Privacy Policy
What personal data we collect, why we hold it, how long we keep it, and the rights you have over it under UK data protection law. This is the same policy published at compoundingenergy.com and covers every Compounding Energy product; where CEAtlas does something specific with your data, it is called out by name.
1. Who we are
CEAtlas is operated by Compounding Energy Ltd, a company registered in England and Wales under company number 17319227, with its registered office at Tanners Farm, Tanners Lane, Chalkhouse Green, Reading RG4 9AB ("we", "us", "our"). We are the data controller for the personal data described in this policy.
For any privacy matter — including the rights described in section 7 — contact privacy@compoundingenergy.com.
2. The data we collect
We collect only what we need to run the service. Specifically:
| Data | When / why |
|---|---|
| Email address | When you join the waitlist, start checkout, or hold a subscription — to create your account, deliver your access key, and contact you about the service. |
| Billing identifiers | Your Stripe customer and subscription IDs, plan tier, and renewal dates. We do not store your card number — card data is handled entirely by Stripe. |
| Poster shop orders | When you buy a poster from the shop: the email address you enter at checkout, the poster bought, the amount paid, and Stripe identifiers (checkout-session, customer, and payment-intent IDs). We keep this order record so your download links can be re-issued and so refunds or chargebacks revoke them. Payment happens on Stripe's hosted checkout page — your card details never touch our servers. |
| Calibration uploads (met-mast / production CSVs) | When you run per-site calibration, the CSV you upload is processed in memory for the duration of that request only — used to compute the calibration factor, then discarded. It is not written to disk, logged, or stored server-side in any form, and the response is marked non-cacheable. Only the derived factor (a single number, plus alignment statistics) is returned to your browser, and only that factor is sent back if you apply it to a study. |
| Saved sites & pipeline runs | Locations and analyses you choose to save, so they sync across your devices. Stored against your account identifier. |
| Usage counters | Monthly counts of metered actions (e.g. site analyses, API calls) to enforce plan limits. |
| Product / intent events | Which features you open and waitlist/lead actions, with a session identifier, truncated browser user-agent, and a one-way hashed IP address (we do not store raw IPs). Used to improve the product and prevent abuse. |
| Error reports | Client-side crash diagnostics (message, stack, page). These carry no email or identity. |
| Local browser storage | Your access token, a session ID, and UI preferences are stored in your browser's localStorage so you stay signed in. These stay on your device. |
3. Legal bases (UK GDPR Art. 6)
- Contract — to provide the service to subscribers (account, billing, saved data, plan limits).
- Legitimate interests — to secure the service and prevent abuse (hashed IPs, error reports) and to understand and improve how the product is used (intent events). We balance these against your rights; you can object (section 7).
- Consent — when you join the waitlist or opt in to product updates. You can withdraw consent at any time.
- Legal obligation — to keep transaction records required by UK tax law.
4. How we use it
To operate your account and subscription; to deliver and gate features by plan; to provide support; to keep the service secure and reliable; to improve the product; and to meet our legal and accounting obligations. We do not sell your personal data, and we do not use it for third-party advertising.
5. Who we share it with
We use a small number of processors, each only for the purpose shown. This list is complete as at the effective date above.
| Provider | Purpose |
|---|---|
| Stripe | Payment processing — subscription billing and one-off poster purchases. Card details are entered on Stripe's own checkout pages and never reach our servers. |
| Fly.io | Application hosting and data storage. Our primary region is London, United Kingdom. |
| Resend | Transactional email only — receipts, access keys and free-trial activation links. Not used for marketing email. |
| Esri (ArcGIS Online) | Base-map tiles, which your browser requests directly when you use a map. |
| Anthropic, Groq | The language models behind the in-product Data Assistant. Messages you type to the assistant are sent to the provider to generate a reply; they are not used to train their models. |
| Vercel | Hosting for our marketing website and its aggregate, cookieless web analytics. Not used by this application. |
| CEGridSight | Single sign-on, if you sign in with a Compounding Energy account. |
We use no third-party error-monitoring service in production, and no third-party analytics in this application.
Our application infrastructure is hosted in the United Kingdom. Some providers above are US-based and may process limited operational data outside the UK and EEA. Where they do, transfers are made under the UK International Data Transfer Agreement or Standard Contractual Clauses, together with the additional safeguards in each provider's data processing terms.
6. How long we keep it
- Account & saved data — for the lifetime of your account plus 12 months.
- Usage counters & product events — 90 days, then deleted or aggregated.
- Billing & order records — 7 years, as UK tax law requires, even after an account closes. This includes poster-shop orders, which also let us re-issue your download.
- Waitlist entries — until you ask us to remove them, or you subscribe.
- Free-trial activation links — the address you enter is held against a pending link for 24 hours, then the link and the address are deleted automatically, whether or not you activate.
- Free-trial fair-use counters — up to 60 days after last use; see section 6a.
- Free account — the email address you sign in with, a salted hash of the network address (for IPv6, the /64 your provider assigns — never the full address) and the browser type at registration, the page you came from (referrer and any campaign tags), the coordinate and technology you were looking at when you asked to sign in (if any) and the browser's analytics session id, your sign-ins, and a per-day log of the coordinates you requested hourly data, a 12 × 24 profile or the annual bars at (14 days, kept for abuse detection). Sign-in link records live for one hour. Without an account, the one free look a day at those three is recorded against a salted hash of the network address (the coordinate and the day; kept for two days). The account is deleted after 400 days without a sign-in, or on request. Every erasure leaves an anonymised marker for 90 days — a salted hash of the address, how much of the free allowance you had used (the one site analysis and that day's coordinate count, never the coordinates) and, if the account was paused for abuse, the pause flag — so that erasing and re-registering neither restores the allowances nor lifts a pause (legitimate interest, abuse prevention; disclosed in your data export; you may object).
6a. Free-trial fair-use counters
The CEAtlas free trial gives full access to paid data, so we count what each trial uses: data volume, studies, API calls, and how many free trials an address has had. Those totals are stored against a salted one-way hash of your email address. The record holds no address, name or account link, but the hash is still personal data, because we can test whether a given address matches it.
We keep these counters for up to 60 days after last use and — unlike everything else — an erasure request does not remove them. Being able to reset them on demand would remove the only limits on how much paid data a free trial can take and how often it can be restarted. We rely on our legitimate interest in preventing abuse (Art 6(1)(f)) and on Art 17(1)(c). You can object, and the counters are shown to you in a data export. Everything that identifies you — your address, account and activity records — is erased as normal, and being refused a second free trial never prevents you from subscribing.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time. To exercise them:
- If you have an account, you can exercise the main two yourself: a signed-in request to
/api/dsr/exportreturns everything we hold for you, and/api/dsr/eraseerases it. Two things deliberately survive that erasure, and both appear in your export — the billing records the law requires us to keep, and the fair-use counters described in section 6a. - Otherwise, email privacy@compoundingenergy.com and we will respond within one month.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies & local storage
CEAtlas does not use third-party advertising or cross-site tracking cookies. We use your browser's localStorage for strictly necessary purposes — keeping you signed in, remembering UI preferences, and a first-party session identifier. Loading map tiles and fonts also involves requests to the providers in section 5. Because nothing we set is non-essential, no consent banner is required under PECR; if that ever changes, we will ask first.
9. Security
Access to paid datasets and account data is gated by signed tokens; IP addresses are stored only as one-way hashes; payment card data never touches our servers. Stored data sits on encrypted volumes. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we will tell you promptly if a breach affects you.
10. Changes to this policy
We may update this policy as our products evolve. We will notify account holders of material changes by email at least 14 days before they take effect. The version and effective date at the top show the current text.