LANDLOOKUP.CAAB · SK · MB · BC

Privacy

Privacy policy

LandLookup is a lookup tool, not a data business. This policy explains exactly what we collect when you use the website, the mobile apps and an account, what we do with it, which other companies touch it, how long we keep it, and how to get it back or delete it. There are no advertising SDKs, we do not sell data, and there is no cross-site tracking.

Last updated: September 4, 2026

The short version

  • Lookups on the website are computed and returned, not logged as a history — unless you are signed in with “Save my recent searches” on.
  • An account stores your email, name, a hashed password (never the password itself) and, if you use them, sign-in provider IDs, two-factor secrets and your saved locations.
  • Payments are handled by Stripe (web) or Apple and Google (apps). We never see card numbers.
  • The website uses cookieless Plausible analytics. The apps use Mixpanel, which does receive the land descriptions you look up, tied to a random install ID — not your name or email.
  • You can export everything or delete your account from Account → Data, any time.

1. Who we are

LandLookup.ca and the LandLookup apps are operated by Pocketknife Apps Inc., based in Alberta, Canada. Questions and requests about your data go to [email protected]. This policy forms part of our terms of service.

2. Lookups

When you search for a land description or a coordinate on the website, the input is sent to our server, which computes the parcel position and returns it. Lookup inputs are processed in memory to produce the result; we do not keep a permanent log of what you searched. The one exception is deliberate and yours to control: if you are signed in and “Save my recent searches” is on, the lookup is added to your recent-searches list (see section 6). In the mobile apps, lookups are computed entirely on the device and never reach our server at all.

3. The daily lookup limit

Free use comes with a limited number of lookups per day. To enforce that, the website sets a signed cookie holding a counter and a date — one for anonymous visitors and one for signed-in free accounts. It contains no searches and no identifier shared with anyone else, and it expires after two days. Pro subscribers are not metered.

4. Your account

Creating an account stores your email address, your name if you give one, whether the email has been verified, and when the account was created and last signed in (and by which method). Passwords are stored only as an argon2id hash; we cannot read them. If you sign in with Google, Apple or Microsoft we store the opaque account identifier that provider gives us — not your password there, and nothing about your activity with them. For Sign in with Apple we also keep an encrypted token whose only use is to revoke the Apple link when you delete your account, as Apple requires. If you turn on two-factor authentication we store the authenticator secret and hashed recovery codes.

5. Sessions and devices

Each sign-in creates a session record holding a hashed token, the IP address and browser or device description it was created from, and when it was created and last used. These power the sessions list in Security settings (so you can sign out a device you don’t recognise), the limit on how many devices can be signed in at once, and detection of stolen tokens. Sessions expire 30 days after they were last refreshed; signed-out or expired ones are deleted within seven days. In your browser, the website keeps a refresh token in local storage if you chose “Remember me”, plus two small non-identifying flags (a cached navigation state and a sign-out reason) that contain no personal data.

6. Saved locations, notes and recent searches

Favourites, the notes you attach to them and your recent searches are stored with your account, along with a snapshot of each result (description, coordinates, outline, municipality) so your lists render without re-running lookups. Recent searches are recorded only while “Save my recent searches” is on in Profile settings, are capped at the most recent 100, and can be cleared at any time. Notes are private to you unless you choose to include one in a share link.

7. Share links

Creating a share link stores a public record of that location — its description, coordinates, outline and municipality, plus the note only if you chose to include it. Anyone who has the link can open it; treat a shared note as public. We record which account created a link, but that is never shown to people who open it. Share links do not currently expire; email us if you want one removed.

8. Organizations

If you belong to an organization, its other members can see your name, email address and role. Inviting someone stores their email address and sends them an invitation email; the invitation is revoked if it is not accepted or if the inviter’s account is deleted. Owners and admins can see the organization’s billing status but not members’ personal payment details, which we never hold in the first place.

9. Payments

Web subscriptions are sold and processed by Stripe as merchant of record. Your card details go directly to Stripe and never touch our servers; we store only a Stripe customer reference and your subscription’s status and billing period, and Stripe shares transaction records with us so we can show your billing history. Purchases in the apps go through Apple’s App Store or Google Play. If you link such a purchase to an account, we receive a transaction identifier and receipt data from Apple or Google to validate it and attach Pro to your account — again, no payment details.

10. Emails we send

We send transactional email only — verifying your address, resetting your password, confirming an email change, security notices (for example when a password is set or two-factor changes), organization invitations and notices, and billing-related messages. There is no newsletter and no marketing email. These are delivered through Postmark, which processes your address and the message contents in order to send them.

11. Analytics

The website uses Plausible, a privacy-first analytics service, to count page views and a handful of product events (such as “a lookup succeeded” and which kind it was). Plausible uses no cookies and no persistent identifiers, doesn’t follow you across sites, and shows us only aggregate numbers. The descriptions and coordinates you look up are never sent to it.

The mobile apps use Mixpanel to understand which features are used. The apps send product events — a lookup was performed (including the land description you entered, its grid system and whether it was found), a favourite was added or removed, the map or directions were opened, the paywall was shown, a purchase succeeded or failed, and account events such as sign-up, sign-in and sign-out with the method used — along with Mixpanel’s automatic events (app opens, sessions, updates) and device information such as model, operating system and app version. These are tied to a random identifier generated for your install, not to your name, email or account ID, which we never send to Mixpanel. Mixpanel derives an approximate (city-level) location from your IP address for its reports. Your GPS position is never sent to Mixpanel. This data is used only to improve the apps and is not shared with advertisers.

12. Reverse geocoding

To label a result with a nearby place name, the server asks OpenStreetMap’s Nominatim service to reverse-geocode the centre point of the parcel in the result. For example, looking up 15-33-20-W4 sends Nominatim the parcel centre 51.830729, -112.757193 — a point in rural Starland County defined by the survey grid, not by you. Your own location is never sent to Nominatim.

13. Map tiles and imagery

Result maps load base-map tiles from OpenFreeMap and imagery tiles from Esri; the apps use the same providers when online. Like any web request, tile requests expose your IP address and the tile coordinates of your map viewport to those services, which operate under their own privacy policies.

14. Server logs

Standard server logs exist for operations — keeping the service up, diagnosing errors and blocking abuse. They include the usual request metadata (IP address, user agent, requested path, timestamp) and are used only for running the service.

15. Your device location

The optional “distance from my location” feature runs entirely in your browser or app: if you grant location permission, your position is used locally to compute distance and bearing to the parcel and never leaves your device. Separately, if you choose to look up a GPS coordinate on the website, that coordinate is sent to our server to compute the result, exactly like a typed land description; in the apps it is computed on the device.

16. Where your data is processed

Our API and database run on DigitalOcean and the website on Render. The other companies that process data on our behalf, each for the purpose described above, are Stripe (payments), Apple and Google (app purchases and sign-in), Microsoft (sign-in), Postmark (email), Plausible (website analytics) and Mixpanel (app analytics), plus the map and geocoding providers named in sections 12 and 13. Some of these process data in the United States. We do not sell personal information and share it only as this policy describes or when the law requires.

17. How long we keep things

  • Account details, saved locations, notes and recent searches: until you delete them or your account.
  • Sessions: 30 days after last use; revoked sessions are purged within seven days.
  • Verification, password-reset and invitation tokens: until used or expired, then deleted.
  • Share links: until removed on request.
  • After account deletion: your personal details are scrubbed immediately and the account is tombstoned so the same email can sign up again. A Stripe customer reference and subscription status are retained, with your name and email removed, so invoice history and tax records stay intact and late payment events resolve correctly.
  • Server logs and analytics: kept only as long as needed for operations and aggregate reporting.

18. Your controls and rights

From your account you can export everything we hold about you as a file (Account → Data), delete your account (same place — it also cancels a web subscription; app-store subscriptions must be cancelled with Apple or Google), turn recent-search history off, review and sign out individual sessions, link or unlink sign-in providers, and change your email or name. Under Canadian privacy law (PIPEDA and its provincial equivalents) you may also ask us to access, correct or delete your personal information, or withdraw consent, by emailing us; we will respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Privacy Commissioner of Canada.

19. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email us and we will delete it.

20. Changes to this policy

When the product changes in a way that affects your data, this page changes with it and the date at the top is updated. For material changes we will also notify account holders by email or within the Service before they take effect.

21. Contact

Questions about this policy: [email protected]. See also how lookups are computed, the iPhone app and Android app, and support.