Privacy Policy
This Privacy Policy explains what personal information Georithm collects when you use our location-intelligence platform, why we collect it, who we share it with, and the rights available to you under laws including the GDPR, UK GDPR, PIPEDA, CCPA/CPRA and the Australian Privacy Principles. It also explains how to submit a privacy request or contact our Data Protection Officer.
- Version
- v1.0
- Last updated
- 29 July 2026
This Privacy Policy applies to personal information processed by Georithm ("we", "us") through our hosted web application, related APIs, and any support or account communications.
This policy is written to address the requirements of multiple privacy frameworks, including the EU General Data Protection Regulation (GDPR), the UK GDPR, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where a specific law grants you additional or different rights, that law will govern in relation to your data.
If you have questions about this policy, contact us at jerogz@georithm.info or write to [Business Address], [Country].
We collect the following categories of information:
- Account information — name, email address, password hash (for email/password sign-in), or profile identifiers provided by Google when you sign in with Google, organization name, and role.
- Usage data — pages viewed, features used, search and query history within the platform, timestamps, and interaction logs.
- Device information — browser type, operating system, IP address, and general device identifiers collected automatically when you access the app.
- Cookies and similar technologies — as described in our [Cookie Policy](/legal/cookie-policy).
- Analytics data — aggregated and event-level usage statistics used to understand product performance.
- Payment information — billing name, billing address, and payment method details, which are processed by our payment processor, Stripe; we do not store full card numbers on our own servers.
- Support communications — messages, attachments, and metadata you share with our support team.
- Location and search queries — addresses, coordinates, place names, and other location-related inputs you enter into the platform to generate maps or AI-driven insights, along with the outputs generated from them.
We use personal information to:
- Create and maintain your account and authenticate sign-ins.
- Provide the core Georithm service, including mapping, search, and AI-generated location insights.
- Process subscription payments and manage billing through Stripe.
- Send transactional email such as account confirmations, security alerts, and billing receipts.
- Analyze usage to maintain, secure, and improve the platform.
- Respond to support requests and communicate service updates.
- Comply with legal obligations and enforce our terms of service.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create your account, provide the Georithm service, and process payments.
- Legitimate interests — to secure the platform, prevent abuse, analyze aggregate usage, and improve features, balanced against your rights and interests.
- Consent — for non-essential cookies, marketing communications, and any optional analytics you opt into; you may withdraw consent at any time.
- Legal obligation — where processing is required to comply with applicable law, such as tax or accounting requirements.
You can review or manage consent-based processing at any time through account Privacy settings.
We retain personal information for as long as your account is active and as needed to provide the service. After account closure, we retain data for a limited period to comply with legal, tax, accounting, or dispute-resolution obligations, after which it is deleted or anonymized in accordance with our internal retention schedules.
Support communications, billing records, and audit logs may be retained longer where required for legal or security purposes. You may request deletion of your data earlier, subject to the limitations described in this policy.
Feedback submissions (including any screenshot or file you attach, and the browser, device, page and timestamp details captured with them) are retained for a maximum of 365 days. An automated daily job permanently deletes submissions and their attachments once that window passes; administrators may purge them sooner. Attachments are held in private storage that only administrators can access, and deleting a submission also deletes its attachment. You can ask us to delete your feedback at any time via a privacy request.
We do not sell personal information. We share personal information with service providers ("sub-processors") who help us operate Georithm, under contractual confidentiality and data protection obligations, including:
- Supabase — database hosting and authentication (email/password and Google sign-in).
- Mapbox — map rendering and geocoding services.
- Stripe — payment processing and billing.
- AI model gateway providers — processing of search and location queries to generate AI-driven insights.
- Transactional email providers — delivery of account and billing notifications.
We may also disclose information where required by law, to protect our rights or the safety of users, or in connection with a merger, acquisition, or asset sale, subject to continued protection of personal information.
Georithm's infrastructure and sub-processors may process personal information in countries other than your own, including the United States and European Union member states. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum (UK IDTA), or other legally recognized transfer mechanisms.
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information, subject to legal exceptions.
- Port your data in a structured, machine-readable format.
- Object to certain processing, including processing based on legitimate interests.
- Restrict processing in certain circumstances.
- Withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Non-discrimination — under the CCPA/CPRA, you will not receive discriminatory treatment for exercising your privacy rights.
Australian users have equivalent rights under the Australian Privacy Principles, including access and correction rights, and the ability to make a complaint about a suspected interference with privacy.
You can exercise most rights directly within the product:
- Use the in-app privacy request form at /legal/privacy-request to submit access, correction, deletion, portability, or objection requests.
- Manage consent, communication preferences, and download your data from account Privacy settings.
- Email jerogz@georithm.info if you need assistance or a request cannot be completed in-app.
We will verify your identity before fulfilling a request and will respond within the timeframes required by applicable law.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. If this practice changes, we will update this policy and provide any required opt-out mechanisms.
Georithm is intended for business and professional use and is not directed to children. We do not knowingly collect personal information from children under the age of applicable legal consent (for example, 13 or 16 depending on jurisdiction). If you believe a child has provided us with personal information, contact jerogz@georithm.info so we can review and, where appropriate, delete it.
We maintain a range of technical and organizational measures designed to protect personal information, including:
- Encryption of data in transit using industry-standard protocols.
- Encryption of data at rest for stored personal information.
- Secure authentication, including support for email/password and Google sign-in.
- Rate limiting to reduce automated abuse.
- Audit logging of administrative and security-relevant actions.
- Role-based permissions restricting access to personal information on a need-to-know basis.
These measures reduce risk but do not guarantee absolute security; no system can be guaranteed to be completely secure.
Georithm uses an AI model gateway to generate location-based insights, summaries, and recommendations from the queries and data you provide. These outputs are intended to support, not replace, your own business judgment. We do not use these AI-generated outputs to make legal or similarly significant automated decisions about individuals without human involvement. Where required by law, you may request information about the logic involved in significant automated processing affecting you.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will update the "last updated" date and, where changes are material, provide additional notice such as an in-app message or email.
For questions about this policy or our privacy practices, or to contact our Data Protection Officer, reach us at:
- Email: jerogz@georithm.info
- Data Protection Officer: [Data Protection Officer]
- Postal address: [Business Address], [Country]
This document is provided as an original template for Georithm and is maintained by the account owner. It is app-owned editable content and is not legal advice or an independent certification. Replace every bracketed placeholder with your company details and have the final text reviewed by a qualified adviser before relying on it.