RAL Reports

Privacy Policy

Last updated June 2026.

This is a working draft for review and is not a substitute for advice from qualified legal counsel.

1. Information we collect

2. Cookies

We use cookies that are necessary to operate the Service — in particular, a secure, HTTP-only session cookie that keeps you signed in. We do not use third-party advertising cookies. Blocking essential cookies will prevent you from logging in.

3. Why we collect IP and device information

We log IP address and browser/device information for security and to protect the integrity of the Service — including detecting and preventing automated access, scraping, and prohibited account sharing (one account per person). This helps us enforce our Terms of Use.

4. How we use information

5. How we share information

Your information stays within RAL Room LLC. We do not sell or rent your personal information, and we do not share it with third parties outside RAL Room LLC for their own marketing. We share it only with service providers acting on our behalf to operate the Service (for example, hosting, database, authentication, payment processing, email delivery, and mapping providers), and where required by law or to protect our rights.

6. Data retention

We keep account and usage information for as long as your account is active and as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.

7. Your choices

You can request access to, correction of, or deletion of your account information by contacting us. Some information may be retained as required for legal or security purposes.

8. Maps and third-party data providers

We use Google Maps Platform to display maps and to geocode locations in our reports. When you view or interact with map features, Google may collect and process information (such as device data and approximate location) as described in the Google Privacy Policy; your use of those features is also governed by Google’s Terms of Service. We also use public and licensed data providers — including the U.S. Census, CMS, CDC, BLS, state licensing records, and Regrid parcel data — as inputs to our reports. We do not sell your personal information to these providers.

9. De-identified & aggregated data

We may create de-identified and aggregated information from account and usage data (for example, to detect abuse such as shared accounts or automated scraping, to understand which features are used, and to operate and improve the Service). We maintain such information in a de-identified form and do not attempt to re-identify it.

10. Data security

We use reasonable administrative, technical, and organizational safeguards designed to protect your information — including encrypted connections, hashed credentials managed by our authentication provider, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Pending counsel review (to be finalized before launch): a full consumer-rights section (e.g., California/CCPA and other U.S. state privacy rights — access, deletion, correction, and how to exercise them); a dedicated privacy contact email; a statement that the Service is intended for users in the United States; and a children’s-privacy statement (the Service is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13).

11. Contact

Questions about this Policy? Visit our Contact page.