Privacy Policy
Last updated: 3 September 2026
This Privacy Policy explains how GeoScale collects, uses, stores, and otherwise processes personal data in connection with its websites, dashboard, APIs, customer accounts, billing, support, and related services.
1. About GeoScale
GeoScale is a business registered with the Dutch Chamber of Commerce (KVK) under number 42141024 and VAT identification number NL005529266B07.
Postal address: Salland 1, 1948 RE Beverwijk, the Netherlands.
For questions or requests concerning personal data, contact support@geoscale.io.
2. When this Privacy Policy applies
This Privacy Policy applies where GeoScale determines the purposes and means of processing personal data, including when you:
- Visit a GeoScale website or dashboard
- Create or use a GeoScale account
- Subscribe to paid Services
- Use the GeoScale API
- Contact GeoScale for support or other business purposes
When a customer submits personal data through the GeoScale API on behalf of its own users or customers, GeoScale generally processes that data on behalf of the customer. In that situation, the customer is responsible for determining the purposes of the processing and the Data Processing Agreement applies.
3. Account and authentication data
When you create a GeoScale account, you provide an email address and password.
GeoScale uses Supabase to provide account authentication and session management. Authentication information is stored in GeoScale's Supabase project, which is hosted in the Central EU (Frankfurt) region.
GeoScale does not maintain a separate copy of your account email address in its own application database. The application associates your account with internal identifiers used to manage access, API keys, usage, and billing.
4. Billing and payment data
GeoScale uses Stripe for subscriptions, usage-based billing, invoicing, and payment processing.
When you subscribe, GeoScale may provide Stripe with information including your account email address and an internal customer or organization identifier. You may provide additional information directly to Stripe, including:
- Name
- Email address
- Telephone number
- Billing information
- Tax or VAT identification number
- Payment information
Payment-card details are handled by Stripe and are not stored by GeoScale.
Stripe may process certain information for its own purposes, including payment security, fraud prevention, and compliance with legal obligations, in accordance with its own privacy documentation.
5. API usage data
GeoScale records information necessary to measure and bill API usage. GeoScale's application usage records consist of timestamps and aggregated request counts associated with the relevant customer account.
GeoScale does not store the content of normal address API queries in its application usage records. Address queries are processed transiently as necessary to return API results.
GeoScale does not use the content of address queries for advertising or to train ranking models or other machine-learning models.
6. Technical and security data
When you access GeoScale, GeoScale and its infrastructure providers may process technical information necessary to deliver, secure, and operate the Services.
Depending on the part of the Services being accessed, this information may include:
- IP address
- Requested URL, path, and query parameters
- Request and response headers
- Request method and response status
- Approximate geographic location derived from an IP address
- Network and connection information
- Browser or protocol information
- Timestamps
- Security and rate-limiting information
GeoScale uses Cloudflare for website and dashboard hosting, network delivery, load balancing, and related infrastructure services. Cloudflare may generate operational request logs containing technical information such as the information described above.
GeoScale may inspect operational logs when reasonably necessary to diagnose technical problems, investigate security events, or maintain the Services.
Certain rate-limiting mechanisms may process IP addresses temporarily without storing them as part of GeoScale's persistent application data.
7. Communications
If you contact GeoScale by email, GeoScale processes the information contained in your message and related correspondence, including your email address and any information you choose to provide.
GeoScale uses Google Workspace for business email and customer support communications.
GeoScale uses Postmark to send transactional emails relating to your account, such as authentication and password-reset messages.
GeoScale does not currently use account information to send newsletters or marketing emails. This does not prevent GeoScale from sending necessary service, security, billing, legal, or account-related communications.
8. Why GeoScale processes personal data
Providing and administering the Services
GeoScale processes account, authentication, usage, and related data to create and administer accounts, authenticate users, provide API access, manage API keys, measure usage, and provide the Services.
The legal basis is the performance of the agreement with you or steps taken at your request before entering into an agreement.
Billing and legal administration
GeoScale processes billing and transaction information to calculate charges, process payments, issue and maintain invoices, keep accounting records, and comply with tax and other legal obligations.
The legal bases are performance of the agreement and compliance with legal obligations.
Security, reliability, and abuse prevention
GeoScale processes technical information where necessary to protect accounts and API credentials, enforce rate limits, detect or investigate abuse, diagnose failures, and maintain the security and reliability of the Services.
The legal basis is GeoScale's legitimate interest in operating a secure and reliable service and protecting GeoScale, its customers, and its infrastructure.
Customer support and communications
GeoScale processes communications to answer questions, provide support, administer customer relationships, and send necessary operational communications.
The legal basis is performance of the agreement or GeoScale's legitimate interest in communicating with customers and operating its business, depending on the context.
9. Service providers
GeoScale uses third-party service providers where necessary to operate the Services. These currently include:
- Cloudflare — website and dashboard hosting, network delivery, load balancing, security, and operational logging
- Supabase — authentication and account management
- Hetzner — backend API and database infrastructure in Falkenstein, Germany
- Stripe — subscription management, usage billing, invoicing, and payment processing
- Postmark — transactional email delivery
- Google Workspace — business email and support communications
Where a service provider processes personal data on behalf of GeoScale, GeoScale uses appropriate contractual and data-protection arrangements.
Providers that process Customer Personal Data on behalf of GeoScale in its role as a processor are described where applicable in the Subprocessor List.
10. International data transfers
GeoScale's core API infrastructure is hosted in Germany, and its Supabase project is hosted in the Central EU (Frankfurt) region.
Some service providers operate internationally and may process personal data outside the European Economic Area.
Where applicable data-protection law restricts such transfers, GeoScale relies on an appropriate transfer mechanism or requires its service providers to do so, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another legally permitted safeguard.
11. Data retention
GeoScale retains personal data only for as long as reasonably necessary for the purposes for which it is processed and to meet applicable legal obligations.
- Account and authentication data is retained while your GeoScale account exists.
- GeoScale application usage records are retained while your account exists and are deleted as part of account deletion, except where continued retention is reasonably necessary for an unresolved billing issue, dispute, or legal obligation.
- Operational infrastructure logs are retained according to the retention settings of the relevant infrastructure service and may be reviewed when necessary for security or troubleshooting.
- Support and other business communications are retained for as long as reasonably necessary to handle the communication, maintain relevant business records, resolve disputes, or comply with legal obligations.
- Invoices, transaction records, tax information, and other records forming part of GeoScale's legally required administration are retained for the applicable statutory retention period.
Service providers such as Stripe may also retain certain information where required for their own legal, regulatory, fraud-prevention, or financial-record obligations.
12. Account deletion
You may request deletion of your GeoScale account by contacting support@geoscale.io.
When an account is deleted, GeoScale deletes account data under its control that is no longer required, including the authentication account, API keys, associated application records, and usage records.
Deletion does not require GeoScale to erase information that must be retained to comply with tax, accounting, legal, fraud-prevention, or other legitimate obligations. Some information may therefore remain in financial records or with service providers where continued retention is required or otherwise lawfully permitted.
13. Cookies
The GeoScale Dashboard uses cookies that are necessary to provide authentication and maintain your signed-in session.
GeoScale may also use strictly necessary technical cookies or similar technologies required for security and operation of its websites and Services.
GeoScale does not currently use analytics or advertising cookies and does not use cookies to track visitors for marketing purposes.
14. Sharing and sale of personal data
GeoScale does not sell personal data.
GeoScale does not share personal data with third parties for their advertising or marketing purposes.
Personal data is disclosed only where reasonably necessary to operate the Services, process payments, comply with legal obligations, protect the Services or the rights of GeoScale or others, or where you direct or authorize the disclosure.
15. Security
GeoScale implements technical and organizational measures intended to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction.
These measures include access controls, authentication, secure transport, infrastructure security, API credential management, network controls, backups, and operational monitoring where appropriate.
No internet-based service can guarantee absolute security.
16. Your data-protection rights
Depending on the circumstances and applicable law, you may have the right to:
- Request access to personal data about you
- Request correction of inaccurate personal data
- Request deletion of personal data
- Request restriction of processing
- Object to processing based on GeoScale's legitimate interests
- Receive certain personal data in a structured, commonly used, and machine-readable format
- Withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal
These rights are subject to applicable legal conditions and exceptions.
To exercise a right, contact support@geoscale.io. GeoScale may request information reasonably necessary to verify your identity.
17. Complaints
If you have a concern about how GeoScale processes personal data, you are encouraged to contact GeoScale first so that the issue can be investigated.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or another competent data-protection authority where applicable.
18. Automated decision-making
GeoScale does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.
19. Changes to this Privacy Policy
GeoScale may update this Privacy Policy to reflect changes to the Services, processing activities, service providers, or applicable law.
The current version will be published on the GeoScale website. Where appropriate, GeoScale will provide additional notice of material changes.
20. Contact
Questions or requests concerning this Privacy Policy or GeoScale's processing of personal data may be sent to support@geoscale.io.