Effective 22 September 2026
WME Requests ("the Service", "we", "us") is a companion dashboard and browser userscript used by Waze Map Editors to submit and route lock/imagery/permissions requests. It is an independent, unofficial community tool and is not affiliated with, endorsed by, or operated by Waze or Google. This policy explains what data the Service processes, why, and who it's shared with. For questions, deletion requests, or anything related to data protection (including GDPR requests), contact wazer@wazetools.com.
We only store the personal data described in this policy — nothing beyond what's needed to run the Service. We don't buy, sell, or trade personal data, and we don't run advertising of any kind. In particular:
When a Waze editor submits a downlock/uplock/imagery/PUR request from inside the Waze Map Editor, the Service stores:
A Waze username is a public in-game identifier you chose yourself, not your legal name — but we recognize it can still identify you, and we treat it accordingly under this policy.
Global admins and users who configure notification channels may store webhook URLs, bot tokens, Google service-account keys, or SMTP/Postmark/Mailgun credentials so the Service can deliver notifications on their behalf. These are encrypted at rest (see § 5) and are never displayed again after saving.
A country's admins choose which of the following channels, if any, receive a copy of a submitted request (permalink, notes, lock level, submitter username, and screenshot if attached). We only send data to a channel that's been deliberately configured — nothing is sent to a third party by default.
None of these providers receive dashboard account data (your login email/password) — only the request content described above, and only for the countries/regions their channel is scoped to.
We use PostHog (hosted in the EU) for product analytics — understanding which features are used and catching errors. There are two categories:
Declining browser analytics doesn't affect your ability to use the Service.
The Service runs entirely on Cloudflare's platform:
As our infrastructure provider, Cloudflare processes this data on our behalf under its own privacy and security commitments; it is not used by Cloudflare for its own purposes.
You can change your analytics choice at any time — clear your browser's local storage for this site to see the cookie banner again.
No system is perfectly secure, but we design the Service to minimize what personal data it holds in the first place, so there's less to protect and less at risk if something goes wrong.
Request records (including notes, screenshots, and permalinks) are automatically and permanently deleted 24 hours after submission, or sooner if an admin removes them manually. Account and configuration data (users, countries, channels) is kept for as long as they're operationally useful, and deleted when an admin removes them. Analytics events in PostHog follow PostHog's own retention settings for our account.
Depending on where you're located, you may have rights under data protection law (such as the GDPR) to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these, or for any other privacy question, email wazer@wazetools.com. We'll respond as soon as we reasonably can.
We may update this policy as the Service changes. Material changes will be reflected by updating the effective date above.