SpatialDue Information Center

Privacy Policy

How we handle personal information for accounts, ledger, checkout, and operations.

Last updated: August 4, 2026. This policy applies to spatialdue.com and related SpatialDue services. Privacy requests: [email protected] or [email protected].

1. Who we are

SpatialDue operates a tenant-first location intelligence platform (map, building pages, community ledger, and paid audits). For privacy purposes, the controller/business is the operator of spatialdue.com ("SpatialDue," "we," "us").

We do not sell personal information as "sale" is commonly understood under California law, and we do not share personal information for cross-context behavioral advertising in the MVP.

2. Information we collect

Account identifiers: email address (stored with encryption at rest where configured), password (Argon2 hash only—never recoverable plaintext), display name / pseudonym used on public ledger entries.

Profile and saved context: when signed in, we may store primary market city, last searched building or coordinates, ledger browse preferences, and watched buildings so your context restores across devices. Review under Account.

User Content: ledger posts, comments, attachments, and related moderation metadata. Public entries show your display name (not your login email). Content is linked to your account for abuse prevention and lawful process.

Checkout and orders: building address selected, tier, consent checkboxes, device fingerprint / session tokens used for fraud prevention, Stripe payment references (we do not store full card PANs), order and report-access records.

Technical and security data: IP address, user agent, approximate geo derived from IP when enabled for abuse checks, server logs, rate-limit counters, and essential cookies described in the Cookie Notice.

Optional browser location: only if you explicitly allow location in the cookie / location prompt. You can decline and still use essential cookies.

We do not intentionally collect phone numbers in the MVP account model.

3. Sources

  • Directly from you (registration, checkout, ledger posts, support email)
  • Automatically from your browser/device when you use the service
  • Payment processor (Stripe) for payment status and limited billing metadata
  • Email delivery provider (Resend) for delivery events on transactional mail
  • Public datasets and map/providers used to build building pages (typically non-personal property/business records)

4. How we use information

  • Provide, secure, and improve the service (accounts, map, ledger, audits)
  • Process payments, entitlements, and report delivery
  • Send transactional email (verification, password reset, order/report status, watch digests you enable)
  • Moderate abuse, enforce Terms, investigate fraud, and respond to legal requests
  • Operate internal ops alerts (for example Telegram to operators)—not marketing blasts to users
  • Comply with law and resolve disputes

We do not use your email for advertising lists in the MVP.

5. Sharing

We share personal information only as needed with:

  • Processors: infrastructure hosts, databases, Stripe (payments), Resend (transactional email), and similar vendors under contract who process data on our instructions.
  • Public display: display name and User Content you choose to publish on ledger / building pages.
  • Legal and safety: when required by law, valid legal process, or to protect rights, safety, and integrity of the service or others.
  • Business transfers: if we undergo a merger, acquisition, or asset sale, subject to continuing protections consistent with this policy.

6. Retention

We retain account, order, consent, and security records for as long as needed to operate the service, meet legal/tax/accounting obligations, and handle disputes. Ledger history and generated report snapshots may be retained under our immutable-history product principles even when your personal access window changes. When you request deletion, we delete or de-identify personal data we are not required to keep, which may leave non-personal or anonymized operational records.

7. Security

We use encryption in transit (TLS), hashing for passwords (Argon2), encryption at rest for sensitive classes where configured, access controls, and abuse rate limits. No method of transmission or storage is 100% secure; you are responsible for safeguarding your credentials.

8. State privacy rights (starting with California)

SpatialDue uses one Privacy Policy for the U.S. service. We do not maintain a separate privacy policy per state. Where a state grants residents specific rights, those rights apply to qualifying residents as required by that state's law.

If you are a California resident, you may have rights under the CCPA/CPRA to know/access, delete, correct, and opt out of sale/sharing of personal information, and to non-discrimination for exercising rights—subject to legal exceptions (including fraud prevention and completing a transaction).

  • Categories we collect are described above (identifiers, commercial order data, internet/technical activity, approximate location if enabled, User Content).
  • We do not sell personal information and do not share it for cross-context behavioral ads in MVP.
  • To exercise rights, email [email protected] with the subject "California Privacy Request" and enough detail to verify your identity and request. We will respond within the timelines required by law.
  • Authorized agents may submit requests with proof of authority as required by California law.

9. Children

SpatialDue is directed to adults and business users. We do not knowingly collect personal information from children under 13 (or under 16 where applicable). If you believe a child provided data, contact us to delete it.

10. International users

We operate from the United States. If you access the service from elsewhere, you understand your information may be processed in the U.S., where laws may differ from your residence.

11. Changes

We may update this policy by posting a new version with a revised "Last updated" date. Material changes will be reasonably highlighted (for example on this page or via account notice).

12. Contact

If you need a postal mailing address for a formal privacy notice, request it from [email protected] once your operating entity address is on file.

Privacy Policy | SpatialDue