Skip to main content
Finding Flock

Privacy

What this site collects

This is a site about being watched, so it owes you a specific answer rather than a page of boilerplate. Finding Flock runs two analytics tools and carries display ads from one advertising network, and nothing else. There are no accounts, and nothing about you is for sale. Below is what each piece does, what leaves your browser, and how to stop all of it.

The short version

Every page loads Google Analytics and Vercel Web Analytics. Most reading pages also show ads from one network, Adsterra — at most two banners, each loaded only after the page has finished and only as you scroll near it. That is the complete list of tracking scripts we put on this site. There is no session recorder, no A/B testing tool, and no retargeting pixel of our own; what the ad network and its advertisers run inside their ads is covered under Advertising below, along with the pages that carry none. The map is the one page that reaches further in other ways: it draws its background from one outside service and answers searches from another, and each sees your IP address the way any web request does. Both are named in full under What the map loads below. The plate lookup is another exception: your browser sends our server only a short hash of the plate you type, and our server asks Have I Been Flocked?, an independent collection of released Flock search logs, for matching records, as set out under The plate lookup. And if you use the contact form, your message is delivered to our inbox by an email service, as described under The contact form, along with the invisible bot check that the form and the plate lookup both run.

There is nothing to sign up for. No accounts, no logins, no newsletter, no comment box. The only places you can type anything are the search box on the map, the plate lookup, and the contact form, and what happens to each is described below. We do not sell, rent, or trade anything about visitors ourselves, and there is no visitor database to sell; what the ad network collects on its own account is set out under Advertising.

Analytics

Google Analytics 4 loads on every page from googletagmanager.com. Its configuration is a short inline snippet you can read in this page’s source — four statements that initialize the tag and send the page view. The one other thing we send it is page-speed measurements: how quickly each page drew, how quickly it responded to a tap or click, and whether its layout jumped, labelled with the kind of page (a city page, an article, the map). We use them to check that ads are not slowing the site down. We set no user identifiers, attach no advertising features, and pass it no other content of our own. It collects what Google collects by default for any site — the page URL and referrer, an approximate location derived from your IP address, and your device and browser — under Google’s own terms, not ours.

Vercel Web Analytics runs alongside it and reports aggregate page views and traffic sources for the site. Vercel documents it as cookieless and non-identifying; the only thing our code does is include it.

We look at both for one reason: to see which explainers and which city pages people actually use, so the reporting and the data go where they are read. Nothing in our own code changes based on who you are, because we do not know — the one exception is whether ads load at all, described next.

The site is served by Vercel, which — like any host — processes the requests needed to deliver a page, including your IP address and browser. That is true whether or not analytics loads.

Advertising

Finding Flock pays for itself with display advertising supplied by Adsterra. A reading page shows at most two banners, each labelled as an ad. The map, the plate lookup, the contact form, this page, the about page and error pages show none. We choose where ads may appear and what sizes they are; the network chooses the ads themselves. Adult advertising is switched off in our account, but we do not review individual ads, and an advertiser’s own page is theirs, not ours. If you see an ad that is misleading, offensive, or pretends to be part of this site, write to us with the page it appeared on.

The ad code loads from Adsterra’s servers only after the page itself has finished loading, and only when you scroll near an ad. Each ad’s creative — the image or text an advertiser supplies — runs inside a sandboxed frame that cannot send your tab to another site unless you click it. The network’s own loader script, which fetches those creatives, has the same access to the page as our own code does, exactly as it would with the network’s standard installation.

What the network sees is what any ad network sees: your IP address, your browser and device, and — because its code runs within our pages — the address of the page you are reading. Adsterra sets cookies to count impressions and clicks, to limit how often you see the same ad, and to detect fraud. Some of those cookies are stored under this site’s own domain, because the ads run in frames on our pages; others belong to the network’s ad-serving domains. In our own test they lasted from a day to a year on this site’s domain, and up to about thirteen months on the ad domains. All of it is governed by Adsterra’s privacy policy, not ours. We pass the network nothing ourselves — no identifiers, no search terms, nothing from the map — but its loader can read anything a script on these pages can, including the Google Analytics cookie.

Some visits get no ads at all. If your browser sends Global Privacy Control, no ad code loads — several US state privacy laws treat ad cookies as sharing personal information for advertising, and that signal is how you opt out of it. If your device is set to a European time zone, no ad code loads either: the UK and EU require consent before ad cookies, and rather than put a consent banner in front of a reference site, we simply leave the ads off there. And any content blocker stops the ads entirely; nothing on the site depends on them.

Cookies

Our own code never sets or reads a cookie, and it stores nothing in your browser’s local storage. Google Analytics does set cookies of its own — the _ga pair — which is how it tells a returning visitor from a new one. The ad network sets its own too, as described under Advertising, including some stored under this site’s domain. Block either script and its cookies never appear.

What the map loads

The map runs in your browser and pulls from a few outside services. Each one necessarily sees your IP address, the way any web request does, and each keeps its own logs under its own policy:

OpenFreeMap (tiles.openfreemap.org) serves the background map — the roads, water, and labels underneath the camera dots.

The camera layer is a single pre-built tile file served from this site or its storage host. It contains camera locations only; nothing about you is sent to fetch it.

Photon (photon.komoot.io) turns what you type in the map’s search box into coordinates. When you type at least two characters and pause, that text is sent there and nowhere else. We do not log searches, store them, or send them to analytics.

OpenStreetMap is contacted only if you click through from a camera’s panel to view or edit its underlying record.

One consequence worth stating plainly: as you pan the map, the coordinates and zoom level are written into the page URL so the view can be linked and reloaded. While Google Analytics is loaded, the page URL is part of what it records — so the area you were looking at can be visible to it. Blocking the analytics script, or clearing the lat, lng, and zoom parameters, ends that.

The contact form

When you send the contact form, your name, email address, topic, and message go to this site’s server, which passes them straight to Resend, an email delivery service, to be sent to our inbox at info@findingflock.com. Nothing is written to a database or kept on the server, and our code logs only whether a send failed, never who wrote or what they said. Vercel, our host, records the request itself (your IP address and browser) as it does for every page, but not what you wrote. To keep the form from being flooded, the server counts recent sends from each sender, holding only a salted hash of the IP address in memory for ten minutes and never writing it down.

The contact page also runs Vercel BotID, an invisible check against automated spam, and so does the plate lookup; no other page does. Your browser solves a small challenge sent by Vercel, and when you press Send message Vercel confirms the answer before the server reads the form. It shows no puzzle, sets no tracking cookie, and checks the browser, not what you wrote. It is the reason the form needs JavaScript; without it, you can email us instead.

Resend keeps a copy of each email it delivers for 30 days, under Resend’s privacy policy, and then deletes it. The message then sits in our inbox like any email you send us. We use your address only to reply; we never add it to a mailing list, and never share or sell it.

The plate lookup

The plate lookup checks a license plate against Flock search records collected by Have I Been Flocked?, an independent project that gathers the audit logs agencies have released through public records requests. During a lookup, the plate itself never leaves your browser. Your browser tidies it (capital letters, no spaces or dashes), adds the look-alike versions a searcher might have entered instead (0 for O, 1 for I, and the reverse), and computes a SHA-256 hash of each, a one-way fingerprint of the text. Only the first eight characters of each hash are sent.

They go to this site’s server, which forwards them to Have I Been Flocked? and passes back the matching records; your browser shows the ones for your plate and its look-alikes. Have I Been Flocked? receives the request from our server, not from your browser, so it does not see your IP address. Our server keeps none of it: the prefixes and the records that pass through are not written to a database, cached, or logged, and our code logs only whether a lookup failed. Vercel, our host, records the request itself (your IP address and browser) as it does for every page, but not what it carries.

A prefix is not anonymous. It keeps the plate out of the request, but anyone who already has a plate, or a list of plates, can compute the same prefix, which is how the lookup finds matches at all. That is why nothing about a lookup is kept.

To keep the lookup from being overused, the server counts recent lookups from each visitor the way it counts contact-form sends, holding only a salted hash of the IP address in memory for ten minutes and never writing it down. The lookup page also runs Vercel BotID, described above. Our code sends nothing about a lookup to analytics, and the plate is never put in the page address, so Google Analytics does not record it.

After a lookup, the page can offer a button that opens Have I Been Flocked? in a new tab with your plate filled in, where you press Search yourself. It appears with results, and in their place when the lookup can’t reach its records. The button sends the plate from your browser straight to Have I Been Flocked?, in the address of the page it opens, under its privacy policy, which says it does not log what you search for. This site takes no part in that search and records nothing about it.

The records are Have I Been Flocked?’s, not ours. The lookup shows some of each record’s fields (the date, the agency, the reason given, and how many cameras were searched) and leaves out the searcher’s name and the case number. To have a plate’s records hidden from this site’s lookup, use the contact form and choose the plate lookup as the topic. Have I Been Flocked?’s redaction policy explains how to ask it to remove personal details from the records it publishes.

The camera data is not about you

The locations on this site come from OpenStreetMap contributors, who document license plate readers they observe on public roads. It is a record of fixed public infrastructure — a pole, a camera, sometimes the manufacturer and the direction it faces. It contains no plate reads, no vehicle records, and no personal information about anyone, visitors of this site included. How it is gathered and how to correct it is documented on the methodology page, and the whole dataset is downloadable.

The plate lookup is the exception: the search records it shows concern a particular plate, and they come from Have I Been Flocked?, fetched when you ask and not kept here.

How to turn it off

Any content blocker or browser tracking protection that blocks googletagmanager.com stops Google Analytics here, and Google publishes an official opt-out browser add-on that does the same across every site. Blocking works on this site without breaking it: analytics is not load-bearing, and every page, the map included, works with both analytics tools blocked. The same goes for the ads: block the ad network, or send Global Privacy Control, and every page reads exactly the same without them.

The map’s own third parties are a different matter, and worth knowing before you block them wholesale. The background map is drawn from OpenFreeMap, so blocking tiles.openfreemap.org leaves the map page without a map. Photon only answers the search box: block photon.komoot.io and search stops returning results, while the rest of the map behaves normally.

To be honest about the limits: the only place this site reads a privacy signal is the ad loader, which stays off when your browser sends Global Privacy Control. Nothing in our code reads Do Not Track, and Google Analytics still loads when Global Privacy Control is on, so for analytics, blocking the script is the route that actually works.

Questions and corrections

If a camera on the map is wrong, moved, or gone, the fix belongs in the underlying OpenStreetMap record — the methodology page explains how, and the change reaches this site with the next refresh. For anything about this page, or about the site generally, use the contact form or write to info@findingflock.com, the same address listed on the about page. If this page and the site’s behavior ever disagree, tell us and we will correct the page.