Privacy policy
This is a draft. It describes how Landmate will handle personal information once the service launches. It is not in effect and may change before it is approved.
Who we are
Landmate is operated by Charlie Ingoglia ("Landmate", "we", "us"). Postal address: TODO(owner-approval). Privacy contact: TODO(owner-approval): email address and phone number for privacy questions.
What this policy covers
This policy covers this website and the Landmate web and mobile apps. Landmate is in early development; parts of the app described here are not available yet.
Information we collect
On this website
- Contact form. When you send a message, we receive your name, email address, organization (if you give one) and your message. We use them only to reply to you. A one-way hash of your network address and of the message is kept briefly in memory to stop repeated or duplicate submissions.
- Technical information. Our hosting provider processes your network address and request details to deliver pages and protect the site from abuse.
- No tracking. This website sets no cookies for visitors, loads no advertising or analytics trackers and keeps no visit counters.
- Content editors. The people who maintain this website sign in to its content editor with their GitHub account. See the cookie policy.
In the Landmate app
- Account information: your name, email address, password (stored only as a secure hash), language, and security settings such as two-step verification.
- Workspace information: the workspaces you belong to, your role and location access, and the files and content you and your colleagues add. A workspace may hold information about other people, such as residents, owners or vendors; the organization that owns the workspace decides what it enters.
- Security records: sign-in sessions, devices and an audit log of administrative actions.
- Billing information for the workspace subscription. Card payments are handled by Stripe on its own pages; full card numbers never reach Landmate. We keep only the references Stripe gives us.
- The demo. "Try the demo" asks for your name, email address and company name, and offers an unticked box for a few tips by email. It then opens a private sample workspace for one visit (about two hours), which is deleted when the visit ends; opening it does not create an account. We keep your name, email address, company name and whether you ticked the box, so the demo's limits apply per person and so we know who has tried the product, plus one-way hashes of your email address and network address and a signed random browser marker (the
lm_demo_devicecookie, see the cookie policy) to count entries. We do not email you about the demo unless you tick the box, and you can withdraw that consent at any time. Please do not enter real information into the demo. - Partner program. If you take part in the partner program, we keep your partner organization's name and contact details, your sign-in email, your password (as a secure hash), your two-step verification settings, and the workspaces that signed up through your link. A referral code from a partner link is kept in your browser for that tab only, so it can be credited at sign-up.
In the mobile app
The mobile app uses the same account as the web app. It does not ask for access to your location, camera, microphone, photos or contacts. Your sign-in is kept in the device's secure storage. If you turn on biometric unlock (Face ID, Touch ID or Android biometrics), the check happens on the device; biometric data never leaves it. The mobile app shows no ads and uses no third-party analytics, crash reporting or tracking.
How we use information
We use your information to provide and secure the service, to respond to you, and to keep the records needed to protect accounts (for example, the audit log), and for nothing else. We do not sell personal information, we do not rent lists, and we do not use it for advertising. We do not use the information in your workspace for our own marketing.
AI assistant
If a workspace uses the optional AI assistant, the content you give it is processed by Anthropic to produce a response. See the AI disclosure.
Service providers
We use service providers to run Landmate. They process data on our instructions and only for the purposes below.
- Cloudflare, Inc.: serves the website and the app, stores uploaded files (R2), sends email from our domains (Email Service), checks forms for bots (Turnstile) and connects the app to its database (Hyperdrive).
- Amazon Web Services, Inc.: hosts the app's database (Amazon Aurora).
- Stripe, Inc.: bills the workspace subscription. Landmate does not collect rent or any other payment on your behalf.
- Anthropic, PBC: processes the content sent to the optional AI assistant to generate a response. We do not send it for model training.
- GitHub, Inc.: hosts this website's source and content, and signs in the people who edit it.
Where your data lives
The service runs on Cloudflare's global network. App data is stored in a MySQL database hosted on Amazon Aurora (AWS) and in Cloudflare R2 storage, and is protected in transit by TLS. TODO(owner-approval): the storage regions and the safeguards for international transfers.
How long we keep it
For as long as your account is in use, and then for a while afterwards, so that leaving by accident costs you nothing.
If you leave (you cancel, or your trial ends and you never subscribe), we keep the workspace for six months after your access actually ends. Canceling takes effect at the end of the period you have already paid for, so the six months start from that day. Coming back within those six months picks up exactly where you left off. After them the workspace becomes eligible for deletion, and a person at Landmate reviews it before anything is deleted. No further notice is sent, so export your data before you go if you want a copy.
If your workspace pays nothing and nobody signs in for a year, we email the workspace Owner and pause the workspace: it is locked, but nothing is deleted, and signing in brings it all back immediately. If nobody signs in during the three months after the pause, the workspace becomes eligible for deletion, again with a person reviewing it first.
When a workspace is deleted, it is deleted in full: every record, every uploaded file and the email addresses of its users, which become free to sign up with again. Deletion does not reach into backups: deleted data can persist in an encrypted database backup until that backup rotates on its normal schedule. Backups are not used to restore deleted accounts.
Everything else keeps its own clock. Contact-form messages are kept so that we can answer you and keep a record of who has asked about the product; you can ask us to delete yours at any time. Demo workspaces are deleted when the visit ends. The name, email address, company name and consent you gave to open the demo are cleared 90 days after you last used or requested the demo; what remains is the hashed counters that make the limits work. Partner records and the referrals credited to them are kept for as long as they must stay auditable.
You can ask us to delete your account sooner, at any time; see Account deletion.
Your choices and rights
Your workspace's data belongs to your organization. A workspace Owner can export it and delete the workspace, and you can export your own account data and delete your account (see Data export and account deletion and Account deletion). You can also ask us for a copy of your information, or to correct or delete it, by writing to the privacy contact above from the email address on your account.
Children
Landmate is a business tool. You must be at least 18 years old to use it, and it is not directed to children.
Changes
We will post changes to this page and update the date above. Material changes will be announced in the app before they take effect.
Contact
Questions about privacy: TODO(owner-approval): privacy contact email address.