Privacy
What we hold about you, for how long, and how to make us delete it. Mapcensus is the controller of the information described here.
The short version
We hold as little as the service can run on. We do not sell your information, we do not share it for advertising, and we do not use your queries or your results to train anything.
Separately from that: the service is paid for delivering information retrieved from public listings, and some of that is about identifiable people - a reviewer's display name, for instance. If you are one of those people rather than a customer, this section is the one written for you, and it includes how to make us stop.
What we hold about you
| What | Why | Kept |
|---|---|---|
| Account id, the email address that opened the account, wallet address if you paid on-chain | To identify your balance and your jobs, and to let you back in | While the account exists |
| A value derived from the sign-in code we sent, and the number of attempts made | To verify the code without storing it | A short period, then deleted |
| The public portion of each passkey, and an opaque handle | To let you sign in without a password | Until you remove the passkey |
| A derived value for each API key and each session - never the key or the token | To authenticate you | Until revoked or expired |
| The network address an account was opened from, and a risk assessment of it | To detect and prevent fraud and abuse of the service | While the account exists |
| Ledger entries: what you bought, when, for how much | Your audit trail, and ours | While the account exists |
| Payment records: amount, network, transaction reference | To settle payments and prevent replay | While the account exists |
| Job records and their results | So you can fetch what you bought | 7 days, then deleted |
| Operational logs | To keep the service working and to investigate abuse | Short-lived |
Signing in
An account is opened with an email address. We send a one-time code to it and you enter the code to continue - there is no password to choose, to reuse, to lose or to have taken from somewhere else. We hold the address because it is how you sign in and how we reach you about the account. We do not ask for a phone number, and we do not ask for anything we do not need.
We do not store the code itself, only a value derived from it, and a code is valid for a limited time and a limited number of attempts. A copy of our database would give nobody a way to sign in as you.
You can add a passkey afterwards, and it is the stronger credential: a key pair created by your own device, whose private portion never leaves it. We hold only the public portion, so there is nothing here that can be used to sign in as you, and nothing to phish or reuse. Once you have one it is what signs you in; the address remains the way back if the device is lost.
Service providers
We use a small number of independent service providers to operate the service - for example to help us assess the risk associated with a network address when an account is opened, to deliver one-time codes by email, and to settle payments. We share with each provider only what it needs for that purpose. Your queries, your results and your account identifier are not sent to any of them. We do not sell your personal information to anyone, and we share no personal information for advertising. Information about other people, retrieved from public listings, is delivered to the customer who asked for it and to nobody else - that delivery is what the service charges for, it is described under Data about other people, and in some jurisdictions it counts as a sale. It is not advertising, it is not onward sale to data brokers, and it is not training data.
Where a provider returns an assessment of a network address, we retain the outcome for a limited period rather than the provider's underlying report. Where an assessment indicates a risk of fraud or abuse, we may decline to provide the service.
A search run from our home page without an account is subject to the same checks, and to technical measures intended to prevent automated abuse. We do not create an account record for you when you run one.
What we do not collect
Your search terms are not written to our logs. Where a request has to be identified in a log we use a derived value that does not reveal what you asked for. We do not store card details, because we never receive any. We set no advertising or analytics cookies, and the site loads nothing from a third party.
Data about other people
This section is for you if you did not ask us for anything, and your name may be in what we returned to someone else. It is the notice that data protection law requires us to give when we obtain information about a person from somewhere other than that person.
What we take, and from where. We read business listings on public map pages. Most of what we return is about a business rather than a person. Some of it is not:
| What | Where it comes from |
|---|---|
| The display name shown on a review, and whether that account is marked a local guide | The public listing page |
| The text of the review, its star ratings, the date it was posted, and how many people marked it helpful | The same page |
| A reply the business posted under a review, and updates the business has published | The same page |
| The phone number, address and coordinates of the business - which for someone trading under their own name, or from home, is personal to them | The same page |
What we deliberately do not take. We drop the reviewer's account identifier, their profile link and their profile photo before anything is stored or returned. That is the identifier which would otherwise let a buyer join one person's reviews across every place they have written about, and turn a set of public opinions into a profile of somebody's movements. We also drop the questions-and-answers section entirely, and every internal measurement of our own crawl.
We do not claim this makes the data anonymous. It does not. A display name, a date and a sentence can still identify someone, so what we hold about you remains your personal data and everything in this section applies to it.
Why we do it, and on what basis. We provide market research: counts, ratings and themes about businesses and places. Our basis is legitimate interests - ours and our customers' interest in researching a market from information the source already publishes. We have weighed that against your interests, which is why the identifiers above are dropped, why we keep results for a short time rather than indefinitely, and why the objection route below exists and works. If you tell us our interest does not outweigh yours in your case, we will stop, and we do not require you to give a reason.
Who receives it. Customers who requested a search that matched the listing. We do not publish results openly, we do not sell them to advertisers, and we do not use them to train any model.
How long. Results are deleted 7 days after the job that produced them; a retrieval kept to answer a later request is reused for at most 1 day. We do not keep a permanent copy, and there is no profile of you here that accumulates over time.
Telling you directly. Data protection law asks us to contact each person whose data we obtain this way. We cannot: the source gives us a display name and nothing to send a message to - no address, no account we can reach - so contacting you would mean first finding out who you are and how to reach you, which is more intrusion than the notice is worth. This page is the public notice the law provides for instead, and it is why this section is written at this length.
Asking us to remove you
Write to privacy@mapcensus.com. To find you we need the place the review is attached to and the name shown on it, or a link to the review itself. That is all - we will not ask you to prove your identity with a document, because we hold nothing to check it against and asking would collect more about you than we already have.
If the listing itself is the problem - you trade under your own name, or from home, so the entry is a publication of where you live - say so, and we withdraw the whole listing rather than one review. Removing a review would not have touched what you were objecting to.
What happens then. We add you to a suppression list. From that moment no new search returns you, no stored retrieval containing you is reused to answer anyone, and every result already delivered expires within 7 days on the schedule above. The list is applied when a row is created, so it also covers every future crawl - you do not come back the next time someone searches that place. We keep the minimum needed to keep you suppressed, and nothing else about you.
You may also ask for a copy of what we hold about you, ask us to correct it, or object to the processing. We respond within one month. If you think we have got it wrong you can complain to your data protection authority - in the EU or UK, the one where you live or work.
If you are a customer reading this: when you request data about identifiable people you become a controller of it in your own right, separately from us. Your own obligations apply to what you do next, including telling people whose data you obtained indirectly and answering their requests. The terms set this out.
Your rights
You may ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it and close your account. Write to privacy@mapcensus.com. We will respond within a month. Deleting an account removes its jobs, results and keys; ledger and payment records are retained where we are required to keep them.
Where data lives
The service runs on servers we operate, and data stays on them. Payment settlement is recorded on a public blockchain by a third-party settlement provider; the record of a transaction there is public and permanent, and is not something we can delete.
Security
Credentials are stored so that a copy of our database yields nothing that can be used to sign in as you: API keys and session tokens as derived values, passkeys as public keys only. Your jobs, your files and your history are private to your account, and no other customer can read them.
Information retrieved from public pages may be retained and used to answer later requests, including requests made by other customers, as the terms describe. Your queries, your account and your activity are never shared that way.
Report a vulnerability to security@mapcensus.com; we will not pursue anyone who reports one in good faith and does not access other people's data.
Changes
Material changes are published on this page. Last updated 13 September 2026.