Legal

Privacy Policy

Effective date: September 1, 2026

This Privacy Policy explains how G Maps Scraper ("G Maps Scraper," "we," "us," or "our") handles information when you use gmapscraper.io, the hosted scraper, API, MCP server, agent Skill, or browser extension (collectively, the "Service"). It also explains how to contact us about privacy or data-removal requests.

1. Information we handle

We handle only the information needed to operate, secure, bill, and improve the Service:

  • Account information: email address, display name, authentication/session records, organization membership, consent versions, and security events.
  • Billing information: subscription, invoice, customer, and payment-status identifiers received from Stripe. We do not receive full payment-card numbers.
  • Customer inputs and configuration: search keywords, map coordinates or location text, locale, requested fields, API settings, webhook configuration, and support messages.
  • Scraped public records: public business and place observations returned by the configured maps-data provider, including contact, review, photo, category, location, and provenance fields requested through the Service.
  • Usage and device information: request/job identifiers, API-key metadata, quota and billing events, timestamps, response status, coarse diagnostics, browser-stored visitor ID, a bound first-party cookie, and IP-derived abuse-prevention signals. The anonymous landing scraper uses both an IP-derived keyed value and a locally stored browser ID to enforce its three-call daily limit.
  • Optional analytics: interaction and conversion events only when the applicable consent setting permits them. Product-critical security, billing, and reliability logs are not marketing analytics.

API-key secrets are stored as one-way keyed digests. Authentication challenges, webhook secrets, and sensitive job input are encrypted or otherwise protected at rest as described by the Service's security controls.

2. How we use information

We use information to:

  • authenticate users and administer organizations;
  • accept, execute, store, deliver, and export scraper jobs;
  • enforce quotas, rate limits, idempotency, fraud controls, and product entitlements;
  • process subscriptions, metered API overage, refunds, and billing reconciliation;
  • send authentication, security, service, and support messages;
  • diagnose incidents, prevent abuse, and maintain audit records;
  • comply with valid legal obligations and operate suppression, takedown, and deletion requests; and
  • improve and develop the Service where we have an appropriate basis to do so.

Public availability does not make every collection or reuse lawful in every context. Customers are responsible for having a lawful purpose for their queries and downstream use. We assess retained-field and reuse eligibility and honor validated legal, privacy, contractual, suppression, and takedown requirements.

3. Canonical scraped-data retention and reuse

Postgres is the canonical store for normalized scraped records and the bounded raw provider records used to validate and reprocess them. These records have no routine expiry and may be retained indefinitely for deduplication, quality improvement, re-normalization, and future product use. This default is subject to an appropriate independent lawful basis and is overridden by validated privacy, suppression, takedown, contractual, or legal deletion requirements.

Customer job associations, saved inputs, and organization-specific access remain private to the authorized organization. Closing an account removes or minimizes customer identity and tenant associations through the deletion workflow; it does not automatically erase an otherwise lawfully retained public-place observation. Contact us if a retained record concerns you and you want us to review, correct, suppress, or remove it.

4. Other retention periods

Our default operational periods are:

  • anonymous result access and replay capability: 24 hours;
  • failed or uncommitted customer input: up to 24 hours after terminal failure unless incident-held;
  • temporary provider-import and generated-export objects: no more than 24 hours;
  • API request metadata: 90 days, with safe aggregates retained for up to 13 months;
  • application logs and traces: 30 days, without raw search or result content;
  • security and authentication events: 13 months;
  • verified Stripe webhook raw envelopes: 30 days, access-restricted;
  • minimized billing ledgers, platform audit events, and deletion evidence: seven years or the applicable statutory period; and
  • canonical structured and raw scraped records: indefinitely by default, subject to the controls in Section 3.

We may retain a narrowly defined record longer when required by law, an active dispute, fraud prevention, or a documented security hold.

5. Service providers and disclosures

We use service providers to operate the Service, including Supabase for authentication and Postgres, Resend for email delivery, Upstash for rate limiting, Stripe for billing, Vercel for the web application, Cloudflare for security and temporary object storage, Hetzner for scraper compute, and PostHog for consent-gated analytics. These providers process information under their own terms and our applicable agreements. Processing locations may differ from your country.

We may also disclose information when required by valid law, to protect users or the Service, in connection with a corporate transaction, or with your direction. We do not sell payment information or raw customer job data. We do not use scraped contact data to determine creditworthiness or eligibility for lending, employment, housing, insurance, or similarly consequential decisions.

6. Security and data durability

We use access controls, tenant checks, encryption or keyed hashing for sensitive values, short-lived download links, least-privilege service credentials, audit logs, and bounded network access. No system is completely secure. The launch Service does not provide a separate application-managed backup guarantee, and catastrophic primary-database loss remains a data-durability risk. Keep copies of exports needed for your own records.

7. Your choices and rights

Depending on your location, you may have rights to access, correct, export, object to, restrict, suppress, or delete certain information. You may also withdraw optional analytics consent, revoke API keys and sessions, cancel subscriptions, or request organization deletion from the Service. We verify requests before acting and may retain minimized billing, security, suppression, or legal records where permitted or required.

To request access, correction, suppression, takedown, or deletion, email contact@gmapscraper.io with enough information for us to locate the relevant account or public record. Do not send passwords, API keys, payment-card numbers, or unnecessary sensitive data.

8. Cookies and local storage

The Service uses essential cookies and browser storage for authentication, security, visitor binding, preferences, and idempotent anonymous results. Optional analytics storage is enabled only under the applicable consent choice. Blocking essential storage may prevent authentication or the anonymous daily-limit workflow from functioning.

9. Children

The Service is intended for business and professional use and is not directed to children. Do not submit information about children or use the Service to profile them.

10. Changes

We may update this Policy as the Service changes. We will post the revised effective date and provide additional notice when required. Material changes do not retroactively authorize an incompatible use of information.

11. Contact

Questions and privacy requests may be sent to contact@gmapscraper.io.

G Maps Scraper is independently operated and is not affiliated with, sponsored by, or endorsed by Google or Google Maps.