POSFLOW Privacy Policy
1. Who We Are and How to Reach Us
This Privacy Policy explains how POSFLOW Geospatial Inc. ("POSFLOW", "we", "us", or "our") collects, uses, shares, and protects information when you visit our website, create an account, upload GNSS data, use our processing tools, receive reports, contact support, or otherwise use our services (the "Service").
The controller of personal data described in this Policy is POSFLOW Geospatial Inc. For privacy questions, rights requests, or general support, contact service@posflow.ai.
Plain-language summaries appear in shaded boxes. They are for convenience and do not replace the full text.
2. Our Two Roles: Your Account vs. Your Data
2.1 POSFLOW as controller. We determine how and why we process the information needed to run the Service itself: account and contact details, billing records, security logs, and usage data. Sections 3-4 describe this processing.
2.2 POSFLOW as processor of Customer Content. The GNSS observation files, metadata, coordinates, and project materials you upload ("Customer Content"), and the results we generate from them ("Outputs"), are yours. We process them only to provide the Service as you direct, to keep the Service secure, and as required by law — as set out in our Terms of Service. If your files contain personal data about other people (for example, a field crew's names in file headers), you are responsible for having the right to upload it. Business customers who need a Data Processing Addendum (DPA) can contact us at service@posflow.ai.
2.3 What we never do. We do not sell personal data or Customer Content. We do not use Customer Content or Outputs for advertising, and we do not use them to train machine-learning models.
3. Information We Collect
3.1 Information you provide.
- Account information — name, email address, password (stored only as a cryptographic hash), organization, and preferences. If you sign in with Google or GitHub, we receive your name, email, and avatar from that provider; we never see your password for those services.
- Billing information — your plan, transaction history, and subscription status. Payments are handled by our payment processors (currently PayPal); we do not receive or store full card numbers.
- Customer Content — the GNSS data files you upload (e.g., RINEX and receiver raw formats) and their metadata: station identifiers, receiver and antenna types, observation details, and coordinates. GNSS data is inherently location data — see Section 10.
- Support communications — messages you send us and related contact details.
3.2 Information collected automatically.
- Usage and log data — actions in the Service (such as jobs run and features used), timestamps, and success/failure records.
- Device and connection data — IP address, browser and operating-system type, and language settings.
- Security records — authentication events, failed login attempts, and related IP address and user-agent details, kept to protect accounts and detect abuse.
- Cookies and local storage — see Section 11.
We do not collect precise location from your device. Location information in the Service comes only from the files and coordinates you choose to upload.
4. How We Use Information (and Legal Bases)
Where GDPR or similar laws apply, we rely on the legal bases noted below.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Account access, running processing jobs, generating reports, storing files for your plan's retention period | Contract performance |
| Billing | Subscriptions, renewals, credits, invoices, dunning | Contract performance; legal obligation (tax/accounting) |
| Support | Answering questions, investigating problems you report | Contract performance |
| Security and abuse prevention | Authentication, rate limiting, detecting suspicious logins, blocking attacks, audit logs | Legitimate interests (protecting the Service and users) |
| Service improvement | Understanding which features and file formats are used, fixing errors, capacity planning — using usage data and aggregated statistics, not the contents of your files | Legitimate interests |
| Communications | Service and security notices, billing emails; product news only where permitted (opt-out anytime) | Contract performance; legitimate interests; consent where required |
| Legal compliance | Responding to lawful requests, enforcing our Terms, establishing or defending legal claims | Legal obligation; legitimate interests |
We do not use personal data for automated decision-making that produces legal or similarly significant effects about you, and we do not use it for profiling for advertising purposes.
6. Data Security
We apply administrative, technical, and organizational safeguards appropriate to the Service, including encryption of traffic in transit (TLS), hashed passwords, short-lived access tokens with httpOnly refresh cookies, role-based access controls, rate limiting, and security logging and monitoring. Access to production systems is limited to authorized personnel. Details are published on our Security & Data Handling page.
No system is completely secure, and we cannot guarantee absolute security. Protect your credentials, limit access to your workspace, and keep independent copies of critical files. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities without undue delay, as required by applicable law.
7. Where Data Is Stored and International Transfers
Your data is processed and stored on POSFLOW-operated infrastructure in the United States, and our service providers may process data in the United States and other countries. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
Where transfer rules apply (for example, for users in the EEA, the United Kingdom, or Switzerland), we rely on appropriate safeguards such as standard contractual clauses with our vendors and, where applicable, adequacy decisions. When you direct a submission to an external positioning service (Section 5.2), you are instructing a transfer to the country where that agency operates.
8. Data Retention
| Data | Retention |
|---|---|
| Customer Content and Outputs (uploaded files, processing tasks, results) | Per your plan's published schedule — currently 30 days (Free), 90 days (Pro), 365 days (Business) — then deleted automatically. Download what you need to keep. |
| Account information | For the life of your account, then deleted or de-identified within a reasonable period after account closure, except where longer retention is legally required |
| Billing and transaction records | As required by tax, accounting, and audit obligations (typically up to 7 years) |
| Security and audit logs | For a limited period appropriate to security investigation and abuse prevention, then deleted or aggregated |
| Support communications | For as long as needed to resolve the matter and improve support quality |
| Backups | Deleted data may persist in backups for a limited period before being overwritten in the ordinary course |
Aggregated, de-identified statistics that do not identify you may be retained without time limit.
9. Your Rights and Choices
9.1 Everyone. Regardless of where you live, you can: access and update your account information in settings; download your Customer Content and Outputs while they remain in the Service; delete individual files and tasks; opt out of non-essential emails; and request account deletion.
9.2 EEA, UK, and Switzerland (GDPR and equivalents). You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent where processing is based on consent (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority.
9.3 California (CCPA/CPRA). You have the rights to know, access, correct, and delete personal information, and the right to non-discrimination for exercising them. We do not sell personal information or share it for cross-context behavioral advertising, so there is no need for a "Do Not Sell or Share" opt-out; we treat recognized opt-out preference signals (such as Global Privacy Control) consistently with this Policy. Comparable rights under other US state privacy laws are honored on the same basis, including a right to appeal a refusal by writing to service@posflow.ai.
9.4 How requests work. Submit requests to service@posflow.ai or through your account. We may need to verify your identity before acting. We respond within the time required by applicable law — generally within 30 days, extendable where the law allows for complex requests. Deletion requests are subject to narrow limits (for example, records we must keep for tax, security, or legal-claims purposes), which we will explain if they apply.
9.5 Account deletion. You can request deletion of your account and associated data by contacting service@posflow.ai. Deletion removes your profile and remaining project data from the active Service, subject to the retention limits in Section 8.
10. GNSS Data Is Location Data
Uploaded GNSS observations, station coordinates, and processing results can reveal precise locations of survey sites, infrastructure, assets, and field operations. We treat Customer Content as confidential (Section 2.2) and do not use it for any purpose other than delivering the Service. You are responsible for ensuring you have the authority to upload location data — particularly data about third-party sites or data subject to national surveying, mapping, geodata, or export regulations — and for applying any sector-specific confidentiality obligations that govern your work.
12. Children's Privacy
The Service is intended for professional and organizational use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, contact service@posflow.ai and we will delete it.
13. Changes to This Policy
We may update this Policy as the Service, our practices, or legal requirements change. For material changes we will provide reasonable advance notice — by email, in-product message, or a prominent website notice — before the new version takes effect. The current version, its effective date, and version number are always shown on this page, and prior versions are available on request.
14. Contact
Privacy questions, rights requests, general support, and legal notices: service@posflow.ai
POSFLOW Geospatial Inc.