ArSite

Privacy Policy

Version 4 · Effective 8/28/2026

Privacy Policy

Effective 28 August 2026

This policy explains what personal information ArSite ("we", "us") collects, why, and what you can do about it. ArSite is operated by ArgonBI from British Columbia, Canada.

We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).

1. Our approach

ArSite is a map. Most of what it does needs no personal information at all, and the public map works without an account. We collect what a feature actually needs to work, and not more.

2. What we collect

Account information. When you create an account we collect your email address and the name you give us. Authentication is handled by Clerk, which also stores your credentials, and we never see your password.

Location you choose to look at. When you search an address or tap the map, the coordinates are sent to our servers to produce a reading. If you use "find my location", your browser asks your permission first and we use the result to position the map. We do not track your location in the background, and we do not build a movement history.

Locations you save. If you save a place, create a trip, or set up an alert, we store what you saved so the feature can work. You can delete these.

Marketing preferences. If you opt in to email updates, we record which purposes you agreed to, when, and through which surface. We also record when you decline or withdraw, so we can show you what you actually chose. That record includes the IP address the choice was made from, because a consent record that cannot be tied to a moment and an origin is not evidence of anything. We also record the IP address of a sign-in session, for account security.

Payment information. Payments go through Stripe. We receive confirmation of payment and a customer reference. We never receive or store your full card number.

API keys and usage. If you use the ArSite API we store a hashed form of each key you hold, and we count the calls made on your account: a daily total per account, and a count per operation, so that limits can be enforced and shown to you. We deliberately do not record the coordinates an API call asked about alongside those counts. Usage counts are kept against your account rather than against an individual key, so rotating a key does not detach your history from you.

Automated and AI client connections. If you connect ArSite to an AI assistant or agent framework, including through our MCP interface, it authenticates as you and its calls are counted against your account exactly like any other, per operation. Authorisation itself is handled by our authentication provider rather than stored by us, and we do not keep a separate transcript of what an assistant asked. What that third-party client does with the results is governed by its own privacy policy, not ours.

Technical and usage information. Server logs, error reports and basic usage counts, used to keep the service working and secure. We deliberately keep the coordinates you look at out of our application logs.

Cookies. We use cookies that are necessary for the service: keeping you signed in, and security. We do not use advertising cookies and we do not sell your information.

3. Why we use it

  • To provide the map, readings, trips, sharing and alerts you ask for.
  • To create and secure your account.
  • To provision API keys, enforce plan limits, and show you your own usage.
  • To take payment and give you access to what you bought.
  • To send you service messages about your account, purchases or alerts you set up.
  • To send marketing email only if you opted in, and only for the purposes you chose.
  • To keep ArSite working, diagnose faults, prevent abuse and meet legal obligations.

4. Consent

We rely on your consent, and on the reasonable purposes permitted by PIPEDA and BC PIPA for running and securing the service.

Marketing consent is always separate from accepting the Terms, is never pre-ticked, and declining it changes nothing about your account. You can withdraw it at any time in your account settings or via the unsubscribe link in any marketing email.

5. Who we share it with

We do not sell personal information. We share it only with service providers who process it on our behalf, under contract:

  • Clerk for authentication and account management
  • Stripe for payment processing
  • Resend for transactional and opted-in email
  • Railway for application and database hosting

We also use third-party data services to answer map queries: our own INFERNIS engine, the Province of British Columbia's open data, Environment and Climate Change Canada, and our self-hosted geocoding and routing services built on OpenStreetMap data. Our geocoding and routing run on our own infrastructure specifically so that the places you search are not sent to a third-party provider.

Map imagery is the exception, and it is worth stating plainly. Satellite imagery is served by Esri. When your browser draws that layer it requests image tiles directly from Esri, which necessarily discloses to Esri the map area you are viewing, together with your IP address and browser details. This happens between your browser and Esri and is governed by Esri's own privacy terms. Choosing the vector "Map" base layer instead avoids those requests.

We may disclose information where required by law, or to protect the rights, safety or property of ArSite, our users or the public.

6. Where it is stored

ArSite is hosted on infrastructure that may process and store data outside Canada, including in the United States. Information stored in another country may be accessible to that country's courts and authorities under its laws. Our providers are bound by contract to protect it.

7. Sharing a trip

If you create a share link, anyone holding that link can see what you shared, subject to any access code you set. You can revoke a link, but we cannot un-see information someone has already viewed. Only share with people you intend to.

8. How long we keep it

  • Account information: while your account is open, then deleted or anonymised within 90 days of closure.
  • Saved locations, trips and alerts: until you delete them, or your account closes.
  • API keys: until you revoke them or your account closes.
  • API usage counts: 400 days, so a full twelve months is always available for a question raised on the anniversary of the period it concerns. These are counts, not a record of what you looked at.
  • Consent records: kept after withdrawal, because the record of what you agreed to and when is what makes a later question answerable. Retained for 7 years.
  • Payment records: as required by tax and accounting law, generally 7 years.
  • Logs: typically 30 days.

9. Your rights

You can:

  • Access the personal information we hold about you.
  • Correct anything inaccurate.
  • Delete your account and the information attached to it.
  • Withdraw consent to marketing at any time.
  • Ask questions about how we handle your information, and complain if you are not satisfied.

Email [email protected] and we will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia.

10. Security

We use encryption in transit, access controls, and least-privilege database access. API keys are stored as a keyed hash and shown to you in full only once, at the moment they are created. Share links are stored hashed, and access codes are stored using a slow password hash. No system is perfectly secure, and we do not claim otherwise.

11. Children

ArSite is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.

12. Changes

If we change this policy materially we will give notice in the product and, where you have an account, by email. The effective date above always reflects the current version.

13. Contact

[email protected]