Privacy
This policy explains what PlaceField collects when people visit the site, request access, sign in to Dashboard, or use the API and browser widgets.
Information We Collect
When you request access or contact PlaceField, we collect the email address and use-case details you submit, plus basic request metadata such as user agent and referrer.
When you use Dashboard, we process account email addresses, password hashes, session cookies, browser public key values, API key metadata, allowed origins, and related operational settings. Server secret keys are stored hashed after creation or rotation and are not shown again.
When the API or widget is used, PlaceField may process request metadata such as request ID, endpoint, status, latency, key/customer identifiers, origin, query text, country/countries/geoBias/type parameters, result count, dataset version, error category, and rate-limit events.
IP Address And Location Bias
PlaceField may use the requester IP address to infer coarse country-level or coordinate-level bias for autocomplete when geographic bias is enabled and no country is supplied. This is used to rank location suggestions, not to return precise device location.
IP geolocation is best effort and may be disabled, fail open, or use a configured provider. Customers can pass geoBias=nearby to prefer nearby places, or geoBias=none when they need deterministic worldwide behavior.
Analytics And Cookies
PlaceField uses necessary cookies for Dashboard sessions. The public site may use Google Analytics when configured to understand page traffic and product interest, and may record privacy-safe site health events such as page path, browser error category, failed asset URL, user agent, and referrer.
Browser public keys are protected with exact allowed origins. Origin headers are processed to decide whether browser requests are allowed.
How We Use Information
We use collected information to provide the API and widget, operate Dashboard, create and manage customer access, secure API keys, apply rate limits, diagnose errors, improve dataset quality, respond to support requests, and understand product interest.
Zero-result queries, top queries, and error patterns may be reviewed to improve search quality and documentation.
Sharing
PlaceField does not sell customer contact details or API request logs. We may use infrastructure, analytics, email, hosting, database, security, and geolocation providers to operate the service. We may disclose information when required by law, to protect the service, or as part of a business transaction.
Retention And Control
Operational logs, analytics, account records, and access records are retained as needed to operate, secure, debug, and improve PlaceField. Customers can ask for access changes, key revocation, or removal of contact information through the site contact flow.
Do not send sensitive personal data, passwords, secret keys, or unnecessary end-user information inside autocomplete query text.