PlaceGap Privacy Policy
Effective Date: March 1, 2026 · Last Updated: September 12, 2026
1. Who We Are
PlaceGap is a location intelligence platform for the fitness industry, operated by PlaceGap LLC, a Texas limited liability company ("we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect your information when you use our website and services at placegap.com.
The Service is offered solely to business users located in the United States, and our data covers the United States only. We store and process information in the United States. If you are outside the United States, the Service is not directed to you and we ask that you not use it.
2. Information We Collect
Account Information
When you create a PlaceGap account, we collect:
- Email address
- Password (stored in hashed form, we never store or see your plain-text password)
- Account creation date
Usage Data
When you use PlaceGap, we automatically collect:
- Search queries (addresses and cities you search)
- Features accessed (Explore, GapFinder, competitor views, exports)
- Pages visited and time spent
- Browser type, device type, and screen resolution
- IP address
Payment Information
If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number, CVC, or full billing details on our servers. Stripe handles all payment data under their own privacy policy. We receive and store: your name on the card, billing email, subscription status, and transaction history.
3. How We Use Your Information
We use your information to:
- Provide the service: process your searches, generate demand scores, display market analysis
- Improve the product: understand which markets users search most, identify feature usage patterns, prioritize development
- Communicate with you: send account confirmations, subscription receipts, service updates, and (with your consent) product announcements
- Prevent abuse: detect and prevent unauthorized access, fraud, or misuse of the platform
- Aggregate market intelligence: we analyze search patterns in aggregate (not individually) to understand market demand across metros. This data is never sold and is never tied to your identity.
4. Information We Do NOT Collect
- We do not sell or share your personal information. "Share" has a specific meaning under California law: disclosing personal information for cross-context behavioral advertising. We do neither, and we never have.
- We do not advertise to you based on your activity here. No advertising account is linked to this site. In our Google Analytics property, Google Signals and ads personalization are both switched off, so your activity is not used to build advertising audiences.
- We do not track your precise location. We do not use GPS, device sensors, or mobile location panels. Analytics does derive an approximate city from your IP address, which is standard for any website and cannot identify a street address or a person.
- We do not share your individual search history with other users.
- We do not use your data, or anything you enter, to train machine learning models.
Section 11 lists every third party that processes data on our behalf, including the two analytics tools, and Section 6 explains how to turn analytics off entirely.
5. Data Sources We Use
PlaceGap displays data from public and licensed sources:
- U.S. Census Bureau: American Community Survey (ACS) demographic data. This is public government data.
- Google Places API: Business listings, ratings, and reviews for fitness businesses. This data is publicly available through Google.
- Mapbox: Drive-time and distance calculations for selected area analysis.
- Business websites: publicly listed locations, published by brands on their own store-locator pages.
What those providers receive from you
We do not send your name, email address, or account identifier to any of them. Some do receive information in the course of doing their job, and you should know which:
- Google receives your IP address and your interactions with the map directly from your browser, because the map is drawn in your browser rather than on our servers. Addresses you search are sent to Google and to Mapbox for geocoding, and sometimes to the U.S. Census Bureau's public geocoder.
- OpenAI receives the search settings and area statistics behind a result, so it can write the short summary shown on Gap Finder cards. It does not receive your name, email, or account identifier.
An address you search is information about a place, not about you, but it is information you typed, so we would rather say plainly where it goes than leave you to assume.
6. Cookies and Local Storage
PlaceGap uses browser local storage to save your preferences (such as map settings and search history within your session). We do not use third-party cookies for advertising or cross-site tracking.
We use two analytics tools: PostHog, to understand which features get used and where people get stuck, and Google Analytics, mainly to see how people find the site from search. Both receive page views, the events listed in Section 2, and your IP address, from which Google derives an approximate city.
Both are off until you agree. We ask on your first visit, and neither script is loaded unless you accept, so declining means the requests are never made rather than made and ignored. Neither is used for advertising: see Section 4.
You can change your mind at any time using the switch below. Turning it off stops further collection from this browser.
7. Data Retention
- Account data is retained as long as your account is active. If you delete your account, we remove your personal information within 30 days.
- Search logs are retained in de-identified form for product improvement. Individual search history tied to your account is deleted when you delete your account.
- Payment records are retained as required by law (typically 7 years for tax and financial compliance).
- Analytics data is retained by Google Analytics for 14 months after your last visit, covering event-level and user-level data, with aggregated reports kept longer. PostHog retains event data for 1 year. We do not record user sessions. Neither tool receives anything from a visitor who has not accepted analytics.
Backups
Deleting your account removes your information from the live system within 30 days. Copies may remain in database backups, which are kept for six days and then deleted. Backed-up data is not used for anything: it is kept only so the service can be restored after a disaster, and a restore does not bring a deleted account back.
What "de-identified" means here
De-identified data cannot reasonably be linked back to you. We maintain technical safeguards to keep it that way, we do not attempt to re-identify it, and we require anyone we share it with to do the same.
8. Data Security
We protect your data using:
- HTTPS encryption for all data in transit
- Hashed passwords (we cannot read your password)
- Access controls limiting who on our team can view user data
- Regular security reviews of our infrastructure
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you by email without undue delay, and in any case within the time applicable law requires. We will tell you what happened, what information was involved, and what we are doing about it. Where we cannot yet answer those questions accurately, we will say so rather than delay telling you at all.
9. Your Rights
You have the right to:
- Access your data: request a copy of the personal information we hold about you
- Correct your data: update your email or account information at any time
- Delete your data: request account deletion and removal of your personal information
- Export your data: request a machine-readable copy of your account data
- Opt out of marketing communications at any time
To exercise any of these rights, email us at [email protected]. We will verify your request against the email address on your account, and respond within 45 days. If we need longer, we will tell you why before that period ends.
State privacy rights
Several states, including Texas, California, Virginia, Colorado, Connecticut and Utah, give residents specific privacy rights. Rather than offer different rights to different people, we extend the rights above to every user regardless of where you live. That covers access, correction, deletion, a portable copy, and opting out of marketing.
Two rights that some of those laws provide do not arise here: we do not sell or share personal information, and we do not use it for targeted advertising or profiling that produces legal or similarly significant effects. There is accordingly nothing to opt out of. If that ever changes, this policy will change first.
If we turn down your request
You may appeal. Reply to our decision, or email [email protected] with "appeal" in the subject line, and we will review it and respond in writing within 60 days, explaining our reasoning. If we deny the appeal, we will tell you how to complain to your state attorney general. Texas residents can contact the Office of the Texas Attorney General at texasattorneygeneral.gov.
10. Children's Privacy
PlaceGap is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.
11. Third-Party Services
These are every third party that processes data on our behalf, what each one is for, and what it receives. Each handles data under its own privacy policy.
- Stripe (stripe.com/privacy): payment processing. Receives your card details directly, plus your name and billing email. We never see your card number.
- Google Maps Platform (policies.google.com/privacy): map display, geocoding, and business listings. Receives your IP address and map interactions directly from your browser, and the addresses you search.
- Google Analytics (policies.google.com/privacy): understanding how people find and move through the site. Receives page views, events, and your IP address. Only after you accept analytics. See Section 4 for what is switched off.
- PostHog (posthog.com/privacy): product analytics, hosted in the United States. Receives page views, events, and your IP address. Only after you accept analytics.
- Mapbox (mapbox.com/legal/privacy): drive-time and distance analysis. Receives the locations being analysed.
- OpenAI (openai.com/policies/privacy-policy): writing the short plain-English summaries on Gap Finder result cards and brand profiles. Receives the search settings and area statistics behind a result. Receives no name, email, or account identifier.
- Formspree (formspree.io/legal/privacy-policy): delivering the form on our request-access page, and nothing else. Receives the name, work email, organization, role or use case, and optional message you enter there. It is not used anywhere else in the Service.
- Railway (railway.com/legal/privacy): hosting for the application and the database, in the United States. Holds everything described in Section 2.
- Our email delivery provider: sending account emails such as verification and receipts. Receives your email address and the contents of those messages.
We add a provider here before it starts processing your data, not after. If you are reviewing us as a vendor and need this as a formal subprocessor list, email [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in the app. The "Last Updated" date at the top reflects the most recent revision, and every revision is listed below so you can see what changed and when.
Revision history
- September 12, 2026: corrected the analytics retention figures in Section 7, which described a shorter period than we actually use.
- September 11, 2026: named every third-party processor rather than a subset, including Google Analytics, PostHog, OpenAI, Formspree, our host and our email provider. Corrected the statement that no data source receives information from you, and described what each one does receive. Replaced a blanket "no advertising trackers" claim with specifics. Added state privacy rights and an appeal route, a backup carve-out to the deletion promise, and a statement that the Service is US-only. Replaced a 72-hour breach notification commitment with notice without undue delay.
- September 2, 2026: disclosed product analytics and added the opt-in consent control in Section 6.
- March 1, 2026: first published.
13. Contact Us
Questions about this Privacy Policy, or want to exercise any of the rights in Section 9? Email us at [email protected].
PlaceGap LLC
5900 Balcones Drive, Ste 100
Austin, TX 78731
United States