We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect
Last updated: July 18, 2026
This Privacy Policy explains what personal data coords.zone ("we", "us") collects, why we collect it, how long we keep it, and what rights you have over it. coords.zone is operated by Markus Nordin as an individual (sole trader) based in Sweden, who acts as the data controller for the purposes of the EU General Data Protection Regulation ("GDPR") and equivalent laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
If anything here is unclear, or you want to exercise any of the rights described below, contact us at [email protected].
If you register for an account, we store your email address. We do not use passwords — authentication is via a one-time "magic link" sent to your email, delivered through our email provider, Resend.
When you generate an API key, we store a SHA-256 hash of the key, not the key itself. We cannot recover a lost key from what we store — only issue a new one. We also store the key's label, optional HTTP referrer allowlist, and last-used timestamp.
Unauthenticated requests are rate-limited and metered per IP address so we can enforce fair-use and free-tier limits. We do not store your IP address in plain text for this purpose: it is converted into a keyed HMAC-SHA256 digest before being written to storage, so the stored value cannot be reversed back into your IP address. We only need to know that a given IP is over its quota, not which IP it is.
For authenticated (API key) requests, we record daily request counts per API key and account, used to enforce the free tier and to calculate metered charges on paid plans. If you subscribe to a paid plan, payment processing is handled entirely by our payment processor, Stripe — we never receive or store your card number. We do store Stripe-issued identifiers (customer ID, subscription ID), subscription status, billing period dates, and the content of billing-related webhook events Stripe sends us, which we keep for accounting and dispute-resolution purposes.
We use Sentry to capture application errors and crashes, which may include the request path, timestamp, and technical metadata about the failure. We use Cloudflare Web Analytics to measure aggregate page views on our marketing pages; it is cookie-less and does not track individuals across sites.
We do not sell your personal data, and we do not use it for third-party advertising.
You can request deletion of your account and associated data at any time (see Section 6); we'll delete what we're not legally required to keep.
We use a small number of subprocessors to run the service. Each only receives the data it needs to perform its function:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing and billing | Email, billing identifiers, usage volume |
| Resend | Transactional email (magic links) | Email address |
| Sentry | Error tracking | Request metadata, crash reports |
| Cloudflare | Cookie-less web analytics | Aggregate page-view counts |
| Hetzner | Application and database hosting | All of the above, at rest |
We do not otherwise share, rent, or sell personal data to third parties, except where required by law (for example, in response to a valid legal request).
Our application and database servers are located in Germany (EU/EEA). Some subprocessors listed above (Stripe, Resend, Sentry) are based in, or transfer data to, the United States. Where that happens, it's covered by appropriate safeguards such as Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
You have the right to:
You have the right to:
To exercise any of these rights, email [email protected]. We'll respond within the timeframe required by applicable law, and may need to verify your identity (typically, confirming you control the email address on the account) before acting on the request.
We use a single strictly-necessary session cookie to keep you logged in after you click a magic link. It is not used for tracking or advertising, and is exempt from consent requirements under EU ePrivacy rules because it's essential to the service you requested. We do not use any other cookies; our analytics beacon (Cloudflare Web Analytics) is cookie-less by design.
API keys are stored as SHA-256 hashes, never in plain text. IP addresses used for rate-limiting are stored as keyed HMAC-SHA256 digests, not raw addresses. All traffic to coords.zone is encrypted in transit via TLS. No method of storage or transmission is 100% secure, but we take reasonable technical measures to protect the data we hold.
coords.zone is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll delete it.
We may update this policy from time to time. Material changes will update the "Last updated" date above; continued use of the service after a change constitutes acceptance of the revised policy.
Questions about this policy or your data can be sent to [email protected].