Legal
Privacy Policy
Last updated 18 July 2026.
This policy explains how Geo-Parity ("we", "us") handles personal data when you use https://geo-parity.com. It is written to comply with the UK GDPR and the Data Protection Act 2018. Geo-Parity is designed to be privacy-first: the calculators run in your browser, and we collect as little as possible.
1. Who we are (data controller)
The data controller is Adam Simmons Spaans (United Kingdom). For any privacy question or to exercise your rights, contact info@geo-parity.com.
Suite 657, 80a Ruskin Avenue, Welling, DA16 3QQ, United Kingdom2. What we collect, why, and our legal basis
a. Tool inputs — not collected
The numbers you type into the calculators (income, savings, itinerary, team timezones,
etc.) are processed in your browser and are not sent to
or stored by us, except when you deliberately call a JSON API endpoint (e.g.
/api/calculate.json), in which case the parameters travel in the request URL
so the result can be computed. Those requests are not tied to your identity.
b. Account data — only if you register
If you create an account, we store your name,
email address, a
securely hashed password (we never store the password
itself), and — if you sign in with Google — the account identifier they return.
We also store session records to keep you signed in. This is handled by the open-source
better-auth library in a Cloudflare D1 database.
Legal basis: performance of a contract (providing the account you asked for).
c. Payment data — only if you buy something
Purchases are processed by Stripe. Your card details go
straight to Stripe and are never seen or stored by us. We
keep only what's needed to know what you've bought: your Stripe customer and subscription
identifiers, the plan and its status, and a record of one-off purchases — linked to your
account. Stripe also collects the billing address and any tax ID it needs to calculate
VAT/GST, and holds your invoices; see
Stripe's privacy policy.
Legal basis: performance of a contract (supplying the plan you bought), and legal
obligation for tax and accounting records.
d. API keys — only if you create one
If you create an API key we store a hash of it (never the
key itself), its short visible prefix, and per-hour request counts used to apply your rate
limit. Anonymous API traffic is counted against your IP address for the same purpose.
Legal basis: performance of a contract, and legitimate interest in protecting the
service from abuse.
e. Analytics — aggregate and cookieless
We may use Cloudflare Web Analytics, which is
privacy-first and cookieless: it records aggregate page
views and performance without setting cookies, without fingerprinting, and without
tracking you across sites.
Legal basis: our legitimate interest in understanding, in aggregate, how the site
is used.
f. Link-click counts
When an outbound affiliate/sponsored link is clicked, the browser sends a minimal
fire-and-forget beacon to our /api/event endpoint recording the link's id and
the page path. It contains no cookies, no user identifier, and is
not stored in a database — it is an aggregate counter written to our server logs.
Legal basis: legitimate interest in measuring, in aggregate, which links are useful.
g. Server logs
Our host records standard technical request data (such as IP address, timestamp, and user
agent) transiently for security and to keep the service running.
Legal basis: legitimate interest in the security and integrity of the service.
3. Cookies & local storage
We use only strictly-necessary and functional storage — there are no advertising or cross-site tracking cookies, so no consent banner is required. Analytics, if enabled, is cookieless.
| Name | Type | Purpose |
|---|---|---|
| better-auth session | Cookie | Keeps you signed in after login. Only set if you have an account. |
theme | Local storage | Remembers your light/dark preference. |
geo-home | Local storage | Remembers your chosen home country and currency so tools default to them. |
4. Who processes your data (sub-processors)
- Cloudflare — hosting, the D1 database that stores accounts, and cookieless analytics.
- Google — only if you choose to sign in with it, to authenticate you.
- Stripe — payment processing, subscription billing, invoicing and tax calculation, only if you buy a plan.
We do not sell your personal data, and we do not share it for advertising.
5. International transfers
Geo-Parity runs on Cloudflare's global edge network, so data may be processed on servers outside the UK. Where that happens, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum / Standard Contractual Clauses.
6. How long we keep it
Account data is kept for as long as your account exists; if you delete your account, it is removed. Sessions expire automatically. Payment and invoice records are kept by Stripe and by us for as long as tax and accounting law requires, even after an account is deleted. Rate-limit counters are discarded within a few hours. Aggregate analytics and log data are retained only for a limited period in line with our host's defaults.
7. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing;
- data portability; and
- withdraw consent where processing relies on it.
To exercise any of these, email info@geo-parity.com. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO).
8. Children
Geo-Parity is not directed at children under 13, and we do not knowingly collect their data.
9. Changes
We may update this policy; material changes will be reflected by the "last updated" date above. Continued use after an update means you accept the revised policy.
Related: Terms of Use · Affiliate & Sponsorship Disclosure · About.