The short version
- We collect your email address, a record of the markets you scan, and a record of what you bought. That is close to all of it.
- Analytics and advertising measurement run only if you allow them in the cookie banner. Say no and no measurement cookie is set.
- We never see your card number. Our payment processor handles that.
- We do not sell your personal information.
- Ask us to delete your account and we delete it, along with your scan history.
1. Who this covers
This policy explains how TamLens ("we", "us") handles personal information on the tamlens.com website and in the TamLens application at app.tamlens.com. It applies to visitors, to people who create an account, and to customers.
TamLens is a market research tool for businesses. It is aimed at business owners and operators, not at consumers, and it is not directed at children.
2. What we collect
Information you give us
- Your email address, when you create an account. There is no password to store: you sign in either with a one-time link sent to your email or with your Google account.
- Basic profile details from Google, if you choose to sign in that way. See section 3.
- What you scan. Each scan records the industry and the city, or the street address if you scanned a specific site, along with the time and whether it was a free scan or a full one. We keep this so we can serve your report back to you and so your history is there when you return.
- Anything you send us through the contact form or by email.
Information created by using the service
- A credit ledger. An append-only record of credits granted, purchased, spent on a scan and refunded, so your balance is always auditable.
- Purchase records. Which pack you bought, the amount, the currency, the date and the reference numbers our payment processor gives us. Card numbers never reach our systems.
- A one-way hash of your network address. Free scans cost us real money to run, so they are capped at a few per day per connection. To do that without keeping your address, we store a salted, irreversible hash of it on the scan record. It is enough to tell that two free scans came from the same connection. It cannot be turned back into an address and we do not use it to identify you.
- Standard server logs kept by our hosting provider, of the kind every website generates.
- How you use the site, if you allow it. With your consent in the cookie banner, we record events such as which pages you view, what you click, and what you enter into forms on this site, so we can see where the site works and where it loses people. This is described fully in section 8.
A note on addresses you type in
If you scan a specific street address, that address is stored as part of the scan record. Treat it the way you would treat anything you type into a business tool, and do not enter an address you would not want stored under your account.
3. Signing in with Google
If you use "Continue with Google", we ask Google only for your name, your email address and your profile picture. We do not ask for, and cannot see, your Gmail, your Drive, your Calendar, your contacts or anything else in your Google account.
We use those details for one purpose: to create and secure your TamLens account. We do not transfer them to anyone else except as described in section 6, we do not use them for advertising, and we do not use them to build a profile of you. You can disconnect TamLens at any time from your Google account permissions page.
4. What we do not collect
- No measurement of any kind before you have made a choice in the cookie banner, and none afterwards beyond what you allowed.
- No pixels from social networks.
- Nothing bought from data brokers about you.
- No card numbers, bank details or government identifiers.
- No precise device location. Map results come from the city or address you type in, not from your device.
5. How we use it
- To run the scans you ask for and to serve your reports and maps back to you.
- To keep an accurate credit balance and to return a credit automatically when a scan fails.
- To take payment and to send receipts.
- To stop abuse of the free tier, which is the only reason the hashed network address exists.
- To answer your questions and provide support.
- To understand how the site is used and whether our advertising works, only with your consent.
- To keep the service secure, and to meet our tax, accounting and legal obligations.
- To send you occasional messages about the service itself, such as a change to these terms or a problem with your account. We do not add you to a marketing list because you signed up.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share only what is needed with the companies that run parts of the service for us, and only so they can perform that work:
- Stripe, our payment processor. You enter your card details on their systems, not ours. Their handling of that data is governed by their own privacy policy.
- Google, in three ways. If you choose to sign in with your Google account. To serve the web font used on this site, where a font request tells Google your network address, as any request to any server does. And through Google Tag Manager, which runs our analytics and advertising measurement, but only measures anything after you allow it in the cookie banner.
- Mapbox, which serves the map tiles and address lookup in the application.
- Our hosting and database providers, who store the data described above on our instructions and are not permitted to use it for their own purposes.
We may also disclose information if the law requires it, or to protect our rights, our users or the security of the service. If TamLens is ever sold or merged, account data would transfer with the business, and we would say so here first.
7. Where the market data comes from
Reports are built from public and licensed market data, not from other users. The population, income, housing, hazard, health, crime, traffic and business figures in a report come from sources such as the U.S. Census Bureau, FEMA, the Centers for Disease Control and Prevention, the FBI's Uniform Crime Reporting program, the U.S. Department of Transportation, federal provider registries, live search data and Google Trends. Your scans are never pooled into anyone else's report, and we do not publish or sell what you searched for.
8. Cookies and site measurement
On your first visit, a banner asks what you will allow. Nothing measurable runs before you answer, and your answer is remembered in your browser. There are three categories:
- Necessary - always on. The application sets a session cookie so that you stay signed in, and this site stores your cookie choice itself. Without these there is no way to know the browser is yours or what you chose.
- Analytics - only if you allow it. We use Google Tag Manager and analytics cookies to see which pages are viewed, what is clicked, and what is entered into forms on this site. We use this to improve the site, not to build an advertising profile of you.
- Advertising - only if you allow it. Advertising cookies let us measure whether the ads we run actually brought anyone here. Decline this and our ads simply go unmeasured.
Change your mind any time with the Cookie settings link in the footer of every page. Declining costs you nothing: every part of the site and the application works identically either way.
One caution that is on us to state plainly: if you allowed analytics, text you type into forms on this site is part of what is measured. Our contact form asks for your name, email and message, so treat the analytics choice as covering those too. Passwords are never captured; the application at app.tamlens.com contains no measurement at all.
You can also clear or block cookies in your browser. Blocking the session cookie will sign you out and keep you out.
9. How long we keep it
- Account and scan records: for as long as your account exists. Your scan history is part of what you paid for, so we do not quietly expire it.
- Credit ledger: for as long as your account exists, because it is the record of what you are owed.
- Purchase records: up to seven years after the purchase, to satisfy tax and accounting rules. This is the one category that survives account deletion, and it is kept in the narrowest form we can.
- Hashed network addresses: stored with the scan record. Only the last twenty four hours are ever looked at.
- Support email: as long as it is useful for support, then deleted.
10. Your choices and your rights
Whatever state or country you are in, we will honor these requests:
- See what we hold. Ask and we will send you your account record, scan history, ledger and purchases.
- Correct it. Tell us what is wrong and we will fix it.
- Delete it. Ask us to close your account and we delete your profile, scan history and ledger. Purchase records are kept only as section 9 describes. Unspent credits are forfeited on deletion, so spend them or ask about a refund first.
- Take it with you. We will export your data in a machine-readable file.
- Opt out. Analytics and advertising measurement are off unless you turned them on, and the Cookie settings link in the footer turns them back off. Service emails you can reply to and ask us to stop, except the ones we are legally required to send.
Email [email protected] to make any of these requests. We will verify that the request comes from the account's email address, answer within thirty days, and never charge you or treat you differently for asking.
If you are in California
The rights above cover the access, deletion, correction and portability rights under the California Consumer Privacy Act. We do not sell personal information. Allowing advertising cookies may count as "sharing" for cross-context behavioral advertising under California law; the cookie banner is how you opt in, and the Cookie settings link in the footer is how you opt out, which satisfies the CCPA's opt-out right. We do not use sensitive personal information for any purpose beyond providing the service. You may use an authorized agent, and you will not be discriminated against for exercising any of this.
If you are outside the United States
TamLens is operated from the United States and your information is stored and processed there, which may not offer the same protections as your home country. Where the law requires a legal basis, ours is: performing our contract with you, for running your account and your scans; our legitimate interest in a secure service that is not being abused; your consent, where you gave it; and our legal obligations, for the financial records.
11. Security
The site and application are served over HTTPS. Access to your rows in our database is enforced at the database level, not just in the application, so one account cannot read another's data. We do not store passwords, because there are none, and we never touch card numbers. No system is perfect, and we will tell you promptly if a breach affects your information.
12. Children
TamLens is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, email us and we will remove it.
13. Changes to this policy
If we change this policy we will update the date at the top. If a change is significant, we will email account holders before it takes effect. Continuing to use TamLens after that means you accept the updated policy.
14. Contact
Questions, requests or complaints: [email protected]. A person reads it and you will hear back within a day.
See also our Terms of Service.