Privacy
How Spatia handles information
Learn what information Spatia collects, how place reports and account data are used, when service providers receive information, and how to make a privacy request.
Effective date and scope
October 5, 2026. This policy describes the information practices of Spatia at runspatia.com and the services used to create, store, purchase, and share Spatia reports. It does not govern a third party's own website or service.
Information Spatia collects
- Account information: the account identifier, email address, display name, and profile image returned through Google sign-in, or, if you use email sign-in, the email address you enter (email sign-in provides no name or profile image), plus the reports you have bought.
- Session information: signed session, OAuth-state, and email sign-in cookies used to sign you in, protect the sign-in flow, remember the address a one-time sign-in code was sent to, and return you to the requested page.
- Report inputs and results: typed and resolved addresses, coordinates, the parcel, building, or unit you pick, the coverage preview shown to you, report records, the written summary, citations, and map evidence.
- Service activity and diagnostics: report and run identifiers, timestamps, token usage and cost records, data-query events, coverage gaps, disputes, failures, logs, and security-related events. These records can include an address from a run.
- Purchase information: the email, account identifier, report purchased, amount, currency, payment status, refund state, and Stripe Checkout, payment-intent, and event identifiers associated with a purchase. Stripe handles payment-card details; Spatia does not receive the full card number.
- Device and network information: request metadata such as IP address, browser or device type, referring page, pages visited, timing, and performance information produced by hosting, security, and analytics systems.
- Communications: messages and attachments you send to support, privacy, or legal addresses, plus information reasonably needed to verify and answer a request.
- Public-source and provider facts: geographic, property, environmental, and other facts retrieved from cited public sources or configured data providers for the place you ask about. A public source does not make the resulting address-specific report public by default.
How Spatia uses information
- Authenticate accounts, send one-time sign-in links and codes when you choose email sign-in, keep sessions working, and provide account entitlements.
- Resolve an address, show a coverage preview, run the report's checks, create and store a report, and re-run a report that failed.
- Sell reports, issue receipts, process disputes, and maintain financial records.
- Operate, secure, debug, and improve the service; investigate incorrect findings and coverage gaps; and measure reliability and performance.
- Respond to communications, enforce service rules, prevent abuse, protect users and the service, and meet legal obligations.
AI and address lookup providers
To write a report's summary, Spatia sends the exact typed or resolved location and the report's records to Google Gemini, which returns text that restates those records. Spatia keeps bulk source rows and GeoJSON out of that request, but it does not keep your address away from the AI provider.
Address text is sent to Spatia's geocoding and autocomplete services, which may use third-party address lookup providers. These providers process information under their own terms and privacy practices.
Service providers may process information in the United States and other countries where they or their subprocessors operate. Laws and protections can differ by location.
When information is disclosed
- Cloudflare provides hosting, delivery, security, compute, database, object-storage, and optional web-analytics services, and sends email sign-in messages (a one-time link and code) to the address you enter through Cloudflare Email Service.
- Google supports Google sign-in; Google Gemini processes report summary requests; Stripe provides hosted checkout and payment services; and address lookup providers perform the requests described above.
- Your browser requests the site's Inter stylesheet and font files from Google Fonts. When you view an evidence map, it may also request map-label glyph assets from Protomaps' GitHub-hosted asset service and basemap tiles from Spatia's Cloudflare-hosted tile service. These requests expose ordinary network and device metadata to the service receiving them.
- Information may be disclosed when reasonably necessary to comply with law or valid legal process, protect rights or safety, investigate fraud or abuse, or secure the service.
- Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the service, subject to applicable notice requirements.
- Report content is disclosed to others only through a report link you share or when you otherwise direct Spatia to disclose it.
Private and shared reports
A completed report is private by default: it is not listed on the site, not included in the sitemap, and not submitted to search engines or AI discovery services, and the site's robots rules ask search engines not to crawl report pages. If a report has a shareable link, anyone holding that link can view the resolved address, records, sources, summary, and map evidence without signing in, so share it only with people you choose.
Spatia cannot guarantee deletion from browser or CDN caches, previously downloaded copies, or copies made by someone you shared a link with. Contact privacy@runspatia.com for help with a removal request.
Cookies, analytics, and tracking choices
Spatia uses a signed, HttpOnly session cookie, which also notes when you signed in by email. The session token generally expires after 24 hours, while the browser cookie can remain for up to 30 days; signing out clears it. Separate OAuth-state and email sign-in cookies each last up to 10 minutes. Theme preference may be stored in your browser. Blocking required cookies can prevent sign-in and account features from working.
When enabled, Cloudflare Web Analytics measures page use and performance. Cloudflare and other infrastructure providers also process ordinary request and security metadata. Spatia does not use third-party advertising cookies and does not currently sell personal information or share it for cross-context behavioral advertising.
Spatia does not currently change service behavior in response to the legacy browser Do Not Track signal. Because Spatia does not currently sell personal information or share it for cross-context behavioral advertising, a Global Privacy Control signal does not change those practices. Spatia does not authorize third parties to track activity on Spatia over time and across unrelated services for advertising; providers such as Google or Stripe may independently collect information when you interact with their services under their own policies.
Retention
There is no single retention period for every category. Session credentials use the expirations described above. Completed reports, report evidence, usage records, purchase records, disputes, and operational telemetry do not all have an automatic expiration and may remain until removed through an operational process.
Spatia evaluates verified deletion requests and may retain information needed to complete a transaction, keep financial or security records, resolve disputes, prevent fraud or abuse, enforce agreements, or meet legal obligations.
Your choices and privacy requests
You can sign out, decline to buy a report, avoid submitting information you do not want processed, and keep report links to yourself.
Email privacy@runspatia.com or write to the address below to ask whether Spatia holds information about you, request access to it, correct it, request deletion, or ask about its use or disclosure. Depending on where you live and whether the relevant law applies, you may have additional rights. Spatia may request enough information to verify your identity and authority before acting, and legal exceptions may apply. Spatia will not treat you differently for making a good-faith privacy request, except where a requested deletion or restriction makes a feature impossible to provide.
Security
Spatia uses safeguards that include HTTPS, signed HttpOnly and Secure cookies in production, short-lived session tokens, private-by-default reports, owner-scoped access checks, and access-controlled report evidence. No internet service can promise absolute security. Please contact privacy support if you believe your account or report information has been exposed.
Children
Spatia is not directed to children under 13. If you believe a child under 13 submitted personal information to Spatia, contact privacy@runspatia.com so the situation can be reviewed and appropriate action taken.
Changes to this policy
Spatia may update this policy as the service or its practices change. The effective date at the top will change when the policy changes. For a material change, Spatia will provide additional notice where appropriate, such as a prominent site or account notice, before the change takes effect when required.
Contact
Privacy requests: privacy@runspatia.com. Business correspondence address: Spatia, 1752 E Lugonia Ave, Ste 117 #1488, Redlands, CA 92374, US.