Effective August 28, 2026
Permit Plotter is a map of public building permit records for the East End of Long Island, New York. This policy explains what information we collect from the people who visit and use the site, who else handles it, and what you can do about it.
It covers you as a visitor or customer of the site. The permit records themselves, including the names that appear in public filings, are covered by our Terms and Conditions, which carry the same effective date as this policy. Section 9 below explains where the two documents meet.
This policy always lives at permitplotter.com/privacy, linked as Privacy in the site footer. If anything in it is unclear, write to legal@permitplotter.com. That inbox is live and monitored.
You can use the public map without an account. When you do, here is what we collect.
Usage analytics. We use a United States analytics service to understand how the site is used: pages viewed, clicks, device and browser information, your approximate location derived from your IP address, and specific product actions we have chosen to measure. We do not send your search text as an analytics event: we record only the shape of a search, meaning its length and whether it contains digits, and we scrub search text from the addresses attached to analytics events.
Session replay. The same analytics service also records how the page is used: clicks, scrolling, and what the page displays, so we can see where the site confuses people or breaks. Text you type into an input field is masked to asterisks in these recordings. Text the page itself displays, including a search the page echoes back on screen, can appear in a recording like anything else on the page. It also collects web performance measurements, heatmaps, and browser console logs for us.
Error reports. When something breaks, a United States error tracking service receives the error, a stack trace, and context about your browser so we can reproduce the problem. Errors also flow into the issue tracking service we use, so they get fixed.
Map tiles. The map is drawn with tiles your browser loads directly from our mapping provider. That means the mapping provider sees your IP address and the map areas you view, and it may collect its own usage telemetry under its own privacy policy.
Searches and filters. What you search and filter goes to our database, hosted with our backend infrastructure provider, because that is how the site answers your query. No town or village sees what anyone searches. Searching happens only inside an account: a signed-out visitor reaches our landing page and sends us no search or filter of any kind.
Accounts and paid subscriptions are built but not yet offered. When they are, this section applies.
Signing in. Sign-in is handled by a United States sign-in service. It collects your name, email address, login credentials, and any organization membership.
Paying. Payments are handled by our payment processor. Your card and billing details go directly to the processor and never touch our servers. We receive your subscription status and billing identifiers so we know what your account includes.
Analytics and errors, tied to your account. Once you sign in, the analytics and error reports described in Section 2 are associated with your account (your user id, email address, name, and, on an office plan, your organization’s id) so we can support you and understand how customers use the service.
Email alerts you save. For each alert, we store the email address it goes to (taken from your sign-in identity), the saved search criteria (including any search text you typed into them), and a log of what each alert email contained. A remembered map view is also stored with your account.
API keys and AI assistant connections. If you use our API or connect an AI assistant, we issue keys tied to your account, and the connector stores authorization grants. For account sign-ins, that means your user id and email address. For key sign-ins, that means an encrypted copy of the key, with only a short hint visible.
Downloads you make. For each spreadsheet download we record who took it, when, a short summary of the filters used, how many rows it held, and whether it was allowed or refused. We use this to run the download limits and to spot misuse.
We are a small operation and we build on established outside services rather than running everything ourselves. Here are the kinds of services we use and what each receives.
Each provider handles data under its own privacy policy.
Alert emails are sent through a United States email delivery service. Every alert email includes a working unsubscribe link, and unsubscribing stops that alert immediately. The only alert email you receive is the one you set up yourself.
Here is what we and the services we use put in your browser.
There are no advertising cookies and no cross-site ad tracking of any kind.
We do not currently respond to Do Not Track or similar browser signals. If your browser sends one, the site behaves the same as it does for everyone else.
The permits on the map are public government records, and they contain names, addresses, and project details filed with towns and villages. How we present those records, what they do and do not show, and how to raise a concern about a name that appears in them are covered by our Terms and Conditions. If your concern is about a name in the permit records rather than about your account, Section 13 of the Terms is the place to look, and legal@permitplotter.com is still the address to write.
Write to legal@permitplotter.com to:
When you ask us to delete your account information, we delete the account data we hold, delete your identity at our sign-in provider, and ask our analytics and error-tracking providers to delete your identified data. One honest exception: we keep records we need for security, fraud prevention, legal, or audit reasons, and some of our internal logs are append-only by design.
You can also stop any alert email at any time through the unsubscribe link inside it.
If a court order, subpoena, or other legal process requires us to disclose information, we disclose only what it requires.
Access to full permit data requires a credential, and payment details never touch our servers; they go directly to our payment processor. Alert and download links are time limited or revocable. We take reasonable safeguards appropriate to the size of our operation. No online service can promise perfect security, and we do not.
We keep information as long as we need it to run the service. Session replays are deleted by our analytics provider after its standard retention period, and error reports expire at our error-tracking provider on its standard schedule. We review what we hold and delete what we no longer need. Account information can be deleted on request, as described in Section 10, apart from the security and audit records noted there. Our service providers otherwise retain data under their own policies.
The service is not directed to children, and we do not knowingly collect information from anyone under 18. If you tell us we have, we will delete it.
When this policy changes, we post the update at this page with a new effective date, and we keep this policy accurate as our practices change. If a change is material, we post a dated notice on the site for at least 30 days and, once accounts exist, we also email account holders.
Questions, corrections, deletion requests, and concerns all go to legal@permitplotter.com. The inbox is live and monitored.