Privacy Policy
Last updated: 3 July 2026
This Privacy Policy ("Policy") explains how the Rootfifteen research team ("Rootfifteen", "we", "us", or "our") collects, uses, discloses, retains, and safeguards information when you visit rootfifteen.com, interact with the Rootfifteen Land Intelligence API, or otherwise use our products, services, dashboards, or documentation (together, the "Service"). It also describes the choices and rights available to you. We designed the Service to collect the minimum information reasonably necessary to operate it reliably, securely, and lawfully. We do not sell personal data, we do not "share" it for cross-context behavioural advertising, and we do not use it to build advertising profiles of you.
The data controller (or, where applicable, "business") responsible for personal data processed under this Policy is the Rootfifteen research team. You can contact us at any time at hello@rootfifteen.com.
1. Scope and definitions
This Policy applies to information we process about visitors to our website, users of the API, and people who contact us. It does not apply to third-party websites, applications, or services that integrate with or link to ours; those are governed by their own privacy notices.
"Personal data" (or "personal information") means information that identifies, relates to, or could reasonably be linked to a specific individual. Coordinates and other geographic inputs are not, by themselves, personal data, but they may become personal data when combined with an identifier that ties them to a specific person.
2. Information we collect
API inputs. Coordinates (latitude/longitude), optional parameters, request headers, and any additional data you choose to include when calling the API.
Request metadata. Timestamp, endpoint path, HTTP method, response status and size, approximate region derived from IP address, user-agent string, referrer, and API-key identifier (where applicable). Used for reliability, capacity planning, abuse prevention, and security investigations.
Account and contact data. If you email us, request commercial access, or sign up for updates, we receive the information you provide: name, email address, organisation, role, country, and the contents of your message and any attachments.
Commercial and billing data. For paid customers, we collect the billing contact, invoicing address, tax identifier, purchase-order references, and payment status. Card and bank details are handled directly by our payment processors; we do not store full card numbers on our systems.
Website telemetry. Privacy-respecting analytics such as page views, referrer, coarse device class, viewport, and language, used to understand aggregate traffic. We do not use advertising trackers, third-party ad pixels, or cross-site profiling cookies.
Security signals. Rate-limit counters, IP reputation signals, WAF/CDN observations, and audit-log events related to authentication, credential rotation, and admin actions.
3. How we use information
- Provide, maintain, secure, monitor, debug, and improve the Service and its scoring model;
- Authenticate users, provision API credentials, and enforce fair-use and rate limits;
- Detect, investigate, and prevent abuse, fraud, and security incidents;
- Respond to inquiries, support requests, and commercial-access discussions;
- Send transactional communications about the Service (e.g. security alerts, breaking changes, invoices);
- Produce aggregated, de-identified statistics for research, capacity planning, and product decisions;
- Comply with legal obligations, respond to lawful requests, and enforce our Terms;
- Where you have opted in, send occasional product updates you may unsubscribe from at any time.
We do not use Customer Data or personal data to train third-party foundation models.
4. Legal bases for processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases, matched to the purposes above:
- Performance of a contract — to provide the Service you have requested and to administer commercial agreements;
- Legitimate interests — to secure the Service, prevent abuse, understand aggregate usage, and improve our products, balanced against your rights and freedoms;
- Consent — for optional communications and any non-essential analytics that require it, which you may withdraw at any time;
- Legal obligation — for tax, accounting, sanctions, and other regulatory requirements.
5. Cookies, local storage, and analytics
We use a minimal set of browser storage mechanisms:
- Local storage. Remembers your theme preference (light/dark) and any preference to dismiss the theme picker. This data never leaves your browser.
- Strictly necessary cookies. Our hosting and CDN providers may set short-lived cookies for security, load balancing, and DDoS protection.
- Analytics. Where enabled, we use privacy-respecting analytics that do not fingerprint devices for advertising and do not sell your data.
We do not use advertising, profiling, or cross-site tracking cookies. Where required by law, we obtain consent before any non-essential telemetry.
6. How we share information
We share information only in these limited circumstances:
- Service providers ("sub-processors"). Cloud hosting, CDN, DDoS mitigation, email delivery, error monitoring, analytics, and payment processing, in each case bound by contractual confidentiality and data-processing obligations and permitted to use the data only to provide services to us.
- Legal and safety. When required by law, subpoena, court order, or regulator, or when necessary to protect the rights, safety, property, or integrity of the Service, our users, or the public.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to standard confidentiality and to this Policy.
- With your direction. Where you explicitly ask us to share information with a third party (e.g. an integration you enable).
We do not sell personal information, and we do not disclose it for cross-context behavioural advertising.
7. International data transfers
The Service may process data in countries other than your own, including India and other jurisdictions where our hosting providers and sub-processors operate. Where personal data is transferred from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures.
8. Security
We use administrative, technical, and physical safeguards designed to protect information, including TLS in transit, encryption at rest for stored logs and backups, principle-of-least- privilege access, mandatory review of production changes, credential rotation, secret scanning, and audit logging. Access to production systems is limited to a small number of authorised maintainers.
No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and applicable authorities within the timeframes required by applicable law.
9. Data retention
We keep information only for as long as needed for the purposes described in this Policy, to comply with our legal obligations, resolve disputes, and enforce agreements:
- Operational request and security logs: up to 90 days, then deleted or anonymised;
- Correspondence and support tickets: for the duration of the relationship plus a reasonable period thereafter for legal and accounting purposes;
- Account and billing records: for the period required by applicable tax and accounting laws (typically up to 7 years);
- Aggregated, non-identifying statistics: may be retained indefinitely.
10. Your rights and choices
Depending on where you live, you may have the right to (a) access the personal data we hold about you, (b) correct inaccurate data, (c) delete data, (d) receive a copy of your data in a portable format, (e) restrict or object to certain processing, (f) withdraw consent where processing is based on consent, and (g) not be subject to solely automated decisions with legal or similarly significant effects.
To exercise these rights, email hello@rootfifteen.com. We will verify your identity before acting on a request and will respond within the timeframes required by applicable law. You may also lodge a complaint with your local data protection authority, though we would appreciate the opportunity to address your concern first.
11. Notice to California residents
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) grants you specific rights regarding your personal information, including the right to know, delete, correct, and limit the use of "sensitive personal information", and the right to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined under California law. To exercise your rights, use the contact details above.
12. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
13. Automated decision-making
The Service produces deterministic, factor-based scores from geospatial inputs and does not use your personal data to make automated decisions that produce legal or similarly significant effects on you. If we introduce such processing in the future, we will update this Policy and, where required, provide meaningful information about the logic involved and your rights.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes in the Service, our practices, or applicable law. Material changes will be reflected by the "Last updated" date at the top of this page; where practical we will provide additional notice, for example an in-product notice or an email to registered contacts.
15. Contact us
Questions, requests, or concerns about privacy? Email hello@rootfifteen.com. We aim to respond within a reasonable period, and always within the timeframes required by applicable law.