Privacy Policy

pointkit ("pointkit", "we", "us") converts addresses into database geometry literals at pointkit.io. This page explains what data the service collects, why, how long it's kept, who else sees it, and how to exercise your rights over it.

For any privacy question or request, contact [email protected] — that inbox is the fastest way to reach us about this policy.

1. What we collect, and why

Using the converter (single lookups)

DataPurposeRetention
The address you enterSent to a geocoding provider to resolve coordinates; the normalized text and result are added to a shared cache (see §3) so the same address doesn't need paying for twiceCache entry: kept while still being reused, purged 18 months after its last lookup (see §3)
A random identifier cookie (pk_client) and your IP addressEnforcing the free daily usage limitCookie: up to 400 days. Usage counters: kept as day-scoped rows, no address content

Uploading a CSV (batch conversion)

DataPurposeRetention
The uploaded file (every column, not just the address one) and the result fileRunning the conversion, letting you poll status and download the resultDeleted within 48 hours of the job finishing
Each row's address textSame shared coordinate cache as single lookupsSame 18-month sliding window (see §3)
Job metadata (id, status, row count, dialect, timestamps)Basic operational record-keeping after the file itself is deletedIndefinite; contains no address or file content

If the file you upload contains other people's addresses (customers, contacts, records) rather than just your own, see §7 — you're the one responsible for having the right to share that data with us.

Buying credits

DataPurposeRetention
Your email address, credit balance, and purchase history (amount, credits, timestamp)Keeping your purchased balance available across devices and cleared cookies, and giving you a purchase historyIndefinite, while the balance exists — deleted on request (§6)
Payment card detailsNever received or stored by pointkit at all — handled entirely by Stripe

Signing in

DataPurposeRetention
Your email address and a single-use sign-in linkPasswordless sign-in ("magic link")Link: expires after 15 minutes or first use, whichever is first
A signed-in session cookie (pk_session)Keeping you signed in30 days, or until you log out
Your IP address, when requesting a sign-in linkRate-limiting that endpoint so it can't be used to spam arbitrary inboxesRolling hourly window

Everyone, automatically

DataPurposeRetention
Request metadata and error details (URL, IP, stack trace) when something breaksDiagnosing and fixing bugsPer our error-monitoring provider's default (see §4)
Browser/device signals used by our bot-protection challengeBlocking automated abuse of the free tierPer our bot-protection provider's policy (see §4)

2. Cookies

pointkit only sets cookies that are strictly necessary for the service to function (pk_client for the free-tier limit, pk_session for signed-in state) — there's no advertising or cross-site tracking, so no cookie-consent banner. Our bot-protection provider (Cloudflare Turnstile) may set its own cookie as part of running its challenge.

3. The address cache — why some data isn't deleted with your file

Geocoding providers charge (or rate-limit) per lookup. To avoid paying for the same address twice, pointkit keeps a single shared cache mapping normalized address text to a coordinate, used across every user's lookups and batch jobs. It is not linked to your account, cookie, IP, or any other identity — it's purely "this address text resolves to this coordinate."

This cache isn't covered by the 48-hour file-deletion window described above. Instead, each entry is kept on a sliding window: every time an address is looked up again, its clock resets, so an address that keeps getting reused stays cached indefinitely in practice; an address nobody's looked up again is deleted 18 months after its last hit. We rely on this being necessary for our legitimate interest in operating the service affordably (rather than re-paying a provider for every repeat lookup), balanced against the limited sensitivity of an address on its own, decoupled from any name, account, or other identifying context, and against a real, finite limit on how long an unused entry sits there. If you want a specific address removed sooner, contact [email protected] and we'll do our best, though because entries aren't linked to any identity, we generally can't verify a request is coming from the address's actual subject.

4. Who else sees your data

We use a small number of providers to run the service. Each only receives what it needs to do its job:

ProviderWhat they getRole
U.S. Census Bureau GeocoderAddress text (US addresses)Geocoding
GeoapifyAddress text (non-US / fallback)Geocoding
StripeEmail, purchase amountPayment processing
ResendEmail address, sign-in linkTransactional email delivery
SupabaseEverything described in §1 (it hosts the database)Database hosting
SentryRequest metadata, IP, error detailsError monitoring
Cloudflare (Turnstile)Browser/network signals during the bot-protection challengeAbuse prevention

We don't sell personal data, and don't share it for advertising purposes. Some of these providers are based outside the UK/EEA (principally the US); where that's the case, we rely on the safeguards they offer (such as Standard Contractual Clauses) for the transfer.

5. Legal bases (UK/EU GDPR)

6. Your rights

Subject to the usual legal exceptions, you can ask us to:

Email [email protected] from the address in question (this lets us confirm the request is really from the account holder). We aim to respond within one month. If you're not satisfied with our response, you can complain to your local data protection authority — in the UK, the Information Commissioner's Office (ICO).

If you have unused purchased credits: your email address is also the key your balance is stored under (see §1), so deleting your account deletes the balance and purchase history along with it — there's currently no way to keep the credits while deleting the account they're attached to. We don't offer automatic refunds for unused credits (see the Terms of Service, §2), but if you'd rather use up or discuss your remaining balance before deleting, say so in the same email and we'll sort it out manually first.

7. If your address is in someone else's upload

pointkit's batch converter is often used to process a list of someone else's customers or contacts, not just the uploader's own data. If that's you — your address was uploaded by an organization you have a relationship with, not entered by you directly — pointkit doesn't have a way to identify which upload contained your data or verify a request against it (see §3). Please contact the organization that uploaded it; they're the data controller responsible for that processing, and pointkit's role is limited to running the conversion on their instructions (see the Terms of Service, §5).

8. Changes to this policy

We'll update the date at the top when this policy changes. Material changes will be reflected here before they take effect.

9. Contact

[email protected]