Privacy Policy
pointkit ("pointkit", "we", "us") converts addresses into database geometry literals at pointkit.io. This page explains what data the service collects, why, how long it's kept, who else sees it, and how to exercise your rights over it.
For any privacy question or request, contact [email protected] — that inbox is the fastest way to reach us about this policy.
1. What we collect, and why
Using the converter (single lookups)
| Data | Purpose | Retention |
|---|---|---|
| The address you enter | Sent to a geocoding provider to resolve coordinates; the normalized text and result are added to a shared cache (see §3) so the same address doesn't need paying for twice | Cache entry: kept while still being reused, purged 18 months after its last lookup (see §3) |
A random identifier cookie (pk_client) and your IP address | Enforcing the free daily usage limit | Cookie: up to 400 days. Usage counters: kept as day-scoped rows, no address content |
Uploading a CSV (batch conversion)
| Data | Purpose | Retention |
|---|---|---|
| The uploaded file (every column, not just the address one) and the result file | Running the conversion, letting you poll status and download the result | Deleted within 48 hours of the job finishing |
| Each row's address text | Same shared coordinate cache as single lookups | Same 18-month sliding window (see §3) |
| Job metadata (id, status, row count, dialect, timestamps) | Basic operational record-keeping after the file itself is deleted | Indefinite; contains no address or file content |
If the file you upload contains other people's addresses (customers, contacts, records) rather than just your own, see §7 — you're the one responsible for having the right to share that data with us.
Buying credits
| Data | Purpose | Retention |
|---|---|---|
| Your email address, credit balance, and purchase history (amount, credits, timestamp) | Keeping your purchased balance available across devices and cleared cookies, and giving you a purchase history | Indefinite, while the balance exists — deleted on request (§6) |
| Payment card details | — | Never received or stored by pointkit at all — handled entirely by Stripe |
Signing in
| Data | Purpose | Retention |
|---|---|---|
| Your email address and a single-use sign-in link | Passwordless sign-in ("magic link") | Link: expires after 15 minutes or first use, whichever is first |
A signed-in session cookie (pk_session) | Keeping you signed in | 30 days, or until you log out |
| Your IP address, when requesting a sign-in link | Rate-limiting that endpoint so it can't be used to spam arbitrary inboxes | Rolling hourly window |
Everyone, automatically
| Data | Purpose | Retention |
|---|---|---|
| Request metadata and error details (URL, IP, stack trace) when something breaks | Diagnosing and fixing bugs | Per our error-monitoring provider's default (see §4) |
| Browser/device signals used by our bot-protection challenge | Blocking automated abuse of the free tier | Per our bot-protection provider's policy (see §4) |
2. Cookies
pointkit only sets cookies that are strictly necessary for the service to function (pk_client for the free-tier limit, pk_session for signed-in state) — there's no advertising or cross-site tracking, so no cookie-consent banner. Our bot-protection provider (Cloudflare Turnstile) may set its own cookie as part of running its challenge.
3. The address cache — why some data isn't deleted with your file
Geocoding providers charge (or rate-limit) per lookup. To avoid paying for the same address twice, pointkit keeps a single shared cache mapping normalized address text to a coordinate, used across every user's lookups and batch jobs. It is not linked to your account, cookie, IP, or any other identity — it's purely "this address text resolves to this coordinate."
This cache isn't covered by the 48-hour file-deletion window described above. Instead, each entry is kept on a sliding window: every time an address is looked up again, its clock resets, so an address that keeps getting reused stays cached indefinitely in practice; an address nobody's looked up again is deleted 18 months after its last hit. We rely on this being necessary for our legitimate interest in operating the service affordably (rather than re-paying a provider for every repeat lookup), balanced against the limited sensitivity of an address on its own, decoupled from any name, account, or other identifying context, and against a real, finite limit on how long an unused entry sits there. If you want a specific address removed sooner, contact [email protected] and we'll do our best, though because entries aren't linked to any identity, we generally can't verify a request is coming from the address's actual subject.
4. Who else sees your data
We use a small number of providers to run the service. Each only receives what it needs to do its job:
| Provider | What they get | Role |
|---|---|---|
| U.S. Census Bureau Geocoder | Address text (US addresses) | Geocoding |
| Geoapify | Address text (non-US / fallback) | Geocoding |
| Stripe | Email, purchase amount | Payment processing |
| Resend | Email address, sign-in link | Transactional email delivery |
| Supabase | Everything described in §1 (it hosts the database) | Database hosting |
| Sentry | Request metadata, IP, error details | Error monitoring |
| Cloudflare (Turnstile) | Browser/network signals during the bot-protection challenge | Abuse prevention |
We don't sell personal data, and don't share it for advertising purposes. Some of these providers are based outside the UK/EEA (principally the US); where that's the case, we rely on the safeguards they offer (such as Standard Contractual Clauses) for the transfer.
5. Legal bases (UK/EU GDPR)
- Performance of a contract — running a conversion you asked for, processing a credit purchase.
- Legitimate interests — the address cache (§3), fraud/abuse prevention, error monitoring, keeping the free tier fair.
- Legal obligation — retaining payment records as required by accounting/tax law.
6. Your rights
Subject to the usual legal exceptions, you can ask us to:
- Access the data we hold about you;
- Correct it, if it's inaccurate;
- Delete it (your credit-account email and purchase history — see the note on credit balances below);
- Restrict or object to our processing of it;
- Receive a copy in a portable format.
Email [email protected] from the address in question (this lets us confirm the request is really from the account holder). We aim to respond within one month. If you're not satisfied with our response, you can complain to your local data protection authority — in the UK, the Information Commissioner's Office (ICO).
If you have unused purchased credits: your email address is also the key your balance is stored under (see §1), so deleting your account deletes the balance and purchase history along with it — there's currently no way to keep the credits while deleting the account they're attached to. We don't offer automatic refunds for unused credits (see the Terms of Service, §2), but if you'd rather use up or discuss your remaining balance before deleting, say so in the same email and we'll sort it out manually first.
7. If your address is in someone else's upload
pointkit's batch converter is often used to process a list of someone else's customers or contacts, not just the uploader's own data. If that's you — your address was uploaded by an organization you have a relationship with, not entered by you directly — pointkit doesn't have a way to identify which upload contained your data or verify a request against it (see §3). Please contact the organization that uploaded it; they're the data controller responsible for that processing, and pointkit's role is limited to running the conversion on their instructions (see the Terms of Service, §5).
8. Changes to this policy
We'll update the date at the top when this policy changes. Material changes will be reflected here before they take effect.