OUR PRIVACY POSTURE
Anonymous by default.
Privacy isn’t a feature — it’s the foundation. Where’s Busy was designed so that even if someone broke into our database, the most they’d find is a count of doors opening.
WHAT WE COLLECT
-
Aggregate door counts
From the venue’s clicker. A number going up, a number going down. No identifier.
-
Anonymous check-in pulses
If you opt in. One button, one tap. No email, no name, no history of you.
-
Venue-tap categories
Helps us know which neighbourhoods are over-served. We don’t store which exact venues you tapped.
WHAT WE DON’T
-
Location, ever
No GPS. No “use your location” prompts. The app uses what you tell it about your city, full stop.
-
Personal IDs
No accounts required. No phone number. No persistent device fingerprint.
-
Demographics
No age, no gender, no ethnicity, no income. We don’t want it and we won’t store it.
-
Re-identification data
Nothing about you that could let us — or anyone who got our database — work out who you are.
HOW WE TALK ABOUT IT
Aggregated by design. Never personal.
Most of the “privacy-first” claims in tech mean something like: we have your personal data, but we promise to behave with it. We don’t want that promise on our shoulders. So we built Where’s Busy as a system that doesn’t accept the data in the first place.
Aggregation isn’t something we do at the end of the pipeline to make a chart. It’s the only data we ever hold. The clicker doesn’t know who you are; the cloud doesn’t know who you are; the dashboard couldn’t tell you, even if it was hacked.
That’s not a marketing line. That’s the architecture.