FrontageRadar · A product by Auroyo
Privacy Policy
Effective and last updated: September 5, 2026
This policy explains information handling for FrontageRadar, a product provided under the Auroyo brand. It covers our website, workspaces and related support, and does not automatically cover other Auroyo products.
1. Information we handle
- Account and workspace information: names, email addresses, authentication records, workspace membership and roles.
- Your work: search requests, filters, saved sites, notes, comparisons, generated reports and related usage limits.
- Billing and support: Stripe customer, subscription and transaction references, plan and payment status, and information you send us. Stripe collects payment details through its hosted services; we do not directly collect or store complete card numbers or card security codes.
- Technical and security information: requests, device/browser information, cookies, session identifiers, errors and abuse-prevention signals. Hosting and security providers may process IP addresses. Our public-trial controls use derived identifiers to enforce limits.
- Public records: parcel, assessment, road, planning, permit and related records. Some records contain owner names or mailing addresses. These are distinct from private customer workspace information.
2. Why we use information
We use information to authenticate users, operate workspaces, return searches and reports, manage subscriptions and limits, respond to requests, prevent fraud and abuse, investigate errors, and meet applicable legal obligations. With your analytics choice, we also measure product usage to improve the service.
We do not sell your private account or workspace information, use it for cross-context behavioral advertising, or share it with unrelated Auroyo products for their marketing. Information intentionally shared within a workspace is available according to its roles and features; workspace owners and administrators control access.
3. Service providers and AI
We use providers to perform specific functions, including:
- Supabase: account authentication, application database and storage.
- Cloudflare: website delivery, hosting and security, including bot protection.
- Stripe: checkout, payment methods, invoices and subscription management.
- OpenAI: AI-assisted searches and explanations.
- PostHog: optional product analytics.
- Resend and Zoho: account emails and support correspondence.
When you use an AI feature, we send the request and relevant site or workspace context needed for that feature to our AI provider. Avoid entering sensitive or confidential information that is unnecessary for your search. Our API requests disable response storage where supported; that setting does not eliminate all provider security or abuse-monitoring retention. We do not authorize our AI provider to use these API inputs to train its general-purpose models.
Providers may also handle information for their own legally required payment, fraud, security or compliance purposes under their policies. External maps and links may involve other providers; visiting another website is governed by that site's practices.
We may disclose necessary information to comply with law or valid legal process, protect rights and security, or complete a business transfer with appropriate safeguards and notice where required. Such a transfer does not itself authorize unrelated new uses of your information.
4. Cookies and analytics choices
Essential cookies and local storage support sign-in, security, trial limits and your saved privacy choice. Optional product analytics remain off until you choose to allow them. Refusing analytics does not prevent normal use of the service.
If you allow analytics, PostHog uses cookies/local storage and records selected page and product events. Signed-in events can be associated with your user and workspace identifiers, so this is not fully anonymous. Our analytics configuration disables session replay and automatic click capture, and excludes raw search text and private workspace content from the selected event properties.
Use to change your choice on this browser. Withdrawal stops future optional collection; you can contact us about previously collected information. We keep analytics disabled when the browser sends Global Privacy Control. Other browser signals such as Do Not Track do not have a separate implementation. Choices are per browser and may need to be set again after clearing storage.
Security, essential service operation and billing records are not switched off by declining analytics.
5. International processing
Our primary application database is hosted in the United States. Hosting, payment, email, analytics and AI providers may process information in the United States and other countries. Authorized personnel may access information from their locations when needed to operate or support the service. We do not promise that all storage, processing or access occurs only in the United States. Where applicable law requires transfer safeguards, those requirements apply.
6. Retention and security
We retain information for the purposes described above for as long as reasonably necessary, taking account of the account's status, your saved work, support requests, security needs and applicable recordkeeping obligations. Saved workspace content is generally retained while the workspace remains in use. Canceling a subscription does not by itself delete the account or workspace.
Following a verified deletion request, we remove information from active systems when required, subject to necessary legal, security and shared-workspace exceptions. Backup copies may remain until normal backup rotation, and limited billing or dispute records may need to be retained separately. We will explain relevant limitations when handling a request; we do not promise immediate deletion from every backup.
We use access controls, workspace permissions, restricted server credentials and encrypted transport to protect information. No online service or security measure is completely secure.
7. Your requests and public-record corrections
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of your information, or to object to or restrict certain processing. Send requests to support@frontageradar.com, preferably from your account email. We may need to verify identity and authority before acting. We will respond within applicable legal time limits; these requests are currently handled through support.
For team content, we consider workspace ownership and other members' rights. To report incorrect public owner or parcel information, send the relevant site or source reference. We can investigate our presentation and any applicable correction or removal request, but cannot change or erase the original government record. Do not send passwords, card details or identity documents in an initial email.
The service is intended for adult business users and is not directed to children. Contact us if you believe a child has provided personal information. You may also raise concerns with a competent data-protection authority where applicable.
8. Policy updates and contact
We update this policy when our practices change and keep the effective date visible. We will notify affected users of material changes and obtain consent where required before using previously collected information for materially different purposes.
Privacy and service contact: support@frontageradar.com. Subscription cancellation and refunds are described in our Terms of Service.