Privacy notice

How SimplyWayfinding handles information

SimplyWayfinding is operated by Allen Gibson, who is the data controller for the processing described in this notice. It helps people find their way around hospital sites using QR links, searchable start points and destinations, and route guidance.

Last updated: 23 July 2026

Who is responsible

Allen Gibson is the data controller for personal information handled for SimplyWayfinding. The privacy contact is info@simplywayfinding.com.

Information handled when you use the site

Route calculations take place in your browser. When you select a route within an already-loaded page, SimplyWayfinding does not intentionally send that selection to a database.

QR codes and shared links may contain a start point, destination, stair-free routing preference or other route parameters in the URL. When one of these links is opened, Netlify processes the complete requested URL as part of delivering the page. The URL may therefore appear in Netlify's technical request information and may contribute to analytics information about requested or popular pages.

SimplyWayfinding does not use destination-level information to infer an individual's health, medical condition, treatment or reason for visiting a hospital. Subsequent route calculation within an already loaded page takes place in the browser and does not intentionally create a separate database record of the selected route.

If you choose to submit feedback, route and technical context is sent with the feedback where it is relevant to the type of report. This can include start location, destination, route summary, avoid-stairs status, current floor, page URL, app and map versions, timestamp, browser user agent and viewport size.

Feedback

Feedback is collected using Netlify Forms. Feedback can be anonymous. Contact details are optional and are only needed if you want a reply.

The feedback form asks for feedback type, optional accessibility issue type, comments and optional email or phone contact details. It also sends technical fields needed to investigate the submission. Route, map, signage and accessibility reports include route context. General feedback does not intentionally include start location, destination, avoid-stairs status or route summary.

SimplyWayfinding does not ask for health information and does not use route destinations to infer anyone's health status. Please do not submit medical records, appointment details or unnecessary confidential medical information. A route destination or submitted comment may sometimes reveal or suggest information relating to healthcare. If feedback contains unnecessary health-related information, it will be redacted or deleted as soon as reasonably practicable.

Redacted or aggregated feedback may be shared with participating NHS organisations during testing and pilot evaluation. Identifiable feedback or contact details are not routinely shared. They will only be shared with a participating NHS organisation where you have made a separate, optional, affirmative choice allowing that sharing, or where disclosure is required by law.

Hosting and service providers

The site is hosted on Netlify. Netlify provides static hosting, Web Analytics and form processing for the feedback form. Netlify processes technical information needed to deliver, secure and administer the service, such as IP address, browser information, request details and server logs.

Netlify processes relevant technical information on behalf of SimplyWayfinding. The public application does not include a client-side analytics tracking script, advertising tag or third-party monitoring script. Netlify Real User Monitoring (RUM) is not enabled.

Netlify states that personal data may be processed outside the country where it was collected and that it uses legal mechanisms such as standard contractual clauses for relevant international transfers. Netlify's privacy information and data processing agreement describe how it handles data for its services. Netlify Forms submissions include the submitted fields and may also involve the submitter's IP address and request metadata as part of Netlify's technical service data.

Website analytics

Netlify Web Analytics is enabled. It is used to understand general use of SimplyWayfinding; measure page views and approximate visitor numbers; understand popular pages and broad traffic patterns; identify technical or navigation problems; establish a baseline and evaluate the service during development, testing and pilots; and support decisions about maintaining and improving the service.

Web Analytics is produced from requests handled through Netlify's servers and content-delivery network. It is server-side and does not require an analytics cookie or a client-side analytics tracking script. Netlify necessarily processes technical request information, which may include IP address, requested URL, date and time, browser or device information, referrer and request metadata. Cookie-free analytics does not mean that no personal data is processed.

Analytics results may include page views, approximate unique visitors, popular pages, referral sources and broad geographic or technical information, depending on what Netlify makes available.

SimplyWayfinding does not use analytics for advertising, individual profiling, automated decision-making or attempting to identify individual visitors. Analytics information is not deliberately combined with feedback contact details. It is not used to determine whether someone followed or completed a route.

Netlify Real User Monitoring (RUM) is not enabled.

Cookies, storage and offline caching

Netlify Web Analytics does not use analytics cookies. Netlify Real User Monitoring is not enabled. The service does not currently use non-essential cookies or other consent-requiring storage technologies, so SimplyWayfinding does not ask for cookie consent for Web Analytics.

This is separate from the functional local browser storage and offline caching described below; those technologies support the application and are not used for Web Analytics.

The application uses browser storage. Local storage keeps the last known site page until it is replaced or browser site data is cleared. Local storage also keeps a saved journey state so a route can recover after a reload; the Reset journey control, clearing the start or destination, or clearing browser site data removes that saved journey.

Session storage keeps the active journey state and a one-session intro flag. Session storage normally clears when the browser session or tab is closed. The Reset journey control clears the active and saved journey state. The intro flag is not cleared by Reset; it clears at the end of the browser session or when browser site data is cleared.

The Progressive Web App service worker stores essential website, map and application files in the browser's Cache Storage. This supports performance and allows parts of the service to continue working when connectivity is limited. Precached files remain until the application is updated, old caches are cleaned up or the browser removes them. Some same-site application assets may be retained for up to 30 days, subject to browser storage management.

Cache Storage and service-worker caching are separate from cookies. They do not by themselves tell the operator which route you planned. You can remove locally stored information by using the application's reset or clear controls where available, or by clearing site data in your browser.

Why information is used

Information is used to:

  • provide the website and route-planning interface;
  • receive, understand and respond to feedback;
  • investigate route, map, accessibility or technical problems;
  • understand use, establish a baseline and identify broad traffic patterns;
  • evaluate and improve the service during testing and pilots;
  • maintain hosting, security and reliability.

The legitimate interests for Web Analytics are understanding whether and how the service is used, establishing a usage baseline, evaluating its usefulness and performance, identifying technical and navigation problems, and maintaining, securing and improving SimplyWayfinding.

Safeguards supporting this assessment include server-side, cookie-free measurement; short analytics retention; no advertising, individual profiling or attempt to identify visitors; no deliberate combination with identifiable feedback; aggregate reporting; no use of destinations to infer health information; avoidance of destination-bearing URLs in retained reports; and keeping RUM disabled.

Retention

Identifiable feedback and associated contact details, including copies held in Netlify Forms and feedback-notification email, will be kept for no longer than 12 months from submission. They will be deleted sooner when no longer required to answer or investigate the feedback.

Feedback may be anonymised or aggregated for evaluation and service-improvement reporting. Properly anonymised findings may be kept for longer because they no longer identify the contributor.

Feedback records are reviewed and deleted manually.

Analytics information is available to SimplyWayfinding through Netlify for no longer than 30 days. The exact period may be shorter depending on the Netlify plan in use. Netlify may separately retain underlying hosting, security and technical service information in accordance with its own data-processing terms.

Aggregate analytics summaries may be retained for longer where they do not identify individual visitors. Manually retained analytics reports will contain aggregate figures only where reasonably practicable. SimplyWayfinding will not deliberately copy or retain destination-bearing URLs in screenshots, spreadsheets or pilot reports.

Changing the Netlify plan will not result in SimplyWayfinding retaining accessible analytics history for longer than 30 days without first updating this notice and reviewing the legitimate-interests assessment.

Your rights

UK data-protection law may give you rights, where applicable, to ask for access to your personal information, correction, deletion and restriction. You may object to processing based on legitimate interests and may withdraw consent where processing genuinely relies on consent.

To make a request, email info@simplywayfinding.com. You may need to provide enough information to identify the relevant feedback or request.

You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint/.

Changes

This notice will be updated when the service changes in a way that affects privacy, such as adding accounts, GPS or current-location features, client-side monitoring, RUM, advertising or profiling, additional analytics providers, live disruption services, databases, longer retention, destination-level analysis, or a material change in the controller or NHS involvement. The updated page will show a new last-updated date.