Privacy Policy
Last updated: June 16, 2026
This Privacy Policy explains how [Company Legal Name] ("we", "us") collects, uses, and shares information in connection with the PUMSdata website and services (the "Service"). It supplements our Terms of Service and Service Agreement. By using the Service, you agree to this Policy.
1. A note on the Census data
The statistics shown in the Service are derived from de-identified, public-domain microdata published by the U.S. Census Bureau (ACS PUMS). It does not identify individuals, and we do not collect personal information about the people represented in that data. Attempting to re-identify any individual is prohibited under our Terms. This Policy concerns the information we collect about you, our user.
2. Information we collect
- Account information — your name, email address, and password. Passwords are managed and stored in hashed form by our authentication provider (Supabase); we never see your plaintext password.
- Content you create — saved maps, segments, comparisons, and preferences.
- Usage & device data — via our analytics provider (PostHog): pages and features used, actions taken, browser/device type, referring pages, and approximate location inferred from IP address.
- Communications — emails you send us and our records of messages we send you.
- Cookies & local storage — see Section 6.
3. How we use information
- Provide, operate, secure, and improve the Service.
- Authenticate you and maintain your session.
- Send transactional messages (confirmations, password resets, important account notices).
- Provide support and respond to inquiries.
- Understand usage through product analytics to improve features.
- Detect, prevent, and address fraud, abuse, and security issues.
- Comply with legal obligations and enforce our agreements.
Where required by law (e.g., GDPR), we rely on these legal bases: performance of our contract with you, our legitimate interests (operating and improving the Service), your consent (e.g., marketing emails, where applicable), and compliance with legal obligations.
4. How we share information
We do not sellyour personal information. We share it only with service providers ("sub-processors") that help us run the Service, under appropriate confidentiality and data-protection obligations:
- Supabase — database, authentication, and storage.
- Mailgun— sending our emails, and measuring what happens to our product-update emails (see "Email tracking" below).
- Zoho — business email / support correspondence.
- PostHog — product analytics.
- Netlify — application hosting and content delivery.
We may also disclose information if required by law or legal process, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets (with notice where required).
5. Data retention
We retain your account and content while your account is active. As described in the Service Agreement, when your account is closed and your access ends, we may deactivate and delete your saved content. We may retain certain records longer where necessary for legal, security, or fraud-prevention purposes.
6. Cookies & tracking
We use strictly necessary cookies/local storage to keep you signed in and remember your preferences. On your first visit we show a cookie banner: choosing "Accept all" lets our analytics provider (PostHog) set cookies that link your visits together over time and to your account; choosing "Reject non-essential" means it sets none, and measurement stays anonymous as described below. You can change your choice anytime via "Cookie settings" in the footer, or through your browser. Disabling essential cookies may break sign-in.
Anonymous measurement without cookies. Whether or not you accept, we count basic usage — pages viewed, how long a visit lasted, rough location by country, device type, and the site that referred you — in a cookieless mode. This stores nothing on your device: no cookie, no local storage, no advertising or persistent identifier. Visits are grouped using a rotating, salted server-side value that cannot be reversed into an identifier for you, is not linked to your account, is never used to recognise you across days, and is never shared with or sold to anyone. Accepting analytics cookies is what lets us connect visits over time and to your account; declining leaves the measurement anonymous and unlinked. We do this because we cannot otherwise tell how many people the site reaches or which pages are failing them.
Separately, and regardless of your banner choice, we set one small first-party cookie (pd_ft, 30 days) recording the page you first landed on and the site that referred you. We are explicit that this one is not covered by the choice above: the anonymous measurement described earlier deliberately cannot connect a visit to a signup days later, so this cookie is the only way we can tell which of our pages actually bring in the people who create accounts. It stays on your device only; it is never shared with or sent to any third party, is never used to follow you across other sites, and is read only if you create an account. If you never sign up, it is never read and simply expires.
Email tracking. If you receive our product-update emails, we measure whether each one was delivered, whether it was opened, and which links you clicked. Opens are detected with a small invisible image; links are routed through Mailgun so we can see which one you followed. We store the event, its time, and a broad device type (desktop, mobile, tablet) — not your IP address, location, or browser details. Open counts are unreliable and we treat them as such: mail apps like Apple Mail and Gmail may load that image for you or block it entirely, so an open can be both missed and over-counted. Unsubscribing stops this along with the emails.
Account and security emails are never tracked.Verification, password-reset, and receipt emails carry no tracking image and no rewritten links. This is deliberate: we will not route a single-use sign-in or reset link through a third party's redirector, because anything that follows the link — including automated corporate email scanners — can consume it before you do.
7. Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit (HTTPS), hashed passwords, access controls, and reputable infrastructure providers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your rights & choices
- Access, correction, deletion, portability — depending on your location (e.g., GDPR/UK GDPR, California CCPA/CPRA), you may request to access, correct, delete, or export your personal information.
- Marketing opt-out — you can opt out of non-essential/marketing emails via the unsubscribe link or your account settings. We will still send essential transactional and account messages.
- Export your data — you can export your saved content before canceling.
To exercise these rights, contact help@pumsdata.com. We will respond as required by applicable law. We will not discriminate against you for exercising your rights.
9. International users
We operate in the United States, and your information may be processed in the U.S. and other countries where our sub-processors operate. Where required, we use appropriate safeguards for international transfers.
10. Children
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the date above and, where appropriate, by additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
12. Contact
Privacy questions or requests: help@pumsdata.com. Mailing address: [Company Legal Name], [Mailing Address].