AtWhatMileage
Legal

Privacy policy

Last updated Applies to AtWhatMileage and every page under https://atwhatmileage.com

The short version: this site has no accounts, no login, no contact form and no comment section, it sets no cookies of its own, and it runs no analytics. It is a set of pre-rendered pages about used cars. The longer version below exists because "we don't collect anything" is a claim that deserves to be itemised.

Who is responsible for your data

The publisher of this site has not been recorded in its configuration, so this policy cannot name the data controller. That is a defect in the install rather than an attempt to hide behind anonymity, and it should be corrected before the site is relied upon.

Privacy questions and requests go to hello@atwhatmileage.com. There is no data protection officer, because the scale of processing described below does not require one and appointing a nominal one would tell you nothing.

What is collected, and what is not

It is easier to start with what does not exist. This site has no user accounts, so there is nothing to register and no profile. It accepts no POST requests at all — every page answers GET and HEAD and nothing else — so there is no form anywhere on it that could submit your details, including on the contact page, which publishes an email address instead. It embeds no social buttons, no video players, no comment platform, no chat widget, no web fonts and no analytics package: no Google Analytics, no Plausible, no Meta pixel, nothing of that kind. It stores nothing in your browser — no cookies, no localStorage, no fingerprinting.

Three things do happen, and here they are in full.

1. Web server access logs

Like every website, this one runs on a web server that records a line for each request it answers. Those lines are created and held by the hosting provider, which acts as a data processor for the publisher, and they typically contain your IP address, the date and time, the page requested, the response code, the size of the response, the page that referred you and your browser's user-agent string. They are used for exactly two purposes: keeping the site running and working out why it broke when it does, and identifying abuse such as a crawler taking the site down. They are not used to build a profile of you, they are not combined with anything else, and they are not sold. Retention is the hosting provider's rolling window, which is measured in days to weeks rather than years.

2. The JSON API's rate limiter

The public JSON API is rate limited, which requires distinguishing one caller from another. It does that without storing an IP address: the address is combined with a secret salt, hashed, truncated, and used as a counter key. What ends up in the database is a short hash and a number of requests in the current window, from which the original address cannot be recovered. Rows older than the current 1 hour window are deleted. Browsing the HTML pages does not touch this at all — the rate limiter exists only on /api/ paths.

3. Anything you choose to send by email

If you email the address on the contact page, we necessarily receive whatever is in your message: your address, your name if you sign it, and any details you include. That correspondence is kept while the matter is open and for a reasonable period afterwards so that a related follow-up makes sense, and it is not added to any mailing list — there is no mailing list.

Cookies and similar technologies

This site sets no cookies. Not a session cookie, not a preference cookie, not an analytics cookie. Nothing on any page reads or writes browser storage, so there is no cookie banner to click, and there is nothing here for you to consent to or refuse. You can verify this in your browser's developer tools in about ten seconds, which is a better assurance than this paragraph.

This will change if advertising is introduced, and the change will be visible: ads would arrive with a consent notice on the same day, and this section would be rewritten to describe them before they were switched on rather than after. The section below is already written for that case and is kept here, plainly labelled, so you can see in advance what would apply.

Not currently in effect. The advertising section that follows describes what happens when ads are enabled on this site. They are not enabled today, no advertising script is loaded on any page, and no third-party cookie is set.

Advertising (if and when it is enabled)

Advertising on this site would be served by Google AdSense, a service of Google LLC and, for visitors in Europe, Google Ireland Limited. The mechanics matter, so here they are without euphemism. Google places its own cookies and reads its own identifiers in your browser in order to select an ad, to count how many times it has been shown, and to detect click fraud. Google receives your IP address, the page you are on and your browser characteristics as a technical consequence of loading the ad. Where you have consented to it, Google may use data from your activity across other sites to personalise which ad you see; this is what the law in California describes as "sharing" for cross-context behavioural advertising.

Google's own account of this is authoritative in a way that a summary cannot be, and it is worth reading rather than taking on trust: see how Google uses cookies in advertising and the Google privacy policy. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this or other websites, and Google's use of advertising cookies enables it and its partners to serve ads based on your visit to this site and other sites on the internet.

Consent, and what happens if you refuse

For visitors in the European Economic Area, the United Kingdom and Switzerland, advertising cookies are only set after consent. That consent is collected by a notice presented before any advertising identifier is written, it records a refusal as readily as an acceptance, and it can be changed later from the same notice. Refusing does not lock you out of anything: every page, every number, the mileage tool and the API work identically without consent. What changes is that ads are then non-personalised — chosen from the page's content and your rough location rather than from your history — which still requires Google to receive the technical request data described above, because there is no way to load a remote ad without it.

Outside those regions, advertising personalisation may be on by default depending on your jurisdiction, and you can turn it off at any time. The most direct controls are Google's own My Ad Center and Ads Settings, where personalisation can be disabled for your Google account or browser. Industry-wide opt-outs are available from the Digital Advertising Alliance, the Network Advertising Initiative and, for Europe, Your Online Choices. Browser-level controls — blocking third-party cookies outright, or a tracker-blocking extension — are more reliable than any of them, and this site is built to work perfectly well with all of them switched on.

Changing your choice on this site

Your answer to the notice is stored in this browser's local storage under the name awm-consent, with the value all if you agreed to personalised advertising or basic if you chose only what is necessary. It is deliberately not a cookie: local storage is never attached to a request, so recording your answer adds nothing to what any server — this one or Google's — receives. Nothing else about you is stored, and the value is not sent anywhere.

To change the answer, clear this site's storage for https://atwhatmileage.com and reload the page: with no stored value the notice appears again and nothing is loaded until you answer it. In Chrome and Edge that is Settings → Privacy → Third-party cookies → See all site data and permissions; in Firefox, Settings → Privacy & Security → Cookies and Site Data → Manage Data; in Safari, Settings → Privacy → Manage Website Data. Any "clear cookies and site data for this site" control does it, as does private browsing, where nothing is stored in the first place. If your browser blocks local storage altogether the notice reappears on every visit, which is the correct behaviour: without somewhere to record consent, consent cannot be assumed.

Choosing only necessary does not remove the advertising, and this policy will not pretend otherwise — the advertising is what pays for the pages. It removes the personalisation: Google is asked for non-personalised ads, chosen from what is on the page rather than from anything it knows about you. Withdrawing consent has no effect on advertising you were shown before you withdrew it, which is a limitation of how the past works rather than a policy choice, and it does not affect the lawfulness of processing that already happened under a consent that was valid at the time.

Why processing is lawful (UK and EU GDPR)

Legal basis for each kind of processing
What Purpose Basis under Article 6
Server access logs Keeping the site available, diagnosing faults, stopping abuse Legitimate interests — running a website securely, which cannot be done without knowing what requests it received
API rate-limit hashes Preventing one caller from exhausting a shared resource Legitimate interests, met with a salted truncated hash rather than an identifier, so the interference is close to nil
Email you send us Answering you Legitimate interests, or the steps taken at your request
Advertising cookies and identifiers Selecting and measuring ads (not currently in use) Consent, collected before any identifier is set, and withdrawable at any time

Who receives data

Nobody buys anything from this site, because nothing is for sale. Personal data is not sold for money, not rented, and not passed to data brokers. The complete list of parties who see anything at all is short: the hosting provider, which necessarily processes every request in order to answer it and which holds the access logs described above; the email provider that carries correspondence you choose to send; and, if advertising is enabled in future, Google for that purpose; and anyone we are legally obliged to disclose to, in response to a valid legal process, which has not happened.

On international transfers: the hosting and email infrastructure may process data outside your country. Where personal data leaves the UK or the EEA it is covered by the mechanisms UK and EU law provide for that — adequacy decisions where they exist, and standard contractual clauses otherwise. This site holds no separate database of visitors that could be transferred, which is the honest reason the exposure here is small.

How long anything is kept

Access logs are kept on the hosting provider's rolling schedule and are not archived by us. API rate-limit hashes survive one 1 hour window and are then deleted, which happens automatically as the API is used rather than on request. Email is kept while a matter is open and for a reasonable period afterwards. There is no other store: no visitor table, no event log, no profile, nothing that accumulates.

Your rights

If you are in the UK or the EEA, the GDPR gives you the right to ask what personal data is held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive a copy in a portable form, and to withdraw consent for anything based on consent — including advertising cookies — without penalty. You also have the right to complain to a supervisory authority: in the UK that is the Information Commissioner's Office, and in the EEA it is the authority for your country of residence. You do not have to complain to us first, though we would rather have the chance.

To exercise any of them, email the address on the contact page saying which right you are using and which country you are in, so that the correct deadline applies. Requests are free and answered within one month, which can be extended for genuinely complex ones with an explanation. Be warned that the answer is often anticlimactic: because this site keeps no identifiers of its own, an access request usually establishes that there is nothing to send you. Where advertising identifiers are involved, they belong to Google rather than to us, and the effective route to them is Google's own controls, which is why they are linked above rather than merely mentioned.

California and other US state privacy rights

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable laws in states including Virginia, Colorado, Connecticut, Utah and Texas, you have the right to know what categories of personal information are collected and why, to request access and deletion, to correct inaccurate information, to opt out of the sale or sharing of personal information and of targeted advertising, and not to be discriminated against for exercising any of it.

Applied to this site, the categories are narrow: identifiers and internet activity information, in the form of the IP address and request details in the server logs. No sensitive personal information is collected. No personal information is sold for money, and none is used for profiling that produces decisions with legal effect. Nothing is currently shared for cross-context behavioural advertising, because the site serves no advertising and loads no third-party script. If that changes, an opt-out mechanism will be live on the same day, and Global Privacy Control signals from your browser will be honoured as a valid opt-out request. Requests may be made by email; because the site holds no account, verification may be limited to the information in your request, and where identity cannot be verified the request will be answered with an explanation rather than with someone else's data.

Children

This site is a technical reference about used vehicles. It is not directed at children, has no features designed to appeal to them, and knowingly collects nothing from anyone under 13 — or under 16, where local law sets the age there. If you believe a child has sent us personal information by email, write to the contact address and it will be deleted.

Security

Every page is served over HTTPS, and requests over plain HTTP are redirected. The site is largely static by design: pages are rendered ahead of time and served as files, the front end accepts no input beyond a search box that builds a URL, and no visitor can cause a database write. That architecture is the security measure, in that it removes most of the surface where visitor data could leak. Nothing on the internet is guaranteed, and this policy does not pretend otherwise.

Changes to this policy

When this policy changes materially — a new third party, a new purpose, advertising being switched on — the date at the top of the page changes with it, and the substance of the change is described in the section it affects rather than absorbed silently into the text. Continuing to use the site after a change means the current version applies to you, which is the only workable rule for a site with no accounts to notify. If you want to hold a copy of the version you read, the page prints cleanly and is also archived by the usual public web archives.

Terms of use Contact and corrections About this site