Privacy policy
Last updated 27 August 2026
This policy covers the My Geocode API, the compatibility hosts, the JavaScript loaders, the dashboard and this website. It is written to be read, not skimmed, so it is short.
What we collect when you call the API
Each request is logged with the client IP address, the endpoint, the query parameters, the API key identifier if one was sent, the response status, the response time, a request ID and the user agent. We need the IP address to count the free tier and enforce burst limits; the rest is for debugging and abuse prevention.
Retention: raw request logs are deleted after 30 days. Per-day counts per IP address are deleted after 7 days. Per-day counts per account are kept for as long as the account exists, because they are the basis of your invoices.
The lookup values themselves (the addresses and coordinates you send, the IP addresses you ask about) are treated the same way as the rest of the log line and are not used to build profiles, train models or enrich any other dataset.
What we collect when you have an account
Your email address, a password hash, the IP addresses you whitelist and your API keys. That is the whole list; we do not ask for a name or a company. If you add an invoicing address for your own records, we keep that too. Card details go directly to our payment processor; we store only the last four digits, the expiry month and a token. For cryptocurrency payments we store the transaction ID and the amount. Receipts are kept for as long as tax law requires, typically seven to ten years.
What we collect on the website
The marketing pages set no cookies and load no analytics scripts. Fonts are loaded from Google Fonts, which means Google sees your IP address for those requests; self-hosting them is on the list. The demo page sends requests from your browser directly to the API, which logs them as described above. The dashboard uses one session cookie to keep you logged in.
Who else sees data
- Hosting providers that run our servers, in the European Union and the United States.
- The payment processor that handles cards and subscriptions.
- The email provider that sends invoices, alerts and replies to support.
Each of these is bound by a data processing agreement. We do not sell data, share it with advertisers, or pass API query contents to anyone.
We disclose data when the law requires it and will tell you when we are allowed to.
Where data is stored
Request logs are stored in the region that served the request. Account data is stored in the European Union. Transfers outside the EU rely on standard contractual clauses.
Your rights
You can see, correct, export or delete your account data from the dashboard. For anything the dashboard cannot do, or if you are not an account holder and want to know what we hold about your IP address, write to [email protected]. We reply within 30 days. If you are in the EU or UK you can also complain to your data protection authority.
Children
The service is not directed at children under 16 and we do not knowingly hold their data.
Changes
We will note changes to this policy in the changelog and, for material changes, email account holders 30 days before they take effect.