Privacy
Privacy notice
Effective August 23, 2026
Big Map is a beta for exploring public parcel information and organizing private workspace notes. Verified-email signup is active: a successful one-time code creates or returns to a private account, while the public parcel map remains available without signing in.
Information we collect
- Access requests: name, email, organization, role, markets, use case, and referral information you submit.
- Account identity and status: the verified email used to sign in, whether access is active or suspended, and account verification and status timestamps. Big Map uses OpenAuth and Resend to deliver a one-time sign-in code, then preserves that email-scoped identity for the user's private workspace.
- Sign-in security records: short-lived code challenges, rate-limit counters, and security events. Email and request-network identifiers in these records are stored only as SHA-256 hashes; codes, cookies, and provider tokens are not stored there.
- Workspace content: saved parcels, projects, custom categories, notes, contacts, next actions, dates, and links you choose to store.
- Email intake: if you request a personal forwarding address, Big Map receives listing emails you send there, extracts candidate property addresses, and stores them in your review inbox until you accept or reject them. Nothing is added to the map automatically.
- Beta feedback: the category, message, page URL, and account identity associated with feedback you submit.
How we use information
We use it to administer account access, provide and secure the workspace, support users, improve the beta, and investigate reliability or abuse. We do not sell beta user information.
Public parcel information
Parcel boundaries and property attributes originate from public government data sources. Availability and accuracy vary by jurisdiction. Your private workspace fields are stored separately from those public source records.
Service providers and retention
Cloudflare provides application hosting, database, file-storage, and sign-in infrastructure. Resend is the email-delivery provider for OpenAuth and processes users' email addresses to deliver one-time sign-in codes. GitHub supports code deployment. Expired code challenges are removed after a 24-hour diagnostic window, rate-limit counters after two hours, and pseudonymous security events after 30 days as later sign-in activity performs retention cleanup. Legacy access requests, account status, workspace content, and feedback are retained while the beta operates or until they are no longer needed for the purposes above.
Your choices
You can sign out the current browser or use “Sign out everywhere” to revoke every application session for your account. To request access removal or deletion of beta account content, submit a message through the signed-in feedback form.
Changes
The beta will evolve. Material changes to this notice will be posted here with a new effective date.