LotContext privacy
Privacy
Last updated: September 2, 2026
LotContext stores account email addresses, submitted property searches, generated report snapshots, source-status metadata, and usage events needed to run and improve the product.
Account requests store a normalized email address, an irreversible hash of a single-use setup token, and a 30-minute expiration. No account or password is stored until the recipient opens the email link and completes setup. Expired requests are removed automatically.
Report data is assembled from public NYC datasets. Account data is used to authenticate users, save report history, prevent abuse, understand product usage, and support customer requests.
We use a first-party event ledger and, only after you accept the analytics banner, Google Analytics 4 to measure search outcomes and feature usage. We never send email addresses, names, exact addresses, BBL/BIN values, report identifiers or contents, authentication tokens, or free-text search input to Google Analytics; only coarse, allowlisted event names and categories are sent. LotContext does not use PostHog or any other browser session recording. You can accept, reject, or later change your analytics choice at any time from the banner or account settings; analytics does not load or transmit data until you accept.
Account, verification, sign-in, and support email is sent from lotcontext.com through Resend. Support replies route to a monitored inbox.
Stripe processes paid subscriptions on Stripe-hosted checkout and billing pages. LotContext sends Stripe your account email, an internal account reference, and the plan you selected. If automatic tax is enabled, Stripe also collects the billing name and address needed for tax calculation. LotContext does not receive or store card details. We retain Stripe customer and subscription identifiers plus a minimized event ledger for access, cancellation, dunning, deduplication, and financial reconciliation; the ledger excludes email, name, billing address, tax IDs, and report or property contents.
Secrets and service credentials must be configured through environment variables or deployment secrets. They should never be committed to the repository.
Transactional account messages are separate from product announcements. Creating an account does not add your address to a marketing broadcast list. Questions or requests about your data can be sent through the support page.
Signed-in users can delete their sign-in from Settings after every open subscription is canceled. That action removes credentials, sessions, and alerts, then detaches temporarily retained report, saved-property, and usage history from the deleted identity. The retained history is not accessible to the deleted account or a later account using the same email. Contact support to request a data export or permanent purge of retained account history.