Privacy policy
Effective September 29, 2026
Flood Zone API (floodzoneapi.com and api.floodzoneapi.com) is operated by CHM Capital Ltd, registered in England and Wales, company number 17466915, registered office 59-60 Russell Square, London WC1B 4HP. CHM Capital Ltd is the data controller for the personal data described here.
What we collect
- Your email address, to create your account, send confirmation and sign-in links, and send receipts and messages about your account.
- Account records: your plan, its status, when you confirmed your email, the IP address the sign-up came from (kept as a record of consent), and an affiliate code if you arrived through a partner link.
- API keys: we store a one-way fingerprint (SHA-256 hash) and the first few characters of each key, never the key itself, plus when it was created and last used.
- Usage counts: how many calls each account makes per month, for the quota.
- Lookup inputs: the addresses and coordinates you send. We use them only to answer the request. They are kept in a cache for up to 24 hours so repeat lookups are fast, then discarded. Our servers also keep standard access logs, which include request addresses (so the addresses or coordinates you send, and a key if you pass it in the URL) and IP addresses, for up to 14 days for security and troubleshooting. We do not keep a history of your lookups in your account.
- Payments are handled by Stripe. We never see your full card number. We receive your Stripe customer and subscription references and whether payment succeeded.
Who processes the data
- Stripe (payments and the billing portal).
- Mailgun (sending account email).
- Cloudflare (hosting and network).
- Amazon Web Services, through Laravel Forge (the API server).
- The US Census Bureau Geocoder and Photon by komoot (OpenStreetMap data): the address text you send is passed to them to find its coordinates. FEMA receives only coordinates.
- Fathom Analytics measures page visits on floodzoneapi.com without cookies and without collecting personal data.
Why we may use it (UK and EU GDPR)
To provide the service you signed up for (contract); to keep accounting and tax records (legal obligation); and to keep the service secure and prevent abuse (legitimate interests). We do not sell personal information or share it for cross-context behavioral advertising, and we honor Global Privacy Control signals as an opt-out.
How long we keep it
Account records are kept while your account exists and for up to six years after it closes where tax and accounting law requires. Revoked key fingerprints are kept with the account. Lookup inputs leave the cache within 24 hours and the server access logs within 14 days.
Your rights
You can ask to access, correct, delete or export your personal data, or object to how we use it, by emailing [email protected]. We will answer within one month. If you are in the UK you can complain to the Information Commissioner's Office; in the EU, to your local data protection authority; in California, you have the rights the CCPA gives you, and we will not treat you differently for using them.
Transfers
Our processors operate in the United States and elsewhere. Where personal data leaves the UK or EU we rely on the processors' standard contractual clauses or equivalent safeguards.
Children
The service is for developers and businesses and is not directed at children under 13 (or under 16 in the EU).
Changes
If we change this policy we will update the date above, and email account holders about material changes.