WeatherLabs
Home Explorer Playground Integrations Docs & API Account
Try the API
Legal

Privacy Policy

How WeatherLabs collects, uses and protects personal data, under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: 12 June 2026

Contents

  1. Who is the controller
  2. What we collect
  3. Purposes & lawful bases
  4. Processors & subprocessors
  5. International transfers
  6. Retention
  7. Your rights
  8. Security & breaches
  9. Complaints
  10. Contact

1. Who is the controller

The data controller for the personal data described here is WeatherLabs Ltd, a limited company registered in England and Wales (company number 17265453), with its registered office at 2 Arnewood House, Everton Road, Lymington, SO41 0HF, United Kingdom. You can contact us about privacy at contact@weatherlabs.io.

2. What we collect

We aim to collect only what we need to run the Service. Specifically:

  • Account data — your email address and the user identifier assigned by our identity provider (Clerk). Authentication (sign-up, sign-in, sessions) is handled by Clerk on our behalf.
  • Billing data — payments are handled by Paddle as merchant of record. We do not see or store your card details. We store the Paddle customer ID and subscription ID so we can match your subscription to your account and apply the right Plan and quota.
  • API usage data — for each request we record metadata such as the API key identifier (not the secret), request and byte counts, the endpoint called, and timestamps. We use this for metering, billing, quotas, abuse-prevention and to show you your usage.
  • Server logs — our servers keep operational logs that may include your IP address, user-agent and request details, for security, debugging and abuse-prevention.
  • Site storage — the website stores small items in your browser's localStorage/sessionStorage to remember your settings and (optionally) your API key on your device. We do not use advertising cookies or third-party tracking cookies. The keys we set are:
    KeyPurpose
    wl_api_keyYour forecast-API key, if you choose to store it (session-only by default; on this device only if you tick "remember").
    wl_api_baseThe API endpoint the Explorer/Playground points at.
    wl_account_baseThe account/dashboard API endpoint.
    wl_dev_emailIdentity in local development mode only.
    We also store a wl_theme preference (light/dark). These items stay in your browser; clearing your browser storage removes them.

3. Purposes & lawful bases

WhatWhyLawful basis (UK GDPR)
Account & authenticationCreate and secure your account; provide the ServicePerformance of a contract (Art. 6(1)(b))
Billing & subscriptionsTake payment, apply your Plan, issue recordsContract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c))
Usage metering & quotasMeter usage, enforce quotas, bill correctlyContract (Art. 6(1)(b))
Security, logging & abuse-preventionKeep the Service safe and available; investigate misuseLegitimate interests (Art. 6(1)(f)) — protecting our service and users
Service communicationsNotify you about changes, incidents, billingContract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have considered your rights and freedoms and limit processing to what is necessary. You can object to processing based on legitimate interests — see your rights.

4. Processors & subprocessors

We use a small number of carefully chosen providers to deliver the Service. They process personal data on our behalf, under contract, only for the purposes we set:

ProviderRoleData involved
Clerk, Inc.Identity / authenticationEmail, user id, session data
Paddle (Paddle.com Market Ltd)Payments & merchant of recordBilling details, payment data (held by Paddle), customer/subscription ids
Amazon Web Services (AWS)Hosting & infrastructure — region eu-west-2 (London)Application data, usage records, server logs

This list may change as the Service evolves; we will keep it current and give notice of material changes. Our primary hosting region is AWS London (eu-west-2).

5. International transfers

Our hosting is in the UK (AWS London). However, some providers — in particular Clerk and Paddle — may process personal data outside the UK (including in the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), and/or transfers to countries the UK government has deemed adequate.

6. Retention

We keep personal data only as long as we need it:

DataRetention
Detailed usage charts / request-level metadataApproximately 45 days
Billing & monthly usage records6 years (to meet HMRC / UK tax record-keeping obligations)
Server logs (incl. IP)90 days or less
Account dataUntil you delete your account (then erased, subject to records we must keep by law)

7. Your rights

Under UK GDPR you have the right to: access your personal data; have it rectified if inaccurate; have it erased; restrict or object to its processing; and request portability of data you provided to us. To exercise these rights, contact us (below) — we will respond within the statutory timeframe (normally one month).

Self-service account deletion. You can delete your account from your dashboard. Deleting your account revokes your API keys, cancels your subscription, and erases your personal data from our systems — except records we are required to keep by law (for example, billing records retained for tax purposes), and copies in routine backups which are overwritten on our normal cycle.

8. Security & breaches

We take appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and storing API keys as secrets rather than in plain logs. No system is perfectly secure, but if a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will inform affected users without undue delay where the breach is likely to result in a high risk to them.

9. Complaints

If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO) — ico.org.uk.

10. Contact

Privacy enquiries and rights requests: contact@weatherlabs.io (general: hello@weatherlabs.io). The controller's full legal details are in section 1.

WeatherLabs

Meteorological research lab making global weather data accessible.

United Kingdom

Product
DocumentationPricingData status
Legal
Terms of ServicePrivacy PolicyAcceptable UseRefunds
Contact
hello@weatherlabs.iocontact@weatherlabs.io
© 2026 WeatherLabs Ltd · Registered in England & Wales · Company No. 17265453Privacy · Terms