Data handling
Privacy notice
A plain-language account of the limited contact, key and request-log information this early-stage service processes.
Last updated August 9, 2026
01
Scope
This notice explains information processed when you visit Global Property Metrics, create or use an API key, or contact the operator about the service. The project does not currently offer user accounts, paid subscriptions, advertising or consumer profiling.
02
Information handled
- Information you provide when creating a key, such as your name, email, organization and intended use.
- API-key records, including a one-way hash of the key, a short identifying prefix, issue and last-used timestamps, status, tier and configured limits. The service does not need to store the full secret key after issuance.
- Metering records, including the key identifier, endpoint category, time bucket and request count.
- A salted network fingerprint and daily count used to limit automated key creation. The raw address is not stored in the application database.
- Aggregate product-event counts, such as API documentation views and market-search selections. These event rows do not contain user or device identifiers.
- Standard infrastructure logs that a hosting or security provider may process, such as IP address, request time, URL, response status, user agent and diagnostic information.
03
API-log privacy
API logs are used to authenticate requests, enforce quotas, investigate errors and misuse, understand aggregate demand, and protect service availability. Metering is associated with the issued key, so API use is not anonymous to the operator even when the response contains only public data.
Do not place personal, confidential or sensitive information in query parameters, headers other than the authentication credential, or other request fields. API keys are secrets and should be rotated if exposed.
04
Why information is used
- Provide and secure the website and API.
- Create keys, limit automated issuance and communicate about misuse, revocation or material service changes.
- Measure quotas, diagnose failures and maintain reliable official-data publication.
- Comply with legal obligations and enforce the service terms.
06
Retention and security
Daily network-fingerprint issuance buckets older than 30 days are deleted during subsequent issuance activity. Access records, key records and infrastructure logs are kept only as long as reasonably needed for service operation, security, dispute handling and legal obligations, then deleted or aggregated where practical.
Reasonable technical and organizational safeguards are used, but no internet service can guarantee absolute security.
07
Your choices and rights
You may stop using the service at any time and may ask through the direct project contact channel to revoke an API key or raise a privacy request. Depending on where you live, applicable law may provide rights to access, correct, delete, restrict or object to certain processing. Identity may need to be verified before a request is completed.
08
International processing
The service and its providers may process information in more than one country. Any legally required safeguards for cross-border processing will apply. Specific hosting locations and transfer mechanisms will be documented as the production setup is finalized.
09
Changes and contact
This notice may change as the service, providers and legal review mature. The updated date will change when a revision is published. Privacy questions may be raised through the same direct project contact channel through which access to the service was provided; a public privacy desk is not yet available.