Legal
Privacy Policy
The short version
- Files and text used in our GIS tools are processed in your browser and are not uploaded to GIS Utils.
- Stripe hosts checkout, processes payments, and calculates applicable taxes. We retain the order details needed to deliver and support purchases, but not full card numbers or card security codes.
- Accounts are optional for dataset snapshot purchases and required for one-time update passes. We do not offer recurring subscriptions.
- On the production site, Google Analytics helps us understand site use and catalog search demand.
- The private grid makes no third-party tile requests. Selecting OpenStreetMap causes your browser to request the visual tiles needed for the current map view.
- We do not sell personal information or use tool input to build datasets.
1. Scope
This policy explains how GIS Utils handles personal information when you browse this website, use the GIS tools, purchase or download a dataset, or contact us. It does not govern the independent privacy practices of Stripe, Google, map providers, or other third-party services.
2. Information we handle
Website and technical information
When you visit the site, our hosting and application infrastructure may process ordinary request information such as your IP address, browser and device type, requested page, referring page, and request time. We use this information to operate the site, protect it from abuse, and diagnose errors.
On the production website, Google Analytics may receive the page path, referring page path, approximate location, browser and device information, session statistics, and limited interaction events such as scroll depth, catalog searches, dataset views and selections, cart and checkout actions, completed purchase identifiers and totals, outbound-link clicks, and file-download requests. We do not send customer names, email addresses, billing details, or search terms that resemble contact information in these events. We remove query strings from page and referrer URLs before sending them, and automatic form-interaction measurement is disabled. Google states that Google Analytics uses IP addresses at collection time to derive location information and discards them before the information is logged.
Purchase and download information
When you purchase a dataset, you are redirected to a Stripe-hosted checkout page. Stripe collects the payment and billing information entered there, calculates applicable tax based on location, and returns the information needed to complete and document the order. Depending on the checkout and later order activity, we may retain:
- Your name, email address, and billing address or location;
- The dataset purchased, order date, currency, subtotal, tax, discount, and total;
- Stripe customer, Checkout Session, payment-intent, payment-status, refund, dispute, and transaction identifiers;
- Your acceptance of the Terms, along with the checkout IP address and browser information used to document that acceptance;
- Dataset entitlements, update-pass access periods, short-lived access tokens, and download events including format, time, IP address, browser information, file size, and checksum.
We do not receive or store your full payment-card number or card security code. Stripe handles payment data under its own Privacy Policy.
Account and sign-in information
If you create an account, we store your name, email address, verification status, password hash when you set a password, account status, registration IP address, sign-in tokens, and purchase relationships. Server-side sessions include an IP address, browser information, and recent activity time. If you use Google sign-in, we receive your Google account identifier, name, email address, and profile image. Google does not provide your Google password to us.
To prevent abusive registrations, we compare registration information with prior registrations and locally stored Tor, VPN/datacenter, and disposable-email blocklists. Registration, sign-in, magic-link, password-reset, and guest purchase-access forms may use Cloudflare Turnstile. Its browser challenge evaluates technical and behavioural signals, and our server sends the resulting token and your IP address to Cloudflare for validation.
Support communications
If you email us, we receive your email address and the information you include in the message. Please do not send payment-card details or unnecessary sensitive information by email.
GIS tool input
GeoJSON, coordinates, CSV content, WKT, polylines, and other content pasted into or opened by our GIS tools are processed locally in your browser. The tools do not send that content to our application server.
The private grid is rendered locally and makes no request to a map provider. If you select OpenStreetMap, your browser requests only the visual tiles needed for the current map view. OpenStreetMap can receive ordinary network information, the referring site, and the tile coordinates needed to display that area. We do not offer tile prefetching, bulk downloading, or offline tile storage.
Google Analytics is separate from GIS tool processing. It receives the limited website and interaction information described above, but not files, geometry, coordinates, attributes, or pasted tool input. A tool event can include only the tool slug, operation identifier, success or broad failure category, input and output format, a coarse input-size bucket, and the identifier of a dataset link you choose. The analytics payload builder rejects all other fields. It does not send filenames, exact sizes or counts, generated output, or arbitrary error messages.
Catalog searches
When you pause after entering at least two characters in a tool or dataset search, Google Analytics may receive the search phrase, the catalog searched, and the number of matching results. Searches that look like an email address or contain a long number are not sent by this feature, but that filter cannot identify every kind of personal information. We use search data to identify missing tools and datasets. We do not retain a separate copy of catalog search phrases in our application database. Do not enter personal or sensitive information into catalog search fields.
3. Cookies and browser storage
- Essential site storage: the site uses session and authentication cookies for sign-in, carts, purchase access, security, and normal request handling. A persistent authentication cookie may keep a signed-in account recognized between visits.
- Preferences: theme and per-tool map-style choices are stored locally in your browser so they persist between visits.
- Analytics: Google Analytics uses identifiers such as
_gaand_ga_*to distinguish browsers and calculate aggregate usage statistics.
You can clear or block cookies and local storage through your browser. Blocking essential cookies may prevent sign-in, carts, and purchase access from working. Blocking preference storage may reset your selected theme or map style. Blocking analytics cookies does not prevent you from using the site.
4. How we use information
- Complete payments and deliver purchased datasets;
- Create accounts, authenticate users, and attach verified guest purchases;
- Send confirmations and provide regenerable, short-lived access links to purchase entitlements;
- Manage one-time dataset update passes and their access periods;
- Verify orders, rate-limit access, and answer support requests;
- Maintain site security, prevent abuse, and troubleshoot failures;
- Understand aggregate site usage and improve navigation and tools;
- Meet accounting, tax, legal, and regulatory obligations.
Depending on where you live, these activities may rely on performance of a contract, our legitimate interests in operating and securing the service, compliance with law, or consent where consent is required.
5. When information is shared
We disclose information only as needed to operate the service or comply with law. Relevant service providers include:
- Stripe, for hosted checkout, payment processing, tax calculation, fraud prevention, receipts, and transaction records;
- Google, for aggregate website analytics and when you choose Google sign-in;
- Cloudflare, for Turnstile automated-abuse prevention, website delivery and security, and private R2 dataset storage;
- Resend, for transactional messages such as verification, sign-in, order, download-access, refund, and dispute emails;
- Hosting and infrastructure providers, for running, backing up, and securing the website and its database;
- OpenStreetMap, when you select its street basemap. The private grid does not contact a map provider;
These providers may process information in countries other than your own and apply their own privacy terms. We may also disclose information when reasonably necessary to comply with law, enforce our terms, protect the service or its users, or complete a business reorganization or transfer.
We do not sell personal information. We do not share GIS tool input with data brokers or use it to create datasets for sale.
6. Retention
Completed purchase entitlements remain available while we operate the applicable download service. Individual guest-access and file links expire quickly and can be regenerated after verification. Order, entitlement, update-pass, download, refund, and dispute records may be retained for purchase support, accounting, fraud prevention, dispute handling, and legal compliance.
Checkout records created before a Stripe session is successfully created are normally removed after 24 hours. Other unpaid or abandoned Checkout attempts are normally removed after 30 days. Expired access tokens are removed on a recurring schedule. These periods may be extended when a record is needed for security, support, a payment dispute, or legal compliance.
Deleted accounts have a 30-day recovery period. After that period, account data is removed or de-identified unless specific records must be retained for completed purchases, update passes, accounting, fraud prevention, disputes, or legal obligations.
Support messages are retained as needed to resolve the request and maintain an appropriate support record. Google controls retention of Analytics event data under the settings for our Analytics property. Browser preferences remain on your device until you clear them.
7. Security
We use HTTPS, password hashing, email verification, restricted access, secure payment processing, signed short-lived links, private file storage, request throttling, and other reasonable administrative and technical safeguards. No website or transmission method can be guaranteed completely secure, so you should keep access links private and store downloaded files appropriately.
8. Your choices and rights
Depending on your location, you may have rights to request access to, correction of, deletion of, or a copy of your personal information, and to object to or restrict certain processing. You may also withdraw consent where processing depends on consent.
Send requests to support@gisutils.com . We may need to verify your identity and purchase details before responding. We may retain information that must be kept for legal, accounting, fraud-prevention, or dispute-resolution purposes.
9. Children
The service is intended for business, professional, and research use and is not directed to children. Do not submit a purchase unless you are legally able to enter into a contract or are acting with the authorization of someone who is.
10. Updates and contact
We may update this policy when the service or our legal obligations change. The effective date at the top identifies the current version. Material changes will be presented on this page before or when they take effect.
Questions or privacy requests can be sent to support@gisutils.com .