Skip to content

Privacy Policy

In short

Geoverio's privacy policy explains what the platform collects, why it is collected, how long it is kept, and which processors handle it. It covers the geoverio.com website, the dashboard and the APIs: account data, billing records and request metadata — and no reselling of anyone's data.

Last reviewed 11 September 2026

Key facts

password storage
Argon2id hash
session cookie attributes
HttpOnly Secure SameSite=Lax
EEA data transfer basis
Standard Contractual Clauses

This policy describes what Geoverio collects, why we collect it, how long we keep it, and who else processes it on our behalf. It covers geoverio.com and every API endpoint we operate.

Last updated: 28 July 2026

The short version

  • We collect what an account needs to exist and what an API call needs to be answered and billed. Nothing else.
  • We do not sell personal data, and we do not use API request content to build advertising or profiling products.
  • API request content — the address or IP address you send us — is processed to answer the request. We do not retain the personal content of API requests beyond what caching and abuse prevention require.
  • You can export or delete your account data by writing to [email protected].

Who is responsible

Geoverio is the controller for account and billing data. For the content of API requests you send us on behalf of your own users, you are the controller and Geoverio is the processor — see our Data Processing Addendum.

What we collect

Account data

Provided by you when you register or update your profile: name, email address, password (stored only as an Argon2id hash with a server-side pepper — never in plain text), and optionally company name, billing address, country, and VAT or Tax ID. If you enable two-factor authentication we store a TOTP secret, and your recovery codes as hashes.

API keys

Keys are generated server-side, shown to you exactly once, and stored as a hash alongside a short non-secret prefix used to identify them in your dashboard. We cannot recover a lost key; you revoke it and create another.

Usage and security data

For each API request we record the timestamp, the endpoint, the key used, the response status and the latency, so we can meter your plan, show you usage, and investigate abuse. We record the IP address of sign-in attempts for rate limiting and account protection; those records are automatically deleted after two days. One-time email codes are deleted after two days.

API request content

To answer a request we necessarily process what you send: a postal address for the Sales Tax and Address Autocomplete APIs, an IP address for the IP Lookup API. Results may be cached to keep the service fast and to reduce load on upstream data sources. We do not use this content to build user profiles, and we do not sell it.

Postal addresses and IP addresses can be personal data. If you send us data about your own users, please read the DPA — it sets out our obligations as your processor.

Support correspondence

If you email us, we keep the message and our reply so we have the history when you write again.

Cookies

We use a small number of strictly necessary cookies and no advertising or cross-site tracking cookies.

  • Session cookie — keeps you signed in. HttpOnly, Secure, SameSite=Lax. Cleared when you sign out.
  • CSRF token — tied to your session; prevents another site submitting forms as you.
  • Remember-me token — only if you tick "Remember me", and revocable by signing out.

Your light/dark theme choice is stored in your browser's local storage, not in a cookie, and is never sent to us.

Who else processes your data

We keep the list short on purpose. Each of these is a processor acting on our instructions.

ProcessorPurposeData involved
StripePayments and subscription billingName, email, billing address, payment method. Card numbers go directly to Stripe and never touch our servers.
CloudflareCDN, TLS termination and DDoS protection in front of our sitesRequest metadata including IP address
Google FontsWeb fonts served on our public pagesYour IP address is visible to Google when your browser fetches a font file. We plan to self-host these to remove the dependency.
Our hosting providersRunning the application and the APIAll of the above, at rest and in transit

Our own outbound email runs on infrastructure we operate; it is not handed to a third-party email marketing platform.

International transfers

Our infrastructure and the processors above operate in the United States and the European Union. Where personal data of individuals in the EEA or the UK is transferred outside those areas, transfers are made under the European Commission's Standard Contractual Clauses.

How long we keep things

DataRetention
Account profileWhile the account exists, then deleted on request
Sign-in attempt records (with IP)2 days, deleted automatically
One-time email codes2 days, deleted automatically
API usage recordsKept for metering, billing history and abuse investigation
Invoices and billing recordsKept as long as tax and accounting law requires
Audit log of account actionsKept for security investigation

Your rights

Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Most of it you can do yourself in Settings. For anything else, write to [email protected] and we will respond within 30 days.

Deleting your account removes your profile and revokes your keys. Invoices and the records we are legally required to keep are retained for the statutory period.

Children

Geoverio is a developer tool sold to businesses and individuals building software. It is not directed at children, and we do not knowingly collect data from anyone under 16.

Changes

If we change this policy materially we will update the date above and email account holders before the change takes effect.

Contact

Privacy questions and data requests: [email protected]. Everything else: [email protected].

Frequently asked questions

Does Geoverio sell personal data?
No. We do not sell personal data, nor do we use API request content to build advertising or profiling products.
How long are sign-in attempt records kept?
We record the IP address of sign-in attempts for two days before automatically deleting them.
Who is responsible for API request content?
When you send us API requests, you act as the controller for that content while we serve as the processor.