Privacy Policy

Last updated: July 12, 2026

This policy describes how Ammasa ("we", "us") handles information in connection with the Ammasa website and property-data API (the "Service"). The Service is business-to-business infrastructure: our product data is about properties and places, not about identified individuals.

1. Information we collect

Account and contact data — name, work email, company, and billing details you provide when requesting access, a quote, or support. API usage data — request metadata (endpoint, key, timestamp, volume, response status and the queried address) collected to operate, meter, bill, rate-limit and secure the API. Website data — standard server logs (IP address, user agent, pages viewed). Your basket on the Services page is stored locally in your browser (localStorage) and is not transmitted to us until you request a quote.

2. What we do not do

We do not sell personal information. We do not use advertising trackers. We do not build profiles of consumers, and we do not offer the Service for making eligibility decisions about individuals (see our Terms — the Service is not for FCRA-regulated uses).

3. How we use information

To provide and secure the Service; to meter usage and invoice customers; to respond to inquiries and provide support; to monitor abuse, enforce rate limits and our Terms; to improve coverage and reliability; and to comply with legal obligations.

4. Sharing

We share information only with service providers that help us run the Service (e.g., hosting, payment processing, email), under contracts limiting their use of it; with professional advisers; and when required by law or to protect our rights. If Ammasa is involved in a merger or acquisition, information may transfer as part of that transaction under equivalent protections.

5. Data about properties

The property-level data returned by the API is aggregated from public government records and licensed commercial sources. It describes parcels, buildings, environmental conditions and localities. If you believe a record contains personal information that should not be there, contact us and we will review it.

6. Retention and security

Account data is retained for the life of the relationship and as required for tax and accounting. API request logs are retained for metering, billing and security purposes and then aggregated or deleted. We use encryption in transit (HTTPS everywhere), hashed API keys at rest, and least-privilege access internally.

7. Your rights

Depending on where you are located (including under the California Consumer Privacy Act and, where applicable, the GDPR), you may have rights to access, correct, delete, or port personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, email privacy@ammasa.com. We will verify and respond within the time required by applicable law. We do not discriminate against you for exercising privacy rights.

8. Cookies

The website uses only functional storage: your theme preference and services basket are kept in your browser's localStorage. We do not set third-party advertising or analytics cookies.

9. Children

The Service is for businesses and is not directed to children under 16.

10. Changes and contact

We may update this policy by posting a revised version with a new "Last updated" date. Questions: privacy@ammasa.com.