1.Who we are and what this covers
Adam Kabessa (GroundZones) operates the GroundZones platform. This policy explains how we handle personal data in connection with our website, applications, and APIs (the “Service”).
Our role depends on the data:
- We are the controller for personal data about our account holders and website visitors - the information in Section 2.1 to 2.4. This policy governs that data.
- We are a processor for personal data contained in the property lists and other content our customers upload (“Customer Data”). The customer is the controller and decides why and how that data is processed; we act on their instructions under our Data Processing Addendum. If your data was uploaded by a business using GroundZones, contact that business to exercise your rights.
2.What we collect
2.1 Account data
When you register, we collect your email address, full name, and a hashed password (we never store your password in readable form). We also store your subscription tier and usage counters, and a record of the version of our Terms and this policy you accepted, with the timestamp.
2.2 Billing data
Payments are processed by Stripe. We store only your Stripe customer and subscription identifiers, your plan, and your billing status. We do not receive or store full payment card numbers. Stripe processes your payment details as an independent controller under its own privacy policy.
2.3 Usage, log, and security data
We automatically collect, in order to run and secure the Service:
- IP address, browser user-agent, and request identifiers;
- timestamps and outcomes of security-relevant events - sign-in, failed sign-in, sign-out, token refresh, registration, account deletion, and billing changes - retained in an audit log;
- API request metadata and usage counts, used to enforce plan quotas and rate limits; and
- diagnostic data from errors, described in Section 2.5.
2.4 Cookies and local storage
We use a strictly necessary authentication cookie and browser local storage to keep you signed in. We do not use advertising, marketing, or third-party analytics cookies. Full detail is in the Cookie Policy.
2.5 Error monitoring
If enabled in our production build, we use Sentry to capture application errors. Sentry is configured not to send default personally identifiable information, and we filter authentication tokens, passwords, cookies, and authorization headers out of error reports before transmission. Error reports may still incidentally contain an IP address and technical context about the page where the error occurred.
2.6 Customer Data you upload
The property lists you upload typically contain business information - hotel names, street addresses, and coordinates. They are not intended to contain personal data, and we ask that you do not upload personal data beyond business contact details. Where they do contain personal data, we process it only as a processor under the DPA.
3.Why we use it, and our lawful basis
For customers and visitors in the EEA and UK, the GDPR requires us to identify a lawful basis for each purpose:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and administer your account; authenticate you | Account data | Performance of a contract (Art. 6(1)(b)) |
| Provide the Service - geocoding, distance, zoning, exports | Account data, Customer Data | Performance of a contract (Art. 6(1)(b)) |
| Take payment and manage subscriptions | Billing data | Performance of a contract (Art. 6(1)(b)) |
| Enforce quotas and rate limits; prevent abuse and fraud | Usage and log data | Legitimate interests (Art. 6(1)(f)) - protecting the Service and our customers |
| Maintain security audit logs and investigate incidents | Log and security data | Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
| Diagnose and fix errors | Diagnostic data | Legitimate interests (Art. 6(1)(f)) - keeping the Service working |
| Send service and transactional emails (security, billing, material changes) | Account data | Performance of a contract (Art. 6(1)(b)) |
| Evidence acceptance of our Terms | Acceptance record, IP, timestamp | Legitimate interests (Art. 6(1)(f)) - establishing and defending legal claims |
| Comply with tax, accounting, and other legal obligations | Billing and account data | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You may object at any time - see Section 8.
4.The shared geocoding cache
To keep costs and latency down, the Service caches geocoding and distance results and shares that cache across all customers. The cache stores address strings, coordinates, and routing results. It does not store which customer submitted a lookup, and it contains no account identifiers. Addresses that identify a private residence would constitute personal data - this is one reason our Terms restrict the Service to business use and ask that you upload business premises rather than individuals’ home addresses.
5.Who we share it with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to:
- Service providers (subprocessors) who host and support the Service, under contracts requiring confidentiality and appropriate safeguards. The current list is on our Subprocessors page.
- Third-party mapping providers, when we send an address or coordinate pair for geocoding or routing. Depending on configuration this may be our self-hosted services or an external provider such as Google Maps Platform or OpenStreetMap Nominatim. Only the location query is sent - never your account identity.
- Professional advisers - lawyers, accountants, auditors - where necessary and under a duty of confidentiality.
- Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims. We will notify you of a legally compelled disclosure unless prohibited from doing so.
- An acquirer, in connection with a merger, acquisition, or sale of assets. We will notify you before your data becomes subject to a different privacy policy.
6.International transfers
We are based in the United States, and our subprocessors may process data in the United States and elsewhere. If you are in the EEA, UK, or Switzerland, this means your personal data may be transferred outside your home jurisdiction.
For those transfers we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures including encryption in transit and at rest. You can request a copy of the relevant transfer mechanism by emailing privacy@groundzones.com.
7.How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account. Deleted when you delete your account. |
| Customer Data (properties, projects, zones, jobs) | For the life of your account; deleted with it. You can delete individual items at any time. |
| Cached geocoding results | Up to 30 days for results from Google, up to 90 days for results from open-data providers, then refreshed or evicted. Not linked to any account. |
| Cached distance results | Up to 30 days from the lookup, then refreshed or evicted. Not linked to any account. |
| Security audit logs | Retained after account deletion with the user reference removed, for security and legal-claims purposes. |
| Billing records | As required by tax and accounting law, typically 7 years, held by us and by Stripe. |
| Error reports | Per our Sentry retention configuration, typically 90 days. |
Backups are kept in two layers. Daily database backups on our server are retained for 5 days and then deleted. Our hosting provider, Hetzner, also keeps daily backups of the whole server, which include the database and those backups, for 7 days. Data deleted from the live system therefore persists in backups until it ages out of both, typically within two weeks. While retained, backups are not accessed for any purpose other than restoring the Service or meeting a legal obligation.
8.Your rights
8.1 If you are in the EEA or UK
Under the GDPR and UK GDPR you have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict processing in certain circumstances;
- receive your data in a portable, machine-readable format;
- object to processing based on legitimate interests, including at any time;
- withdraw consent where we rely on it, without affecting prior processing; and
- lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
8.2 If you are a California resident
Under the CCPA/CPRA you have the right to:
- know the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of recipients;
- delete personal information we hold about you, subject to legal exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information - note that we do not sell or share personal information, and have not in the preceding 12 months;
- limit use of sensitive personal information - we do not collect sensitive personal information as defined by the CPRA; and
- not be discriminated against for exercising these rights. We do not offer financial incentives tied to your data.
You may use an authorised agent to submit a request; we will require proof of authorisation and may verify your identity directly.
8.3 How to exercise your rights
You can exercise the two most common rights yourself, immediately, from your profile settings:
- Export - download a machine-readable archive of your account and Customer Data.
- Delete - permanently delete your account and the data it owns.
For anything else, email privacy@groundzones.com. We will respond within 30 days (or one month under the GDPR), and may extend by a further 60 days for complex requests, telling you why. We may need to verify your identity before acting. There is no charge unless a request is manifestly unfounded or excessive.
9.Security
We maintain technical and organisational measures including:
- encryption of data in transit (TLS), and server-side encryption (AES-256) for uploaded files in object storage;
- passwords stored using a slow, salted one-way hash (bcrypt), never in readable form;
- short-lived access tokens paired with rotating refresh tokens held in httpOnly cookies, with replay detection;
- constant-time credential comparison and rate limiting on authentication endpoints to resist brute-force and account-enumeration attacks;
- role-based access control and workspace-scoped authorisation on every request;
- audit logging of security-relevant events; and
- least-privilege access to production systems by our personnel.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law - under the GDPR, without undue delay and within 72 hours of becoming aware where feasible. Report a suspected vulnerability to security@groundzones.com.
10.Children
The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact privacy@groundzones.com and we will delete it.
11.Changes to this policy
We may update this policy. For material changes we will notify you by email or by prominent notice in the Service at least 30 days before they take effect, and we will update the effective date above.
12.Contact us
Privacy questions and rights requests: privacy@groundzones.com
Security reports: security@groundzones.com
Adam Kabessa, Mailing address to be published, New Jersey, United States
If you are in the EEA or UK and we are required to appoint a representative under Article 27 GDPR, their details will be published here.