Legal and operations
Privacy policy
Last updated September 3, 2026
Information we collect
We collect account, property-search, support, and audit information necessary to provide PermitProof. Our hosting also receives the technical information any web request carries, such as your IP address, browser user agent, and the page you requested. If you use the public contact form, we also store what you submit there - the fields are listed under Contact below.
How information is used
Information is used to authenticate users, operate searches, create reports, improve connector reliability, prevent abuse, and meet legal obligations. Accounts that have never subscribed have no payment method on file and no billing records. Subscription billing is processed by Stripe. Card and bank details are entered on Stripe's own pages and never reach PermitProof. PermitProof stores only what it needs to know whether an account has access: the subscription's status, its billing period, whether it is set to cancel, the Stripe customer and subscription identifiers, and a record that the renewal terms were acknowledged before purchase.
Property addresses you search
An address you search is sent to the services needed to answer it: Google's Address Validation API to standardize it, the U.S. Census Bureau geocoder to determine which jurisdiction issues permits there, and the official city or county permit source for that jurisdiction, in some cases through the PermitProof browser worker. Google's validation service and the PermitProof browser worker receive the address in the body of a request. The Census geocoder and the official ArcGIS permit sources receive it as part of the request address itself, which means it can appear in those operators' own server logs. PermitProof never puts a searched address in a link you could share or in a page you could bookmark. The searches and reports themselves are stored against your account and are visible only to it.
Address suggestions while you type
The search form suggests real addresses as you type, and that begins before you run any search. Once you have typed a house number and enough of a street name for a match to be possible, and your typing pauses, PermitProof's own server sends the street text you have entered, together with the two-letter state code, to the U.S. Census Bureau geocoder, and offers you the addresses it returns. This happens whether or not you go on to use a suggestion, and whether or not you ever press Search. The Census geocoder receives that partial address as part of the request address, the same way a full search reaches it, which means it can appear in that operator's own server logs. Your browser does not contact the geocoder directly; the request goes through PermitProof so it can be rate-limited and so repeated keystrokes are not re-sent. A city you have entered stays in your browser, where it only orders suggestions your browser already has, so the city is not sent to the Census Bureau or to PermitProof's own server, and typing one sends no new request at all. Recent geocoder replies are held in memory on PermitProof's server for a few minutes so the same partial address is not sent twice. What you type for suggestions is not recorded in your search history or stored in PermitProof's database, and choosing a suggestion only fills in the form - it does not run a search or verify the address.
Visit measurement (Vercel Web Analytics)
The site loads Vercel Web Analytics on every page to count visits and product events. Loading it sends the request metadata your browser already sends any server - IP address and user agent - to Vercel, together with the address of the page you are viewing; Vercel documents the product as cookieless, and PermitProof sets no analytics cookie and receives no advertising identifier from it. PermitProof also records named product events through it: that a search was submitted and whether it completed, was held, or could not run; which call-to-action button was clicked; that a report PDF was requested; that a sign-up form became usable and that a sign-up was submitted, and whether it completed or failed, a failure carrying only a coarse status word such as “validation” or “server”; and that a subscription checkout was started or completed. An event carries its name, at most a coarse label such as a button location or a status word, and the address of the page it happened on - which, inside the signed-in application, can include the internal identifier of a report, the same way that page's own address bar does. Events never include an address you searched, the contents of a report, or your email address.
Advertising, Google, and cookies
This site loads the Google AdSense library on its public marketing pages: the home page, pricing, the FAQ, the guides, the coverage directory and every jurisdiction page beneath it, the California permit records report, the sample report, the data sources page, and these legal pages. It is not loaded on the sign-in, sign-up, or password-reset pages, and it is not loaded on any page inside the signed-in application. Loading it sends your IP address, browser user agent, and the address of the page you are viewing to Google, and lets Google set or read cookies and similar identifiers in your browser, which Google may use for personalized advertising. This happens on the first marketing page you open: PermitProof does not show a cookie or consent banner and does not ask you to opt in first. PermitProof configures no ad unit of its own, so this site places no advertisement on any page; Google may still place advertisements automatically on the pages that load the library, and the library loads and contacts Google either way. What Google does with what it collects is governed by Google's advertising privacy notice at policies.google.com/technologies/ads, and you can change or turn off personalized advertising for your browser or Google account at myadcenter.google.com. PermitProof does not offer its own control for this.
Cookies PermitProof sets
PermitProof sets its own cookies only to sign you in, keep you signed in, and remember which account a request belongs to. They are required for an account to work and are not used for advertising or analytics.
Public-record data
Permit records may be copied from public government sources and stored with retrieval metadata so a report can be reproduced and reprocessed.
Sharing
We use service providers to run the product: Supabase (database, authentication, and stored files), Vercel (hosting), Stripe (subscription billing and payment processing), Google (address validation and the advertising library described above), and the U.S. Census Bureau geocoder. Running a search also sends the address to the official government permit source for that jurisdiction, and the address suggestions described above send partial addresses to the Census Bureau geocoder before any search runs. We do not sell your search history, and we do not send your searches or reports to an advertiser or data broker.
Retention and security
Retention is configurable, and expired property records, reports, and stored files are deleted on a schedule. Access controls, audit logs, row-level security, encrypted transport, and restricted storage are used to protect information.
Contact
To reach PermitProof without an account - including for privacy questions and requests to delete your data - use the public contact form at getpermitproof.com/contact. Account holders can also submit a support request from inside the application. A contact form submission stores the category you chose, the name you entered if any, your email address, your message, your browser's user-agent string, a SHA-256 hash of your IP address rather than the address itself, and the time it was received. It is written to PermitProof's database, read by the operator, and kept until the operator deletes it; it is not sent to any third party beyond the service providers listed above, and it is not used for advertising.