Plain-language summary: TerrAlert collects only what it needs to run the service, never sells personal data, lets you export or delete your data at any time, and complies with GDPR (EU), UK GDPR, and CCPA (California).
TerrAlert, Inc. ("TerrAlert", "we", "us", or "our") operates the TerrAlert satellite change detection platform available at https://terralert.io and via API. TerrAlert is the data controller for personal data processed in connection with the TerrAlert service.
Registered address: TerrAlert, Inc., [TODO: registered business address], United States.
Data Protection Officer (DPO) contact: [email protected]
When you register or subscribe, we collect:
We do not collect or store your password. Sign-in is handled entirely by our authentication provider, Supabase (email/password or Google OAuth) — your credentials are created, verified, and held on Supabase's infrastructure and are never transmitted to or stored on TerrAlert servers. We receive only a short-lived, signed session token confirming who you are.
AOI coordinates you draw or upload are your data. We process them to deliver the change-detection service but do not claim ownership of or sell them. Satellite imagery tiles are sourced from public archives (Sentinel-2, Landsat 9) and third-party CDNs (Esri, CartoDB) — we do not store raw imagery on your behalf.
Payment card details are processed exclusively by Stripe, Inc. and are never transmitted to or stored on TerrAlert servers. We retain only Stripe customer IDs and subscription metadata (plan, status, renewal date).
If you contact us via email or in-app support, we retain the message content and your contact details for the duration of the support relationship.
| Purpose | Data used | Basis |
|---|---|---|
| Provide and operate the TerrAlert service | Account, AOI, usage data | Contract performance |
| Process billing and prevent fraud | Billing address, Stripe metadata | Contract performance / legal obligation |
| Send change-detection alerts (email / webhook) | Email address, webhook URL | Contract performance |
| Provide customer support | Communications data | Legitimate interest |
| Improve and develop the product | Aggregated usage events | Legitimate interest |
| Send product updates and security notices | Email address | Legitimate interest / consent |
| Comply with legal obligations | Account and billing data | Legal obligation |
| Send marketing communications (opt-in only) | Email address | Consent |
We do not sell, rent, or broker your personal data to any third party for their marketing purposes, at any time, ever.
For individuals in the European Economic Area (EEA) or United Kingdom, we rely on the following lawful bases under Article 6 GDPR:
For special-category data, we do not intentionally collect any. If geospatial AOI coordinates in certain contexts could reveal special-category information, we process them solely on the basis of Article 9(2)(a) (explicit consent) or Article 9(2)(g) (substantial public interest).
We share data only with the following categories of sub-processors, all bound by data processing agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA (SCCs) |
| Supabase, Inc. | Authentication and database hosting | USA / EU (configurable region) |
| Twilio SendGrid | Transactional email delivery | USA (SCCs) |
| Redis / Celery (self-hosted) | Job queue and task processing | Customer-selected cloud region |
| Esri / CartoDB | Tile CDN for map rendering (no personal data sent) | USA / Global CDN |
| Nominatim / OpenStreetMap | Place-name geocoding — anonymous requests only | EU |
We may also disclose data if required by law, court order, or to protect the rights, safety, or property of TerrAlert, our users, or the public.
TerrAlert operates globally. If your data is transferred outside the EEA or UK, we ensure adequate protection through:
A list of applicable transfer mechanisms for each sub-processor is available on request at [email protected]. Enterprise and business customers may also request a signed Data Processing Agreement (DPA), including the EU Standard Contractual Clauses, by contacting the same address before processing any personal data on their behalf.
| Data category | Retention period | Reason |
|---|---|---|
| Account data | Duration of subscription + 90 days post-cancellation | Allows reactivation; then purged |
| AOI definitions and alert history | Per plan — 30 days (Free) up to unlimited (Enterprise); see the Pricing page for your plan's exact window | Plan feature |
| Billing records | 7 years from invoice date | Tax and legal obligation (EU/US) |
| API access logs | 90 days (then anonymised) | Security monitoring |
| Support communications | 3 years from ticket close | Legitimate interest |
| Marketing consent records | Until consent withdrawn + 3 years | Proof of consent |
| Anonymised analytics | Indefinite | Product improvement — not personal data |
On account deletion we immediately soft-delete your profile and queue permanent deletion within 30 days, except for data we must retain for legal obligations.
TerrAlert implements defence-in-depth security controls. We describe them here at the same level of precision as our Security page, which is independently verified against the live system and updated after every audit cycle — where a control is partial or in progress, we say so rather than round up:
For the full, itemised security posture — including what's still in progress — see our Security page.
These cookies are essential to the service and cannot be disabled:
| Cookie name | Purpose | Expiry |
|---|---|---|
ta_session | Authenticated session token (JWT wrapper) | Session / 7 days (remember me) |
ta_csrf | CSRF protection token | Session |
ta_consent | Records your cookie consent preference | 1 year |
| Cookie name | Provider | Purpose | Expiry |
|---|---|---|---|
_ta_anon | TerrAlert (first-party) | Anonymous product analytics | 90 days |
We do not use Google Analytics, Meta Pixel, or any third-party advertising cookies.
You can manage or withdraw consent at any time via the Cookie Settings link in the site footer, or by clearing cookies in your browser. Withdrawing consent for analytics cookies does not affect your ability to use the service.
If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation:
| Right | Description | Available |
|---|---|---|
| Access (Art. 15) | Receive a copy of all personal data we hold about you | Yes |
| Rectification (Art. 16) | Correct inaccurate or incomplete data | Yes |
| Erasure (Art. 17) | Request deletion of your personal data ("right to be forgotten") | Yes |
| Portability (Art. 20) | Export your data in machine-readable format (JSON / GeoJSON) | Yes |
| Restriction (Art. 18) | Restrict processing while a dispute is resolved | Yes |
| Object (Art. 21) | Object to processing based on legitimate interests | Yes |
| Withdraw consent (Art. 7) | Withdraw consent for consent-based processing at any time | Yes |
| Automated decisions (Art. 22) | Not be subject to solely automated decisions with significant legal effects | Yes — no such decisions made |
To exercise any right, email [email protected] with subject line "GDPR Request — [Right]". We will respond within 30 days (or 3 months for complex requests, with notice).
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national supervisory authority. For EEA residents: your local DPA. For UK residents: the Information Commissioner's Office (ICO).
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights:
To submit a CCPA request, email [email protected] with subject "CCPA Request". We will verify your identity and respond within 45 days.
TerrAlert is a B2B professional service not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact [email protected] and we will delete it promptly.
We may update this Privacy Policy periodically. Material changes will be communicated via:
Continued use of the service after the effective date constitutes acceptance of the revised policy. If you do not agree, you may close your account before the effective date.
For any privacy questions, data subject requests, or to contact our Data Protection Officer:
This policy is compliant with GDPR (Regulation (EU) 2016/679), UK GDPR (retained EU law), and the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.).