Privacy policy
Last updated 1 September 2026
MarketGround is a location analysis tool. This page explains what information we hold about you when you use it, why we hold it, who else is involved, and what you can ask us to do with it. We have tried to write it the way we would want to read it.
What we collect
Account details. Your email address, the name you give us, and a hashed form of your password. We never store the password itself. We record when your email was verified and when you last signed in.
Organisation and membership. The organisation your account belongs to, your role in it, and invitations sent to or from it.
Your work. The projects you create and the areas you save into them: their names, their shapes, and the settings used to draw them. This is your content. We treat it as confidential and do not look at it except to operate the service or to help you when you ask.
Sessions. When you sign in we set one cookie, pop_session, which identifies your session. Alongside it we record the browser (user agent) and the IP address the session was created from, when it was last used, and when it was ended. Sessions expire after 30 days.
Usage counts. To apply plan limits we count things: how many projects and areas you have, how many assistant questions you have asked this day and this month, and how much text the assistant processed. These are counts, not copies of what you did.
Assistant conversations. If you use the assistant, the messages you send it, and the results of the lookups it runs on your behalf, are sent to the model provider to generate a reply (see below). We do not keep a transcript of your conversation after the reply is delivered.
Request logs. Our servers keep short-lived logs of requests, including IP addresses, for security, rate limiting and diagnosing faults. Rate-limit counters keyed by IP address are kept for at most one hour.
What we do not collect. We do not run analytics trackers, advertising pixels or third-party scripts on the site. We do not sell or share information about you for marketing. We do not build profiles of you from other sources.
Why we use it
- To provide the service: sign you in, keep your projects, run your analyses.
- To apply the limits of your plan fairly.
- To send you emails you have triggered: verification, password reset, invitations to an organisation. We do not send marketing email.
- To keep the service secure and available, including detecting abuse.
Who else is involved
We use a small number of providers to run the service. Each receives only what it needs for its job.
- Hosting: Hetzner, on a server located in Ashburn, Virginia, United States. All of our data lives there.
- Email delivery: Resend, which receives your email address and the content of the transactional emails we send you.
- Assistant: Anthropic, which receives the messages you send to the assistant and the data the assistant looks up to answer them. We use Anthropic's API under terms that do not permit training on customer content.
- Payments: paid plans are not yet on sale. When they are, a payment provider will handle card details; we will not store card numbers ourselves, and this page will be updated first.
Map tiles for population and places are served publicly and carry no information about you. The basemap is served by us from Protomaps data.
How long we keep it
Your account and your projects are kept for as long as your account exists. If you close your account, we delete them. Because we keep database backups for disaster recovery, a deleted record can persist in backups for up to four weeks before those backups are rotated out. Backups are never used to restore individual deleted data.
Your choices
- You can change your name and password in settings, and end any session by signing out.
- You can export your saved areas and their analysis on plans that include export.
- You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete your account and everything in it. Write to contact@marketground.io from the address on your account and we will respond within 30 days.
If you are in a jurisdiction that grants you further rights over your personal data, such as the European Union, the United Kingdom or California, those rights apply and the same address is the way to exercise them.
Security
Traffic is encrypted in transit. Passwords are stored only as salted hashes. Session and reset tokens are stored only as hashes, so a copy of the database does not contain usable credentials. Access to one organisation's data from another is denied by design and tested on every release.
Children
The service is for businesses and professionals. It is not directed at children under 16 and we do not knowingly collect information from them.
Changes
If we change this policy in a way that matters, we will say so on this page with a new date and, for account holders, by email. The current version is always at this address.
Contact
Questions about privacy go to contact@marketground.io. Our terms of service cover the rest of the relationship.