Last updated: August 8, 2026
Note: This is a reasonable, conservative default privacy policy for a small US software service, written in plain language. It is not legal advice and is pending review by an attorney.
UrbanKit Studio ("UrbanKit Studio", "we", "us") provides web-based planning and property-research tools such as public-notice radius mailing lists, Avery® label PDF generation, and parcel lookups against public county records (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices.
In short: the property data the Service shows comes from public government records and is served as-is. We do not build profiles or dossiers on people, and we do not sell personal information. The only personal data we collect from you is what you choose to give us — your email if you sign up or subscribe, and payment details handled by our payment processor if you buy a paid plan.
Important: Please avoid uploading or entering sensitive personal information. Urban planning data can include addresses and owner names; treat that as personal data.
When you look up a parcel, the property-owner names, mailing addresses, and related fields you see come from public government records — county assessors, GIS departments, and similar public sources — which publish this information themselves. This is publicly-available information, and we serve it as-is and largely pass-through from the source.
We do not aggregate these records into profiles or dossiers on individuals, we do not enrich them with non-public data, and we do not sell them. The Service is a directory and a thin client that helps you reach records the government already makes public; it is not a people-search or data-broker product.
Takedown / opt-out: If your information appears through the Service and you would like us to look into restricting it, email contact@urbankitstudio.com. Because the data originates with government sources, the authoritative place to correct or restrict a public record is usually the county or agency that maintains it, and we will point you there where that applies.
The Service may accept CSV and GeoJSON files and may ask you to enter addresses for geocoding. Files you upload are processed locally in your browser and are not uploaded to our servers — CSVs you map into labels, GeoJSON you upload for a radius, and the PDFs and CSVs you generate stay on your device.
Some tools are backed by our own API rather than running purely in your browser: bulk enrichment, auto-county radius lookups, property reports, and the parcel atlas API. For those, the addresses or parcel you enter are sent to our servers so we can run the query against the relevant public county endpoint, and we may cache the county's response briefly for reliability and billing. We do not use those queries to build profiles of you or of the properties you look up, and we do not sell them.
If you create an account, we store the email you sign up with and your plan/subscription state (see Payments below). Accounts and application data are hosted with Supabase, a US-hosted database and authentication provider.
We may use platform-provided analytics (for example, from our hosting provider) to understand aggregate usage (such as page views, device/browser type, and approximate location). This helps us improve the Service. We do not intentionally collect sensitive personal information through analytics.
First-party product telemetry, on account pages only. To diagnose problems and see which features work, the Service records a small set of product events in our own US-hosted database (Supabase). This happens on the signed-in account and admin pages and nowhere else. The public pages and the free browser tools record no product telemetry: no page view, no interaction, not one event. That is enforced in code by a single route check every event must pass, and a test in our public repository fails the build if a public page ever gains one. One thing is counted outside that system: when a lookup names a county, we add to a per-county tally, described under Third-party services below. It holds no address, no IP address, no account and no record of an individual lookup. On the account pages the events recorded are: page views, account actions such as copying an API key or starting or returning from checkout, and client-side errors. Each event carries the page path (never the query string), a random session identifier, and your account id. It never includes the contents of your files, your lookups or your searches, and it is never sent to or shared with a third-party analytics service. These records are visible only to the site operator, are used for debugging, support, and product decisions, and are retained for a limited period.
Like most websites, our hosting infrastructure may automatically receive standard log information when you access the Service (for example, IP address, pages visited, and timestamps). Logs are typically used for security, reliability, and troubleshooting.
If you use geocoding features, the address you enter is sent to the U.S. Census Bureau's geocoding service to return coordinates and match details. Please review the Census Bureau's Terms of Service for more information. The request is relayed by our servers rather than sent straight from your browser, so the address you type reaches us on the way. We cache the Census response for up to 30 days, and that cached response includes the address the Census Bureau matched. Caching also makes repeat lookups faster and sends fewer requests to the Census service.
We also keep a count of which counties people look for, so that we know which counties to add next. The tally is one row per county rather than one per search: a public five-digit Census county code, that county's name and state, a running count, and the first and last time that county came up. It holds no address, no IP address, no account and no record of an individual lookup.
The Service uses the open-source MapLibre library and loads map tiles from OpenStreetMap. When your browser requests map tiles, the tile host may receive limited technical data (such as IP address and browser details), as with any web request. We do not embed a paid or proprietary basemap.
When you run a free parcel lookup, your query goes directly from your browser to the relevant public county or government endpoint (for example, a county ArcGIS® REST service). That source may log the request under its own policies, and nothing passes through our servers. For the API-backed tools described above, the query is routed through our servers instead, and the county's response may be cached briefly for reliability and billing — those caches are operational and short-lived, and the county remains the system of record.
Forms that can be abused by bots (for example, the newsletter signup) are protected by Cloudflare Turnstile, which evaluates browser signals to tell humans from bots without showing a puzzle in most cases. Cloudflare processes that data under its own privacy policy; we receive only a pass/fail token.
If you purchase a paid plan, payments are processed by Stripe, a US-based payment processor. Stripe collects and processes your payment details (such as card information) under its own privacy policy. We do not receive or store your full card number. We retain only limited billing and subscription information needed to provide the paid service (for example, your plan, status, and the email tied to your account).
The Service does not currently display third-party advertising and does not set advertising cookies. If we introduce advertising in the future, we will update this policy first to describe the provider, the cookies or identifiers it uses, and how you can opt out.
You can opt in to our newsletter through the signup form in the footer or on the Parcel REST API Atlas page. Subscribing is voluntary. Every tool on the site works without it.
Only the email address you enter. We do not require a name. We tag each submission with the page it came from (for example, "footer" or "parcel-atlas") so we can see which placements work; nothing else is recorded.
We send about one to two emails a month, when a new tool ships or a major article goes up. That's it. No drip sequences, no automated marketing funnel, no third-party sale or sharing.
Email addresses are stored with Resend, a US-based transactional email provider, in an audience scoped to UrbanKit Studio. Resend's privacy policy applies to data stored on their platform, and Resend remains the authority for your subscription status — including unsubscribes.
We also keep our own copy of the subscriber list in our US-hosted database (Supabase): the email address, the page it was submitted from, the provider's contact reference, and signup timestamps. We keep this mirror so we can report signup growth and attribution without widening access to the email platform itself. It is locked to administrative access only, is never used to build recipient lists (those always come from Resend, which knows who has unsubscribed), and is removed on request along with your Resend record.
Every email includes a one-click unsubscribe link. You can also email contact@urbankitstudio.com and we will remove you within one business day.
For the free browser-based tools, we use browser local storage to track usage limits (e.g., number of exports). That data stays on your device and is not transmitted to our servers; you can clear it through your browser settings.
For signed-in accounts and metered (pay-per-use) features, usage is also counted on our servers — that server-side ledger is what makes your plan limits and any usage-based billing accurate, and it is retained as part of your billing records. A row is written for every request to our developer API that passes the rate limit, including requests that carry no API key; those rows name no account, because there is none to name.
That ledger also records, for a request we could not answer, the five-digit Census county code the request named — either the code an address resolved to, or the code you sent us directly. We use it to see which counties people look for that our atlas does not yet cover, and build those next. It is a public county code, never your search text, the matched address or the county name, and it is recorded only when we had no answer for you.
A request can also name a county by its state and county slug rather than by a code — for example the state "illinois" and the county "kane-county". When our atlas does not carry that county there is no code to record, so we keep a separate count of the slug pair itself: one row per county, a running total, and the first and last time that county came up. A slug is a fixed shape rather than free text — at most 64 lowercase letters, digits and hyphens, which the database enforces — and we count the pair only when the state part names one of the fifty states or the District of Columbia. Both parts are what you typed, and we treat them as a name for a county we do not yet cover and nothing more. Like the county tally above, the row holds no address, no IP address, no account and no record of an individual request.
Your browser may allow you to control cookies and local storage through settings. The Service does not use advertising cookies; disabling cookies may affect certain site functionality. If we implement a consent banner in the future, you will be able to manage your preferences there as well.
Uploaded files are processed in your browser and are not stored by us. Server-side query caches for the API-backed tools are short-lived and operational. Account, subscription, and usage-ledger records are retained while your account is active and as required for billing and tax records. Hosting logs and aggregate analytics may be retained for a limited period for security and service improvement.
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
We do not sell your personal information, and we do not sell the public-records property data the Service displays. We do not share your email or account information with third parties for their own marketing. The limited third-party processors we use (for example, our hosting provider, our email provider, and our payment processor) handle data only to provide the Service on our behalf.
UrbanKit Studio is a US-based service intended for users in the United States. Pricing is in US dollars and the Service is not localized, geo-targeted, or marketed to the European Union or other regions. We do not intentionally target or solicit users outside the United States. If you access the Service from elsewhere, you do so on your own initiative and are responsible for compliance with your local laws.
We may update this Privacy Policy from time to time. We will update the "Last updated" date above when changes are made.
Questions, or a takedown/opt-out request? Contact us using the contact method listed on the UrbanKit Studio website, or email contact@urbankitstudio.com.