GR1D GR1D.io
Get In Touch Sign in
Legal

Privacy Policy

Last updated: April 24, 2026 · Effective date: April 24, 2026

This Privacy Policy explains how GR1D Recon ("we," "us," "our") collects, uses, shares, and protects information when you use our commercial real estate site intelligence platform (the "Service"). It also describes your rights and how to exercise them. If you have questions about anything here, email us at admin@gr1drecon.io.

Beta Notice: GR1D Recon is under active development. This policy may be updated as we add features or refine our data practices. We will notify users of material changes at least 30 days before they take effect (or sooner where required by law).

1. Who This Policy Applies To

This Policy applies to personal information about users of the Service — the individuals who create accounts and use the platform. The Service is directed at professionals working in commercial real estate, site selection, development, and related business contexts.

The Service also processes information about real properties, parcels, owners of record, and government activity sourced from public records. That information is not personal information of our users and is governed by Section 3 of our Terms of Service, including the restriction that the Service must not be used in any manner governed by the Fair Credit Reporting Act or used to make consumer-eligibility decisions.

2. Information We Collect

Account information you provide.

  • Name and email address you provide at sign-up
  • Authentication credentials (password, managed by our identity provider and stored hashed; OAuth identifiers if you use a social login)
  • Records of your acceptance of our Terms of Service and Privacy Policy (date and timestamp)
  • Your communication preferences (for example, whether you have opted in to marketing emails)
  • Billing information if you subscribe to a paid plan (processed by our payment processor — we do not store full card numbers)

Usage and activity data.

  • Parcels you view, search, save, compare, or export
  • Search queries, filters, saved searches, and starred/favorited items
  • Notes, annotations, and other content you create in the platform
  • Feature interactions, click paths, and session duration
  • Errors and diagnostic events

Technical data collected automatically.

  • IP address and approximate geolocation derived from it
  • Browser type, version, user-agent string, device type, operating system, and screen size
  • Referring URL and the pages you view on the Service
  • Timestamps and duration of sessions

Communications.

  • If you email us, we retain the contents of the email and our reply
  • If you provide feedback through the platform, we retain it

We do not intentionally collect sensitive personal information (such as Social Security numbers, government IDs, health information, precise geolocation, or biometric data). Please do not submit such information through the Service.

3. How We Use Your Information

We use the information above to:

  • Provide the Service — authenticate you, deliver parcel data and scoring, honor your saved searches, generate exports, and fulfill paid-plan obligations
  • Operate and improve the platform — understand usage patterns, debug issues, optimize performance, and plan new features
  • Communicate with you — respond to support requests, send transactional notices (verification, billing, security, policy updates), and, if you have opted in, send marketing emails
  • Protect the Service and our users — detect and prevent abuse, fraud, security incidents, and violations of our Terms of Service
  • Comply with legal obligations — respond to lawful requests, enforce our agreements, and meet tax, accounting, and regulatory requirements

We do not sell your personal information for money, and we do not "share" personal information for cross-context behavioral advertising (as those terms are defined under California law). We do not use your data for advertising and we do not participate in advertising networks or data-broker exchanges.

4. Legal Bases for Processing (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR:

  • Contract — to provide the Service you requested, including account creation, authentication, and fulfilling paid-plan obligations
  • Legitimate interests — to operate, secure, and improve the Service, to understand usage, to prevent fraud and abuse, and to provide the tools we believe our users want. We balance these interests against your privacy rights.
  • Consent — for marketing emails (you can withdraw consent at any time without affecting the lawfulness of past processing) and any other processing we specifically ask your permission for
  • Legal obligation — where we must retain or disclose information to comply with applicable law

5. Third-Party Services

We use the following categories of third-party processors and sub-processors to operate the Service. Each has its own privacy commitments and handles only the information necessary to perform its service.

  • Supabase (database, authentication, storage; hosted on AWS, United States) — stores your account data and platform data
  • Vercel (application hosting and deployment; United States) — serves the web application and logs request metadata
  • Railway (backend API hosting; United States) — runs our application backend
  • Cloudflare R2 / S3-compatible storage — hosts map tiles and static assets
  • MapTiler, MapLibre, Protomaps — map rendering and tile delivery; your IP is disclosed to map tile endpoints in the ordinary course of map display
  • Google Street View API — delivers panoramic imagery where you request it. Subject to Google's Privacy Policy.
  • OpenAI and Anthropic — provide the AI and large-language-model services we use to generate zoning classifications, ordinance extractions, and government-activity summaries. We do not send account-identifying personal data to these providers in the ordinary course of these workloads. Neither provider is authorized to train on our API content under our agreements.
  • Payment processor — if you purchase a paid plan, your payment details are handled by a third-party processor (we will identify the processor on the checkout page). We do not store full card numbers.

We may update this list as our infrastructure evolves. A current list is available on request.

We may also disclose information (a) to comply with law, legal process, or lawful government request; (b) to enforce our Terms of Service; (c) to protect the rights, property, or safety of GR1D Recon, our users, or the public; or (d) in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

6. Analytics

We currently do not use third-party analytics or advertising cookies (such as Google Analytics, Meta Pixel, or similar). We may use first-party server-side logs and metrics provided by our hosting infrastructure (Vercel, Supabase) for debugging, security, and capacity planning. If we add a third-party analytics provider in the future, we will update this Policy and, where required, obtain your consent.

7. AI and Automated Processing

Portions of the Service rely on artificial intelligence and machine learning to classify zoning codes, extract ordinance provisions, summarize government activity, and generate district-intent summaries. These workloads operate primarily on public records, government documents, and aggregated platform data — not on your personal account information.

We do not engage in automated decision-making that produces legal or similarly significant effects concerning you. Parcel scoring is an informational ranking aid, not a decision about any individual.

8. Data Storage, Security, and International Transfers

Your data is stored on cloud infrastructure located in the United States (primarily AWS us-east-1, via Supabase). We implement reasonable administrative, technical, and physical safeguards, including encrypted connections (HTTPS/TLS), encrypted storage, role-based access controls, authentication via an identity provider with modern password hashing, and row-level access controls that limit each user to their own profile data.

If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data-protection laws than your home country. Where required by law (for example, for transfers from the EEA, UK, or Switzerland), we rely on appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our sub-processors.

No system is completely secure. While we work to protect your information, we cannot guarantee absolute security.

9. Email Communications

Transactional emails (verification, billing, security notices, policy updates, service changes) are required to operate the Service. You cannot opt out of transactional emails while your account is active.

Marketing emails (product announcements, platform news, feature launches) are sent only if you opt in. You can opt in or out at any time in Settings → Notifications → Communication Preferences or by clicking the unsubscribe link in any marketing email. We comply with the CAN-SPAM Act and will process unsubscribe requests within ten (10) business days.

10. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy or as required by law.

  • Account information — retained while your account is active. If you delete your account, we remove or anonymize your personal data within 30 days, except records we are required to retain (for example, for tax, accounting, or legal-hold purposes).
  • Usage data — retained for up to 24 months, after which it is aggregated or deleted
  • Backups — may persist for up to 90 days after deletion from live systems and are overwritten on a rolling basis
  • Security and audit logs — retained for up to 12 months
  • Billing records — retained as required by applicable tax and accounting law (typically 7 years)

11. Your Rights

Subject to applicable law, you have the right to:

  • Access personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and associated personal data
  • Export your data in a portable format
  • Restrict or object to certain processing (where applicable under GDPR)
  • Withdraw consent you previously gave (for example, by opting out of marketing)
  • Lodge a complaint with a supervisory authority (for EEA/UK users)

To exercise any of these rights, email admin@gr1drecon.io. We may need to verify your identity before responding. We will respond within 30 days (or 45 days under U.S. state laws, extendable once where permitted).

We will not discriminate against you for exercising these rights.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the rights described in Section 11 and additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to know the specific personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it
  • Right to delete personal information we collected from you, subject to legal exceptions
  • Right to correct inaccurate personal information
  • Right to limit the use and disclosure of sensitive personal information (we do not use sensitive personal information for purposes that would require a limit right)
  • Right to opt out of "sale" or "sharing" — we do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. There is accordingly nothing to opt out of.
  • Right to non-discrimination for exercising your privacy rights

Categories of personal information we collect. Identifiers (name, email, IP address); commercial information (subscription and billing records); internet/network activity information (browsing, search, and usage logs); geolocation information (approximate, derived from IP); professional information (if you voluntarily share it); inferences drawn from the above (communication preferences, usage patterns). We collect these categories directly from you and automatically from your device. We use them for the purposes described in Section 3.

To exercise your California rights, email admin@gr1drecon.io. You may designate an authorized agent; we may require written verification of the agent's authority.

13. Other U.S. State Privacy Rights

Residents of Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Virginia (VCDPA), and other states with comprehensive privacy laws have rights similar to those described in Sections 11 and 12, which may include the rights to access, correct, delete, and port personal information, and the right to opt out of targeted advertising, sale of personal information, or certain profiling. Because we do not engage in targeted advertising, sale of personal information, or high-impact profiling, no opt-out mechanism is needed. To exercise your rights, email admin@gr1drecon.io. If we deny a request, you may appeal by replying to our denial; we will respond to appeals within 60 days.

14. Children's Privacy

The Service is not directed at children. We do not knowingly collect personal information from anyone under the age of 13 (or 16 in the EEA/UK and other jurisdictions that require a higher age). If we learn we have collected personal information from a child without verified parental consent, we will delete it. If you believe a child has provided us with personal information, please contact admin@gr1drecon.io.

15. Cookies and Local Storage

The Service uses a small number of strictly necessary cookies and browser local-storage entries for:

  • Session management — keeping you logged in across page visits (authentication tokens issued by our identity provider)
  • User preferences — remembering your selected jurisdiction, map state, project type, and display settings
  • Comparison and favorites data — storing parcel comparisons, saved searches, and starred items locally for fast access
  • Security — detecting tampering and preserving session integrity

We do not use third-party advertising cookies, cross-site tracking pixels, or data-broker cookies. Most browsers allow you to clear or block cookies and local storage, but doing so may prevent the Service from functioning correctly.

16. Security Incident Notification

If we discover a security incident that results in the unauthorized acquisition of or access to your personal information, we will notify you and any applicable regulators as required by applicable law (including, where applicable, U.S. state breach-notification laws and Articles 33–34 of the GDPR). Our notice will describe, to the extent known, the nature of the incident, the categories of data involved, the likely consequences, and the measures we have taken.

17. Do Not Track

Some browsers offer a "Do Not Track" signal. Because there is no common industry standard for how to respond, we do not currently respond to Do Not Track signals. As noted above, we do not track users across third-party sites for advertising purposes.

18. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by email or in-app notification before the changes take effect (or sooner where required by law). Non-material changes are effective when posted. The "Last updated" date at the top indicates the most recent revision. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

19. Contact

For privacy questions, rights requests, or any concern about this Policy, contact us at admin@gr1drecon.io. We aim to respond within 30 days.

Questions or Concerns?

If you have questions about this Privacy Policy or how we handle your data, reach out to us.

admin@gr1drecon.io
GR1D.io
© 2026 GR1D Recon · All rights reserved
Contact Privacy Terms