HubPlaces is built with privacy in mind. We collect only what is necessary to provide the service and never sell your data to third parties.
HubPlaces is operated by an individual based in Ireland. For the purposes of the EU General Data Protection Regulation (GDPR) and Irish data protection law, we are the data controller for the personal data we process.
Contact: [YOUR_EMAIL]
| Data | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Email address | Account creation, login, password reset emails | Contract performance |
| Hashed password | Account authentication — your actual password is never stored | Contract performance |
| Subscription status and plan | Determining which features you can access | Contract performance |
| Daily lookup count | Enforcing free tier limits — resets every 24 hours | Contract performance |
| Stripe customer ID | Linking your account to your payment subscription | Contract performance |
| Payment information | Processed directly by Stripe — we never see or store card details | Contract performance |
We do not collect, store, or transmit:
When you type a postcode in HubSpot, the extension sends your query directly to Google Places using your own API key. This request goes from your browser to Google — it does not pass through our servers. We only handle licence verification (checking your plan and usage count) when a lookup is made.
We use the following third-party services:
We retain your account data for as long as your account is active. If you delete your account, your personal data is deleted within 30 days. Usage counters (daily lookup counts) reset automatically every 24 hours. Password reset tokens expire after 1 hour and are deleted after use.
As a data subject under GDPR, you have the right to:
To exercise any of these rights, contact us at [YOUR_EMAIL]. We will respond within 30 days.
You also have the right to lodge a complaint with the Data Protection Commission (Ireland): dataprotection.ie
We take reasonable technical measures to protect your data, including password hashing (bcrypt), encrypted HTTPS connections, and JWT-based authentication with 30-day expiry. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
The HubPlaces website does not use cookies. The Chrome extension uses chrome.storage.sync to store your API key and authentication token locally in your browser — this data is not accessible to us and stays on your device.
HubPlaces is not directed at children under 18. We do not knowingly collect personal data from anyone under 18.
We may update this privacy policy from time to time. We will notify you of significant changes by email. The date at the top of this page indicates when it was last updated.
For any privacy-related questions or to exercise your rights, contact us at: [YOUR_EMAIL]