Skip to content

Legal

Privacy Policy

Effective Date: 31 August 2026

PermitPal Inc. (“PermitPal”, “we”, “us”, or “our”) is committed to protecting your privacy and handling personal data transparently and responsibly. This Privacy Policy explains how we collect, use, store, and share personal data when you access or use our platform, products, reports, and related services (the “Services”).

This policy is designed to comply with applicable data protection laws.

1. Key Summary

This section provides a high-level overview. You should still read the full policy.

  • We collect limited personal and professional information necessary to deliver our Services.
  • We use your data primarily to provide permitting intelligence, site analysis, and customer support.
  • When you use a connector, API, or AI assistant to access our Services, we record the parameters of each request — including any site coordinates you submit — together with a pseudonymous identifier derived from your network address. Section 4.5 explains this in full.
  • We do not sell your personal data.
  • We may use anonymised and aggregated data to improve our platform and produce market insights.
  • Where you reach us through your own AI assistant, that provider is not our processor and its own privacy policy governs your conversation with it. See Section 6.
  • We implement appropriate technical and organisational security safeguards.
  • You retain full data protection rights under applicable law.

2. Who We Are

  • Legal Entity: PermitPal Inc., a Delaware C-Corporation
  • Registered Address: 2810 N Church St STE 89912, Wilmington, DE, 19802, United States
  • Role: Data Controller

As the data controller, we determine the purposes and means of processing personal data collected through the Platform. For privacy enquiries, you may contact contact@permitpal.ai.

3. Scope of This Policy

This Privacy Policy applies to:

  • Users of the PermitPal platform
  • Customers purchasing permitting due diligence reports
  • Visitors to our website
  • Anyone accessing our Services through an API, a connector, or an AI assistant, including free and beta connectors that require no account and no sign-in

Where this policy refers to a “request”, that includes a call made by an AI assistant or agent on your behalf.

4. What Personal Data We Collect

4.1 When you register, create an account, complete a form, or otherwise interact with us, we may collect information you provide to us.

This may include contact details, professional and organisational information, account information, information about your interests or use of our services, and your marketing and communication preferences.

4.2 Project and Site Information.

To deliver our core Services, we collect:

  • Project site locations
  • Development details you submit (e.g., project type, capacity, or jurisdiction)
  • Documents or data uploaded for analysis

Note: Site data is treated as commercially sensitive and is only used to deliver analytical outputs and platform functionality.

4.3 Technical and Usage Data.

We may automatically collect:

  • IP address
  • Device and browser type
  • Login activity
  • Platform usage metrics
  • Cookie identifiers and analytics data

This helps us maintain platform performance, security, and usability.

4.4 Cookies and Analytics

We use cookies and similar technologies to enable platform functionality and analyse usage patterns. You can manage or disable cookies via your browser settings. Some platform features may not function properly without essential cookies.

Cookies are used on our website and platform. They are not used by our connectors or APIs, which are accessed programmatically and set no cookies.

4.5 Connector, API, and AI Assistant Requests

This section describes what we collect when you access our Services through a connector, an API, or an AI assistant. It applies to free and beta connectors as well as to paid access.

Every request records a single log entry containing:

FieldWhat it is
Tool or endpointWhich capability was called, for example a site lookup
ParametersThe values you sent — including latitude and longitude for a site lookup, and jurisdiction names for a records lookup
Caller identifierA pseudonym derived from your network address (see below)
Access tierWhich plan the request was served under
Client identifierThe software identifier your assistant or client sends, if any
Timing and statusHow long the request took and whether it succeeded
Dataset versionWhich data release answered the request

Site coordinates. A coordinate you submit may identify a parcel you are evaluating. Aggregated over time under one caller identifier, these records can indicate which locations a single party has been interested in. We treat them as commercially sensitive under Section 11 and apply internal access controls accordingly.

How the caller identifier works. We do not store your network address alongside your requests. We combine it with a secret value and store only the resulting hash. Because the secret is not disclosed, the identifier cannot be reversed to a network address by anyone who obtains the logs. It is stable enough to count distinct users and detect misuse, and is a pseudonym rather than a direct identifier.

What we do not collect through a connector. We do not receive your conversation with an AI assistant, your prompts, your name, your email address, or any account identifier, unless you separately provide them. A connector receives only the parameters that a single call carries.

No account is required for free connectors, and we do not attempt to link connector requests to a platform account unless you access the connector using credentials that identify one.

5. How We Use Your Personal Data

We only process personal data where there is a lawful basis under applicable data protection law.

5.1 To Provide and Operate the Services

  • Account creation and administration
  • Delivering site analysis and permitting intelligence reports
  • Processing project and jurisdictional data
  • Providing customer support

5.2 Product Improvement and Analytics

  • Improving platform accuracy and performance
  • Training internal analytical systems using anonymised datasets
  • Generating aggregated market insights and benchmarking reports
  • Understanding which capabilities are used through connectors and APIs, and sizing capacity accordingly

We ensure that any analytics or datasets used for product improvement are anonymised where possible and do not identify individual users or projects. Where we publish or share insights derived from connector and API logs, we do so only in aggregated form that does not identify a caller or a specific site.

5.3 Communications and Marketing

  • Service updates
  • Product announcements
  • Relevant industry insights
  • Customer feedback requests

You may opt out of marketing communications at any time via the unsubscribe link or by emailing contact@permitpal.ai.

5.4 Security, Fraud Prevention, and Platform Integrity

  • Detecting misuse or unauthorised access
  • Protecting intellectual property and confidential data
  • Ensuring platform security and reliability
  • Identifying usage patterns inconsistent with permitted use — for example systematic extraction of a dataset, or attempts to evade usage limits — and suspending access in accordance with our Platform Terms

5.5 Legal and Regulatory Compliance (Legal Obligation)

  • Compliance with applicable laws and regulations
  • Responding to lawful requests from authorities
  • Maintaining business records and audit trails

6. Data Sharing & Transfers

PermitPal provides AI-assisted analysis through its platform and AI assistant (“Clara”).

When you submit prompts, documents, project details, or other inputs to the Services:

  • Your inputs may be processed using third-party artificial intelligence model providers, including large language model APIs
  • These providers act as data processors on our behalf and process data solely to generate analytical outputs requested by you
  • Processing may involve transmitting submitted content to secure external AI infrastructure for analysis and response generation
  • We may use third-party analytics, logging, error monitoring, and session replay tools to help us: diagnose bugs and crashes and understand user journeys and improve usability

We do not intentionally use identifiable customer project data, uploaded documents, or user prompts to train external AI models where API-based processing is used, and we rely on contractual protections provided by our AI service providers.

AI-generated outputs are probabilistic and provided for informational and analytical purposes only. They do not constitute legal, regulatory or investment advice.

AI assistants acting for you. The paragraphs above describe AI providers acting as our processors. The reverse arrangement is different and the distinction matters.

Where you access our Services through an AI assistant, agent, or client application operated by a third party — including but not limited to Anthropic’s Claude and OpenAI’s ChatGPT — that provider is not our processor, and we are not the controller of your conversation with it. Your relationship with that provider is governed by its own terms and privacy policy, which you should review. In that arrangement:

  • we receive only the parameters of each request, not the conversation around it;
  • our response is returned to that provider, which may retain or process it under its own policy; and
  • we have no visibility into, and no control over, what that provider does with the response.

Infrastructure. Our Services run on third-party cloud infrastructure providers, which process data on our behalf as processors under contract. Connector and API logs are stored in cloud infrastructure located in the United States.

Other Service Providers: We may also share personal data with our professional advisors, such as lawyers, accountants, auditors, and insurers, but only if and to the minimum extent needed.

Regulators and Government/Law Enforcement Agencies: We may have to share personal data with these parties where it’s necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party.

No Selling: Rest assured, we do not sell your personal data to third parties.

Finally, we take your right to privacy extremely seriously and we make sure that others do the same. We’ll always ensure that any parties we share your information with also have appropriate safeguards and protections in place.

7. Data Retention

We retain personal data only for as long as necessary to:

  • Deliver the Services
  • Fulfil contractual obligations
  • Comply with legal and regulatory requirements
  • Resolve disputes and enforce agreements

Project and analytical data may be retained in anonymised form for research, benchmarking, and product improvement.

7.1 Connector and API logs

DataRetention
Request logs, including parameters and caller identifier24 months, after which they are deleted
Aggregated, non-identifying usage statisticsRetained indefinitely
Operational logs held by our cloud provider30 days

Deletion at the end of the retention period is automatic.

The aggregated statistics that are retained indefinitely record counts of requests and of distinct callers by month, capability, and jurisdiction. They do not contain the caller identifier and do not contain any coordinates , so they do not preserve what the retention period removes.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Secure cloud infrastructure
  • Access controls and authentication protocols
  • Encryption where appropriate
  • Confidentiality obligations for staff and contractors
  • Secrets used to pseudonymise caller identifiers held in dedicated secret storage, separate from application code

While we take reasonable safeguards, no system can be guaranteed to be completely secure.

9. Your Data Protection Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion (“right to be forgotten”)
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time (where processing is based on consent)

To exercise your rights, contact: contact@permitpal.ai. We will respond in accordance with applicable data protection laws.

9.1 Requests relating to connector and API logs

Because free connector access requires no account, we usually cannot connect a request log to you as an individual — that is the intended effect of the pseudonymisation described in Section 4.5.

To act on a right relating to those records, we would need enough information to identify them, which may include the approximate time of your requests and the network address you used. Where we cannot reliably verify that link, we may be unable to act on the request, and we will tell you so rather than act on an unverified match.

10. U.S. State Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). Residents of certain other U.S. states may have similar rights as described below.

Right to Know: Request details about the personal information we’ve collected about you in the past 12 months, including categories of personal information, categories of sources, purposes, and categories of third parties to whom we disclose it, and (where applicable) the specific pieces of personal information.

Right to Delete: Request deletion of your personal information, subject to certain exceptions.

Right to Correct: Request correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing/Targeted Advertising/Profiling: We do not sell your personal information. If our use of cookies or other online identifiers is considered a “sale,” “sharing,” “targeted advertising,” or profiling in furtherance of decisions that produce legal or similarly significant effects under applicable U.S. state privacy laws, you may opt out by emailing contact@permitpal.ai.

Right to Limit Use of Sensitive Personal Information: If you share sensitive information during conversations with “Clara” (our AI), you may request we limit its use to providing our Services.

Right to Non-Discrimination: We will not discriminate against you for exercising these rights.

How to Exercise Your Rights: To exercise your rights, contact: contact@permitpal.ai. We will respond within 30 days (and may extend as permitted by law). We may need to verify your identity. You may designate an authorised agent to make requests on your behalf. Where required, you may appeal our decision by emailing contact@permitpal.ai with the subject line “Privacy Appeal.” Where required, we also process opt-out preference signals (such as the Global Privacy Control).

11. Confidentiality of Commercial and Site Data

Given the nature of PermitPal’s Services, we recognise that submitted project locations and development data are commercially sensitive.

We treat all such data as confidential and:

  • Use it solely to deliver analytical outputs and platform functionality
  • Do not disclose identifiable project information without permission
  • Apply strict internal access controls

This applies equally to site coordinates and jurisdiction names submitted through a connector or API, whether or not they are associated with an account.

12. Changes to This Policy

We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. Where material changes occur, we will notify users via the Platform or email where appropriate.

The latest version will always be available on our website with the updated effective date.

13. Contact

If you have any questions about this Privacy Policy or how we process your data, please contact:

Email: contact@permitpal.ai
Company: PermitPal Inc.

Platform Terms