abuse detection, not for cross-site advertising or tracking.
What the identification service collects
The script collects technical signals only. These include: browser and platform identifiers (user agent, vendor), screen properties (resolution, color depth, pixel ratio), hardware characteristics (CPU core count, device memory, touch support), installed font detection, graphics rendering characteristics (canvas and WebGL output, supported extensions), audio processing characteristics, language and timezone settings, and math rounding behavior. In addition, our servers observe the IP address and user agent of each request.
The service does not collect names, email addresses, page contents, browsing history, form input, or anything the user typed. It does not read or set advertising cookies. The signals are used to answer one question for the customer whose key made the request: is this the same device we have seen before on this same customer's site?
Legal basis for the identification service
Customers deploy WhorlID to prevent fraud, secure accounts, and detect abuse (for example: blocking credential-stuffing, spotting multi-account abuse, protecting checkouts). Recital 47 GDPR recognizes fraud prevention as a legitimate interest (Article 6(1)(f)). Each customer remains responsible for their own legitimate-interest assessment and for meeting ePrivacy requirements in the jurisdictions where they operate, including disclosure in their own privacy notice.
Data retention
Retention is short and enforced automatically in the production database:
- Raw device signals attached to identification events are deleted after 30 days.
- Identification event records (visitor id, match score, IP, user agent, timestamp) are deleted after 90 days.
- Visitor profiles (the current signal set and visit counters for a device) are deleted automatically after 365 days without a new visit. Deleting a project from the dashboard immediately and permanently deletes all of its visitor profiles, events, keys, and webhooks. When a customer closes their account we delete their remaining projects and data on request via the privacy contact above.
- Account and billing records are kept as long as the account exists, then as required by tax law.
Tenant isolation
Visitor identifiers are scoped to a single customer project. The same physical device visiting two different customers' websites receives two unrelated identifiers, and no customer can query another customer's data. We do not build cross-site profiles.
Sub-processors
We use a small number of infrastructure providers to run the service: hosting of the API and database, and Paddle as merchant of record for payments (Paddle processes billing data under its own terms). We do not sell data and we do not share identification data with advertisers or data brokers.
Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. For dashboard accounts, contact us directly. For data collected on a customer's website, contact that website's operator (the controller); we assist customers in fulfilling such requests. You also have the right to lodge a complaint with a supervisory authority; in Ireland this is the Data Protection Commission (dataprotection.ie).
Security
Data is encrypted in transit. Secret API keys are stored only as cryptographic hashes. Access to production data is limited to what is needed to operate the service.
Changes
We will update this page when the service or the law changes and adjust the date above. Material changes affecting customers will be announced by email.