Privacy notice
Last updated: August 27, 2026
Website analytics
This site uses Cloudflare Web Analytics to understand aggregate page traffic and site performance. Cloudflare hosts and secures the Pages website and may process ordinary request information needed to deliver and protect it.
Support correspondence
When you email support, we receive the contact information and content you send. We use it to respond, reproduce product issues, maintain service records, and protect the service. Do not send passwords, API tokens, payment-card data, or other secrets.
STR AI guide
The STR page identifies the assistant as CivicDataForge AI. After you affirm AI processing, your question is sent through our Cloudflare-hosted service to Cloudflare Workers AI to generate a reply. The guide answers questions about our service and coverage; it does not perform live property checks, make legal determinations, submit messages, connect accounts or take payment. AI answers can contain errors. Our application does not store chat transcripts or send them to marketing analytics. The page holds the visible conversation in memory until you reload or leave. Cloudflare processes requests under its Workers AI data-usage terms and privacy policies. Do not send credentials, guest data, financial information or sensitive personal details.
To control abuse and cost, we store daily request counts under an HMAC-derived, daily-changing identifier based on the network IP supplied by Cloudflare. We do not store the raw IP in this application table. The counter records expire after two days and are removed as requests are processed. The STR landing page does not load advertising pixels or send chat/form content to our conversion analytics.
STR messages and coverage requests
The separate request form collects your email, requested location, message and explicit permission to contact you about that request. Submission is optional and is not consent to marketing. We store the submitted fields, receipt ID, payload fingerprint and timestamps in a private Cloudflare D1 inbox accessible through our authorized operations account. A successful receipt means the message was stored, not that a person has read it or a city will be added. Chat transcripts are not automatically attached. Request records have a 90-day expiry and expired records are removed when the request service processes traffic or the team performs inbox maintenance. Support correspondence or subsequent customer records may be retained separately to handle the relationship and applicable obligations. Contact the address below for access, correction or deletion requests.
Airbnb listing connection through Hospitable
Account linking is optional. With your explicit consent, we send your name, email and a random customer identifier to Hospitable Connect. Your email is contact information, not proof of identity or a way to recover another connection. You authorize Airbnb access on the provider’s own page; CivicDataForge does not collect your password. We retain a limited projection of listing identifiers, property details, addresses, channel identifiers and signed-event receipts in private Cloudflare D1 storage. This flow does not request reservations, guest messages or payment details. Other unsolicited event bodies are not retained by our webhook handler.
An essential Secure, HttpOnly cookie permits access to your private connection status and received listing addresses for up to 30 days. Its random secret is hashed in our database. An existing browser can explicitly issue a one-use, ten-minute code for up to five additional browsers; only hashes of access codes and device secrets are retained. A short-lived HttpOnly receiving-browser cookie allows the same browser to retry a lost acknowledgement without issuing another connection. Added browsers expire no later than the original session. Session contact details expire after 30 days and expired session records are removed when the service processes requests. Rate-limit counters use an HMAC-derived, hourly-changing network identifier, not a stored raw IP, and expire after two hours.
The connection page separately offers revocation of all local browser access or deletion of our local connection data. Deletion removes the connection profile, listing details and retained event bodies, and retains minimal hashed-capability, customer/listing-identifier and event-hash/timestamp receipts to suppress later imports and prevent replay. It does not delete paid orders, evidence packets, billing records or separately retained support correspondence. Neither local action disconnects Airbnb/Hospitable or cancels a subscription. Closing a browser does not revoke provider access. If no authorized browser remains, contact us for ownership-verified recovery or provider disconnection assistance; never send passwords or one-use access codes. No marketing subscription or payment is created by linking.
Private STR intake and monitoring
The paid STR intake collects up to 25 property addresses and a selected jurisdiction before checkout. These inputs are stored privately in Cloudflare D1 and processed by our Apify evidence service. For Chicago, normalized building addresses are also queried against the City of Chicago public building-violations API; they are not sent to website analytics. The private results link acts as an access credential: keep it private. We retain the evidence packet to deliver and support the order. For monitoring, we retain the fixed address list and check history while providing the service, and remove those monitoring inputs and history after 90 days without a paid service period. Billing identifiers and transaction records may be retained separately for accounting, disputes and support. You may request deletion using our support address.
After a paid property delivery, you may optionally submit normalized caller-authorized market facts or owner/authorized-operator financial records to the private property-composition route. Each input binds to an exact delivered property ID. The service processes these inputs in memory to produce a new response marked persisted:false; it does not rewrite the stored paid packet or silently reapply the inputs during monitoring. Do not send provider credentials, bank-account details, guest data, full tax returns, Social Security numbers or other secrets. Credential-shaped fields and credential-bearing source URLs are rejected. Downloaded composed records remain private files under your control.
Legacy evaluation request form
The Permit Match Audit request uses Google Forms to collect a manually entered email address, company or organization, requested geography, approximate portfolio size, workflow, evaluation condition, commercial-path preference, and responsible-use confirmation. Google processes the form under its own privacy terms. CivicDataForge uses the response to qualify and fulfill the request, maintain business records, and prevent repeated free-audit abuse. Do not submit property addresses, passwords, API tokens, payment-card data, or sensitive personal data through the initial form.
Measurement and attribution
Cloudflare Web Analytics measures page traffic and performance without cookies, local storage, cross-site identity, or personal-data collection. CivicDataForge also sends minimized, same-origin funnel events to a private Cloudflare Analytics Engine dataset so we can distinguish page views, commercial-route opens, checkout intent, contact intent, marketplace opens, and agent-integration opens. These records contain the page path, campaign labels, referrer hostname, coarse country code, product/funnel label, and hashed ephemeral page and checkout references. They do not contain raw IP addresses, full referrer URLs, user-agent strings, names, email addresses, phone numbers, property addresses, payment credentials, or device fingerprints.
X marketing measurement is disabled by default. The X Pixel is loaded only after a visitor selects Allow marketing measurement. Visitors can keep essential-only measurement or change that choice through the persistent Privacy choices control. X may then use cookies or similar identifiers for conversion measurement and interest-based advertising under its own notice and opt-out controls. CivicDataForge sends X a checkout-intent event only; it does not send contact fields or sensitive public-record queries, and it does not label checkout intent as a purchase.
Stripe receives supported UTM campaign fields and an anonymous client_reference_id containing only campaign, product, and random click labels. Confirmed revenue is reported only from Stripe or another payment provider, never inferred from a click.
Direct payments and subscriptions
Stripe hosts CivicDataForge checkout and billing-management pages. Stripe processes payment credentials under its own privacy notice; CivicDataForge does not receive complete card numbers. CivicDataForge may receive customer contact details, business name, payment status, subscription status, invoice records, and transaction identifiers needed to fulfill purchases, provide support, prevent fraud, and maintain business records.
Marketplace transactions
Apify and AWS Marketplace operate their respective accounts, billing, access controls, and transaction systems under their own notices and terms. CivicDataForge may receive the customer, entitlement, usage, or support information those platforms make available to a seller or provider.
AWS Government Evidence Gateway
Activation collects your service email, AWS account and license identifiers, access state and a non-reversible keyed hash of your API credential. The credential is revealed once. The account console uses the credential over HTTPS and does not store it in browser storage. Request records include an idempotency identifier, input hash, response, source tool, timestamps and success/failure state so we can deliver results, recover identical retries and reconcile billing. Do not send private personal information or credentials as evidence queries.
The gateway uses AWS for Marketplace registration and billing integration, Cloudflare for the application and account database, and Apify for the supported source-processing requests. Query inputs go to the processing services needed to answer them; activation email is not included in source-tool queries. Our support email is hosted by Google. We do not use activation emails for marketing or sell them. These services handle information under their respective terms. Contact us for data-access, deletion, retention or backup questions and for security incident reports. Billing and legally required records may need to be retained after service ends. We will notify affected customers of relevant security incidents through their service contact.
Hostex read-only import
If you choose the Hostex import on the permit-audit page, the access token you enter is used ephemerally by our server to request your property list from Hostex. CivicDataForge does not intentionally store the token in its fulfillment database, return it in the response, place it in a URL, or send it to analytics. Normal infrastructure security and abuse logs may record request metadata, but the application does not log the request body. The normalized property response is displayed in your browser so you can choose and review addresses; only addresses you submit through the separate permit intake are stored behind an opaque intake reference.
Product data
For the AWS gateway, service contact data and stored responses are deleted within 30 days of a verified deletion request or a determination that they are no longer needed. Minimal legally required billing records and at least one year of security audit records are retained separately. The account database uses Cloudflare D1's automatic point-in-time recovery; backup history ages out within a window of no more than 30 days. A recovery must reapply completed deletion requests before customer access resumes. Security logging records credential lifecycle, successful authenticated access and license-state changes without recording raw credentials or service emails in that log. Access to database administration is restricted to authorized operators; this is not a claim that an administrator cannot alter the infrastructure.
CivicDataForge products transform records made available by the identified government publishers. Product documentation describes the included fields and intentionally removed personal contact fields. Public-record status does not remove the customer's obligation to use the data lawfully.
Questions and requests
Contact civicdataforgehq@gmail.com for a privacy question concerning CivicDataForge or visit Customer Support.