AtWhatMileage
Legal

Privacy policy

Last updated Applies to AtWhatMileage and every page under https://atwhatmileage.com

The short version: this site has no accounts, no login, no contact form and no comment section, and it sets no cookies of its own. It does load Google Analytics, which sets two, and both are named below. It is a set of pre-rendered pages about used cars. The longer version exists because "we barely collect anything" is a claim that deserves to be itemised.

Who is responsible for your data

The controller of any personal data processed through this site is AtWhatMileage, United States, publisher of AtWhatMileage. "Controller" is the term the UK and EU General Data Protection Regulations use for whoever decides why and how data is processed; in plain terms, it means the buck stops with the publisher named here.

Privacy questions and requests go to contact@atwhatmileage.com. There is no data protection officer, because the scale of processing described below does not require one and appointing a nominal one would tell you nothing.

What is collected, and what is not

It is easier to start with what does not exist. This site has no user accounts, so there is nothing to register and no profile. It accepts no POST requests at all — every page answers GET and HEAD and nothing else — so there is no form anywhere on it that could submit your details, including on the contact page, which publishes an email address instead. It embeds no social buttons, no video players, no comment platform, no chat widget and no web fonts, and it runs no advertising. Its own code writes nothing to your browser: there is no login cookie, no preference cookie and no fingerprinting.

There is one third-party script, and it is the ordinary one: Google Analytics, which does set cookies. It is described in full below and named in the cookie table, because a policy that lists what a site avoids and then quietly omits the one thing it loads is not worth reading.

Four things do happen, and here they are in full.

1. Web server access logs

Like every website, this one runs on a web server that records a line for each request it answers. Those lines are created and held by the hosting provider, which acts as a data processor for the publisher, and they typically contain your IP address, the date and time, the page requested, the response code, the size of the response, the page that referred you and your browser's user-agent string. They are used for exactly two purposes: keeping the site running and working out why it broke when it does, and identifying abuse such as a crawler taking the site down. They are not used to build a profile of you, they are not combined with anything else, and they are not sold. Retention is the hosting provider's rolling window, which is measured in days to weeks rather than years.

2. The JSON API's rate limiter

The public JSON API is rate limited, which requires distinguishing one caller from another. It does that without storing an IP address: the address is combined with a secret salt, hashed, truncated, and used as a counter key. What ends up in the database is a short hash and a number of requests in the current window, from which the original address cannot be recovered. Rows older than the current 1 hour window are deleted. Browsing the HTML pages does not touch this at all — the rate limiter exists only on /api/ paths.

3. Anything you choose to send by email

If you email the address on the contact page, we necessarily receive whatever is in your message: your address, your name if you sign it, and any details you include. That correspondence is kept while the matter is open and for a reasonable period afterwards so that a related follow-up makes sense, and it is not added to any mailing list — there is no mailing list.

4. Google Analytics

Every page on this site loads Google Analytics 4 (property G-KLWFYCZH08), supplied by Google LLC and, for visitors in Europe, Google Ireland Limited. It is installed in its standard configuration, which means it does what you would expect a standard analytics tag to do, and this section says so rather than dressing it up.

When you open a page, the tag writes two first-party cookies in your browser — _ga and _ga_KLWFYCZH08 — each lasting up to two years. They hold a randomly generated client identifier and session state. That identifier is what makes it possible to tell that the same browser read three pages in one visit, and to tell that a browser which came back a week later had been here before. It is not linked to a name, an email address or an account, because this site holds none of those; it is a pseudonymous number that identifies a browser.

With each page you open, Google receives the page address and title, the page that referred you, your screen size, language, device and browser, an approximate location derived from your IP address, and that client identifier. Google's documentation is authoritative on what it then does, and it is worth reading rather than taking on trust: see how Google uses data when you use its partners' sites and the Google privacy policy. Google acts as our processor for this measurement, processes it in the United States and elsewhere, and retains event-level data for the period set on the property. The purpose here is the ordinary one and the only one: knowing which pages people actually read, so that the next thing written is about something useful. Nothing measured is sold, and no advertising audience is built from it — this site carries no advertising.

How to refuse it

Nothing on this site depends on the tag, and no page behaves differently when it is blocked, so refusing costs you nothing at all. Any content or tracker blocker stops it. So does Google's own Analytics opt-out extension, which is the most direct option if you would rather not install a blocker. Blocking cookies for this site, or browsing in a private window, prevents the identifier from persisting; clearing this site's cookies deletes it, and the next visit starts a new one. Global Privacy Control and "Do Not Track" headers are not honoured by Google Analytics, which is worth knowing if you rely on them elsewhere.

Being straight about the part that is uncomfortable: at present these cookies are written when the page loads, and you are not asked first. There is no consent notice in front of them. If you are in a place whose rules require consent for analytics cookies before they are set — the EEA and the UK among them — that requirement is not being met by the way this site is currently built, and the controls in the paragraph above are the ones actually available to you today. That is a statement of fact rather than a defence of it.

Cookies and similar technologies

Two cookies are set on this site, and both belong to Google Analytics. Nothing else on any page reads or writes browser storage: this site's own code sets no cookie of any kind, there is no session, no preference store and no advertising identifier, because there is no advertising. You can check the whole of that claim in your browser's developer tools in about ten seconds, under Application → Cookies, which is a better assurance than this paragraph.

Every cookie this site causes to be set
NameSet by PurposeExpires
_ga Google Analytics (first-party) Holds the randomly generated client identifier that distinguishes one browser from another 2 years
_ga_KLWFYCZH08 Google Analytics (first-party) Holds session state for this property: whether a visit is in progress and when it started 2 years

Both are described in the Google Analytics section above, along with every way of refusing them and the plain statement that you are not asked before they are written. If advertising is ever introduced it will add cookies of its own, set by Google on its own behalf rather than ours, and it would arrive with a consent notice on the same day. The section below is already written for that case and is kept here, plainly labelled, so you can see in advance what would apply.

Not currently in effect. The advertising section that follows describes what happens when ads are enabled on this site. They are not enabled today, no advertising script is loaded on any page, and no advertising cookie is set.

Advertising (if and when it is enabled)

Advertising on this site would be served by Google AdSense, a service of Google LLC and, for visitors in Europe, Google Ireland Limited. The mechanics matter, so here they are without euphemism. Google places its own cookies and reads its own identifiers in your browser in order to select an ad, to count how many times it has been shown, and to detect click fraud. Google receives your IP address, the page you are on and your browser characteristics as a technical consequence of loading the ad. Where you have consented to it, Google may use data from your activity across other sites to personalise which ad you see; this is what the law in California describes as "sharing" for cross-context behavioural advertising.

Google's own account of this is authoritative in a way that a summary cannot be, and it is worth reading rather than taking on trust: see how Google uses cookies in advertising and the Google privacy policy. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this or other websites, and Google's use of advertising cookies enables it and its partners to serve ads based on your visit to this site and other sites on the internet.

Consent, and what happens if you refuse

For visitors in the European Economic Area, the United Kingdom and Switzerland, advertising cookies are only set after consent. That consent is collected by a notice presented before any advertising identifier is written, it records a refusal as readily as an acceptance, and it can be changed later from the same notice. Refusing does not lock you out of anything: every page, every number, the mileage tool and the API work identically without consent. What changes is that ads are then non-personalised — chosen from the page's content and your rough location rather than from your history — which still requires Google to receive the technical request data described above, because there is no way to load a remote ad without it.

Outside those regions, advertising personalisation may be on by default depending on your jurisdiction, and you can turn it off at any time. The most direct controls are Google's own My Ad Center and Ads Settings, where personalisation can be disabled for your Google account or browser. Industry-wide opt-outs are available from the Digital Advertising Alliance, the Network Advertising Initiative and, for Europe, Your Online Choices. Browser-level controls — blocking third-party cookies outright, or a tracker-blocking extension — are more reliable than any of them, and this site is built to work perfectly well with all of them switched on.

Changing your choice on this site

Your answer to the notice is stored in this browser's local storage under the name awm-consent, with the value all if you agreed to personalised advertising or basic if you chose only what is necessary. It is deliberately not a cookie: local storage is never attached to a request, so recording your answer adds nothing to what any server — this one or Google's — receives. Nothing else about you is stored, and the value is not sent anywhere.

To change the answer, clear this site's storage for https://atwhatmileage.com and reload the page: with no stored value the notice appears again and nothing is loaded until you answer it. In Chrome and Edge that is Settings → Privacy → Third-party cookies → See all site data and permissions; in Firefox, Settings → Privacy & Security → Cookies and Site Data → Manage Data; in Safari, Settings → Privacy → Manage Website Data. Any "clear cookies and site data for this site" control does it, as does private browsing, where nothing is stored in the first place. If your browser blocks local storage altogether the notice reappears on every visit, which is the correct behaviour: without somewhere to record consent, consent cannot be assumed.

Choosing only necessary does not remove the advertising, and this policy will not pretend otherwise — the advertising is what pays for the pages. It removes the personalisation: Google is asked for non-personalised ads, chosen from what is on the page rather than from anything it knows about you. Withdrawing consent has no effect on advertising you were shown before you withdrew it, which is a limitation of how the past works rather than a policy choice, and it does not affect the lawfulness of processing that already happened under a consent that was valid at the time.

Why processing is lawful (UK and EU GDPR)

Legal basis for each kind of processing
What Purpose Basis under Article 6
Server access logs Keeping the site available, diagnosing faults, stopping abuse Legitimate interests — running a website securely, which cannot be done without knowing what requests it received
API rate-limit hashes Preventing one caller from exhausting a shared resource Legitimate interests, met with a salted truncated hash rather than an identifier, so the interference is close to nil
Email you send us Answering you Legitimate interests, or the steps taken at your request
Google Analytics cookies and measurement Counting page views to see which pages are worth expanding Legitimate interests for the analysis itself. The separate consent rule that applies to storing cookies on your device is not currently satisfied on this site, which the analytics section above states plainly rather than leaving you to work out
Advertising cookies and identifiers Selecting and measuring ads (not currently in use) Consent, collected before any identifier is set, and withdrawable at any time

Who receives data

Nobody buys anything from this site, because nothing is for sale. Personal data is not sold for money, not rented, and not passed to data brokers. The complete list of parties who see anything at all is short: the hosting provider, which necessarily processes every request in order to answer it and which holds the access logs described above; the email provider that carries correspondence you choose to send; Google, which receives one measurement request per page view as described above and acts as our processor for it; and, if advertising is enabled in future, Google for that purpose; and anyone we are legally obliged to disclose to, in response to a valid legal process, which has not happened.

On international transfers: the hosting and email infrastructure may process data outside your country, Google processes measurement data in the United States and elsewhere. Where personal data leaves the UK or the EEA it is covered by the mechanisms UK and EU law provide for that — adequacy decisions where they exist, and standard contractual clauses otherwise. This site holds no separate database of visitors that could be transferred, which is the honest reason the exposure here is small.

How long anything is kept

Access logs are kept on the hosting provider's rolling schedule and are not archived by us. API rate-limit hashes survive one 1 hour window and are then deleted, which happens automatically as the API is used rather than on request. Email is kept while a matter is open and for a reasonable period afterwards. There is no other store: no visitor table, no event log, no profile, nothing that accumulates.

Your rights

If you are in the UK or the EEA, the GDPR gives you the right to ask what personal data is held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive a copy in a portable form, and to withdraw consent for anything based on consent — including advertising cookies — without penalty. You also have the right to complain to a supervisory authority: in the UK that is the Information Commissioner's Office, and in the EEA it is the authority for your country of residence. You do not have to complain to us first, though we would rather have the chance.

To exercise any of them, email the address on the contact page saying which right you are using and which country you are in, so that the correct deadline applies. Requests are free and answered within one month, which can be extended for genuinely complex ones with an explanation. Be warned that the answer is often anticlimactic: because this site keeps no identifiers of its own, an access request usually establishes that there is nothing to send you. Where advertising identifiers are involved, they belong to Google rather than to us, and the effective route to them is Google's own controls, which is why they are linked above rather than merely mentioned.

California and other US state privacy rights

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable laws in states including Virginia, Colorado, Connecticut, Utah and Texas, you have the right to know what categories of personal information are collected and why, to request access and deletion, to correct inaccurate information, to opt out of the sale or sharing of personal information and of targeted advertising, and not to be discriminated against for exercising any of it.

Applied to this site, the categories are narrow: identifiers and internet activity information, in the form of the IP address and request details in the server logs. No sensitive personal information is collected. No personal information is sold for money, and none is used for profiling that produces decisions with legal effect. Nothing is currently shared for cross-context behavioural advertising, because the site serves no advertising and loads no third-party script. If that changes, an opt-out mechanism will be live on the same day, and Global Privacy Control signals from your browser will be honoured as a valid opt-out request. Requests may be made by email; because the site holds no account, verification may be limited to the information in your request, and where identity cannot be verified the request will be answered with an explanation rather than with someone else's data.

Children

This site is a technical reference about used vehicles. It is not directed at children, has no features designed to appeal to them, and knowingly collects nothing from anyone under 13 — or under 16, where local law sets the age there. If you believe a child has sent us personal information by email, write to the contact address and it will be deleted.

Security

Every page is served over HTTPS, and requests over plain HTTP are redirected. The site is largely static by design: pages are rendered ahead of time and served as files, the front end accepts no input beyond a search box that builds a URL, and no visitor can cause a database write. That architecture is the security measure, in that it removes most of the surface where visitor data could leak. Nothing on the internet is guaranteed, and this policy does not pretend otherwise.

Changes to this policy

When this policy changes materially — a new third party, a new purpose, advertising being switched on — the date at the top of the page changes with it, and the substance of the change is described in the section it affects rather than absorbed silently into the text. Continuing to use the site after a change means the current version applies to you, which is the only workable rule for a site with no accounts to notify. If you want to hold a copy of the version you read, the page prints cleanly and is also archived by the usual public web archives.

Terms of use Contact and corrections About this site