Privacy Policy

Effective: 23 March 2026 | Applies to users in Australia, New Zealand, and Canada

1. What We Collect

Server access logs: When you use the Service, our server records your IP address, the pages you request, and timestamps. These logs are retained for up to 30 days and used only for security and diagnostic purposes.

Google Tag Manager and Google Analytics 4: We use Google Tag Manager (container GTM-MQFRGSSZ) to load Google Analytics 4, which collects anonymised usage data (page views, session duration, conversion events) to help us understand how the service is used and improve it. Google Analytics uses cookies and may collect your IP address (anonymised) and browser information. Data is processed by Google in accordance with their privacy policy. You can opt out via Google Analytics Opt-out.

Google Search Console: We use Google Search Console to monitor how the site appears in Google Search. Search Console receives aggregated, anonymised search query data linked to our GA4 property. No personal data is shared.

PostHog: We use PostHog (US cloud, us.i.posthog.com) to record session replays and capture behavioural events (e.g. map interactions, feature usage, checkout steps). For signed-in users, we associate your Clerk user ID and email address with your PostHog person profile so we can understand the user journey across sessions. Anonymous visitors are tracked without any personally identifiable information. Data is stored on PostHog servers in the United States and retained for 1 year by default. PostHog Privacy Policy

Campaign attribution: If you arrive from a marketing email, first-party cookies (mml_abg and mml_abg_touchpoint) may retain the campaign link identifier and email stage for up to 30 days. A local-storage backup has the same expiry. These identifiers help us connect property lookups, signups and purchases with the relevant campaign. Our campaign system receives the purchase type, currency, amount and an email address used to match the customer; it stores an email hash for paid-event matching. We also use subscription status to stop acquisition follow-ups to subscribers. These attribution identifiers are not set for visitors without the relevant campaign link parameters.

Feedback reports: If you submit a bug report or feature request through the in-app Feedback button, we store your message, the current page URL, your selected jurisdiction and parcel (if any), toggled map layers, browser and viewport details, and, if you are signed in, your Clerk user ID and plan tier. If you provide a reply email, we store that too. This report is saved in our application database and emailed to our support mailbox so we can follow up.

2. What We Do NOT Collect

We do not collect or store:

- Your search queries or the addresses you look up (these are sent to our API to perform lookups but not logged). The one exception is a feedback report you choose to submit: because it captures the page URL and any selected parcel so we can reproduce the issue, it can identify a property you looked up. This only happens when you submit feedback, not on ordinary searches.

- Location data beyond what is in your search query

3. Third-Party Services

Google Tag Manager / Google Analytics 4 - analytics and tag management. May set cookies; data processed by Google. Google Privacy Policy

Google Search Console - search performance monitoring. Aggregated, anonymised data only. Google Privacy Policy

Cloudflare - CDN and DDoS protection. Your requests may pass through Cloudflare infrastructure. Cloudflare Privacy Policy

PostHog - session recordings and behavioural analytics. For signed-in users, email and user ID are stored as person properties. Data stored in the United States. PostHog Privacy Policy

Nominatim / OpenStreetMap - Used as a fallback geocoder for addresses not covered by primary data sources. When used, your address query is sent to OpenStreetMap servers. OSM Privacy Policy

Microsoft 365 / Microsoft Graph - If you submit a feedback report, we use Microsoft Graph to email a notification of it to our support mailbox. Microsoft Privacy Statement

4. Data Retention

Server access logs are retained for 30 days then deleted. Analytics data in Google Analytics 4 is retained for 14 months by default. PostHog session recordings and event data are retained for 1 year by default. For signed-in users, PostHog person profiles (containing your user ID and email) persist until deleted. Feedback reports are retained in our application database until actioned or dismissed by our team.

5. Your Rights

For anonymous visitors, we do not hold personal data that can be linked to you. For signed-in users, your email address is stored in PostHog as a person property. To request deletion of your PostHog data, contact us at: [email protected] and we will submit a deletion request to PostHog on your behalf.

6. Changes to This Policy

We may update this policy at any time. The effective date at the top of this page will reflect the most recent revision.