Privacy
This page is maintained by FairWhere Limited to answer common privacy questions about the FairWhere service. Last updated 6 October 2026.
Children
FairWhere is not for children under 13. We do not knowingly collect data from them. If we learn an account belongs to someone under 13, we delete it when asked or when we find out. You must confirm you are 13 or over and agree to the Terms and this policy to keep using a website account. We ask for this when you sign up, and after you sign in if that confirmation is not already saved or is out of date. Contact us at privacy@fairwhere.com.
Data controller
The data controller for personal data processed through FairWhere is FairWhere Limited, a limited company incorporated under the laws of England and Wales. You can reach us at privacy@fairwhere.com.
What we collect
When you make a plan we process the starting places you type, any return places, what you want to do, and the name you give the plan if you give it one. We use these to rank meeting places for your group.
The app does not use your phone's location and never asks for location permission. It does send addresses you type (start points, and saved addresses on your account) to our server. On the website, your browser's location is used only if you tap a control that asks for it, so we can fill in a starting place.
If you sign in, we store the email address for the account. You can sign in with Apple, with Google, or with email (a password or a link we email you). Apple confirms your identity. A name you set on your profile can be shown to people you invite. If you add a phone number on your profile, we store that too. Sign-in emails, such as a sign-in link, a sign-up confirmation or a password reset, are triggered by our sign-in provider, Supabase, and sent through Lovable's email service.
You can use the app as a guest, without an email account. That guest use keeps the plans on that phone. If you later sign in on the same phone, those guest plans can be moved onto the account.
An invite link lets someone join a plan. The link contains a private code. The person who opens it can give a name and a starting place for that meet. Addresses a guest shares through an invite are visible to the plan owner.
If you allow notifications in the app, we store a notification code for that phone. Expo creates that code. We also store whether the phone is iOS or Android. If you do not allow notifications, we do not store a code. On the website, if you turn on alerts, we store a browser notification subscription for your account.
On the website you can save a place you use often, such as home or work. We store the address you type.
If you save addresses, we store them on your account until you delete them or delete your account.
If you opt in to product updates, we record that choice. You can change it later in Profile, then Privacy, when you are signed in.
The app camera is used only to scan a connect code. No photos are taken or uploaded.
The app can add plans to your calendar. It only writes, and that stays on your phone.
Report a problem opens your own mail app.
How we use it
On the website, places you type are sent to Google Maps and Google Places so we can turn them into a point on the map and, when a live journey is needed, estimate travel time. That request can go through Lovable on the way to Google. For journeys in London we also ask Transport for London. A UK postcode may be sent to postcodes.io to find the point on the map. In the app, the map is Apple Maps. Address suggestions go through our own server.
Results are shown to you. If you save the plan, we store it under your account, or as a guest if you have not signed in.
AI features may be added, and this policy will be updated first.
Notification codes are used only to tell you about plans you organise or join. That can include voting closing, the chosen place changing, a reminder to check the place is free, and a note when a place is named but not yet confirmed. The message can include the plan name and the place name. We do not use these notifications for advertising. Someone who only opened the plan in a browser, and has not allowed app notifications, is not sent an app notification.
When a plan is ranked, on the website, in the app, or through an AI assistant, we also store a separate record. It holds approximate starting areas rounded to about 100 metres (not the street address), the activity, the city, the meeting time, the group size, which Placelists were used, and the names of the top places. A Placelist is a saved list of places. That record does not include your account.
A ranking on the website may also be logged with your IP address. If you are signed in for a live Google search, that log can also include your account id. We use this to run and protect the service. Deleting your account removes the account id and the IP address from logs that were tied to your account. The page view record under Analytics does not include an IP address.
Plans you share
People on a shared plan can see the plan name, names (usually first names only), and each person's travel time. They see a general area for someone else's start when one was saved, never a street address or postcode. The organiser can see any email address given for a person.
What happens to a shared plan when you delete your account is described under Delete your account and How long we keep it.
Third parties
Supabase stores accounts, plans, guest data, invite records, and notification codes. Lovable hosts the website. Lovable also provides some connections to other services, such as Google Maps, email, and text messages. Sentry (Functional Software, Inc.) receives crash reports from the iOS app. Those reports are stored in the EU (Germany).
Google Maps and Google Places process the places and journeys you ask us to look up. If you sign in with Google, Google handles that sign-in. Transport for London processes London journey requests. postcodes.io turns a UK postcode you type into a point on the map.
Expo and Apple deliver app notifications. Apple confirms your identity when you use Sign in with Apple.
Some service messages, such as a note about a table request, are sent by email through Resend or by text through Twilio.
Payments for credits are handled by Paddle. We keep a record of each purchase: how many credits were added, and the amount and currency if they were stored. That record is removed when your account is deleted.
Google Analytics, if you accept it, is described under Analytics. We do not use Google Analytics for advertising. The app does not use Google Analytics or other analytics or advertising trackers, and it does not ask to track you.
Analytics
On the website we keep our own record of pages opened: the page address, the page you came from, the page title, and a random id stored in the browser for that visit. Invite codes and anything after a question mark in the address are not stored. We do not store an IP address in that record, and it does not use a cookie. Page view logging runs until a visitor declines. Your account id is added only if you have accepted analytics.
The Google tag may load when you visit the site, but it sets no analytics cookies and sends no page events until you accept. If you opt in, FairWhere may use Google Analytics 4 to understand which pages people visit and whether they start a plan (for example after landing from search or social). You can decline the banner, or change your choice later in Profile, then Privacy, when signed in. We do not use Google Analytics for advertising.
Crash reports
The iOS app sends crash and error reports to our crash-reporting provider, Sentry (Functional Software, Inc.). Reports are stored in the EU (Germany). Reports include device model, iOS version, screen size, memory, app version and build, the phone's language setting, the name of the screen that was open, and technical details of the error. Native crash reports may include a random identifier for that install of the app. Sentry may work out an approximate, city-level location from the internet connection's IP address. We do not attach your name, email or account to crash reports, and we do not use session recordings, screenshots or performance tracking. Crash reports are used only to find and fix bugs.
AI assistants and connectors
When someone uses FairWhere from an AI assistant, FairWhere receives what the assistant sends. That can include place names, areas or addresses entered as starting points, names for the people, the activity, and Placelist choices.
FairWhere returns rankings, venue names, journey estimates, citations, and a link to continue on FairWhere. No FairWhere account is needed, and no account data is returned.
Starting-point text is sent to Google so FairWhere can turn it into a point on the map. The assistant ranks places with FairWhere's own estimate. It does not run a live Transport for London check or a Google Deep Search.
That ranking also stores the approximate record described under How we use it: rounded starting areas, the meeting time, the group size, and the names of the top places, not street addresses. The record does not include an account.
How long we keep it
We keep your account, saved plans, and profile until you delete them.
If you delete your account, a plan you shared is kept for the group when the meet is still ahead or was in the last day, or when the plan has no meet time and was created in the last 30 days. Where we can match your name on that plan, it is replaced with Organiser, and we remove your own start and end places. If we cannot match a name, those places can stay. Once the meet is more than 30 days past, that leftover plan is removed automatically, together with its vote seats and ratings. If there was no meet time, the same happens 30 days after you deleted the account.
A plan you have not shared, and a shared plan whose meet ended more than a day ago, are deleted with the account.
The approximate ranking record does not include your account, so deleting the account does not remove it. The approximate ranking records are not deleted on a fixed timetable. Page view records are deleted automatically after 14 months.
If an email address has been unsubscribed, we keep it on a list of addresses we must not email. That list is not removed when the account is deleted.
Your controls
You can delete a saved plan from the Plans page. When you are signed in, you can change analytics and product updates in Profile, then Privacy. You can delete your account as described below. As a UK or EEA user you have rights of access, rectification, erasure, restriction, portability and objection under UK GDPR: write to privacy@fairwhere.com to exercise them.
Delete your account
In the app, choose Delete account. The screen asks you to type DELETE, then Delete my account. We then remove the account and the data tied to it, as described on this page, and we delete the notification code stored for that account. If the account used Sign in with Apple, and the app gives us a fresh code from Apple, we ask Apple to revoke this app's sign-in token. Your FairWhere account is deleted even if that step does not happen.
If you are using the app as a guest, open Your guest data and choose Clear my data on FairWhere. That removes that guest use in the same way.
Your account id is removed from page view records. Those records stay until they are deleted after 14 months.
If you joined a plan someone else organised through a group link, we remove the link to your account. If that record stored your email, we remove the email. A saved copy of someone else's plan stores your name and account link, not your email or phone number, and we remove that account link. The starting place on that plan can stay, because the group still uses it for the meet. A rating you gave stays as a score, under the name Guest. A vote you cast can stay, without your account attached.
A private Placelist you own is deleted. A public or official Placelist is kept without your account attached. Files you uploaded are no longer linked to your account. This step does not delete those files.
The website has no delete button. Email privacy@fairwhere.com to ask us to delete your account or your data. We monitor that address. Use the same address if delete in the app does not complete.