Privacy Policy

Last updated: July 18, 2026

This Privacy Policy explains what personal data coords.zone ("we", "us") collects, why we collect it, how long we keep it, and what rights you have over it. coords.zone is operated by Markus Nordin as an individual (sole trader) based in Sweden, who acts as the data controller for the purposes of the EU General Data Protection Regulation ("GDPR") and equivalent laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").

If anything here is unclear, or you want to exercise any of the rights described below, contact us at [email protected].

1. Data we collect

Account data

If you register for an account, we store your email address. We do not use passwords — authentication is via a one-time "magic link" sent to your email, delivered through our email provider, Resend.

API keys

When you generate an API key, we store a SHA-256 hash of the key, not the key itself. We cannot recover a lost key from what we store — only issue a new one. We also store the key's label, optional HTTP referrer allowlist, and last-used timestamp.

Request data and IP addresses

Unauthenticated requests are rate-limited and metered per IP address so we can enforce fair-use and free-tier limits. We do not store your IP address in plain text for this purpose: it is converted into a keyed HMAC-SHA256 digest before being written to storage, so the stored value cannot be reversed back into your IP address. We only need to know that a given IP is over its quota, not which IP it is.

Usage and billing data

For authenticated (API key) requests, we record daily request counts per API key and account, used to enforce the free tier and to calculate metered charges on paid plans. If you subscribe to a paid plan, payment processing is handled entirely by our payment processor, Stripe — we never receive or store your card number. We do store Stripe-issued identifiers (customer ID, subscription ID), subscription status, billing period dates, and the content of billing-related webhook events Stripe sends us, which we keep for accounting and dispute-resolution purposes.

Error and diagnostic data

We use Sentry to capture application errors and crashes, which may include the request path, timestamp, and technical metadata about the failure. We use Cloudflare Web Analytics to measure aggregate page views on our marketing pages; it is cookie-less and does not track individuals across sites.

2. Why we process this data

  • Performance of a contract — to create your account, authenticate you, issue API keys, and provide the API service you've requested.
  • Legitimate interests — to enforce rate limits and quotas, detect and prevent abuse or fraud, and keep the service operating reliably (error monitoring, aggregate analytics).
  • Legal obligation — to keep accounting and billing records for as long as required under applicable tax and bookkeeping law.

We do not sell your personal data, and we do not use it for third-party advertising.

3. How long we keep it

  • Hashed IP-based usage records (unauthenticated quota enforcement) are deleted after 3 months — that window is all that's needed to enforce the current quota period.
  • Account, API key, and billing/usage records are kept for as long as your account is active, and afterwards for as long as required by tax and accounting law (currently up to 7 years under Swedish bookkeeping law for records tied to invoiced usage).
  • Error/diagnostic events are retained by Sentry according to our plan's retention window, after which they are automatically deleted.

You can request deletion of your account and associated data at any time (see Section 6); we'll delete what we're not legally required to keep.

4. Who we share it with

We use a small number of subprocessors to run the service. Each only receives the data it needs to perform its function:

Provider Purpose Data involved
Stripe Payment processing and billing Email, billing identifiers, usage volume
Resend Transactional email (magic links) Email address
Sentry Error tracking Request metadata, crash reports
Cloudflare Cookie-less web analytics Aggregate page-view counts
Hetzner Application and database hosting All of the above, at rest

We do not otherwise share, rent, or sell personal data to third parties, except where required by law (for example, in response to a valid legal request).

5. International data transfers

Our application and database servers are located in Germany (EU/EEA). Some subprocessors listed above (Stripe, Resend, Sentry) are based in, or transfer data to, the United States. Where that happens, it's covered by appropriate safeguards such as Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

6. Your rights

If you're in the EEA, UK, or Switzerland (GDPR)

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive a copy of your data in a portable format
  • Withdraw consent, where processing is based on consent
  • Lodge a complaint with your national supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY), imy.se

If you're a California resident (CCPA/CPRA)

You have the right to:

  • Know what personal information we've collected about you and why
  • Request deletion of your personal information
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information — we do not sell or share personal information as defined by the CCPA/CPRA, so there's nothing to opt out of
  • Not be discriminated against for exercising any of these rights

To exercise any of these rights, email [email protected]. We'll respond within the timeframe required by applicable law, and may need to verify your identity (typically, confirming you control the email address on the account) before acting on the request.

7. Cookies

We use a single strictly-necessary session cookie to keep you logged in after you click a magic link. It is not used for tracking or advertising, and is exempt from consent requirements under EU ePrivacy rules because it's essential to the service you requested. We do not use any other cookies; our analytics beacon (Cloudflare Web Analytics) is cookie-less by design.

8. Security

API keys are stored as SHA-256 hashes, never in plain text. IP addresses used for rate-limiting are stored as keyed HMAC-SHA256 digests, not raw addresses. All traffic to coords.zone is encrypted in transit via TLS. No method of storage or transmission is 100% secure, but we take reasonable technical measures to protect the data we hold.

9. Children's privacy

coords.zone is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will update the "Last updated" date above; continued use of the service after a change constitutes acceptance of the revised policy.

11. Contact

Questions about this policy or your data can be sent to [email protected].

coords.zone