Meet API v2.0 with UK support 🇬🇧 Try it out

We never share or sell your data. Ever.

Geocodio's privacy policies. How to exercise your rights, including deleting your Geocodio account.

You're probably on this page because you're curious about our privacy practices, or you want to exercise your privacy rights, like deleting your account. Here are a few quick links for self-service customers to do so:

Signed agreements

If you have a signed agreement with Geocodio that covers data privacy or data processing — for example, a Data Processing Agreement, a UK Data Services Attachment, or a Business Associate Agreement — that agreement supersedes this Privacy Statement with respect to the matters it addresses. This Privacy Statement continues to apply to anything not covered by the signed agreement.

Any conflicts are understood to be superseded by the signed agreement.

Privacy Laws We Follow

As a company that values treating our users fairly and transparently, we welcome privacy laws' efforts to increase privacy across the board. We are fully committed to being compliant with all applicable data privacy laws.

This page outlines our commitment to complying with these privacy laws and upholding our users' individual privacy and the privacy of the data they transmit to us. As best practices evolve, we will make changes to this statement and to our product accordingly.

Europe

  • General Data Protection Regulation (GDPR) - European Union legislation effective May 25, 2018

United Kingdom

  • UK General Data Protection Regulation (UK GDPR) — The retained EU GDPR as it forms part of UK law following Brexit

  • Data Protection Act 2018 (DPA 2018) — UK legislation supplementing UK GDPR

  • Privacy and Electronic Communications Regulations (PECR) — UK rules governing electronic marketing communications and cookies

Canada

  • Canada's Anti-Spam Legislation (CASL) - Effective July 1, 2014

  • Personal Information Protection Act of Alberta (PIPA Alberta) - Effective January 1, 2004

  • Personal Information Protection Act of British Columbia (PIPA BC) - Effective January 1, 2004

  • Personal Information Protection and Electronic Documents Act (PIPEDA) - Effective January 1, 2001

  • Quebec Law 25 - Effective September 22, 2024

Australia and New Zealand

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) - Australian federal privacy law

  • Spam Act 2003 (Cth) - Australian rules governing commercial electronic messages

  • Privacy Act 2020 and the Information Privacy Principles (IPPs) - New Zealand privacy law

  • Unsolicited Electronic Messages Act 2007 - New Zealand rules governing commercial electronic messages

United States

Federal Laws

  • Health Insurance Portability and Accountability Act (HIPAA) of 1996 and the Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 (BAA required, Enterprise platform only)

  • Children's Online Privacy Protection Act (COPPA) - Amended rule effective June 23, 2025; compliance required by April 22, 2026

  • Family Educational Rights and Privacy Act (FERPA) (NRDPA required)

US State Privacy Laws

We comply with comprehensive privacy laws in all of the states that have enacted them:

Relevant Laws:

  • Alabama Personal Data Protection Act (APDPA) - Effective May 1, 2027

  • California Consumer Privacy Act (CCPA) - Effective January 1, 2020

  • California Privacy Rights Act (CPRA) - Effective January 1, 2023

  • Colorado Privacy Act (CPA) - Effective July 1, 2023

  • Connecticut Data Protection Act (CTDPA) - Effective July 1, 2023

  • Delaware Personal Data Privacy Act (DPDPA) - Effective January 1, 2025

  • Florida Digital Bill of Rights - Effective July 1, 2024. Applies only to controllers with more than $1 billion in annual global gross revenue, so it does not currently apply to Geocodio

  • Indiana Consumer Data Protection Act - Effective January 1, 2026

  • Iowa Consumer Data Protection Act (ICDPA) - Effective January 1, 2025

  • Kentucky Consumer Data Protection Act (KCDPA) - Effective January 1, 2026

  • Louisiana Data Privacy Act - Effective January 1, 2027

  • Maryland Online Data Privacy Act (MODPA) - Effective October 1, 2025

  • Minnesota Consumer Data Privacy Act (MCDPA) - Effective July 31, 2025

  • Montana Consumer Data Privacy Act - Effective October 1, 2024

  • Nebraska Data Privacy Act - Effective January 1, 2025

  • New Hampshire Privacy Act (NHPA) - Effective January 1, 2025

  • New Jersey Data Privacy Act (NJDPA) - Effective January 15, 2025

  • Oklahoma Personal Data Protection Act - Effective January 1, 2027

  • Oregon Consumer Privacy Act (OCPA) - Effective July 1, 2024

  • Rhode Island Data Transparency and Privacy Protection Act - Effective January 1, 2026

  • Tennessee Information Protection Act (TIPA) - Effective July 1, 2025

  • Texas Data Privacy and Security Act (TDPSA) - Effective July 1, 2024

  • Utah Consumer Privacy Act (UCPA) - Effective December 31, 2023

  • Vermont Data Privacy and Online Surveillance Act - Effective January 1, 2028

  • Virginia Consumer Data Protection Act (VCDPA) - Effective January 1, 2023

Agreements for Specific Privacy Laws

Beyond the universal privacy practices described above, certain privacy laws require additional agreements. We make these agreements available to qualifying customers as described below. If you transmit data subject to any of these frameworks without first executing the required agreement with us, you remain solely responsible for that processing, and Geocodio bears no liability for it.

  • FERPA (SDPC NDPA): Geocodio will sign an NDPA for processing student data. Please contact us for more information.

  • HIPAA/HITECH (Business Associate Agreements): Geocodio can only sign BAAs for our Enterprise product. Please contact us for more information.

  • GDPR (Data Processing Agreement): If you want to process data for EU persons, GDPR requires that we have a signed Data Processing Agreement. Customers who need a signed Data Processing Agreement must be on a subscription plan at the time of signing (one-month or recurring). All users transmitting data about EU persons are required to have a subscription plan. That is, if you’d like to upload a file or use our API with data about EU persons, you must have a Data Processing Agreement with us. You can sign our Data Processing Agreement on the Self-Serve and Enterprise dashboards. If you want a custom DPA, you need to be on an Enterprise Unlimited annual plan.

  • UK GDPR (UK Data Processing Agreement): If you want to upload data for UK persons, UK GDPR and the Data Protection Act 2018 require that we have a signed UK Data Processing Agreement. Users who need a signed UK Data Processing Agreement must be on a subscription plan at the time of signing (one-month or recurring). All users transmitting data about UK persons are required to have a subscription plan. That is, if you'd like to upload a file or use our API with data about UK persons, you must have a UK Data Processing Agreement with us. You can sign our Data Processing Agreement on the Self-Serve and Enterprise dashboards. If you want a custom DPA, you need to be on an Enterprise Unlimited annual plan.

  • Quebec Law 25: If you process personal information about Quebec residents, Quebec Law 25 imposes contractual requirements between controllers and processors similar to GDPR Article 28. These obligations are covered by our standard Data Processing Agreement. If you require a Quebec-specific addendum, please contact us.

Age Restriction and Children's Privacy (COPPA)

Our service is only available to individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18 years of age. By using our service, you confirm that you are at least 18 years old.

If we learn that we have collected personal information from someone under 18, we will delete that information immediately. If you believe we have collected information from someone under 18, please contact us at [email protected].

During registration, users must accept our Terms of Use, which stipulates that they must be at least 18 years old in order to create an account. This age restriction helps us comply with various state laws that have enhanced protections for minors under 18.

Your Privacy Rights

Depending on your location, you have the following rights regarding your personal information:

Universal Rights (Available to All Users)

  • Right to Know - Request information about what personal data we collect, use, and share

  • Right to Delete - Request deletion of your personal data (with some legal exceptions)

  • Right to Correct - Request correction of inaccurate personal information

  • Right to Opt-Out of Sales - We don't sell data, but we can confirm this applies to you

  • Right to Opt-Out of Targeted Advertising - Right to opt-out of targeted advertising

  • Right to Non-Discrimination - We won't deny services or charge different prices for exercising your rights

Enhanced Rights (Varies by Location)

  • Right to Data Portability - Request your data in a portable format (CA, CT, CO, DE, MD, MN, NJ, OR)

  • Right to Opt-Out of Profiling - Opt-out of automated decision-making that produces legal effects (CA, CT, CO, VA, MD, MN, TN, NH, DE, MT, RI)

  • Right to Limit Sensitive Data Use - Limit use of sensitive personal information (CA, CO, CT, TX, OR, NJ, NH, DE, MT)

  • Right to Question Profiling Results - Unique to Minnesota: question automated decisions and understand the rationale

  • Right to Third-Party Transparency - Request list of third parties who received your data (OR, MN) or categories of recipients (DE, MD)

  • United Kingdom Residents (UK GDPR / DPA 2018). If you are in the United Kingdom, you have the following rights under UK GDPR and the Data Protection Act 2018:

    • Right of access to your personal data

    • Right to rectification of inaccurate personal data

    • Right to erasure ("right to be forgotten")

    • Right to restrict processing

    • Right to data portability

    • Right to object to processing, including direct marketing

    • Rights related to automated decision-making and profiling — we do not use your personal data for automated decision-making that produces legal or similarly significant effects

    • Right to withdraw consent at any time, where processing is based on consent

    • Right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority

  • Canadian Residents (PIPEDA, Quebec Law 25, PIPA Alberta, PIPA BC). If you are in Canada, you have the following rights under the applicable federal and provincial privacy laws:

    • Right of access to your personal information

    • Right to correction of inaccurate or incomplete personal information

    • Right to withdraw consent to the collection, use, or disclosure of your personal information

    • Right to know how your personal information is being used and disclosed

    • Right to challenge compliance with the applicable privacy law

    If you are a Quebec resident, you additionally have the following rights under Quebec Law 25:

    • Right to data portability — receive your personal information in a structured, commonly used technological format

    • Right to be informed of automated decision-making that produces legal or similarly significant effects, and to request the reasoning behind it

    • Right to deindexation ("right to be forgotten") in certain circumstances

    • Right to be informed of cross-border transfers of your personal information and the privacy impact assessment conducted

For Quebec users: tracking technologies that can identify, locate, or profile users are subject to the cookie consent on our website. You can refuse or withdraw your consent at any time through the cookie preferences (the “Cookie settings” link in the footer of every page), and these technologies are not activated without your consent.

How to Exercise Your Rights

  • Delete Your Account: Delete via dashboard

  • Delete Spreadsheet Data: Delete via dashboard

  • Other Requests: Email us at [email protected] with your specific request

  • Response Time: We respond to requests within 15 days (some states and countries allow up to 45 days)

  • Verification: We may ask for additional information to verify your identity

Authorized Agents

You may designate an authorized agent to make requests on your behalf. Agents must:

  • Provide written authorization signed by you

  • Verify their own identity

  • For deletion requests, provide a power of attorney where required by state law

Appeal Process

If we deny your privacy request, you may appeal by:

  1. Emailing us at [email protected] within 30 days

  2. We'll review and respond within 15 days

  3. If still unsatisfied, you may contact your state's attorney general

Global Privacy Control

We recognize Global Privacy Control (GPC) signals as valid opt-out requests for the sale and sharing of personal information where required by law.

What Personal Information We Collect

We collect the following categories of personal information:

Account Information

  • Identifiers: Name, email address, country, IP address, account ID

  • Commercial Information: Payment history, billing information, plan details, account usage

Usage Information

  • Internet Activity: Website behavior (such as the pages you visit on our website and documentation, the page that referred you, and device and browser information), feature usage, API calls, service interactions

  • Professional Information: Employer, work address and phone number, and how you use our service in a business context

  • Inferences: Usage patterns to send relevant service updates and improvements

Sensitive Personal Information

We may collect limited sensitive information:

  • Precise Geolocation: Only in data you upload for processing (not your device location)

  • Account Login Information: Encrypted credentials and authentication data

  • Payment Information: Stored securely with Stripe (we never see full card numbers)

We do NOT collect: Biometric identifiers, genetic data, health information, information about sexual orientation, racial or ethnic origin, religious beliefs, union membership, or data from anyone under 18.

How We Use Your Information

We use personal information only for these specific purposes:

  • Service Delivery: Providing geocoding services and API access

  • Account Management: Creating and maintaining your account

  • Billing and Payment: Processing payments and sending invoices

  • Customer Support: Responding to questions and providing help

  • Service Improvement: Analyzing usage, including product analytics on our website and documentation, to improve our content and service (without profiling individuals)

  • Marketing and advertising: Using our users’ email addresses (and only their email addresses), which may be hashed, to show them Geocodio ads on LinkedIn and measure how they perform (see Advertising on LinkedIn)

  • Legal Compliance: Meeting legal obligations and preventing fraud

  • Communication: Sending relevant service updates based on your usage patterns

We do NOT use your information for:

  • Psychographic profiling

  • Automated decision-making that produces legal or similarly significant effects

  • Any purpose not explicitly listed above

We do not use personal information — whether account information or data you upload to our service — to train large language models or other artificial intelligence models.

Who We Share Information With

Third-Party Service Providers

We work with these vendors who have signed Data Processing Agreements with us where relevant:

  • Intercom (customer support) - Contact information, support conversations

  • Google Analytics (traffic tracking) - Website behavior data, anonymized for visitors who are not signed in

  • Ahrefs (anonymized traffic tracking) - Anonymized website traffic patterns

  • LinkedIn (advertising to account holders, email audience matching) - Users' email addresses only (which may be hashed), for advertising to our users and measuring ad performance. No other data, and never data uploaded to or processed through the service. LinkedIn Corporation (United States) and LinkedIn Ireland Unlimited Company (Ireland); data may be processed in the United States and other countries

  • Satismeter (satisfaction surveys) - Email address, survey responses

  • Stripe (payments) - Billing information, payment history (PCI-compliant)

  • QuickBooks (invoicing) - Invoice data, payment records for accounting

  • Tally (contact forms) - Form responses, contact information

  • Sentry (error tracking) - Technical error logs, performance data

  • Bento (email) - Transactional and marketing email

  • Laravel Nightwatch (error tracking) - Technical error logs, performance data

Customers with a signed Data Processing Agreement: this list is the canonical sub-processor list referenced in our DPA. Any changes will be reflected here.

Advertising on LinkedIn

We may share our users' email addresses with LinkedIn, which may be hashed, so that LinkedIn can match them to LinkedIn members and show them Geocodio ads on LinkedIn (using LinkedIn Matched Audiences), and so that we can measure how our ads perform. LinkedIn is the recipient of this information and may process it in the United States and other countries. The only data we share with LinkedIn is our users' email addresses (which may be hashed). We do not share any other personal information with LinkedIn, and we never share any data you upload to or process through our service. We do not sell your personal information, and we do not provide it to LinkedIn for any purpose other than showing and measuring Geocodio ads.

If you are in the EU or the UK, our legal basis is our legitimate interests in marketing our services to business users.

We exclude users from our LinkedIn advertising audiences if we can determine from the information we hold that they are California residents, such as a California billing or shipping address. If you have not provided us with a California billing or shipping address, we may not be able to identify you as a California resident, and you may not be excluded.

You can opt out at any time by emailing [email protected], and we will stop using your email address for this purpose and remove it from our advertising audiences. You can also change your ad settings in your LinkedIn account. If you are in Australia, you may also ask us to stop using your personal information for direct marketing (APP 7), as described in the Australia and New Zealand section.

Data Sharing Practices

  • We do NOT sell personal information to anyone, ever

  • We do NOT share personal information with third parties for their own advertising purposes. The only data we share with LinkedIn is our users’ email addresses (which may be hashed), solely to show Geocodio ads to our users and measure them, as described under Advertising on LinkedIn

  • We do NOT share data for profiling that produces legal or significant effects

  • All vendor sharing is solely for the specific business purposes listed above

  • We have signed Data Processing Agreements with all vendors

Data Retention

We retain personal information according to these schedules:

  • Account Data: Retained for as long as reasonably necessary for our business purposes, including while your account is active and until you delete your account, plus legal retention requirements

  • Prospect Data: Retained for as long as reasonably necessary for our business purposes

  • Product Analytics Data: Retained for as long as reasonably necessary for our business purposes

  • LinkedIn Audience Lists: Retained for as long as reasonably necessary for our business purposes

  • Usage Logs: According to our data retention policy

  • Payment and Invoice Records: Kept indefinitely for record-keeping

  • Support Communications: 3 years from last interaction

  • Marketing Consents: Until you withdraw consent

  • Spreadsheet/API Data: Input data you send to us for processing (such as addresses and coordinates), whether through the API or a spreadsheet upload, and the results are deleted within 45 days. The only exception is spreadsheet results that you save as a map, which are kept until you delete the map. See our data retention policy

  • Error Logs: 90 days for technical troubleshooting

You can delete your account and associated data at any time, except for information we must retain for legal compliance (such as payment records for tax purposes).

Our Role in Data Processing

For Your Account Information

We are a "data controller" (GDPR, UK GDPR, Quebec Law 25) or "business" (US state laws) for your personal account details like email address, billing information, and service usage. Under PIPEDA, PIPA Alberta, and PIPA BC, we are the organization responsible for your personal information.

For Data You Process

We are a "data processor" (GDPR and UK GDPR) or "service provider" (US state laws) "person carrying on an enterprise to whom personal information is communicated for processing" (Quebec Law 25) for data you upload to our service. You are responsible for ensuring you have proper rights to process any personal data you upload and that such data complies with applicable privacy laws.

EU Data Processing

If you upload data about EU persons, GDPR requires a signed Data Processing Agreement. If you upload data about UK persons, UK GDPR requires a signed UK Data Processing Agreement. Users who need either must be on a subscription plan. You can sign a DPA on the dashboard.

Data Processing Assessments

We conduct data protection impact assessments for high-risk processing activities as required by applicable laws, including for:

  • Large-scale processing of sensitive data

  • Systematic monitoring of public areas

  • Processing that could result in high risk to individual rights

UK Address and Location Data

When you use Geocodio to process UK addresses or location data, we may use licensed data sources including Ordnance Survey, Royal Mail's Postcode Address File (PAF), and other UK data providers. All data is processed in-house. Use of these data sources is governed by the licensing terms in our UK Data Services Attachment.

Security and Storage

  • User Database: Encrypted and regularly backed up to Amazon S3 in the US

  • Website Hosting: Amazon S3 and CloudFront with SSL/TLS encryption

  • API Services (including Spreadsheet Uploads):

    • Self-Serve customers: Hetzner servers physically located in Germany (EU)

    • Enterprise customers: AWS infrastructure in the US

  • Payment Security: All payment data handled by PCI-compliant Stripe

  • Data Encryption: All data encrypted in transit and at rest

  • Access Controls: Multi-factor authentication and role-based access controls

  • Security Monitoring: Continuous monitoring for security threats

  • No Known Breaches: We have no history of data breaches

Cookies and Tracking

We use cookies to:

  • Maintain your logged-in status

  • Provide core website functionality

  • Track website and documentation usage for product analytics: anonymized for visitors who are not signed in, and linked to your account when you are signed in (see Product Analytics below)

  • Remember your privacy preferences

  • Remember how you first reached this site (the referring page, campaign parameters in the link, and the page you landed on) so Geocodio can tell which guides and campaigns bring in customers. This cookie is only set after you accept it in the cookie notice, and a second cookie remembers your choice. Both cookies last up to one year.

We do NOT use cookies for:

  • Cross-site tracking or advertising

  • Behavioral profiling for commercial purposes

  • Sharing cookie data with advertising networks

  • Following you across other websites, selling your data to data brokers, or combining what Geocodio collects with data bought from third parties

The optional cookie is off until you accept it in the cookie notice. You can decline it there, and change your mind at any time using the "Cookie settings" link in the footer of every page, which reopens the notice and lets you withdraw. Withdrawing also deletes the attribution cookie. You can control all cookies through your browser preferences.

Third parties that can receive data from this site:

  • YouTube (Google), for video playback. Embedded videos stay blocked until you accept the cookie notice or choose to load a single video, so nothing is requested from YouTube before then.

  • SavvyCal, for scheduling, on the booking pages only. The calendar stays blocked on the same terms as video.

Attribution data itself is not shared with anyone. It is read only by Geocodio's own systems. If that ever changes, the provider will be named here and everyone will be asked for consent again.

Product Analytics

We use product analytics on our website and documentation to understand which pages are visited and how our content is used, so that we can improve our content and our product. We collect the pages you visit, the page that referred you, and device and browser information. For visitors who are not signed in, this tracking is anonymized. When you are signed in to your Geocodio account, we track your website and documentation activity and link it to your account, so it is not anonymous.

If you are in the EU or the UK, we use cookies or similar technologies for product analytics that are not strictly necessary only with your consent, where required by law. You can change your choice at any time using the "Cookie settings" link in the footer of every page.

This is separate from the email-based advertising on LinkedIn described under Advertising on LinkedIn, which does not use cookies on our site.

International Data Transfers

  • US Users: Data processing in the EU (Self-Serve) or US (Enterprise)

  • EU Users: Data processing in the EU (Self-Serve) or US (Enterprise)

  • UK Users: Data processing in the EU (Self-Serve) or US (Enterprise)

  • Canadian Users: Data processing in the EU (Self-Serve) or US (Enterprise)

  • Australian and New Zealand Users: Data processing in the EU (Self-Serve) or US (Enterprise)

  • All Users: Account data may be stored in the EU or US with appropriate transfer mechanisms

For EU users, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms as required by GDPR.

For UK users, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, or other approved transfer mechanisms as required by UK GDPR. Where data is transferred to the US, we rely on the UK Extension to the EU-US Data Privacy Framework where applicable.

For Canadian users, we comply with PIPEDA's accountability principle when transferring personal information across borders. We remain responsible for the protection of Canadian personal information transferred to third parties for processing. For Quebec residents, we are subject to conducting privacy impact assessments for cross-border transfers as required by Quebec Law 25 and ensure that personal information receives equivalent protection in the destination jurisdiction.

For Australian and New Zealand users, see the Australia and New Zealand section below for information about overseas disclosure.

Australia and New Zealand

This section applies if you are an individual in Australia or New Zealand. It supplements the rest of this Privacy Statement and explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the Privacy Act 2020 and the Information Privacy Principles (IPPs) of New Zealand.

The kinds of personal information we collect are described in What Personal Information We Collect, and the purposes for which we collect, hold, use, and disclose it are described in How We Use Your Information. We do not repeat them here.

Access and Correction

You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, or misleading. Email us at [email protected] with your request. We may ask for additional information to verify your identity, and we will respond within the time required by applicable law. If we refuse a request, we will tell you why and how to complain.

Overseas Disclosure

We do not store or process personal information in Australia or New Zealand. Information is stored and processed in the United States and Germany, using Hetzner (Self-Serve customers, in the EU) and Amazon Web Services (Enterprise customers, in the US). We also share personal information with service providers such as Intercom, Stripe, and Bento, who may store and process it in the United States and other countries. We also share our users’ email addresses, and no other personal information, with LinkedIn for advertising, and LinkedIn may store and process them in the United States and other countries. We take reasonable steps to ensure that these providers handle your personal information in a way that is consistent with the APPs and IPPs.

Automated Decisions

We do not use personal information in computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests.

Marketing Emails

We send marketing emails in compliance with the Spam Act 2003 (Cth) and the Unsolicited Electronic Messages Act 2007 (NZ). You can unsubscribe at any time by clicking unsubscribe at the bottom of any of our emails. We will honor your request promptly.

Direct Marketing and Advertising

We may use our users’ email addresses, which may be hashed, to show them Geocodio ads on LinkedIn and measure how they perform, as described under Advertising on LinkedIn. You can ask us at any time to stop using your personal information for direct marketing (APP 7 in Australia), including this advertising, by emailing [email protected]. We will act on your request promptly and free of charge, and we will tell you the source of the information if you ask us to.

Complaints

If you have a privacy concern, contact us first at [email protected] and we will work with you to resolve it. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or the New Zealand Office of the Privacy Commissioner at www.privacy.org.nz.

We Do Not Sell Personal Information

We do not sell personal information. We process addresses and locations to provide our services, and we share limited information with service providers, as set out elsewhere in this Privacy Statement. The only data we share with LinkedIn for advertising, as described above, is our users’ email addresses.

Your State-Specific Rights

California Residents (CCPA/CPRA)

You have enhanced rights including data portability and the right to limit use of sensitive personal information. You can opt-out of automated decision-making and request information about our data practices.

Categories of Personal Information We Collect

In the past 12 months we have collected the following categories of personal information:

  • Identifiers: name, email address, IP address, account ID

  • Professional information: employer, work address and phone number

  • Commercial information: purchase, payment, and invoice records

  • Internet activity: website and documentation page views (linked to your account when you are signed in) and service usage

  • Approximate location: derived from your IP address; we do not collect precise geolocation about you

  • Sensitive personal information: account login credentials, used only to provide secure access to your account

Sources

We collect personal information directly from you, automatically from your use of our website and service, and from the data you upload to our service. We do not collect personal information about you from other third-party sources.

Recipients

We disclose personal information to service providers for business purposes, as listed under Third-Party Service Providers. We also disclose users’ email addresses to LinkedIn, a third party, as described below.

Sale and Sharing

We do not sell personal information. We may share identifiers, limited to our users’ email addresses (which may be hashed), with LinkedIn to show Geocodio ads to our users on LinkedIn. California law may treat this as “sharing” for cross-context behavioral advertising. We exclude users from our LinkedIn advertising audiences if we can determine from the information we hold that they are California residents, such as a California billing or shipping address. If you have not provided us with a California billing or shipping address, we may not be able to identify you as a California resident, and you may not be excluded. You can opt out at any time by emailing [email protected]. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.

Sensitive Personal Information

We do not use sensitive personal information to infer characteristics about you.

Retention

We keep payment and invoice records indefinitely for record-keeping. We keep input data (such as addresses and coordinates) as described under Data Retention above. We keep other personal information, including account information, prospect data, analytics data, and LinkedIn audience lists, for as long as reasonably necessary for our business purposes.

Colorado, Connecticut, Virginia, Utah Residents

You have privacy rights including the right to opt-out of profiling for automated decision-making, correct inaccurate information, and receive portable copies of your data.

Delaware, Iowa, Nebraska, New Hampshire, New Jersey Residents

You have privacy rights including access, correction, deletion, and opt-out rights. New Jersey residents have enhanced protections and we recognize universal opt-out signals.

Florida, Montana, Oregon, Texas Residents

You have comprehensive privacy rights with some state-specific variations in thresholds and enforcement mechanisms. The Florida Digital Bill of Rights applies only to controllers with more than $1 billion in annual global gross revenue, so it does not currently apply to Geocodio.

Maryland, Minnesota, Tennessee Residents

Enhanced privacy rights including:

  • Maryland: Stricter data minimization requirements and enhanced transparency

  • Minnesota: Right to question profiling decisions and data inventory requirements

  • Tennessee: Comprehensive privacy protections with unique threshold requirements

Indiana, Kentucky, Rhode Island Residents (Effective 2026)

Comprehensive privacy rights will become available, including access, correction, deletion, and opt-out rights.

Enforcement and Cure Periods

Different states have varying enforcement timelines and cure periods:

  • 30-day cure periods: Available in several states until specific expiration dates

  • 60-day cure periods: Available in some states with discretionary extension by attorneys general

  • No cure periods: Some states provide immediate enforcement without cure opportunities

  • Penalties: Range from $2,500 to $25,000 per violation depending on the state

Data Minimization and Purpose Limitation

We collect only personal information that is:

  • Adequate: Sufficient for the stated purpose

  • Relevant: Directly related to our services

  • Limited: Not excessive for the purpose

  • Necessary: Required to provide the requested service

  • Proportionate: Reasonable in relation to the service provided (required by Maryland law)

We do not collect personal information for purposes unrelated to our geocoding services.

Changes to This Policy

We will notify users of material changes to this Privacy Statement via:

  • Prominent notice on our website

  • Updated effective date on this page

Material changes that expand our use of personal information may require renewed consent.

Contact Us

For privacy questions, requests, or concerns:

  • Email: [email protected]

  • Response Time: As required by applicable law

  • Appeals: Use the same email address

  • Data Protection Officer: Available for EU, UK, and Canadian-related inquiries

Regulatory Contacts

If we cannot resolve your privacy concern, you may contact:

  • United States

    • California: California Privacy Protection Agency

    • Colorado: Colorado Attorney General's Office

    • Connecticut: Connecticut Attorney General's Office

    • Your State's Attorney General: For residents of other states with privacy laws

  • EU Residents: Your local data protection authority (a list is available on the European Data Protection Board website)

  • UK Residents: The Information Commissioner's Office (ICO) — ico.org.uk

  • Australian Residents: The Office of the Australian Information Commissioner (OAIC) — oaic.gov.au

  • New Zealand Residents: The Office of the Privacy Commissioner — privacy.org.nz

  • Canada

    • Canadian Residents: The Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca

    • Quebec Residents: Commission d'accès à l'information du Québec (CAI) — cai.gouv.qc.ca

    • Alberta Residents: Office of the Information and Privacy Commissioner of Alberta — oipc.ab.ca

    • British Columbia Residents: Office of the Information and Privacy Commissioner for British Columbia — oipc.bc.ca


Effective Date: 10/9/2026

This privacy policy applies to all users and services provided by Geocodio. We are committed to maintaining compliance with all applicable privacy laws and will update this policy as new laws take effect or existing laws are amended.

For our complete legal privacy policy, please see our formal Privacy Policy document.

Related Resources

Data Processing Agreement

Geocodio's Data Processing Agreement for GDPR (EU) and UK GDPR

Learn More

Terms of Use

Geocodio's Terms of Use and API Use Guidelines.

Learn more

Security

Secure geocoding without compromises.

Learn more

Infrastructure

Geocodio's resilient, hardened infrastructure processes over 2 billion lookups per month.

Learn more

Data Retention Policy

Specifies the kinds of data we keep and how long we keep it for.

Learn more

Delete Your Account

When logged in, you can permanently delete your account and all associated data by following the button below and scrolling to the bottom of the page.

Go to Dashboard

By the time you finish reading this page, the Geocodio API will have processed 5.3 million lookups.

Your data could be next...

A delightfully boring cookie banner

1 optional cookie from us
2 embeds blocked by default
0 ad tracking / data brokers

Geocodio would like to set one first-party cookie to remember how you found this site. Accepting also unblocks embedded videos and calendars, which set their own cookies.

Read the privacy policy