Legal

Privacy Policy

Effective June 26, 2026

Who we are

Petrel ("Petrel," "we," "us"), operator of petreldata.io, is the controller of the personal data described in this policy. For questions or to exercise your rights, contact petreldata.io@gmail.com.

What we collect

Account data: when you sign up we collect your email address and authentication identifiers via Firebase Authentication (Google). If you sign in with Google, we receive your name and email from your Google account.

Usage data: for every API request we log the API key used, the endpoint path, a timestamp, response status, and the client IP address. We use this for metering, billing, abuse prevention, and the usage analytics shown in your dashboard.

Billing data: payments are processed by Stripe. Card numbers never touch Petrel servers — we store only the Stripe customer reference, subscription state, plan tier, and invoice records.

Public demo ("Try Petrel"): when you use the on-site demo, the address or place you enter is sent to our geocoding provider (MapTiler) to locate it, and is used to return hazard scores. If you ask us to email you a demo report, we collect the email address you provide and send the report via our billing service and email provider (Resend). We do not require an account to use the demo.

Sales and contact requests: if you request a demo or contact us, we receive the information you choose to send.

What we do not collect

We do not run third-party advertising trackers and we do not sell personal data. Query coordinates and demo locations are processed to serve the response and retained only in request logs as described here — we do not build profiles of the locations you query, and we do not share them. We do not knowingly collect data from children under 16; the Service is intended for business users.

Cookies and analytics

We use browser local storage for Firebase session persistence (keeping you signed in). For website analytics we use Plausible, which is cookieless and collects only aggregate, non-identifying usage metrics — no cross-site or advertising tracking cookies are set, so no cookie-consent banner is required for our analytics.

Lawful basis for processing (GDPR)

Where the EU/UK GDPR applies, we process personal data on these bases: performance of a contract (operating your account, API, and billing); our legitimate interests (securing the Service, preventing abuse, and understanding aggregate usage), balanced against your rights; consent (for optional marketing email, which you may withdraw at any time); and compliance with legal obligations (tax and accounting records).

Processors and infrastructure

We rely on the following processors, each acting only as needed to provide their service to us: Google Firebase (authentication), Stripe (payments and metered billing), Amazon Web Services (hosting and data delivery, US region us-east-1), Resend (transactional email), MapTiler (geocoding for the public demo), and Plausible (privacy-preserving analytics). We maintain data-processing terms with these providers.

International transfers

The Service is hosted in the United States (AWS us-east-1). If you access it from the EU/UK or another region, your personal data is transferred to and processed in the United States. For such transfers we rely on appropriate safeguards, including the Standard Contractual Clauses with our processors. A Data Processing Addendum is available to enterprise and EU/UK customers on request.

Retention and deletion

We retain account and usage records while your account is active and as required for billing, tax, and legal compliance (financial records are typically retained for up to seven years). API request logs are retained for a limited operational window for security and metering. Demo report-request emails are retained until you ask us to delete them or for a limited follow-up window. You can request deletion of your account at any time via the email below; we deactivate the account and associated API keys immediately and delete or anonymize personal data that is not subject to a legal or financial retention requirement.

Your rights

Depending on your jurisdiction (including the EU/UK GDPR), you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority. Contact us at the address below and we will respond within the timeframe required by applicable law.

California residents (CCPA/CPRA): in the past 12 months we have collected identifiers (email, IP), commercial information (subscription and billing records), and internet activity (API usage logs), for the business purposes described above. We do not "sell" or "share" personal information as those terms are defined under the CPRA, and we do not use sensitive personal information for inferring characteristics. You have the right to know, delete, and correct your information, and to be free from discrimination for exercising these rights.

Security

We protect personal data with the controls described on our Security page, including TLS in transit, hashed API-key secrets, secrets management, and PCI-DSS-compliant payment processing through Stripe.

Contact

Data questions and requests: petreldata.io@gmail.com. We will update this policy as the Service evolves; material changes are announced to the email on your account.