← Back to GoToAtlas

Legal

Privacy Policy

Effective date: April 5, 2026 · Last updated: April 5, 2026

Our Core Privacy Commitment

Raw address data from every CSV you upload is automatically and permanently deleted from our servers within 24 hours of processing. This is not a policy aspiration — it is a hard automated system-level deletion. We designed GoToAtlas specifically so that we do not need to hold your customers' raw data.

1. Who We Are

GoToAnalyze operates the GoToAtlas platform at atlas.gotoanalyze.com. This Privacy Policy explains how we collect, use, store, and delete data when you use our service. We are committed to minimising the data we hold and to being transparent about what we do with it.

2. Data We Collect

Account data: When you register, we collect your name and email address. Your password is stored as a one-way bcrypt hash — we cannot recover it.

Billing data: We collect your billing name, billing country, and Indian state code (for GST) when you make a purchase. Payment card details are handled exclusively by Razorpay and are never transmitted to or stored on our servers.

Upload data (temporary): CSV files you upload contain B2B company names and addresses. This raw data is stored only for the duration of processing and the 24-hour export window. See Section 4 for the deletion timeline.

Derived data (retained): After processing, we retain geocoded coordinates (latitude/longitude), industry classification, employee count, revenue tier, and account grade. This derived data contains no raw addresses and is retained to power the territory map and export features.

Usage data: We log server-side events such as API call timestamps and IP addresses for security and fraud prevention. We do not use third-party analytics trackers (e.g. Google Analytics) on the application.

3. How We Use Your Data

  • To authenticate you and operate your account
  • To process CRM uploads and generate territory intelligence maps
  • To calculate applicable GST on Indian transactions and generate receipts
  • To send transactional emails (receipts, welcome messages) — no marketing without consent
  • To detect and prevent fraud and abuse
  • To respond to support inquiries you initiate

We do not sell, rent, or share your data with third parties for advertising purposes.

4. Raw Data Deletion — The 24-Hour TTL

This is the most important privacy feature of GoToAtlas and the reason it was built the way it was.

Deletion Timeline

T + 0 hours

CSV uploaded and processed. Raw fields written to the database.

T + ~0 hours

Geocoding runs. Coordinates are derived and stored separately.

T + 24 hours

Automated cleanup job fires. rawAddress, rawCity, rawState are set to empty strings and become unrecoverable.

T + 24 hours+

Only geocoded coordinates and derived intelligence remain. No raw company addresses exist on our servers.

The 24-hour window gives you time to download the enriched export CSV. Once the window closes, the raw data is gone — we cannot recover it even if asked to do so by a court order, because it no longer exists.

5. Data Retention

Account data (name, email, password hash) is retained for as long as your account is active. You may request deletion at any time (see Section 7).

Billing records (transaction amounts, GST breakdown, Razorpay IDs) are retained for 7 years as required by Indian tax law.

Raw upload data is deleted within 24 hours of upload, as described above.

Derived intelligence (geocodes, segments, territory assignments) is retained until you delete your account.

6. Security

All data is transmitted over HTTPS (TLS 1.2+). Database access is restricted to the application server via Docker's internal network — PostgreSQL is not exposed to the internet. Passwords are hashed with bcrypt (cost factor 12). Razorpay webhook signatures are verified using HMAC-SHA256 before any webhook is processed.

We conduct no third-party security audits at this time. If you discover a security vulnerability, please report it responsibly to Request@gotoanalyze.com.

7. Your Rights

Under applicable law (including GDPR where applicable and India's DPDP Act 2023), you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — request account deletion; we will remove all data except billing records required by law
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing for purposes other than those described here

To exercise any of these rights, email Request@gotoanalyze.com with "Privacy Request" in the subject line. We will respond within 30 days.

8. Third-Party Services

We use the following sub-processors:

  • Razorpay — payment processing (India). Subject to Razorpay's Privacy Policy.
  • Resend — transactional email delivery. We transmit your email address to send receipts and account emails.
  • Hetzner Cloud — cloud hosting (EU datacentres). Your data is physically hosted on Hetzner servers.
  • GeoNames — postal code geocoding database, used offline (no data sent externally during geocoding).

9. Contact & Complaints

For any privacy questions, data requests, or complaints, contact us at: Request@gotoanalyze.com

If you are dissatisfied with our response, you may lodge a complaint with the Data Protection Board of India or your local supervisory authority (for EU residents, the relevant national Data Protection Authority).