This policy explains what personal data ZipMarketData collects, why we collect it, who else processes it, and what you can do about it. It covers the website, the dashboard and the API.

The data controller is ZipMarketData. Privacy enquiries go to support@zipmarketdata.com.

The Short Version

SummaryWe collect an email address, a Stripe billing reference and a count of how many requests you make. We never see or store your card number. We do not sell personal data, we do not share it for advertising, and you can delete your account and its data yourself from the dashboard at any time.

What We Collect

CategoryWhat it isWhy we hold it
AccountEmail address, password credential held by our authentication provider, account identifier, creation dateTo create and secure your account and to contact you about the Service
BillingStripe customer ID, subscription ID, plan level, trial-used markerTo operate subscriptions, trials and plan entitlements
UsagePer-day request counts against your plan quotaTo enforce plan limits fairly and to show you your own usage
Content you createSaved searches, alerts, API key prefixes and labelsTo provide the features you have chosen to use
TechnicalStandard web and application server logs, which include IP address, timestamp, requested URL and user agentSecurity, abuse prevention, rate limiting and diagnosing faults

What We Do Not Collect

  • Card numbers. Payment details are entered directly with Stripe and never reach our servers. We store only Stripe's opaque identifiers.
  • Personal data about the properties you look up. The market dataset is aggregate — ZIP-code and metro statistics from Redfin, HUD and the Census Bureau. It contains no names, no addresses, no owner records and nothing about individual transactions.
  • Advertising or cross-site tracking identifiers. We run no advertising network and no third-party analytics tags on these pages.

Processors We Use

  • Supabase — authentication. Holds your email address and password credential and issues the session token your browser uses.
  • Stripe — payments and subscription management, including the billing portal where you can cancel. Stripe is the controller of your card data under its own privacy policy.
  • RapidAPI — for API customers only. Subscription, metering and billing for marketplace plans happen on RapidAPI under RapidAPI's own terms and privacy policy; we receive usage and subscription information from them, not your card details.
  • Hosting — the application and database run on infrastructure provided by Hetzner Online GmbH.
  • Google Fonts — public pages load typefaces from fonts.googleapis.com, which means Google receives your IP address when a page loads. No account is required and no cookie is set by us for this.

We do not sell personal data, and we do not disclose it to anyone else except where we are legally required to, or where it is necessary to establish or defend a legal claim.

Cookies and Local Storage

The dashboard stores your authentication session in your browser so you stay signed in. That is the only storage strictly necessary for the Service to work. We set no advertising cookies and run no behavioural profiling.

How Long We Keep It

Account, billing reference and content records are kept while your account exists. Daily usage counters are kept for as long as they are needed to enforce quotas and to answer billing questions. Server logs are kept for a short operational period and then discarded. Records we are required to retain for tax or accounting purposes — principally the fact and amount of a payment — are kept for the statutory period even after account deletion.

Deleting Your Data

You can delete your account from the dashboard. Deletion removes your account record, saved searches, alerts, API keys and usage history from our database and cancels any active subscription. Data held by Stripe as the payment controller, and any records we must retain for tax purposes, are subject to their own retention rules. If you would rather we did it for you, email support@zipmarketdata.com from the address on the account.

Your Rights

Depending on where you live you may have rights to access a copy of your personal data, to correct it, to delete it, to restrict or object to processing, to data portability, and to withdraw consent. Residents of the EU and UK have these rights under the GDPR and UK GDPR; California residents have comparable rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal data as those terms are defined under California law. To exercise any right, email support@zipmarketdata.com from your account address; we will respond within the period required by the applicable law. You also have the right to complain to your local data protection authority.

International Transfers

Our processors operate internationally, so your data may be processed outside your country, including in the United States. Where required, transfers rely on the safeguards those providers offer, such as standard contractual clauses.

Security

Traffic is served over HTTPS, passwords are handled by our authentication provider rather than stored by us, API access is authenticated by key or signed token, and access to the production database is restricted. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the relevant regulator as required by law.

Children

The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

Changes

If this policy changes materially we will notify account holders by email or by prominent notice on this page before the change takes effect. The date at the top of this page is the date of the current version.