Legal
Privacy policy
Version 2.1 · Last updated: Jul 1, 2026 · Controller: Daywhere Labs S.L. · dpo@daywhere.app
In short
By creating your account you authorize us to process your location to count your days and to store your data and proof, encrypted. The detail of your position is processed on your device; only the essentials reach our servers. We do not sell your data to anyone, and you can revoke consent, export everything, or delete your account from Settings at any time.
1. What data we process
CategoryWhat it includes and where it lives
AccountName, email and password (hashed). On our EU servers.
LocationPrecise coordinates are processed on your device and discarded; what is kept is the result (country/zone and day). With backup enabled, that result travels encrypted to EU servers.
ProofThe documents you upload (tickets, receipts) and their metadata (date, coordinates, stay). Encrypted on your device and in the backup.
Usage and diagnosticsOn the web, anonymous cookie-free navigation statistics; events tied to your repeat visits and error logs, only if you accept analytics (optional).
PaymentsHandled by our payment provider; Daywhere never sees your full card number.
2. Purposes and legal basis
Counting your days and generating reports — your explicit consent when enabling location (revocable; automatic counting stops if you revoke it). Storing your encrypted backup — consent and performance of the contract. Billing and support — performance of the contract and legal obligations. Analytics and improvement — anonymous, cookie-free statistics under legitimate interest (they write nothing to your device and cannot identify you); the cookie that recognises repeat visits, only with your consent. We do not make automated decisions with legal effects on you, and we do not use your data for advertising or sell it.
3. How long we keep it
For as long as your account exists: the multi-year history is the whole point of Daywhere in the event of an audit of past years. If you delete your account, we erase your data and backup within 30 days at most, except what the law requires us to retain (invoices, for example).
4. Who we share it with
No one, by default. We use data processors (hosting and payments) located in the EU under GDPR-compliant contracts. We will only disclose data to authorities when required by law, and we will notify you unless legally prohibited.
5. Your rights
Access, rectification, erasure, objection, restriction and portability: from Settings → Data and privacy, or by writing to dpo@daywhere.app. We respond within 30 days at most. If you are not satisfied, you can file a complaint with the AEPD (aepd.es).
6. Security
AES-256 encryption at rest and TLS in transit, per-user keys, and internal access under least privilege. If a breach posing a risk to you were to occur, we will notify you and report it to the AEPD within 72 hours.
7. Cookies and similar technologies
TypePurposeConsent
NecessarySession, security and basic site preferences.Not required
AnalyticsMeasure web and app usage to improve them. Without your consent, measurement is anonymous and cookie-free; with it, a cookie recognises your repeat visits.Optional
MarketingCampaign measurement. Never profiled with your location data.Optional
You can change your choice anytime from the website's cookie page or, in the app, in Settings → Data and privacy.
8. Changes to this policy
If a change affects how we process your location or your proof, we will ask for your consent again; for everything else, we will give you 30 days' notice in the app and by email.