Privacy Policy
Last updated: July 21, 2026
This document describes the data processed by atm-fees.com and by the ATM Fees Android app, which displays that same website.
Who is responsible
The site is published and operated by an individual, Vincent Reuter, in a personal and non-commercial capacity. For any question or request regarding your data, please use the contact form.
No account required
There are no user accounts. You can browse every withdrawal fee without providing any information whatsoever.
Collected automatically
For each page viewed, an analytics record is stored:
- the page viewed, date and time, display language;
- the referring page and the country the connection originates from;
- device type, browser and operating system;
- technical browser characteristics (screen size, CPU cores, colour depth) and automation signals, used to tell human visitors from bots — without which the statistics would be meaningless;
- a session identifier, valid for the duration of your visit;
- a fingerprint of your IP address.
Your IP address is never stored in clear text. It is converted into a cryptographic fingerprint before being recorded, which makes it possible to recognise two visits from the same origin without storing an identifying address.
This data is never sold, shared, or used for advertising. It serves only to understand how the site is used and to improve its content. No advertising cookies and no third-party trackers are set.
What you provide voluntarily
- Comments — nickname, comment, language, and optionally an email address. Nickname and comment become public after moderation. The email address is never displayed: it is only used to show your avatar if you have one, and to reply to you where appropriate.
- Contact form — your email address and your message.
- Fee or country suggestions — the information you enter, the display language, the country the connection originates from, and optionally your email for follow-up.
For comments and contact messages, a fingerprint of your IP address is also kept, to limit abuse. Again, never the address itself.
Cookies and local storage
The site uses a minimal number of cookies, all strictly functional:
- a session cookie, required for form security;
- a cookie recording that you are using the site in app mode;
- an analytics identifier.
Your browser also stores, locally and without sending it to the site:
- the nickname and email address you entered in the comment form, to pre-fill them next time;
- the currency you selected for fee conversion;
- how often informational messages and banners are shown;
- in the app, the date of the last offline save.
Clearing the site's data in your browser removes all of it.
No advertising cookies, no social network cookies, no sharing with ad networks.
Offline use
The Android app stores country pages on your device so they remain available without a network connection. This data stays on your phone and is not transmitted to anyone. Uninstalling the app removes it.
Third-party services
- IONOS (Germany) — website and database hosting.
- ip-api.com — determines the country of connection, for
statistics. We never send your full address: it is truncated to its
network prefix first (for example
81.240.17.42becomes81.240.17.0), which is enough to identify the country without transmitting an individual address. Prefixes already seen are cached, which greatly limits the number of calls. - jsDelivr — delivery of display components (flags, charts). Your browser downloads these directly from that service.
- Gravatar — commenter avatars. Images are relayed by our server: your browser never contacts Gravatar, and no information about you is sent to it.
- open.er-api.com — exchange rates, called by our server. No data about you is sent to it.
- Google Play — distribution of the Android app, subject to Google's own privacy policy.
Retention
Data is deleted automatically beyond the following periods, by a daily task:
- Analytics: 25 months. This matches the maximum recommended by the
French data protection authority (CNIL) for audience measurement; it allows one year to
be compared with the previous one, which a shorter period would prevent.
Beyond that, detailed records are deleted, but anonymous monthly totals are kept indefinitely: page views per country, language, browser or device type. These counters contain no identifier whatsoever — no IP fingerprint, no session identifier, no individual browser characteristic — and therefore cannot be traced back to anyone. They exist to track how traffic evolves over time. - Fee suggestions: 24 months, the time needed to verify and incorporate them.
- Contact messages: 12 months, along with the technical log of emails sent (recipient and subject).
- Administration login attempts: 1 hour.
- Published comments are not deleted automatically: they are published content. They are removed at your request or at our initiative. For as long as a comment exists, the email address you may have provided and the associated IP fingerprint are kept with it — neither is ever displayed.
- The identifiers attached to fee confirmations (IP fingerprint and session identifier) are erased after 25 months; the confirmation date itself is kept, as it is displayed on the site.
Your rights
Under the GDPR you have rights of access, rectification, erasure, objection and portability. Write to us through the contact form.
One useful clarification: because analytics data is recorded as non-reversible fingerprints, we are technically unable to locate your visits from your IP address. This limitation protects your privacy, but it also prevents us from answering an access request covering that data. Comments and messages, by contrast, can be located from their content or the email address used.
You may also lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
Children
The site is not directed at children and does not knowingly collect data about them.
Changes
Any change to this policy will be published on this page, with the date above updated.