Privacy policy 2026-07-30.1

Privacy and data flows

Local 95 starts with no optional storage. One required cookie remembers your privacy choice; preferences and session analytics are enabled only when you choose them.

Your choicePurpose gateLimited storage or recipient

Necessary (required)

Remember your privacy decision, secure accounts, and provide catalogue and business-authority features you explicitly request.

Data
Privacy policy version, consent choices, and decision time; Account name, email, verification state, password hash, and linked sign-in provider; Session token, expiry, IP address, and browser user agent; Authenticator secret, recovery codes, failed attempts, and temporary lock time; Business mandates, invitations, cases, messages, evidence checks, decisions, and audit events; Public address fields sent to Stadia only when a merchant requests address lookup; Encrypted transactional-email payloads and delivery status
Storage
Signed first-party l95_privacy and l95_session cookies; account and authority records in PostgreSQL
Retention
Privacy choice: six months; sessions: up to 30 days; invitations: 14 days to accept and addresses anonymized 30 days after expiry; sent mail queue: 30 days; authority decisions and audit history are retained for integrity, with account identity pseudonymized on deletion
Recipients
Local 95; Resend or Postmark for transactional email; Google only when you choose Google sign-in; Stadia Maps when you explicitly open /map; Stadia Maps when a merchant explicitly requests address lookup

Preferences

Automatically load map previews and remember your colour theme and catalogue trust threshold.

Data
Permission to load optional map previews; Colour theme choice; Catalogue trust threshold
Storage
Recorded in the required privacy-choice cookie, plus signed l95_theme and l95_trust cookies when selected; signed-in trust preferences are stored with the account in PostgreSQL
Retention
Until the privacy choice expires or is changed
Recipients
Local 95; Stadia Maps for automatically loaded previews

Analytics

Measure anonymous aggregate journeys through the catalogue for statistics and tree art.

Data
Normalized route type; Public catalogue slug; Event order and server receipt time
Storage
Signed browser-session cookie plus pseudonymous navigation rows in PostgreSQL
Retention
Session-level paths: 90 days; anonymous daily nodes and edges: indefinite
Recipients
Local 95 only

Navigation analytics

With Analytics enabled, Local 95 links normalized pages within a short pseudonymous browser session. Sessions rotate after 30 minutes without activity. We do not put query strings, search terms, selected map locations, coordinates, referrers, IP addresses, or browser fingerprints in analytics tables. Session paths are deleted after 90 days; daily page and transition totals contain no session identifier and may be kept for statistics andtree art.

Withdrawing Analytics deletes the identifiable current raw session when it is still available and stops collection. Counts already incorporated into anonymous aggregates remain.

Maps

Opening the dedicated map is an explicit request, so its Stadia basemap loads under Necessary only. Detail-page previews load automatically with Preferences; otherwise, “Load map once” makes only that one request and stores no preference. Stadia receives ordinary network request information such as an IP address and browser headers. In the merchant workspace, pressing “Find address” sends the typed public address fields to Stadia through the Local 95 server; manual coordinates remain available without that lookup.