Skip to content
WheyWijzer

Privacy Policy

WheyWijzer respects your privacy. This privacy policy explains what data we collect, why, and how long we retain it.

Data Controller

WheyWijzer is responsible for processing personal data as described in this privacy policy. For questions, contact us at the email address at the bottom of this page.

What data do we collect?

  • Rating data: stars (1-5) and thumbs (up/down) you give to products.
  • IP address: stored as a hash (encrypted) for spam prevention. The original IP address is not retained.
  • Browser fingerprint: a hash of technical browser characteristics (screen size, timezone, language) for spam prevention. This is not unique identification.
  • Cookie (ww_rid): a functional cookie to prevent duplicate ratings. Valid for 30 days.
  • Language preference: stored in your browser (localStorage) to display the site in your language.
  • Country detection: we use headers from our hosting provider (Netlify/Cloudflare) to detect your country. This is stored in a cookie (ww_country, 30 days) to show relevant products.
  • Discount codes: when submitting a discount code, we store a hashed version of your IP address to prevent abuse (maximum 3 codes per IP per 24 hours).
  • Code votes: when voting on whether a code works, we store a hashed version of your IP address to prevent duplicate votes.
  • Review requests: when you request a review via our form, your brand name, product, email address and message are processed by Netlify Forms.

Cookies

Below is an overview of all cookies and similar technologies we use.

CookiePurposeTypeRetention
cookie_consentStoring your cookie preferencelocalStoragepermanent
ww_countryShowing products available in your countrycookie30 days
ww_ridPreventing duplicate ratingscookie (httpOnly)30 days
_ga / _gidGoogle Analytics (only after consent)cookie (opt-in)2y / 24h

Why do we collect this data?

We collect this data solely to operate the rating system and prevent spam. When you accept all cookies, we use Google Analytics 4 to anonymously measure site usage. It is not loaded without your consent.

Third parties

We only share data with third parties when necessary for the operation of our service. Below is a complete overview:

  • Google Analytics 4: only active after your explicit consent. IP addresses are anonymised. Google processes aggregated visitor statistics. Privacy policy: https://policies.google.com/privacy
  • Netlify: our hosting provider. Processes web traffic, provides country detection via Cloudflare, and handles review request forms (Netlify Forms). Privacy policy: https://www.netlify.com/privacy/
  • Awin and Daisycon: affiliate networks that track clicks to web shops. We do not share personal data; only an anonymous click reference is forwarded.
  • Neon (PostgreSQL): our database provider, hosted in the EU (Frankfurt). Stores all product data and hashed user data. Privacy policy: https://neon.tech/privacy

Affiliate links

WheyWijzer earns a commission when you purchase a product through our affiliate links. Clicks are tracked by the affiliate network (Awin/Daisycon). No personal data is shared, only an anonymous click reference. This does not influence our rankings or reviews. All products are objectively evaluated regardless of affiliate partnerships.

Legal Basis

We process data on the following legal bases: (1) Consent (Art. 6(1)(a) GDPR): Google Analytics is only activated after your explicit consent via the cookie banner. (2) Legitimate interest (Art. 6(1)(f) GDPR): preventing spam and abuse via IP hashing, fingerprinting and cookies. Affiliate tracking also falls under legitimate interest. (3) Performance of a contract (Art. 6(1)(b) GDPR): processing email addresses for newsletters and price alerts you voluntarily sign up for.

Retention Period

Rating data and associated hashes: maximum 30 days, then automatically deleted. IP hashes for discount codes and votes: indefinite (anonymised). Newsletter emails: until unsubscription. Price alerts: until triggered or deleted by you. Google Analytics data: according to Google's own retention policy. Cookies: ww_country and ww_rid maximum 30 days, cookie_consent permanent until you change it.

Your Rights

Under GDPR you have the following rights:

  • Right to access your data
  • Right to rectify your data
  • Right to erasure of your data
  • Right to restrict processing
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

If you believe we are not handling your data carefully, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, https://autoriteitpersoonsgegevens.nl).

Contact

For privacy questions or to exercise your rights, contact us at: privacy@whey-wijzer.fit

Changes

This privacy policy may be updated. The most current version is always available on this page. Last updated: March 2026.