Privacy Policy
Last updated: 26 September 2026 · Pending final legal review
1. Data we process
- Account data: your email address, display name and account membership.
- Authentication data: PBKDF2 password hashes (never plaintext passwords), session records, rate-limit counters and security audit events (IP and email are stored as salted hashes).
- Product data: the searches you run, saved businesses, derived contact information, projects and exports.
- Billing data: plan, subscription status and payment references from Stripe. Card details are handled by Stripe and never reach our servers.
- Operational logs: request metadata and errors used to operate and secure the service.
2. Why we process it
To provide the service you request, authenticate you, keep accounts isolated, prevent abuse, process subscriptions and payments, provide support, and meet legal obligations.
3. Processors
We use a small set of processors to operate Gmap Data: cloud hosting and database infrastructure, Stripe for payments and billing, and — only when you explicitly connect them — your own email-enrichment and verification providers, which receive the queries you run through them. Google Places data is retrieved through the Google Places API. A transactional email provider will process verification and password-reset delivery; the provider is being selected and this policy will name it before public signup opens.
4. Cookies and analytics
We set essential cookies only: a session cookie for customer authentication, a CSRF token cookie, and the operator/admin session cookie. No advertising or cross-site tracking cookies are used. The service may use aggregate, privacy-friendly traffic analytics (Cloudflare Web Analytics) that do not receive account data, scraped business data or reset/verification tokens.
5. Retention
Account and product data are retained while your account is active. The credit ledger is append-only and retained for financial auditing. Security and request logs are bounded and rotated. If you need data deleted, contact us; we will handle requests in line with applicable law and any records we must retain.
6. Security
Passwords are hashed, sessions are server-side and revocable, provider keys you connect are encrypted at rest with AES-256-GCM, and account data is scoped to your account. See the Security page for details.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Contact us to exercise them.
8. Contact
AppLabx, operator of Gmap Data: [email protected].