Skip to main content

Privacy Policy

Last updated: August 30, 2026

1. Introduction

At Weganar, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our location and property intelligence platform (geocoding, parcel data, and reports).

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Your email address, as verified by the sign-in provider you choose (Google or GitHub). We receive your display name during sign-in but do not store it.
  • A record of each sign-in provider you link: which provider it is (Google or GitHub), the account identifier that provider assigns you, the email address the provider reported when you linked it, and when the link was made and last used
  • The name you give each API key
  • The allowed browser origins you set on each API key
  • Your plan and credit balance, and the dates your account was created, last signed in, and first called the API (billing records are covered in Section 2.5)

2.2 API Usage Data

When you use our API services, we collect:

  • Requested API endpoint and HTTP method
  • The address you submitted, stored with the request so you can review it in your usage history (see Section 2.3)
  • Request timestamps and frequency
  • IP addresses for security and rate limiting
  • User agent information
  • Error logs and performance metrics

2.3 Address Data

We process submitted addresses to return geocoding, standardization, and report results. We store the address you submit alongside the corresponding request in your account's usage history. For a successful authenticated web report, we also store the submitted and standardized address, the complete report result, available source and data vintage metadata, the report type, and the credits charged. This lets you reopen the same saved result as HTML or PDF without buying it twice. Saved reports and usage-history addresses are tied to your account, retained for up to 90 days (see Section 6), and can be deleted earlier. They are visible only to you and our administrators, and are not sold or shared for marketing. REST API and MCP report response bodies are not saved as reports unless that capability is added and explicitly requested in the future.

Separately, when optional quality sampling is enabled, we may retain a keyed, pseudonymous address fingerprint plus coarse parsed and match metadata (such as street name, city, state, ZIP prefix, result type, and score) to evaluate service quality; household-level matched address text is excluded. Because API requests submit the address in a JSON request body, it is not placed in the request URL or browser history. Do not include addresses in unrelated URL parameters or client-side logs.

2.4 Technical Information

  • Browser type and version
  • Operating system
  • Referring website
  • Pages visited on our site
  • Time and date of visits

2.5 Billing Information

Paid subscriptions, prepaid credit purchases, and one-time parcel-data purchases are processed by Stripe. Stripe collects and stores payment-card and billing details; Weganar does not receive or store full card numbers. We retain Stripe customer, subscription, price, status, renewal, and cancellation identifiers, plus one-time payment and credit-ledger records, needed to provision and manage your plan, credits, and purchases.

3. How We Use Your Information

We use the collected information for:

  • Providing and maintaining our location and property intelligence services
  • Processing API requests, generating reports, and delivering purchased data
  • Managing your account and authentication
  • Monitoring usage and enforcing rate limits
  • Improving our services and developing new features
  • Communicating with you about your account or our services
  • Detecting and preventing fraud, abuse, or security violations
  • Complying with legal obligations

When you sign in, we use the verified email address your provider reports to find an existing account with that address, and we attach the new sign-in provider to it. This is how one person can use both Google and GitHub to reach the same account. If you no longer control an email address that was used to sign in, contact support@weganar.com rather than signing in with it, so we can separate the account from that address.

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information in the following circumstances:

4.1 Service Providers

We may share information with trusted third-party service providers who assist us in operating our service, such as hosting providers, email services, Stripe for payment and subscription processing, and Google Analytics for site traffic measurement.

4.2 Legal Requirements

We may disclose information if required by law, court order, or to protect our rights, property, or safety.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of the transaction.

5. Data Security

The measures we operate to protect your data:

  • Encryption of data in transit using HTTPS/TLS
  • Sign-in delegated to Google or GitHub; we never receive or store a password
  • API key authentication, with per-key rate limits and optional per-key browser-origin allowlists
  • Session cookies that are HTTP-only and scoped to this site, plus cross-site request forgery protection on form submissions
  • A Content Security Policy restricting what the pages are permitted to load
  • Automatic expiry of saved reports and API usage logs after 90 days, run on a schedule rather than on request
  • Payment card details are handled by Stripe and never reach our systems

6. Data Retention

Account Data

Retained while your account is active and as needed for security, legal, and operational obligations. You may request deletion as described below.

API Usage Logs

Usage-history records (including the submitted address, endpoint, status, and timing) are retained for up to 90 days and then automatically deleted. Aggregate usage accounting and security records may be kept longer as needed for abuse prevention and service operations.

Saved Web Reports

Successful authenticated web-report snapshots, including their address and result data, are retained for up to 90 days so you can reopen HTML or download PDF without another report charge. You can delete an individual saved report sooner from its report page. Refreshing creates a new snapshot with its own 90-day period.

Address Data

The address you submit is stored with its request in your usage history and, for successful web reports, with the saved report snapshot, for up to 90 days (see Section 2.3), then automatically deleted; you may delete a saved report sooner or request other earlier deletion. Optional sampled fingerprints and coarse metadata are handled as described in Section 2.3.

7. Your Rights and Choices

We honour the following requests from any account holder, wherever you are and whether or not a privacy law in your jurisdiction requires it of us:

  • Access: A copy of the personal information we hold about you
  • Correction: Correction of inaccurate personal information
  • Deletion: Deletion of your account and the personal information attached to it
  • Portability: A copy of your data in a structured, machine-readable format
  • Withdrawal: Withdrawal of consent for processing, where processing rests on consent

How to make a request. Email privacy@weganar.com from the email address on the account, which is how we verify that a request is yours — we will not act on a request to delete or export an account from any other address without further checks. We respond within 30 days.

There is no self-service delete button today; deletion is carried out by an administrator on request. It removes your account, your API keys, your saved reports, your usage history, and your credit balance, and cancels any active subscription. Records we are required to keep for tax, accounting, or fraud-prevention purposes are retained for as long as that obligation lasts.

If a data-protection law in your jurisdiction gives you rights beyond these, nothing here limits them.

8. Cookies and Tracking

We set cookies for:

  • Authentication and session management
  • Protecting form submissions against cross-site request forgery
  • Analytics. Google Analytics 4 sets its own cookies (_ga and _ga_<id>) to distinguish visitors across pages and visits. These are not required for the service to work and can be blocked without affecting sign-in, the API, or your account.

You can control cookie preferences through your browser settings. Disabling cookies may affect some functionality.

9. Third-Party Services

Our service may contain links to third-party websites or integrate with third-party services. Stripe processes billing information under its own Privacy Policy. Google Analytics receives page-view data from this site — including your IP address, the pages you visit, and general device and browser information — and processes it under Google's Privacy Policy. It runs on our marketing and documentation pages; the API does not load it. We disable Google's advertising features on it — Google Signals and ad personalisation are both switched off — so it is not used to build cross-device advertising profiles, and we do not run ads or remarketing. We are not responsible for the privacy practices of third parties.

10. International Data Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.

11. Children's Privacy

Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will delete the information immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through our service interface. The updated date will be reflected at the top of this policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Note: This Privacy Policy is designed to be transparent about our data practices. If you have specific questions or concerns, please don't hesitate to contact us.