Effective 2 October 2026
Your WMEKit account (auth.wmekit.com, "the account service", "we", "us") is the one sign-in for WMEKit apps such as WME Requests and WME Sync. WMEKit is an independent, unofficial community project for Waze Map Editors. It is not affiliated with, endorsed by, or operated by Waze or Google. WMEKit is run from South Africa, so this policy follows the Protection of Personal Information Act (POPIA), and the GDPR and UK GDPR for people in Europe and the UK. It explains what we collect, why, how long we keep it, who it's shared with, and the choices you have. If anything is unclear, email wazer@wmekit.com.
This policy covers the account service: signing up, signing in, the account and security pages, and the emails it sends. Each WMEKit app has its own privacy policy for the data it keeps itself (for example the requests you submit in WME Requests, or the settings you sync in WME Sync).
If you sign in with or connect Google or Discord, that provider tells us your account ID there, your name, email address, whether the email is verified, and your profile picture. We store these along with the tokens the provider issues for the connection. We don't request access to your contacts, files, messages, or anything else. You can disconnect a provider at any time on your account page.
POPIA, the GDPR and the UK GDPR each require a lawful reason (a "legal basis") for using personal information. These are ours:
| Purpose | Legal basis |
|---|---|
| Creating your account, signing you in to WMEKit apps, sending verification, password and sign-in code emails | Providing the service you asked for (contract) |
| Keeping accounts secure: the security log, bot protection, alerting you to important account changes, detecting and stopping abuse, error reports | Our legitimate interest in keeping the service and your account safe |
| Product analytics | Your consent, which you can withdraw at any time |
| Answering your emails and requests | Our legitimate interest in helping you, or a legal obligation (for data requests) |
We send emails only about your account: verification, password resets, sign-in codes, invitations from an app admin, and security alerts. We don't send marketing emails.
Cloudflare and PostHog process data on our behalf and may only use it to provide their services to us. We don't sell personal data or share it for advertising.
Cloudflare runs a global network, and our service providers may process data in countries other than yours, including the United States. We only use providers bound by agreements that protect your data to a standard comparable to POPIA (as section 72 of POPIA requires), such as standard contractual clauses for data from Europe and the UK.
Essential cookies keep you signed in. They're scoped to wmekit.com so every WMEKit app can recognise you, and they're needed for the service to work, so they don't need consent.
| Name | Purpose | Lasts |
|---|---|---|
| wmekit.session_token | Keeps you signed in across WMEKit apps | 7 days, renewed while you use it |
| wmekit.session_data | A signed copy of your session, so apps don't look it up on every request | 5 minutes |
| wmekit.two_factor | Remembers that you're midway through a two-factor sign-in | 10 minutes |
| wmekit.trust_device | Skips the two-factor step on a device you chose to trust | 30 days |
| Sign-in state cookies | Protect a Google or Discord sign-in from being tampered with | Minutes, during sign-in |
| wmekit-account-cookie-consent (local storage) | Remembers your analytics choice | Until you clear it |
| mantine-color-scheme-value (local storage) | Remembers light or dark mode | Until you clear it |
| ph_* (PostHog), only if you accept analytics | Tells visits apart for analytics | Up to 1 year |
To change your analytics choice, clear this site's data in your browser and choose again when the banner reappears.
Everything is served over HTTPS. Passwords and email codes are hashed, two-factor secrets are encrypted, and passkeys and security keys never share their private keys with us. Sign-in forms are protected against bots, and the security log lets you spot activity you don't recognise. You can add two-factor authentication on your account page. No system is perfectly secure, so if we ever learn of a breach that affects your data, we'll tell you and, where required, the relevant authorities.
On your account page you can at any time:
Depending on where you live, you may also have the right to access your data, get a copy of it in a portable format, have it corrected or deleted, restrict or object to how we use it, and withdraw consent. To use any of these, email wazer@wmekit.com from the address on your account. We'll respond within 30 days and may need to confirm it's really you. Deleting your WMEKit account doesn't by itself delete data an app keeps (such as your synced settings in WME Sync); tell us if you'd like that removed too, and we'll do it.
If you're unhappy with how we've handled your data, please contact us first. You also have the right to complain to South Africa's Information Regulator, or, if you live elsewhere, to your local data protection authority.
WMEKit is meant for Waze Map Editors and isn't directed at children. You must be at least 16 to create an account. If you believe a child has given us their data, contact us and we'll delete it.
We'll update the effective date above whenever this policy changes. If a change significantly affects how we use your data, we'll tell you by email or with a notice when you sign in, before it takes effect.
For questions, requests or complaints about privacy, email wazer@wmekit.com. See also our Terms of Service.