Privacy policy

Last updated 5 September 2026

The short version

We do not store the coordinates you look up. A lookup records that a key made a call and when — never where. We keep your account email and name so you can sign in, and enough usage metadata to bill you and enforce quotas. You can erase all of it yourself from the dashboard.

Who we are

AtlasFetch is operated by ATLASIQ PTY LTD, a company registered in South Africa. We are the responsible party under South Africa's Protection of Personal Information Act (POPIA) and the data controller under the UK and EU GDPR for the data described below.

Questions, requests or complaints: atlasfetch@atlas-iq.co

What we collect

Account information

When you sign in with Google we receive your email address, display name and profile picture URL. We do not receive or store your Google password. We use this to identify you, show you your account, and contact you about the service.

Usage records

For each API call we record which account and API key made it, which endpoint was called, how many lookups it consumed, and the time. This is what your quota and invoice are calculated from.

Request origins are off by default.You can turn on “record request origins” for an individual API key, and only then do we store the domain each call came from — so you can see which of your sites is spending your allowance. It is per-key, you choose, and turning it off stops new records immediately. Origins on existing records are removed when the key or the account is deleted.

We do not record the coordinates. The latitude and longitude you send are used to answer the request and are not written to our database or our application logs. We cannot tell you, or anyone else, where your users have been, because we never keep it.

Data you upload

If you create custom boundary sets, we store the geometries and any properties you attach to them. That content is yours. We process it only to answer your own lookups. If it contains personal information, you are the controller of that information and we act as your processor.

Cookies

One essential cookie holds your signed-in session. It is not used for advertising or tracking, and there is no third-party analytics or advertising cookie on this site.

Why we are allowed to hold it

  • Performance of a contract — account data and usage records are needed to provide the service, apply your plan limits and bill you.
  • Legitimate interests — keeping the service secure, detecting abuse, and preventing one account from degrading the service for others.
  • Legal obligation — retaining billing records for the period tax law requires.

Who else processes it

  • Google Cloud Platform — hosting and database, in the europe-west1 region (Belgium, EU).
  • Google — sign-in, if you choose to use it.
  • Paddle — our merchant of record. Paddle handles checkout, payment and tax. We never see or store your card details. Paddle is a separate controller for the payment data it collects and has its own privacy notice.

We do not sell your personal information, and we do not share it with anyone for their own marketing.

Where it is stored, and transfers

Your data is stored in the European Union (Belgium). As a South African company, our access to it constitutes a transfer out of the EU/UK; that transfer is made under the appropriate safeguards for the countries involved. Paddle processes payment data in its own locations under its own terms.

How long we keep it

  • Account and profile data — until you delete the account.
  • Custom boundary sets — until you delete them, or the account.
  • Usage records — retained while the account is open so you can see your own history, and deleted with the account.
  • Invoices and payment records held by Paddle — retained for as long as tax and accounting law requires, independently of your account.

Your rights

Under GDPR and POPIA you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You may also complain to a supervisory authority — the Information Regulator in South Africa, or your local authority in the EU/UK.

Erasure is self-service. Sign in and use Delete account and data at the bottom of your dashboard. It removes your API keys, boundary sets, uploaded geometries, usage records and profile. It cannot be undone, and we keep no backup copy for you. If a subscription is still active you will need to cancel it first, so that billing stops cleanly.

For anything the dashboard cannot do, email atlasfetch@atlas-iq.co and we will respond within the period the law allows.

Security

API keys are stored hashed, never in plain text, which is why a key is shown only once when you create it. Traffic is encrypted in transit. The database is not reachable from the public internet. No system is perfectly secure, and we do not claim otherwise.

Children

AtlasFetch is a developer tool and is not directed at children. We do not knowingly collect information from anyone under 18.

Changes

If we change this policy we will update the date above, and tell account holders by email if the change is material.

See also our terms of service and data attribution.