Our Core Privacy Commitment
Raw address data from every CSV you upload is automatically and permanently deleted from our servers within 24 hours of processing. This is not a policy aspiration — it is a hard automated system-level deletion. We designed GoToAtlas specifically so that we do not need to hold your customers' raw data.
GoToAnalyze operates the GoToAtlas platform at atlas.gotoanalyze.com. This Privacy Policy explains how we collect, use, store, and delete data when you use our service. We are committed to minimising the data we hold and to being transparent about what we do with it.
Account data: When you register, we collect your name and email address. Your password is stored as a one-way bcrypt hash — we cannot recover it.
Billing data: We collect your billing name, billing country, and Indian state code (for GST) when you make a purchase. Payment card details are handled exclusively by Razorpay and are never transmitted to or stored on our servers.
Upload data (temporary): CSV files you upload contain B2B company names and addresses. This raw data is stored only for the duration of processing and the 24-hour export window. See Section 4 for the deletion timeline.
Derived data (retained): After processing, we retain geocoded coordinates (latitude/longitude), industry classification, employee count, revenue tier, and account grade. This derived data contains no raw addresses and is retained to power the territory map and export features.
Usage data: We log server-side events such as API call timestamps and IP addresses for security and fraud prevention. We do not use third-party analytics trackers (e.g. Google Analytics) on the application.
We do not sell, rent, or share your data with third parties for advertising purposes.
This is the most important privacy feature of GoToAtlas and the reason it was built the way it was.
Deletion Timeline
T + 0 hours
CSV uploaded and processed. Raw fields written to the database.
T + ~0 hours
Geocoding runs. Coordinates are derived and stored separately.
T + 24 hours
Automated cleanup job fires. rawAddress, rawCity, rawState are set to empty strings and become unrecoverable.
T + 24 hours+
Only geocoded coordinates and derived intelligence remain. No raw company addresses exist on our servers.
The 24-hour window gives you time to download the enriched export CSV. Once the window closes, the raw data is gone — we cannot recover it even if asked to do so by a court order, because it no longer exists.
Account data (name, email, password hash) is retained for as long as your account is active. You may request deletion at any time (see Section 7).
Billing records (transaction amounts, GST breakdown, Razorpay IDs) are retained for 7 years as required by Indian tax law.
Raw upload data is deleted within 24 hours of upload, as described above.
Derived intelligence (geocodes, segments, territory assignments) is retained until you delete your account.
All data is transmitted over HTTPS (TLS 1.2+). Database access is restricted to the application server via Docker's internal network — PostgreSQL is not exposed to the internet. Passwords are hashed with bcrypt (cost factor 12). Razorpay webhook signatures are verified using HMAC-SHA256 before any webhook is processed.
We conduct no third-party security audits at this time. If you discover a security vulnerability, please report it responsibly to Request@gotoanalyze.com.
Under applicable law (including GDPR where applicable and India's DPDP Act 2023), you have the right to:
To exercise any of these rights, email Request@gotoanalyze.com with "Privacy Request" in the subject line. We will respond within 30 days.
We use the following sub-processors:
For any privacy questions, data requests, or complaints, contact us at: Request@gotoanalyze.com
If you are dissatisfied with our response, you may lodge a complaint with the Data Protection Board of India or your local supervisory authority (for EU residents, the relevant national Data Protection Authority).