Privacy policy
What StreetShape collects, why we are allowed to, who else sees it, and what you can do about all of it.
Last updated
1. The short version
Almost nobody reads past the first screen of a privacy policy, so this is the accurate summary rather than a warm-up. Everything below expands on it; nothing below contradicts it.
- We collect your email address so you can have an account, and whatever you draw so you can save it.
- Your plans are private. Nothing you draw is visible to anyone else unless you share it.
- We never see your card. Paddle takes the payment as merchant of record.
- We do not sell your data, share it with advertisers, or use what you draw to train machine-learning models.
- There is no analytics tracker and no advertising on this site, which is why you were never asked to accept cookies.
- Delete your account and your work is deleted with it — by the database, immediately, not by a cleanup job that might be forgotten.
2. Who we are
StreetShape is operated by [legal entity name], registered in [country of incorporation] under number [company registration number], with its registered office at [registered office address]. VAT number [VAT number].
For the purposes of the General Data Protection Regulation (EU) 2016/679 we are the controller of the personal data described here, except as noted under who we share it with. Our representative in the EU, where one is required, is [EU representative, if the entity sits outside the EU], and our data protection officer, where one is required, is [data protection officer, if one is required].
Write to us about anything on this page at hello@streetshape.io. A person reads it.
3. What this policy covers
The StreetShape website at [canonical domain — the code uses streetshape.app, the site publishes streetshape.io], the editor, and any account you hold with us. It does not cover other sites we link to, including the map, payment and authentication providers we use — each of those has its own policy, and who we share it with links to every one.
4. What we collect
What you give us
An email address, and a name and profile picture if you provide them. These arrive from our authentication provider when you sign up, including when you sign up through Google or another provider.
We never see your password. Authentication is handled entirely by Clerk; no password, and no hash of one, is stored in our database. The same is true of your two-factor settings.
If you apply for Student Pro we hold that application: your academic email address, its domain, and the institution you name. If you ask for a municipal demo we hold the request: your name, email address, role and the municipality. If you join a municipality as a resident, we record which one.
What you make
The plans you draw — the roads, objects and markings, where they sit on the map, the name and description you give them, and the saved versions of each. Also your preferences: which basemap you like, whether buildings are drawn, how your dashboard is sorted.
What we record about your account
Which plan you are on, its status and dates, the limits that plan resolves to, and how many exports you have taken this month. If you pay, a record of the billing events behind that.
What your browser sends
Ordinary web-server logs — IP address, user agent, the URL you asked for — which our hosting provider records for every request any website receives. We derive an approximate country from the IP address at the edge, for one purpose: quoting a price in a sensible currency. We do not store it.
What we do not collect
There is no analytics package, no session recording, no heatmap, no advertising pixel and no cross-site tracking of any kind. We do not buy data about you. We do not ask for your age, your home address, your politics or anything else the GDPR calls special-category data — and you should not put any of it into a plan name either.
5. Why we are allowed to
Every purpose we process personal data for, and the basis under Article 6 that permits it.
| What | Basis | Why |
|---|---|---|
| Your account: email, name, sessions | Contract | There is no account without one |
| Your plans, versions and preferences | Contract | It is the service you asked for |
| Subscriptions, invoices and billing records | Contract, and legal obligation | Providing what you paid for, and keeping the accounting records the law requires |
| Export counts and plan limits | Contract | The limits are part of the plan you chose |
| Student Pro applications | Contract | You applied, and a person reviews it |
| Demo requests and the waiting list | Consent | You asked to be contacted, and can ask us to stop |
| Server logs, rate limiting, abuse prevention | Legitimate interests | Keeping the service up and not letting it be abused |
| Replying to you | Contract, or legitimate interests if you are not a customer | You wrote to us |
Where we rely on legitimate interests, the interest is running a secure service that works, and we have satisfied ourselves it does not override your rights. You can object — see your data rights.
6. Your plans, and who can see them
Your plans are private by default. Nobody else can open a plan you have drawn unless you take a deliberate action to share it.
That is a property of the database, not a setting we remember to apply: a plan is created with its visibility set to private, and the row-level security policies in Postgres are what decide who may read it. An application bug cannot make your plans public.
There are exactly three ways a plan reaches somebody else, and you start all three:
- Inviting a collaborator. You give us an email address, we send an invitation to it, and that person can open the plan as a viewer or an editor once they sign in with that address. You can remove them again.
- Creating a share link. Anyone holding the link can open that one plan. You can set a password on it and you can revoke it, after which it opens nothing. We store only a hash of the link and of the password, never either in the clear.
- Publishing the plan. You can give a plan an address of its own and let anyone open it there, read-only. Publishing shows the plan and your display name to whoever opens it. “Anyone with the link” asks search engines not to index the page and we list it nowhere; “Public” allows both. Setting the plan back to private takes the page down.
We do not sell your plans, license them to anyone, or use them to train machine-learning models — ours or anybody else’s. If we ever want to show one publicly as an example, we will ask you first, and no is a complete answer.
Our staff can reach your plans only where operating the service requires it: investigating a fault you have reported, complying with a legal obligation, or investigating a credible report of abuse.
8. Where your data is
The region each provider processes data in is listed in the table above. Where a provider is outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one covers that country.
The regions are marked as outstanding above rather than asserted, because several of these providers offer EU hosting without defaulting to it, and a data-residency claim that turns out to be wrong is worse than one not yet made.
9. How long we keep it
| Data | Kept for | Why |
|---|---|---|
| Your account, your plans, their versions and your preferences | While your account exists | It is the service. All of it is removed by the database when the account row goes |
| Plan thumbnails in file storage | While your account exists | Deleted by the account-deletion webhook, because storage objects have no foreign key to cascade along |
| Subscription and entitlement records | While your account exists | They are what your account is allowed to do |
| Payment and tax records | [statutory accounting retention period] | Accounting law, which does not leave us a choice |
| Collaboration invites you sent or received | Until the invite is removed, or the plan is deleted | An invite is how somebody else has access to a plan |
| The email delivery log | [email log retention window] | So "the invite never arrived" can be answered from our own records rather than a provider dashboard |
| Municipality demo requests | [municipality lead retention window] | They are not tied to an account and are not deleted with one |
| Student Pro applications | While your account exists | Deleted with the account, and needed while a grant is running |
| Waiting-list email addresses | Until you ask us to remove it, or the list is used | The address survives account deletion, because it was left without needing an account |
| Stored payment-provider webhook payloads | [billing webhook payload retention window] | Kept to make a repeated webhook harmless. Currently unbounded, which is a defect we are fixing |
What deletion actually does
When you delete your account, everything you made goes with it — your plans, their version history, your preferences, your entitlements and usage counts, your thumbnails, your Student Pro application and any collaboration access you held.
This is worth being specific about, because it is a structural promise rather than a procedural one. Your account row is the root every other table hangs off by foreign key, so deleting it deletes the rest as a consequence — not because a cleanup job ran and remembered every table. A deletion path that has to be edited each time a table is added is a privacy bug waiting to happen, and the schema was built to avoid having one.
What deletion does not remove
Being honest about the exceptions is more useful than a clean sentence that is not quite true:
- Billing and tax records are kept for as long as accounting law requires. The record stays; the link to your account is severed.
- An address you left on the waiting list or on a municipal demo request is not attached to an account, so deleting an account does not remove it. Ask us and we will.
- The email delivery log keeps a record that a message was sent to an address, so we can answer “the invite never arrived”.
- Backups expire on their own cycle rather than being edited, so a copy can persist for a short period after deletion.
10. Your rights
You can ask for a copy of your data, correct it, have it deleted, restrict or object to what we do with it, take it elsewhere, and withdraw any consent you have given. All of it is free, none of it needs a particular form of words, and we answer within a month.
Your data rights is the page that tells you how to use each one, including which of them you can do yourself without asking us. Or write to hello@streetshape.io and say what you want.
You can also complain to the data protection authority in the EU country where you live or work, or where you think the problem happened — in our case [supervisory authority] ([supervisory authority website]). You do not have to come to us first, though we would rather you did.
12. Children
StreetShape is not directed at children and we do not knowingly collect their personal data. The minimum age for an account is [minimum age — GDPR Art. 8 allows 13 to 16 by member state].
If a school or university is using StreetShape with students, the institution holds the relationship with those students and should get in touch so we can put the right arrangement in place. If you believe a child has given us personal data, tell us and we will delete it.
13. Security
Identity is delegated to a specialist provider rather than home-rolled, so there is no password for us to lose. Access to your data is enforced by row-level policies in the database itself, which means an application bug cannot hand your plans to another account — the check is not in the code that renders the page, it is in the engine that answers the query. Plan limits are enforced by database triggers for the same reason.
No system is perfect. If we suffer a breach affecting your personal data, we will notify the supervisory authority within 72 hours as Article 33 requires, and tell you directly where Article 34 requires it.
How the service is built, what protection it does not yet have, and how to report something you have found are on our security page.
14. Changes to this policy
We will post any change here and update the date at the top. Where a change materially affects how your data is used, we will email account holders before it takes effect rather than relying on you to notice.
Contact
[legal entity name], [registered office address] · hello@streetshape.io