The short version
- You can browse, filter and compare every car without an account, and without telling us anything about yourself.
- To stop one browser rating the same car twice, an anonymous rater gets a single first-party cookie containing a random number. It is not linked to a name, an email address, an IP address or any account.
- An account exists only so you can edit or delete your own ratings later. It holds a username, a password hash, a consent timestamp and your ratings. Nothing else.
- Both the anonymous cookie and the whole account can be removed by you, immediately, without asking anyone.
What is stored, and why
| Username | Chosen by you. Shown next to the ratings you leave. Required for an account (GDPR art. 6(1)(b), performance of a service you asked for). |
|---|---|
| Password | Never stored. Only a scrypt hash (N=16384, r=8, p=1) plus a per-user random salt is kept, and it cannot be reversed into your password. The plaintext exists only in the request that created or used it, in memory. |
| Consent record | Timestamp and notice version (currently 1.0.0) captured at registration, so consent can be demonstrated (art. 7(1)). |
| Ratings | The car slug, three integers from 1 to 5, an optional note of up to 280 characters, and created/updated timestamps. Notes are published, so do not put personal information in one. |
| Account timestamps | Creation date and last-seen date, used to expire abandoned sessions and to show you what is held. |
| Anonymous rater identity | A random identifier in your own browser cookie, stored hashed as the owner of an anonymous rating. It carries no personal data in either direction and is deleted with the rating. |
Cookies and local storage
| <code>ws_voter</code> | Anonymous rater identity. Set the first time you rate a car, or when you open an account page without one. Random, first-party, SameSite=Strict, up to one year. Functional, not tracking: it exists so the same browser cannot vote twice on the same car. |
|---|---|
| <code>ws_session</code> | Signed-in session. Contains a random session id only; the session record (your user id and a CSRF token) lives on the server. HttpOnly, SameSite=Strict, 30 days. |
| <code>ws_csrf</code> | Short-lived anti-forgery token, readable by the page's own scripts so they can send it back in a header. It carries no identity. |
No cookie here is used for advertising, profiling or cross-site tracking, and none is set by a third party. There is no local storage, no sessionStorage, no IndexedDB and no service worker. Clearing your browser's cookies for this site is therefore a complete reset of everything we know about your browser, and blocks nothing else.
What this site never does
- No IP addresses are stored. A salted digest of the address is kept in memory for at most the current day (salt rotated every 24 hours) and is used only to rate-limit abuse. It is never written to the database, so there is nothing to leak and nothing to request.
- No third parties. No fonts, no CDNs, no analytics, no tag managers, no
embeds, no social buttons. Every request the page makes goes to this server: the Content
Security Policy is
script-src 'self'; style-src 'self'with no inline script and no inline style. - No profiling and no automated decisions. Scores are simple arithmetic over ratings (see how scoring works). Nobody is scored, ranked or segmented - cars are.
- No sale or sharing of personal data, because there is effectively no personal data beyond a username you invented.
How long things are kept
| Account | Until you erase it. There is no automatic expiry and no dormant-account purge. |
|---|---|
| Session | 30 days of inactivity, then the server-side session row is discarded. Signing out revokes it immediately. |
| Anonymous rater cookie | Up to one year, or until you clear your browser data, or until you create an account (at which point it is retired and its ratings are transferred). |
| Ratings | Until you delete the rating or the account it belongs to. |
| Rate-limit digests | In memory only, reset with the daily salt rotation. Never persisted. |
| Server logs | This application writes no access log and no request log by default. |
Your rights, and how to use them
Under the GDPR you can access, correct, export and erase your data, and object to processing based on legitimate interests. Every one of those is a feature here, not an email request:
| Access / portability (art. 15, 20) | Everything held about you is shown on your account page, and the same payload is available as JSON at GET /api/me if you are signed in. |
|---|---|
| Rectification (art. 16) | Edit any rating from your account page; scores and the affected car page update at once. There is no username change - delete the account and register again if you want a different one. |
| Erasure (art. 17) | Erase the account removes the account row, every rating it owns and all its sessions in one action. Anonymous ratings can be removed from the car's page in the same browser that created them. |
| Withdraw consent (art. 7(3)) | Consent is only used for the account record itself; withdrawing it means erasing the account, which the button above does. |
| Complaint (art. 77) | Contact the EU supervisory authority for your country if you believe this processing is unlawful. privacy@example.invalid is the contact for anything else first. |
Requests are answered within one month where they cannot be handled instantly by the buttons above.
Security measures
- Passwords are hashed with scrypt using a per-user salt and compared in constant time. A leaked database therefore does not reveal passwords, and cannot be used to sign in elsewhere without cracking each hash individually.
- Session cookies are
HttpOnly,SameSite=StrictandSecurewhen served over HTTPS, so scripts and cross-site requests cannot read them. - Every state-changing request needs a session-bound CSRF token plus a JSON content type that a cross-site HTML form cannot produce.
- The Content Security Policy forbids inline script and inline style, and the pages load nothing from other origins - so a would-be script injection has no route in and nothing to phone home to.
- Sign-in attempts and writes are rate-limited per anonymous identity, which slows credential stuffing without logging who you are.
Children
WheelScore is not directed at children and collects no age information. There is no account field for a date of birth, no advertising and no social feature, so there is nothing here that a child could be profiled by. If you believe a child has registered, deleting the account removes everything associated with it.
Changes to this notice
The version string at the top of this page is stored with every account at the moment of registration. If the notice changes in a way that affects what is collected, the version is increased - which makes it obvious, in the data itself, who agreed to what and when. Because accounts contain no email address, material changes are announced on this page rather than by email.
Contact
Data-protection contact: privacy@example.invalid. Controller: WheelScore (demo deployment). Please include your username and nothing else - we cannot look up an account by email address, and we would rather not hold the address you sent from.
This is a demonstration deployment; the contact details above are placeholders that any operator must replace before serving real users.