Privacy Policy
Last updated 5 September 2026
This policy explains what Ingress3D collects, why, who else sees it, and what you can ask us to do about it. It covers our website at ingress3d.com, the client portal, and the interactive homesite maps we build and host for our clients.
- 1. Who we are
- 2. Two kinds of people
- 3. What we collect
- 4. Cookies and tracking
- 5. How we use it
- 6. Who else sees it
- 7. Where it is processed
- 8. How long we keep it
- 9. How we protect it
- 10. Your rights
- 11. Do Not Track
- 12. Children
- 13. Other sites
- 14. Changes
- 15. Contact
1. Who we are
Ingress3D operates from 545 N McClurg Ct #2620, Chicago, IL 60611, USA. We build interactive homesite maps for residential and land developments, and we host a portal where our clients manage those maps.
For the purposes of the UK and EU General Data Protection Regulation, we are a controller of the information described in section 3.1 and 3.2, and a processor acting on our clients' instructions for the information described in section 3.3.
2. Two kinds of people
This policy has two audiences and they are treated differently, so it is worth knowing which one you are.
- Our clients. Developers and their sales teams who buy a map from us and sign in to the portal. We decide what to collect about you and this policy governs it.
- People browsing a map. If you are looking at homesites on a developer's website, the map may be one of ours. In that case the developer — not us — decides what happens to your enquiry. We handle it on their behalf, under a contract with them, and their own privacy policy governs what they then do with it. If you want your enquiry deleted, ask them; if you cannot reach them, tell us and we will pass it on.
3. What we collect
3.1 When you use our website
Ordinary request data — IP address, user agent, the pages you asked for and when — processed by our host at the network edge. We use Cloudflare Web Analytics, which is cookieless: it records page views without building a profile of you and without following you to other sites.
3.2 When you deal with us directly
| If you… | We collect | Because |
|---|---|---|
| Sign in to the portal | Name, email address, a hashed password, your role, and a log of what you changed | To give you an account and keep an audit trail of edits to client data |
| Sign in — or try to | Email attempted, IP address, whether it worked, and when | To rate-limit password guessing. Most rows are for addresses that have no account here |
| Book a demo | Name, email, company, phone if you give it, what you wrote, your timezone, and IP address | To hold the appointment, send you a confirmation and calendar invite, and prevent abuse of the form |
| Subscribe to the newsletter | Email, name if you give it, the IP you signed up from, and confirmation status | To send the newsletter and to prove the subscription was genuine, which anti-spam law requires |
| Raise a support ticket | Your name, email and everything in the thread | To answer you and keep a record of what was said |
| Reset your password | A single-use token, stored hashed, that expires | To let you back in without us ever seeing the new password |
We do not take payment card details. Invoicing is handled outside the platform and no card number ever reaches our systems.
3.3 When you use a map we host for a developer
Our maps are embedded on developers' websites. When you use one we may process:
- Your enquiry, if you send one — name, email, phone, your message, and which homesites you were asking about. This goes to the developer's inbox and to their dashboard in our portal.
- Anonymous interaction data, where the developer has bought our Intelligence Layer — which homesites were opened, how long a session lasted, how many enquiries followed. This is counted, not attributed: it tells a developer that lot 14 gets attention, not that you looked at it.
- A bot-protection check on the enquiry form, provided by Cloudflare Turnstile. Turnstile is designed to work without tracking cookies or profiling.
We do not sell any of this, and we do not combine one developer's data with another's.
4. Cookies and tracking
We use one cookie, and only if you sign in to the portal: an encrypted session cookie that keeps you signed in for a week. It is httpOnly, secure, and SameSite=Lax — it cannot be read by scripts and is not sent to other sites.
We run no advertising cookies, no third-party trackers, and no cross-site profiling. Cloudflare may set short-lived cookies for security and bot management on requests that pass through its network.
5. How we use it
- To run the service — accounts, maps, dashboards, enquiries.
- To answer you when you contact us or book a demo.
- To send the newsletter, if you asked for it, until you tell us to stop.
- To keep the service secure — rate limiting, bot protection, audit logs.
- To bill our clients and keep the records our accountants and tax authorities need.
- To understand, in aggregate, how the product is used and where it is failing.
In the UK and EU, our lawful bases are: contract for running accounts and delivering the service; consent for the newsletter, withdrawable at any time; legitimate interests for security, fraud prevention, and product improvement; and legal obligation for tax and accounting records.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law.
6. Who else sees it
Only the companies that make the service work, listed here by name so you can check them yourself:
| Company | What they do | What they get |
|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery, bot protection (Turnstile) and privacy-first web analytics | Requests to our sites and the maps we host, including IP address and user agent, processed at the network edge |
| Supabase, Inc. | Managed PostgreSQL database | Everything stored in the portal: accounts, homesite records, enquiries, tickets, demo bookings, newsletter subscribers |
| Resend (Plus Five Five, Inc.) | Transactional and newsletter email delivery | Recipient name and address, and the content of the message being sent |
Beyond those, we share information: with the developer whose map you used, where you sent them an enquiry; with professional advisers under a duty of confidence; where a law, subpoena or court order requires it; and with a buyer, if the business is ever sold — in which case this policy travels with the data until it is replaced by one no less protective.
7. Where it is processed
Our database and email provider are in the United States. Our host operates a global edge network, so a request may be served from the country you are in. If you are in the UK or EEA, transfers rely on the UK Addendum and the European Commission's Standard Contractual Clauses, which our providers incorporate into their terms.
8. How long we keep it
| What | How long |
|---|---|
| Portal accounts and audit log | For as long as the client is with us, then up to 12 months |
| Enquiries from a map | Controlled by the developer; we delete on their instruction |
| Demo bookings | 24 months after the appointment |
| Newsletter subscribers | Until you unsubscribe, plus a record of the unsubscribe so we do not mail you again |
| Support tickets | 24 months after the ticket closes |
| Failed sign-in records | Short-lived; kept only long enough to rate-limit |
| Invoices and accounting records | As long as tax law requires |
9. How we protect it
Traffic is encrypted in transit and HSTS is enforced. Passwords are hashed with bcrypt; reset and booking-management tokens are stored hashed, never in the clear. Database access is limited to our servers — the database rejects requests made with a public key. Sign-in is rate-limited per address and per account. Staff access is role-based and every change to client data is written to an audit log.
No system is perfectly secure. If a breach affects you and the law requires it, we will tell you and the relevant regulator within the time the law allows.
10. Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable format, and you can unsubscribe from the newsletter in one click from any email we send.
If you are in the UK or EEA, you additionally have the right to object to processing based on legitimate interests, to ask us to restrict processing while a dispute is resolved, to withdraw consent at any time, and to complain to your data protection authority — in the UK, the Information Commissioner's Office.
If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and to be free from retaliation for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is no opt-out to offer you — but you are welcome to confirm that with us.
Write to hello@ingress3d.com. We answer within 30 days. We may need to check who you are first, and if the data belongs to one of our clients we will pass your request to them and tell you we have done so.
11. Do Not Track
There is still no agreed standard for what a Do Not Track header should mean, so we do not respond to one. This costs you nothing here: we do not track you across sites in the first place.
12. Children
This service is for property professionals and prospective buyers. It is not directed at children under 16 and we do not knowingly collect their information. If you believe a child has given us data, write to us and we will delete it.
13. Other sites
Our maps sit inside developers' websites, and our site links to others. Once you follow a link, or interact with the page around one of our maps, you are on someone else's property and their policy applies. We are not responsible for what they do.
14. Changes
We will update this page when what we do changes, and move the date at the top. If a change materially affects you we will say so — by email to account holders, or a notice on the site.
15. Contact
Ingress3D
545 N McClurg Ct #2620, Chicago, IL 60611, USA
hello@ingress3d.com