SpatialDue Information Center
Privacy Policy
How we handle personal information for accounts, ledger, checkout, and operations.
Last updated: August 4, 2026. This policy applies to spatialdue.com and related SpatialDue services. Privacy requests: [email protected] or [email protected].
1. Who we are
SpatialDue operates a tenant-first location intelligence platform (map, building pages, community ledger, and paid audits). For privacy purposes, the controller/business is the operator of spatialdue.com ("SpatialDue," "we," "us").
We do not sell personal information as "sale" is commonly understood under California law, and we do not share personal information for cross-context behavioral advertising in the MVP.
2. Information we collect
Account identifiers: email address (stored with encryption at rest where configured), password (Argon2 hash only—never recoverable plaintext), display name / pseudonym used on public ledger entries.
Profile and saved context: when signed in, we may store primary market city, last searched building or coordinates, ledger browse preferences, and watched buildings so your context restores across devices. Review under Account.
User Content: ledger posts, comments, attachments, and related moderation metadata. Public entries show your display name (not your login email). Content is linked to your account for abuse prevention and lawful process.
Checkout and orders: building address selected, tier, consent checkboxes, device fingerprint / session tokens used for fraud prevention, Stripe payment references (we do not store full card PANs), order and report-access records.
Technical and security data: IP address, user agent, approximate geo derived from IP when enabled for abuse checks, server logs, rate-limit counters, and essential cookies described in the Cookie Notice.
Optional browser location: only if you explicitly allow location in the cookie / location prompt. You can decline and still use essential cookies.
We do not intentionally collect phone numbers in the MVP account model.
3. Sources
- Directly from you (registration, checkout, ledger posts, support email)
- Automatically from your browser/device when you use the service
- Payment processor (Stripe) for payment status and limited billing metadata
- Email delivery provider (Resend) for delivery events on transactional mail
- Public datasets and map/providers used to build building pages (typically non-personal property/business records)
4. How we use information
- Provide, secure, and improve the service (accounts, map, ledger, audits)
- Process payments, entitlements, and report delivery
- Send transactional email (verification, password reset, order/report status, watch digests you enable)
- Moderate abuse, enforce Terms, investigate fraud, and respond to legal requests
- Operate internal ops alerts (for example Telegram to operators)—not marketing blasts to users
- Comply with law and resolve disputes
We do not use your email for advertising lists in the MVP.
6. Retention
We retain account, order, consent, and security records for as long as needed to operate the service, meet legal/tax/accounting obligations, and handle disputes. Ledger history and generated report snapshots may be retained under our immutable-history product principles even when your personal access window changes. When you request deletion, we delete or de-identify personal data we are not required to keep, which may leave non-personal or anonymized operational records.
7. Security
We use encryption in transit (TLS), hashing for passwords (Argon2), encryption at rest for sensitive classes where configured, access controls, and abuse rate limits. No method of transmission or storage is 100% secure; you are responsible for safeguarding your credentials.
8. State privacy rights (starting with California)
SpatialDue uses one Privacy Policy for the U.S. service. We do not maintain a separate privacy policy per state. Where a state grants residents specific rights, those rights apply to qualifying residents as required by that state's law.
If you are a California resident, you may have rights under the CCPA/CPRA to know/access, delete, correct, and opt out of sale/sharing of personal information, and to non-discrimination for exercising rights—subject to legal exceptions (including fraud prevention and completing a transaction).
- Categories we collect are described above (identifiers, commercial order data, internet/technical activity, approximate location if enabled, User Content).
- We do not sell personal information and do not share it for cross-context behavioral ads in MVP.
- To exercise rights, email [email protected] with the subject "California Privacy Request" and enough detail to verify your identity and request. We will respond within the timelines required by law.
- Authorized agents may submit requests with proof of authority as required by California law.
9. Children
SpatialDue is directed to adults and business users. We do not knowingly collect personal information from children under 13 (or under 16 where applicable). If you believe a child provided data, contact us to delete it.
10. International users
We operate from the United States. If you access the service from elsewhere, you understand your information may be processed in the U.S., where laws may differ from your residence.
11. Changes
We may update this policy by posting a new version with a revised "Last updated" date. Material changes will be reasonably highlighted (for example on this page or via account notice).
12. Contact
- Privacy / deletion / export: [email protected]
- Legal: [email protected]
- Related: Terms of Use, Cookie Notice
If you need a postal mailing address for a formal privacy notice, request it from [email protected] once your operating entity address is on file.