🔒 Legal

Privacy Policy

Effective date: 1 July 2026 Last updated: 20 July 2026 Version: 1.1

Plain-language summary: TerrAlert collects only what it needs to run the service, never sells personal data, lets you export or delete your data at any time, and complies with GDPR (EU), UK GDPR, and CCPA (California).

1 Who we are

TerrAlert, Inc. ("TerrAlert", "we", "us", or "our") operates the TerrAlert satellite change detection platform available at https://terralert.io and via API. TerrAlert is the data controller for personal data processed in connection with the TerrAlert service.

Registered address: TerrAlert, Inc., [TODO: registered business address], United States.

Data Protection Officer (DPO) contact: [email protected]

2 Data we collect

2.1 Account and identity data

When you register or subscribe, we collect:

We do not collect or store your password. Sign-in is handled entirely by our authentication provider, Supabase (email/password or Google OAuth) — your credentials are created, verified, and held on Supabase's infrastructure and are never transmitted to or stored on TerrAlert servers. We receive only a short-lived, signed session token confirming who you are.

2.2 Usage and product data

2.3 Geospatial data

AOI coordinates you draw or upload are your data. We process them to deliver the change-detection service but do not claim ownership of or sell them. Satellite imagery tiles are sourced from public archives (Sentinel-2, Landsat 9) and third-party CDNs (Esri, CartoDB) — we do not store raw imagery on your behalf.

2.4 Payment data

Payment card details are processed exclusively by Stripe, Inc. and are never transmitted to or stored on TerrAlert servers. We retain only Stripe customer IDs and subscription metadata (plan, status, renewal date).

2.5 Technical and log data

2.6 Communications data

If you contact us via email or in-app support, we retain the message content and your contact details for the duration of the support relationship.

3 How we use your data

PurposeData usedBasis
Provide and operate the TerrAlert serviceAccount, AOI, usage dataContract performance
Process billing and prevent fraudBilling address, Stripe metadataContract performance / legal obligation
Send change-detection alerts (email / webhook)Email address, webhook URLContract performance
Provide customer supportCommunications dataLegitimate interest
Improve and develop the productAggregated usage eventsLegitimate interest
Send product updates and security noticesEmail addressLegitimate interest / consent
Comply with legal obligationsAccount and billing dataLegal obligation
Send marketing communications (opt-in only)Email addressConsent

We do not sell, rent, or broker your personal data to any third party for their marketing purposes, at any time, ever.

5 Data sharing and third parties

We share data only with the following categories of sub-processors, all bound by data processing agreements:

Sub-processorPurposeLocation
Stripe, Inc.Payment processingUSA (SCCs)
Supabase, Inc.Authentication and database hostingUSA / EU (configurable region)
Twilio SendGridTransactional email deliveryUSA (SCCs)
Redis / Celery (self-hosted)Job queue and task processingCustomer-selected cloud region
Esri / CartoDBTile CDN for map rendering (no personal data sent)USA / Global CDN
Nominatim / OpenStreetMapPlace-name geocoding — anonymous requests onlyEU

We may also disclose data if required by law, court order, or to protect the rights, safety, or property of TerrAlert, our users, or the public.

6 International transfers

TerrAlert operates globally. If your data is transferred outside the EEA or UK, we ensure adequate protection through:

A list of applicable transfer mechanisms for each sub-processor is available on request at [email protected]. Enterprise and business customers may also request a signed Data Processing Agreement (DPA), including the EU Standard Contractual Clauses, by contacting the same address before processing any personal data on their behalf.

7 Data retention

Data categoryRetention periodReason
Account dataDuration of subscription + 90 days post-cancellationAllows reactivation; then purged
AOI definitions and alert historyPer plan — 30 days (Free) up to unlimited (Enterprise); see the Pricing page for your plan's exact windowPlan feature
Billing records7 years from invoice dateTax and legal obligation (EU/US)
API access logs90 days (then anonymised)Security monitoring
Support communications3 years from ticket closeLegitimate interest
Marketing consent recordsUntil consent withdrawn + 3 yearsProof of consent
Anonymised analyticsIndefiniteProduct improvement — not personal data

On account deletion we immediately soft-delete your profile and queue permanent deletion within 30 days, except for data we must retain for legal obligations.

8 Security measures

TerrAlert implements defence-in-depth security controls. We describe them here at the same level of precision as our Security page, which is independently verified against the live system and updated after every audit cycle — where a control is partial or in progress, we say so rather than round up:

For the full, itemised security posture — including what's still in progress — see our Security page.

9 Cookies and tracking

9.1 Strictly necessary cookies

These cookies are essential to the service and cannot be disabled:

Cookie namePurposeExpiry
ta_sessionAuthenticated session token (JWT wrapper)Session / 7 days (remember me)
ta_csrfCSRF protection tokenSession
ta_consentRecords your cookie consent preference1 year

9.2 Analytics cookies (consent required)

Cookie nameProviderPurposeExpiry
_ta_anonTerrAlert (first-party)Anonymous product analytics90 days

We do not use Google Analytics, Meta Pixel, or any third-party advertising cookies.

9.3 Managing cookies

You can manage or withdraw consent at any time via the Cookie Settings link in the site footer, or by clearing cookies in your browser. Withdrawing consent for analytics cookies does not affect your ability to use the service.

10 Your rights (GDPR / UK GDPR)

If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation:

RightDescriptionAvailable
Access (Art. 15)Receive a copy of all personal data we hold about youYes
Rectification (Art. 16)Correct inaccurate or incomplete dataYes
Erasure (Art. 17)Request deletion of your personal data ("right to be forgotten")Yes
Portability (Art. 20)Export your data in machine-readable format (JSON / GeoJSON)Yes
Restriction (Art. 18)Restrict processing while a dispute is resolvedYes
Object (Art. 21)Object to processing based on legitimate interestsYes
Withdraw consent (Art. 7)Withdraw consent for consent-based processing at any timeYes
Automated decisions (Art. 22)Not be subject to solely automated decisions with significant legal effectsYes — no such decisions made

To exercise any right, email [email protected] with subject line "GDPR Request — [Right]". We will respond within 30 days (or 3 months for complex requests, with notice).

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national supervisory authority. For EEA residents: your local DPA. For UK residents: the Information Commissioner's Office (ICO).

11 California privacy rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights:

To submit a CCPA request, email [email protected] with subject "CCPA Request". We will verify your identity and respond within 45 days.

12 Children's privacy

TerrAlert is a B2B professional service not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact [email protected] and we will delete it promptly.

13 Changes to this policy

We may update this Privacy Policy periodically. Material changes will be communicated via:

Continued use of the service after the effective date constitutes acceptance of the revised policy. If you do not agree, you may close your account before the effective date.

14 Contact and DPO

For any privacy questions, data subject requests, or to contact our Data Protection Officer:

This policy is compliant with GDPR (Regulation (EU) 2016/679), UK GDPR (retained EU law), and the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.).