Ingress3DDemo

Privacy Policy

Last updated 5 September 2026

This policy explains what Ingress3D collects, why, who else sees it, and what you can ask us to do about it. It covers our website at ingress3d.com, the client portal, and the interactive homesite maps we build and host for our clients.

  1. 1. Who we are
  2. 2. Two kinds of people
  3. 3. What we collect
  4. 4. Cookies and tracking
  5. 5. How we use it
  6. 6. Who else sees it
  7. 7. Where it is processed
  8. 8. How long we keep it
  9. 9. How we protect it
  10. 10. Your rights
  11. 11. Do Not Track
  12. 12. Children
  13. 13. Other sites
  14. 14. Changes
  15. 15. Contact

1. Who we are

Ingress3D operates from 545 N McClurg Ct #2620, Chicago, IL 60611, USA. We build interactive homesite maps for residential and land developments, and we host a portal where our clients manage those maps.

For the purposes of the UK and EU General Data Protection Regulation, we are a controller of the information described in section 3.1 and 3.2, and a processor acting on our clients' instructions for the information described in section 3.3.

2. Two kinds of people

This policy has two audiences and they are treated differently, so it is worth knowing which one you are.

  • Our clients. Developers and their sales teams who buy a map from us and sign in to the portal. We decide what to collect about you and this policy governs it.
  • People browsing a map. If you are looking at homesites on a developer's website, the map may be one of ours. In that case the developer — not us — decides what happens to your enquiry. We handle it on their behalf, under a contract with them, and their own privacy policy governs what they then do with it. If you want your enquiry deleted, ask them; if you cannot reach them, tell us and we will pass it on.

3. What we collect

3.1 When you use our website

Ordinary request data — IP address, user agent, the pages you asked for and when — processed by our host at the network edge. We use Cloudflare Web Analytics, which is cookieless: it records page views without building a profile of you and without following you to other sites.

3.2 When you deal with us directly

If you…We collectBecause
Sign in to the portalName, email address, a hashed password, your role, and a log of what you changedTo give you an account and keep an audit trail of edits to client data
Sign in — or try toEmail attempted, IP address, whether it worked, and whenTo rate-limit password guessing. Most rows are for addresses that have no account here
Book a demoName, email, company, phone if you give it, what you wrote, your timezone, and IP addressTo hold the appointment, send you a confirmation and calendar invite, and prevent abuse of the form
Subscribe to the newsletterEmail, name if you give it, the IP you signed up from, and confirmation statusTo send the newsletter and to prove the subscription was genuine, which anti-spam law requires
Raise a support ticketYour name, email and everything in the threadTo answer you and keep a record of what was said
Reset your passwordA single-use token, stored hashed, that expiresTo let you back in without us ever seeing the new password

We do not take payment card details. Invoicing is handled outside the platform and no card number ever reaches our systems.

3.3 When you use a map we host for a developer

Our maps are embedded on developers' websites. When you use one we may process:

  • Your enquiry, if you send one — name, email, phone, your message, and which homesites you were asking about. This goes to the developer's inbox and to their dashboard in our portal.
  • Anonymous interaction data, where the developer has bought our Intelligence Layer — which homesites were opened, how long a session lasted, how many enquiries followed. This is counted, not attributed: it tells a developer that lot 14 gets attention, not that you looked at it.
  • A bot-protection check on the enquiry form, provided by Cloudflare Turnstile. Turnstile is designed to work without tracking cookies or profiling.

We do not sell any of this, and we do not combine one developer's data with another's.

4. Cookies and tracking

We use one cookie, and only if you sign in to the portal: an encrypted session cookie that keeps you signed in for a week. It is httpOnly, secure, and SameSite=Lax — it cannot be read by scripts and is not sent to other sites.

We run no advertising cookies, no third-party trackers, and no cross-site profiling. Cloudflare may set short-lived cookies for security and bot management on requests that pass through its network.

5. How we use it

  • To run the service — accounts, maps, dashboards, enquiries.
  • To answer you when you contact us or book a demo.
  • To send the newsletter, if you asked for it, until you tell us to stop.
  • To keep the service secure — rate limiting, bot protection, audit logs.
  • To bill our clients and keep the records our accountants and tax authorities need.
  • To understand, in aggregate, how the product is used and where it is failing.

In the UK and EU, our lawful bases are: contract for running accounts and delivering the service; consent for the newsletter, withdrawable at any time; legitimate interests for security, fraud prevention, and product improvement; and legal obligation for tax and accounting records.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law.

6. Who else sees it

Only the companies that make the service work, listed here by name so you can check them yourself:

CompanyWhat they doWhat they get
Cloudflare, Inc.Hosting, content delivery, bot protection (Turnstile) and privacy-first web analyticsRequests to our sites and the maps we host, including IP address and user agent, processed at the network edge
Supabase, Inc.Managed PostgreSQL databaseEverything stored in the portal: accounts, homesite records, enquiries, tickets, demo bookings, newsletter subscribers
Resend (Plus Five Five, Inc.)Transactional and newsletter email deliveryRecipient name and address, and the content of the message being sent

Beyond those, we share information: with the developer whose map you used, where you sent them an enquiry; with professional advisers under a duty of confidence; where a law, subpoena or court order requires it; and with a buyer, if the business is ever sold — in which case this policy travels with the data until it is replaced by one no less protective.

7. Where it is processed

Our database and email provider are in the United States. Our host operates a global edge network, so a request may be served from the country you are in. If you are in the UK or EEA, transfers rely on the UK Addendum and the European Commission's Standard Contractual Clauses, which our providers incorporate into their terms.

8. How long we keep it

WhatHow long
Portal accounts and audit logFor as long as the client is with us, then up to 12 months
Enquiries from a mapControlled by the developer; we delete on their instruction
Demo bookings24 months after the appointment
Newsletter subscribersUntil you unsubscribe, plus a record of the unsubscribe so we do not mail you again
Support tickets24 months after the ticket closes
Failed sign-in recordsShort-lived; kept only long enough to rate-limit
Invoices and accounting recordsAs long as tax law requires

9. How we protect it

Traffic is encrypted in transit and HSTS is enforced. Passwords are hashed with bcrypt; reset and booking-management tokens are stored hashed, never in the clear. Database access is limited to our servers — the database rejects requests made with a public key. Sign-in is rate-limited per address and per account. Staff access is role-based and every change to client data is written to an audit log.

No system is perfectly secure. If a breach affects you and the law requires it, we will tell you and the relevant regulator within the time the law allows.

10. Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable format, and you can unsubscribe from the newsletter in one click from any email we send.

If you are in the UK or EEA, you additionally have the right to object to processing based on legitimate interests, to ask us to restrict processing while a dispute is resolved, to withdraw consent at any time, and to complain to your data protection authority — in the UK, the Information Commissioner's Office.

If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and to be free from retaliation for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is no opt-out to offer you — but you are welcome to confirm that with us.

Write to hello@ingress3d.com. We answer within 30 days. We may need to check who you are first, and if the data belongs to one of our clients we will pass your request to them and tell you we have done so.

11. Do Not Track

There is still no agreed standard for what a Do Not Track header should mean, so we do not respond to one. This costs you nothing here: we do not track you across sites in the first place.

12. Children

This service is for property professionals and prospective buyers. It is not directed at children under 16 and we do not knowingly collect their information. If you believe a child has given us data, write to us and we will delete it.

Our maps sit inside developers' websites, and our site links to others. Once you follow a link, or interact with the page around one of our maps, you are on someone else's property and their policy applies. We are not responsible for what they do.

14. Changes

We will update this page when what we do changes, and move the date at the top. If a change materially affects you we will say so — by email to account holders, or a notice on the site.

15. Contact

Ingress3D
545 N McClurg Ct #2620, Chicago, IL 60611, USA
hello@ingress3d.com