Privacy Policy
Last updated: September 9, 2026
Who We Are
Low Point Labs (“we”, “us”, “our”) provides Drainage Intelligence Reports™ and related property-analysis tools powered by the LPCA™ methodology. This policy explains the information processed through our public website, invitation and support workflows, customer accounts, and report tools.
Information We Collect
- Invitation, demo, contact, and waitlist information — your name, email address, selected subject, free-text message, and, when provided for a waitlist or coverage request, a property address and coordinates. Contact, invitation, and demo submissions become support records. If you are signed in, a support record may also be associated with your account.
- Account and authentication information — email, name, username, a hashed password, role, password-reset information, account preferences, session records, and a first-party session cookie used to keep you signed in.
- Property, project, and report information — addresses, coordinates, parcel identifiers and geometry, map areas, project names and notes, drawings, structures, terrain and drainage features, report inputs, generated reports, and report status. Address coverage checks also store the address, coordinates, coverage result, and available-dataset details.
- Transaction and entitlement information — historical and current orders, credits, trial or plan tier, subscription status, invoices, amounts, and Stripe customer, checkout, subscription, invoice, and payment identifiers. Payment-card details are collected by Stripe rather than by our forms.
- Communications — support tickets, contact submissions, email replies, and service emails. Authorized staff use these records to evaluate invitation and demo requests, answer questions, fulfill requests, and maintain a support history.
- First-party traffic analytics — pageviews, sample-report opens, and clicks on calls to action; the page path; an external referrer; UTM source, medium, and campaign fields; and the event time. Our server temporarily processes your IP address and browser/user-agent to filter bots, limit abuse, and create a daily pseudonymous visitor identifier. Raw IP addresses and full user-agent strings are not stored in the traffic-event table.
How We Use Information
We use information to review invitation and demo requests, provide customer support, check geographic coverage, create and manage projects, generate and deliver reports, administer trial entitlements and credits, support existing billing relationships, send service communications, measure site performance and acquisition sources, improve the product, secure the Service, and prevent fraud or abuse.
Third-Party Services and Data Sources
We use a provider only when its service is needed for a feature. A provider does not receive every category of information listed above.
- Replit hosts the application and database and stores private report files, so it processes information handled by the Service as our infrastructure provider. Privacy
- Mapbox receives an address or city search when you use our geocoding features. Our server also requests map imagery from Mapbox using map-tile coordinates; the tile request does not include the typed address. Privacy
- Regrid receives address-search text for suggestions and parcel identifiers, polygons, or map areas for parcel and building lookup. Returned parcel information may include an address, owner information, geometry, and other public-record attributes used in a saved project. Privacy
- Anthropic receives the structured site inventory used to produce an AI-assisted report narrative and annotations. Depending on the project, that inventory can contain a property address, coordinates, parcel and building geometry, terrain and drainage features, climate or soil context, and user drawings. Anthropic also receives administrator-provided topics and related editorial instructions when generating blog drafts. Privacy
- OpenAI is used to generate administrator-requested blog imagery. It receives an image prompt derived from an editorial topic; ordinary visitor contact submissions and the current report-narrative inventory are not sent to OpenAI through that feature. Privacy
- Resend receives recipient email addresses and the content and attachments needed to deliver account, support, order, report, and other service emails. Contact-form content is included in confirmation and staff-notification emails. Privacy
- Stripe handles payment-card entry, historical and existing-customer billing, invoices, and billing-portal access. It may receive your email, our internal customer reference, plan details, and property address or coordinates included in checkout or subscription metadata. Privacy
- Public data sources, which may include USGS, NOAA, FEMA, NWI, and other government or scientific sources, provide terrain, elevation, precipitation, flood, wetland, stream, and related datasets. A geographic area or coordinates may be used to retrieve data relevant to a report.
Cookies and Pseudonymous Analytics
We use a first-party session cookie to keep customers and administrators signed in. Our traffic analytics do not use a third-party analytics cookie or an advertising tracker.
The daily visitor identifier is a shortened cryptographic hash derived from the requesting IP address, browser/user-agent, and current UTC date. Because it is derived from device and network information, it is pseudonymous rather than anonymous. It changes each day and is used for daily visitor counts, visit estimates, bot filtering, and abuse prevention.
Data Retention
- Raw traffic events are retained for 90 days. Events older than 90 days are rolled into daily summaries. Those summaries and their pseudonymous visitor-count records may be retained longer for historical reporting.
- Authentication records include sign-in sessions that expire after 30 days and password-reset tokens that expire after one hour. Expiration prevents future use; an expired database record may remain until routine cleanup.
- Contact, invitation, demo, support, and waitlist records are retained while we evaluate or respond to the request and afterward as needed for support history, suppression of unwanted marketing, recordkeeping, or dispute handling. The application does not currently apply an automatic deletion deadline to these records.
- Address and coverage-search records are retained for coverage operations, service planning, quality review, and support while those features remain active. The application does not currently apply an automatic deletion deadline to coverage-search records.
- Accounts, projects, reports, orders, credits, subscriptions, and billing records are retained while needed to provide the Service and afterward as needed for customer access, accounting, tax, fraud prevention, dispute resolution, security, and other legal obligations. Deleting an account does not necessarily delete historical orders, reports, payment records, or records we must retain.
We may keep a record longer when required by law, needed to establish or defend a claim, or necessary to protect the Service. We may delete records sooner when they are no longer needed.
Your Rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a portable export of your personal information. A signed-in, non-administrator customer can delete the sign-in account from the Dashboard after confirming the account password. That action removes the account, active sessions, and available credits. Historical orders and reports are retained without their account association for recordkeeping and are not removed by the Dashboard action. Dashboard deletion is not a general privacy-request tool and does not delete contact, support, waitlist, analytics, project, or other retained records.
Email support@lowpointlabs.com from the email address associated with your account or submission, describe the records and request, and include enough detail for us to locate the information. We may verify your identity before acting. We will respond within the period required by applicable law. A request may be limited when we must retain transaction, security, tax, legal, or dispute records.
Email Communications
We send service and transactional emails, such as account, support, order, and report messages. If we send marketing or waitlist-announcement emails, the message will identify a way to opt out. We use opt-out requests to suppress future marketing messages, although we may still send necessary service or transactional emails. You may also submit an opt-out request to support@lowpointlabs.com.
Children
The Service is not directed to anyone under 18 and we do not knowingly collect information from children.
International Users
The Service is operated from the United States, and our providers may process information in the United States and other locations where they operate. If you use the Service from another country, your information may be transferred to and processed in those locations.
Security
We use password hashing, authenticated customer and administrative access controls, private storage for report files, and provider-hosted payment-card collection. No security measure is perfect, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.
Changes to This Policy
We may update this Privacy Policy as our practices or legal obligations change. The “Last updated” date shows when the revised policy took effect. When appropriate, we may also provide notice by email or in the Service.
Contact
Privacy questions or requests: support@lowpointlabs.com.