enter.place legal
Privacy Policy
This Policy explains how enter.place handles personal information about account holders, guests and other visitors.
- Effective date
- 31 August 2026
- Version
- 2.1
1. Controller and scope
DOMUS SAPIENS LTD, company number 15319608, registered at 128 City Road, London, EC1V 2NX, United Kingdom, is the controller for the personal information it determines how and why to use in connection with enter.place.
Contact: info@enter.place.
Place owners decide what information to upload and disclose through their place pages and access links. Depending on the circumstances, an owner may be an independent controller for personal information in that content, while we process the content to provide the Service. Questions about the substance of an owner’s page should normally be directed to that owner; you may also contact us where the request concerns our own processing.
2. People covered by this Policy
- owners and administrators who create or manage an account or place;
- registered guests who open, save or revisit a place through an access link;
- unregistered visitors who open a guest link or public page;
- people who contact us or receive a transactional email; and
- people whose information an owner lawfully includes in Owner Content.
3. Information we collect
Account and authentication information
Email address, authentication-provider user ID, display name, profile photo, interface language, account role, sign-in records and authentication-session data. If you choose Google sign-in, Google supplies the profile information authorised by that sign-in flow. We do not receive your Google password.
Place and published content
Place names, addresses, country and region fields, coordinates, routes, route steps, photographs, image annotations, custom plans, map points, descriptions, comments and information blocks. Information blocks may contain contacts, opening hours, parking information, links, rules, Wi-Fi details, access instructions or other information selected by the owner.
Access links and permissions
Link names, slugs, encrypted or digested link secrets, active or revoked state, expiry settings and the routes, steps and information blocks made available through each link.
Guest activity and identity choices
For ordinary guest links, we may record that a page, route, step, external map or information section was opened, together with a per-page visit identifier, time, broad device/browser label and the relevant internal route, step or information type. The identifier is created in memory on the device and can be stored with the server-side event records, but it is not stored on the device between visits and cannot recognise the same anonymous visitor after a reload.
If a signed-in guest opens a link, the place may be added to their recent or saved places. The owner can see that guest’s account identity only according to the guest’s identity-disclosure setting: all opened links, saved places only, or no identity disclosure. Otherwise, activity is displayed under a pseudonymous visitor label. Public demonstration pages do not record guest activity or create received-place records.
Location and map information
Owners may save a place address and coordinates and assign coordinates to route steps. A guest’s browser requests precise current location only when the guest enters the live-map experience that needs it and permits the browser request. When the guest requests a walking route, the current origin and selected destination are sent to our route endpoint and to Google Maps Platform to calculate the route. We do not store the guest’s precise current location as place content or in the guest-activity table. Browser and infrastructure logs may still contain ordinary technical request information.
Technical, security and support information
IP address, request time, user agent, device category, referring page, requested URL, request or deployment identifier, approximate country supplied by hosting infrastructure, error details and security events. Support communications may contain the information you choose to provide.
Product analytics and application reliability
We record a limited allowlist of product events such as completed registration, place, route, step and access-link actions, guest-page opens and external-map opens. For signed-in account holders, we may also associate canonical account or administration page categories and the relevant internal place identifier with the account. A public document request is added directly to separate daily counters for the initial canonical page, external referring hostname, interface language, country and broad device category. These counters do not contain a visitor identifier or an exact visit time and cannot be combined into an individual journey. Dynamic link identifiers, URL parameters, full referrer URLs and free-form page content are not included. Analytics does not include email addresses, names, precise addresses, coordinates, access-link secrets, page content or payment-card information.
We also collect page-view statistics and limited application error and performance information to understand service use and diagnose failures. We do not use session replay, advertising profiles or cross-site tracking for these purposes.
When an unregistered person starts Google or email sign-in in the same browsing journey, we may temporarily associate a random one-time code with a coarse acquisition channel, a bounded campaign code and the canonical landing route. The code expires after approximately 20 minutes, is stored by us only as a cryptographic hash and is consumed after successful authentication. If a new account is created, its first-touch record is saved as Google organic, Bing organic, ChatGPT, Scout, partner, QR, email, direct or unknown. We do not store the raw referrer, URL parameters, IP address or user agent in this record, and we do not use it to recognise an anonymous person across days or devices. accounts.google.com is treated only as an authentication provider, not as an acquisition source. Scout rewards rely on separately verified place attribution and never on this coarse signup channel.
Email information
Email address, language, sign-in request, delivery status and essential authentication or operational messages. The current Service does not operate a marketing-email programme or automatically email guest access links.
Subscriptions, payments and tax
Stripe customer, Checkout, subscription, invoice, payment, refund and dispute identifiers; plan, currency, amount, tax treatment, billing country, business tax ID status, trial and renewal dates, cancellation state, payment status and a limited card brand/last-four display supplied by Stripe. Complete card numbers and card security codes are collected by Stripe and are not received by us.
Scout participation and payouts
Scout country, status, accepted terms version and timestamp, attributed places, reward and negative-balance records, payout status, risk reviews and Stripe recipient identifiers. Identity, bank and tax information needed for a payout is collected through the approved Stripe flow; we retain only the provider identifiers, status and reporting information needed to operate and account for the programme.
Fraud and payment-risk signals
We may compare keyed, non-reversible hashes derived from billing email or a Stripe payment-method fingerprint across otherwise unrelated customer accounts. We also use account, place, subscription, refund, dispute and product-use patterns. A shared card or email is a review signal, not proof of wrongdoing; one legitimate owner may pay for several places with the same card.
Translations
Source text, source and target languages, content hashes, translation results, job status and limited error information. Text that requires machine translation may be sent to Google Cloud Translation. Owners should avoid placing unnecessary personal or sensitive information in text submitted for translation.
4. Sources of information
- directly from account holders, guests and people who contact us;
- from owners who create place content or identify a contact;
- from Google when a user chooses Google sign-in;
- from a browser or device when a user interacts with the Service;
- from Vercel and Supabase infrastructure used to deliver and secure requests;
- from PostHog and Sentry analytics and reliability services;
- from map, geocoding, routing and translation providers used for a requested feature;
- from Stripe when a customer starts or manages billing or a Scout completes payout onboarding; and
- from email-delivery status returned by Resend.
5. Purposes and legal bases
| Purpose | Typical information | Legal basis |
|---|---|---|
| Provide accounts, places, links and requested features | Account, content, permissions, authentication and preferences | Performance of a contract; steps requested before a contract |
| Display owner-selected content to link recipients | Place content, routes, photos, plans and information blocks | Contract with the owner; legitimate interests in delivering the requested link |
| Maps, geocoding, walking routes and external navigation | Address, saved coordinates and, when requested, current origin | Contract or user-requested steps; consent to device geolocation where required |
| Translate owner content | Source text, languages, translation result and job status | Contract; legitimate interests in making content understandable |
| Deliver sign-in and essential operational email | Email, language, sign-in request and delivery status | Contract; legitimate interests in reliable account operation and security |
| Guest activity and received-place functionality | Pseudonymous visit, actions, device label and optional signed-in identity | Legitimate interests in link operation, owner visibility and product security, balanced against guest choices |
| Measure product use and improve the Service | Daily public-entry counters; signed-in account journeys; pseudonymous allowlisted product events; canonical page categories without URL parameters or secret links; associated place identifier and coarse market/device dimensions | Legitimate interests in understanding and improving the Service |
| Secure, troubleshoot and prevent abuse | Request, device, error, performance, rate-limit and security logs | Legitimate interests; legal obligations where applicable |
| Operate paid subscriptions, tax and refunds | Checkout, customer, subscription, invoice, payment, billing and tax records | Performance of a contract; legal obligation; legitimate interests in payment administration |
| Operate Scout attribution, rewards and payouts | Scout profile, consent, attributed places, commissions, recipient and payout status | Performance of the Scout agreement; legal obligation; legitimate interests in administering the programme |
| Prevent payment and referral fraud | Keyed matching signals, account relationships, payment outcomes, disputes and risk reviews | Legitimate interests in preventing fraud and protecting customers; legal claims |
| Respond to rights requests, disputes and authorities | Account, content, correspondence and relevant logs | Legal obligation; legitimate interests in legal claims |
Where we rely on legitimate interests, we consider necessity, reasonable expectations, data minimisation and the impact on individuals. You may object to that processing as described below. Where consent is the legal basis, you may withdraw it without affecting earlier lawful processing.
6. Recipients and service providers
We disclose information only as needed for the purposes above:
- Supabase — hosted authentication, PostgreSQL database and file storage for accounts, content and photographs;
- Vercel — hosting, content delivery, serverless execution, image delivery and operational request and security logs;
- PostHog — EU-hosted event-only product analytics using pseudonymous identifiers, disabled person profiles and disabled GeoIP enrichment;
- Sentry — EU-hosted application error and limited performance monitoring with user PII and Session Replay disabled;
- Google — optional Google sign-in; Maps Platform services including places, geocoding, map imagery, street imagery and routes; Cloud Translation for requested content translation; and aggregated Search Console reports about how enter.place appears in Google Search;
- Resend — delivery of authentication and essential operational email;
- Stripe — Checkout, Billing, tax calculation, payment-method storage, invoices, refunds, disputes, Scout recipient verification and payouts, acting under the roles described in Stripe's own privacy materials;
- OpenStreetMap tile services — city-map tiles requested by the visitor’s browser, which can reveal IP address and request information to the tile operator; and
- external navigation providers such as Google Maps, Apple Maps, Yandex Maps and 2GIS, which receive the destination or route information only after the user chooses to open that provider and then act under their own terms and privacy notices.
We may also disclose information to professional advisers, insurers, courts, regulators or law-enforcement bodies where lawful and necessary, and to a buyer or successor in a genuine corporate transaction subject to appropriate confidentiality and legal safeguards.
7. International transfers
We are a UK company and our providers may process information in the United Kingdom, European Economic Area, United States or other countries in which they operate. When UK data protection rules treat a disclosure as a restricted international transfer, we use an available lawful mechanism such as UK adequacy regulations or appropriate contractual safeguards, including the UK International Data Transfer Agreement or the UK Addendum where applicable, and carry out required transfer assessments.
Provider infrastructure and subprocessor locations can change. Contact us if you need information about the safeguard relevant to a particular transfer.
8. Retention and deletion
We use the following retention criteria:
- account information is kept while the account is active and afterwards only as needed to complete deletion, prevent abuse, resolve disputes or meet legal duties;
- place content, photographs, routes, access links, translations and associated activity remain while the owner keeps the relevant place or link, and are removed from active systems when the relevant content, place or account is deleted;
- revoked or expired link configuration may be retained with the place until it is deleted where needed to preserve security and audit history;
- precise guest location used for a walking-route request is not written to the place or activity database;
- authentication, request, email-delivery, security and error records are kept only for the operational, security, legal or dispute period for which they remain necessary, including provider-controlled log cycles;
- subscription, invoice, refund, tax, Scout consent, commission and payout records are retained for the period required for accounting, tax, fraud prevention, disputes and legal claims, then deleted or de-identified where continued identification is no longer necessary;
- individual signed-in and pseudonymous product-analytics event records are deleted on a rolling schedule after 90 days; anonymous public-entry counters contain no visitor identifier or exact visit time and are retained for up to 760 days for year-over-year comparison; and
- signup-journey codes expire after approximately 20 minutes and expired or consumed temporary rows are removed operationally; the resulting coarse first-touch record remains with the account until account deletion or until it is no longer needed for product measurement;
- deleted information may remain temporarily in encrypted backups until the applicable provider backup cycle expires.
The current product does not yet expose a self-service account deletion control. Owners may request deletion at info@enter.place. We verify the requester before acting. We may retain a minimal record where required by law or necessary to establish, exercise or defend legal claims.
9. Your rights
Depending on the law that applies, you may have rights to be informed, access your personal information, correct it, erase it, restrict or object to processing, receive portable information, withdraw consent and complain to a regulator. You also have rights concerning decisions made solely by automated processing; the current Service does not make legal or similarly significant decisions about individuals solely by automated means.
Send a request to info@enter.place. Describe the account, guest link or interaction involved without emailing access codes or passwords. We may request proportionate identity verification. If the request primarily concerns content controlled by a place owner, we may direct it to or coordinate with that owner.
Where limited signed-in product analytics relies on our legitimate interests, you may object to that processing by contacting us at the same address. We will stop the processing unless applicable law permits compelling overriding grounds or it is needed for legal claims.
UK residents may complain to the Information Commissioner’s Office at ico.org.uk. You may also have a right to contact the regulator in your country.
10. Security
We use technical and organisational measures intended to protect information, including authenticated owner areas, access-controlled guest content, encrypted or digested link secrets, transport encryption, provider access controls, request validation, rate limits and restricted administrative access. No internet service or storage method is completely secure.
Owners should avoid publishing sensitive information unless necessary, limit each link to the required content, reissue compromised links and keep email and device access secure.
11. Children
Owner accounts are for people aged 18 or over. The Service is not directed to children under 13, and we do not knowingly ask children to create owner accounts. A guest link can be opened in a browser without registration. Owners must not use the Service to collect or publish children’s information without a lawful basis and appropriate safeguards. Contact us if you believe a child’s information has been handled improperly.
12. Cookies and device storage
We use authentication, language and interface-preference storage as described in the Cookie Policy. Product analytics, aggregated Web Analytics and error monitoring operate without placing product-analytics or advertising cookies or persistent analytics identifiers. Session replay and cross-site tracking are not used.
13. Changes to this Policy
We will update the effective date and version when this Policy changes. We may revise it to reflect changes in the Service, law, processors, analytics, maps, translations, email, retention, geolocation, markets or future payment features. We will provide reasonable notice of material changes through the Service or account contact details where appropriate, unless urgent legal or security reasons require faster action. Changes do not retrospectively remove rights that have already arisen where applicable law prohibits that result.