Privacy policy
Effective 7 September 2026
This policy explains what personal data Aspen Ridge Capital LLC, an Arizona limited liability company, doing business as Mapford ("we", "us") collects when you visit the Mapford website or use the Mapford service (together, the "Service"), why, and what you can do about it.
Who is responsible. For the personal data described in sections 2 to 4, we are the controller. For personal data an agency enters into the Service about its own clients (section 5), the agency is the controller and we process it on the agency's behalf under a data processing agreement.
Contact. thomas@mapford.com. We have not appointed a representative in the United Kingdom or the European Union.
1. In one paragraph
We collect the minimum an account needs: an email address, a password we store only as a one-way hash, and, if you turn it on, an encrypted authenticator secret. We keep a log of security-relevant actions, with the IP address they came from, for four hundred days. We set one cookie to keep you signed in and a second, five-minute cookie during the second sign-in step. We do not run advertising, we do not sell data, and five companies handle data for us: our host, our database provider, our email provider, and the two providers that carry out the measurements. Everything is stored in the United States.
2. Data we collect from visitors to the public site
Access requests. If you fill in the access-request form we store the name, email address, company and message you enter, the source tag on the link you arrived from (if any), and the time. We use it to reply to you and to record where enquiries come from. Legal basis: our legitimate interest in answering a request you made.
Site analytics. The public marketing pages load Vercel Web Analytics and Vercel Speed Insights, which report page views and page performance to Vercel. Per Vercel's documentation these do not use cookies and do not build a profile of you across sites; we have not independently verified Vercel's implementation. They are not loaded inside the signed-in application or on shared report links. Legal basis: our legitimate interest in knowing which pages are read and whether they load quickly. If a law that applies to you requires consent before these scripts load, we will ask for it before loading them.
Rate limiting. To slow down abuse of the sign-in, access-request, invitation, password-reset and shared-report pages, we count requests per IP address and per email address in ten-minute windows. The identifier is hashed before it is stored, so the counter table cannot be read back as a list of who visited; rows expire with their window. Legal basis: our legitimate interest in protecting the Service.
Shared report links. A shared report is readable by anyone holding its link, without an account. We do not record who opens one beyond the rate-limit counter above.
3. Data we collect from people with accounts
Account record. Your email address, your role, the agency you belong to, and your password stored as an argon2id hash. We never store or log the password itself.
Second sign-in step (optional). If you enrol an authenticator app we store its shared secret encrypted under a key the database does not hold, the time you enrolled, hashes of your eight single-use recovery codes, and the last code step used (to refuse a replayed code). The operator account is required to enrol; agency accounts choose.
Sign-in protection. A count of consecutive failed sign-ins and, after five, a fifteen-minute lock time.
Invitations and password resets. When you are invited we store your email address, the agency and role you are invited to, who invited you and a hash of the invitation token, for the seven days the invitation lasts. When you ask for a password reset we store a hash of the reset token for the sixty minutes it lasts. In both cases only the hash is kept; the link itself exists only in the email and your browser.
API keys. If your agency creates an API key we store a name for it, a one-way hash of the key, who created it, when it was last used and whether it has been revoked. The key itself is shown once and never stored.
Audit log. We keep an append-only record of security-relevant actions: sign-ins and failed sign-ins, password changes, second-step enrolment, invitations, share links created or revoked, API keys created or revoked, settings changes and similar. Each entry records who acted, the action, what it acted on, the time, the IP address the request came from and the browser's user-agent string (truncated). Secrets are stripped before an entry is written. The operator can read this log. It is kept for four hundred days.
Emails we send. We send three kinds of email: an invitation, a password-reset link, and a notice that a month's report is ready. They are sent through Resend (section 7). We log the template name only, never the recipient or the body.
Error reports. The server can send error reports to Sentry, but only if we have configured it to; as of the effective date of this policy it is not configured and no error report leaves the server. If it is turned on, the software is set not to send IP addresses, cookies, headers or request bodies, and a scrubber removes tokens and secrets from what remains. No error reporting runs in your browser.
Legal basis for everything in this section: performing the contract with the agency you work for, and our legitimate interest in keeping accounts secure and keeping a record of who did what.
4. Cookies
We set exactly two cookies, both first-party, both needed for the Service to work. Neither is used for advertising or analytics.
| Cookie | Purpose | Lifetime | Properties |
|---|---|---|---|
placeable_session | Keeps you signed in. Contains a signed token, not your data; it is re-checked against the database on every request that reads your data. | 7 days, refreshed after 24 hours of use; deleted on sign-out | HttpOnly, Secure in production, SameSite=Lax |
placeable_mfa_pending | Carries you from the password step to the authenticator-code step. It cannot be used to reach anything in the Service. | 5 minutes; deleted when the code is entered | HttpOnly, Secure in production, SameSite=Lax |
The cookie names carry the product's earlier working name, Placeable; they are the literal names your browser will show you.
There is no cookie banner because neither of these cookies needs consent: they exist only to keep you signed in. The analytics scripts described in section 2 set no cookie of their own, per Vercel's documentation.
5. Data agencies enter about their clients
An agency using the Service enters the businesses it measures: brand names, competitor names, website domains, prompts, notes and, optionally, a client contact. It may also upload a logo and set a display name for its shared reports. The Service then stores the answers the AI assistants returned, the pages they cited, evidence gathered about those pages, and the statistics built from them.
For this data the agency is the controller and we are the processor. We process it only to provide the Service, under the data processing agreement available on request. If you are a client of an agency and have a question about data an agency holds about you, ask the agency; if a request reaches us directly we will forward it to the agency.
Agencies are asked not to enter special-category personal data; the Service has no use for it.
6. What the measurement itself touches
A measurement sends the agency's prompts (buying questions such as "best X for Y") to AI assistants through the providers in section 7, and stores the answers. The prompts do not normally contain personal data. The answers are public assistant output and may name people who are public figures in a market; we store them as returned.
The Service also fetches the public web pages the assistants cited, to gather evidence for the reachability grade. What is stored about a page is its address, HTTP status, title, visible text and a few derived flags, shared across all customers and expiring after thirty days. This is public web content, not data about our users. The fetcher identifies itself with a standard browser user-agent string.
When an agency uses "suggest prompts", the Service fetches up to six pages of the client's own website, extracts the title, headings and description, and sends that summary to Perplexity to generate candidate prompts. Nothing is stored until the agency saves a prompt set.
7. Who we share data with
We do not sell personal data and we do not share it with advertisers. The following companies process data for us, each under the data protection terms that apply to our account with it:
| Company | What it processes | Where |
|---|---|---|
| Vercel Inc. | Hosts the application: every request passes through it, including cookies in transit. Also provides the site analytics in section 2. | United States |
| Supabase, Inc. | Hosts the database: every record described in this policy. | United States (AWS us-west-2, Oregon) |
| Resend | Delivers the three kinds of email we send: recipient address, subject and body. Never a report or measurement. | United States |
| DataForSEO | Carries out the sampling against ChatGPT, Gemini, Google AI Overviews and Google AI Mode. Receives prompt text; returns answers and citations. No data about our users. | Per its published terms |
| Perplexity AI, Inc. | Queried directly for its own answers and for prompt suggestions. Receives prompt text or a website summary. No data about our users. | United States |
| Sentry (Functional Software, Inc.) | Server error reports, only if configured; not configured as of the effective date of this policy. | United States |
We may also disclose personal data where the law requires it, or to a successor if the business is sold, in which case this policy continues to apply.
8. International transfers
All data is stored in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, your data is transferred to the United States to provide the Service. Where a transfer mechanism is required, the transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where the United Kingdom's rules apply), incorporated into the data processing agreement we sign with each agency, and on the transfer terms of the providers in section 7.
9. How long we keep data
| Data | Retention |
|---|---|
| Account record, agency record, brands, prompts, runs, reports | For as long as the agency's account is active, then deleted within thirty days of a written request or the end of the agreement. There is not yet an automatic deletion schedule; deletion is done by a person on request. |
| Access requests | Until the enquiry is closed; deleted on request at any time. |
| Audit log | Four hundred days. No automatic purge runs yet; the retention is a stated policy, not a timer. |
| Invitations | Seven days, or until accepted. |
| Password-reset tokens | Sixty minutes, or until used. |
| Rate-limit counters | The ten-minute window they belong to; expired rows are pruned opportunistically. |
| Fetched page evidence | Thirty days from the fetch. |
| De-identified measurement corpus | Retained indefinitely, as described in the terms of service. It does not identify a person, an agency or an agency's client. |
Accounts are never hard-deleted while their agency exists; they are deactivated, which stops sign-in and kills the agency's API keys. Deletion of the personal data in the account happens on the request described above.
10. Your rights
If you are in the United Kingdom or the European Economic Area you have the right to ask for access to your personal data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw any consent you have given. You also have the right to complain to your supervisory authority (in the UK, the Information Commissioner's Office).
We are based in Arizona, which has no comprehensive consumer privacy statute in force as of the effective date of this policy. If you live in a state whose privacy law gives you rights over your personal data, you have the rights that law gives you, which typically include access, correction, deletion and a portable copy, and the right not to be treated differently for exercising them. We do not sell personal data and we do not share it for targeted advertising, so there is nothing to opt out of on that score.
To exercise a right, wherever you are, email thomas@mapford.com. We will respond within one month. If your request concerns data an agency entered about you, we will pass it to the agency, who is the controller for it.
11. Security
Passwords are hashed with argon2id. Session cookies are HttpOnly, Secure in production, and re-checked against the database on every request that reads data. Every request for stored data passes through one access-control layer scoped to the signed-in user. Connections to the database use TLS. The database's general-purpose external data interface is disabled and its permissions revoked, and that state is re-checked before every change to the production database. A fuller account, kept current, is on the Service's security page.
12. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email thomas@mapford.com and we will delete it.
13. Changes to this policy
We will post any change here with a new effective date at the top, and for a material change we will email the contact address on each agency's account at least thirty days before it takes effect.