← LOCATIONiQ

Privacy Policy

Last updated: August 2026

1. Who we are

LOCATIONiQ is operated by [LEGAL ENTITY NAME], [BUSINESS MAILING ADDRESS], New York ("we", "us"). This policy explains what we collect, how we use it, and your choices. For privacy questions, email privacy@locationiq.io.

2. What we collect

  • Account data: your name, email, and authentication identifiers (Google OAuth / email magic-link).
  • Organization data: the sites, brands, criteria, analyses, reports, and attachments you create.
  • Contact data you supply: broker/landlord/agent/owner names, emails, and phone numbers you enter or import (with provenance).
  • Billing data: handled by Stripe; we store a customer/subscription id and plan status, not full card numbers.
  • Operational data: audit logs of sensitive actions, usage metering, and basic technical logs (e.g., IP address, timestamps) used for security and to run the Service.

3. How we use it

To provide and secure the Service, enforce plan limits, process payments, send transactional email (sign-in, invites, receipts, dunning, and digests you opt into), respond to support, comply with law, and improve the product. We do not sell or share your personal information for advertising, and we do not use it for third-party advertising.

4. Cookies

We use strictly-necessary cookies only — to keep you signed in and to secure your session. We do not use advertising, cross-site tracking, or third-party analytics cookies, so no cookie-consent gate is required; the notice you see is informational. You can clear cookies in your browser, but the Service will not stay signed in without the session cookie.

5. Sub-processors

We share data only with the providers needed to run the Service: hosting (Vercel), database (Neon/Postgres), payments (Stripe), email (Resend), file storage (Supabase), AI (Anthropic), and the public/third-party data APIs that power analyses (US Census, BLS, FRED, OpenStreetMap, mapping, and — where you enable them — parcel, places, foot-traffic, and listings providers). Each processes data under its own terms. A current list is available on request.

6. Tenant isolation

Your organization's data is logically isolated; members of other organizations cannot access it. Platform administrators may access data only for support, security, and operations.

7. Retention

We keep your data while your account is active. Delete your account to remove it (see below). Backups roll off on a standard schedule. Some records may be retained where required by law or to resolve disputes.

8. Your rights (CCPA/CPRA & GDPR)

You can export your data and delete your account at any time from Account settings, or by emailing privacy@locationiq.io. Deleting your account removes your personal data and, where you are the sole member of an organization, that organization and its data.

California residents (CCPA/CPRA): you have the right to know, access, correct, and delete your personal information, and to opt out of "sale" or "sharing." We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising these rights.

Residents of the EU/UK (GDPR/UK GDPR) have rights of access, rectification, erasure, restriction, portability, and objection. For customer data you upload as a controller, we act as your processor under our Data Processing Addendum.

9. Public Location Scores

Our free Location Score tool creates a public web page for any address you submit — showing the address, an approximate location, and a generic suitability score from public Census and OpenStreetMap data. These pages are shareable and may be indexed by search engines. Please do not submit a private residence you do not want made public. Every score page has a one-click Remove link, or email privacy@locationiq.io to have a page taken down; removed pages are de-indexed and cannot be re-created.

10. Security & breach notification

We maintain reasonable administrative, technical, and physical safeguards for the private information of New York residents and others, consistent with the NY SHIELD Act and applicable law: data is encrypted in transit, access is authenticated and role-scoped, file downloads use short-lived signed URLs, secrets are encrypted at rest, and sensitive endpoints are rate-limited. No system is perfectly secure. If a breach affecting your personal information occurs, we will notify affected users and authorities as required by applicable law.

11. Children

The Service is for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child provided us data, email privacy@locationiq.io and we will delete it.

12. International users

We operate in the United States and process data here. If you access the Service from outside the US, you consent to processing in the US, which may have different data-protection laws than your country.

13. Changes & contact

We may update this policy; material changes will be posted here with a new date and, where appropriate, notified by email. Questions or requests: privacy@locationiq.io.