Privacy Policy
Last updated: August 7, 2026
This Privacy Policy explains how Overhead Measure ("Overhead Measure", "we", "us", or "our") collects, uses, discloses, stores, and deletes personal information when you use overheadmeasure.com, overheadmeasure.ca, and related services (the "Service").
By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. Our Terms of Service govern use of the Service separately.
Depending on your location, you may have rights under laws such as Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws, the EU/UK GDPR, and U.S. state laws such as the California Consumer Privacy Act (CCPA/CPRA). We describe those rights below.
1. Who we are and how to contact us
Overhead Measure operates the Service. For privacy requests (access, correction, deletion, complaints), email generalinbox@overheadmeasure.com. We aim to respond within thirty (30) days, or sooner where law requires.
2. Information we collect
2.1 Account and identity information
When you sign up or sign in through Clerk, we (and Clerk) process information such as your email address, name (if provided), authentication identifiers, and session/security metadata. Social or SSO sign-in may share profile information according to that provider's settings.
2.2 Billing and payment information
If you start a trial or subscribe, Stripe processes payment method details, billing address, tax-related location data, invoices, and transaction history. We do not store your full card number on our servers; Stripe handles card data. We store Stripe customer/subscription IDs and plan status needed to unlock features and apply quotas.
2.3 Measurement and workspace data
When you use the measurement tools we may store: addresses or search queries you enter; map locations/coordinates; drawn geometries; surface types; calculated area estimates; AI detection results you generate; and related workspace metadata (for example plan, usage counters, timestamps).
2.4 Technical and usage data
We automatically collect technical data such as IP address, approximate location derived from IP, browser/device type, pages viewed, referring URLs, timestamps, and diagnostic/error logs. We use this for security, rate limiting, abuse prevention, debugging, and improving reliability.
2.5 Cookies and similar technologies
We and our providers use cookies, local storage, and similar technologies for authentication (Clerk), session continuity, security, and product analytics. We use Vercel Analytics and Vercel Speed Insights for aggregated performance and usage metrics. Browser settings can block some cookies; doing so may break sign-in or other features.
2.6 Communications
If you email us or we send transactional email (for example welcome / receipt confirmation via Resend), we process the content of those messages and related delivery metadata.
2.7 Information we do not intentionally collect
We do not intentionally collect sensitive government ID numbers, precise GPS tracks from your phone beyond map interactions you initiate, or payment card PANs. Do not submit special-category personal data unless necessary and lawful.
3. How we use information
We use personal information to:
- Provide, operate, secure, and maintain the Service
- Authenticate users and protect accounts
- Process trials, subscriptions, invoices, taxes, and quota enforcement
- Run geocoding, map tile delivery, and (when you request it) AI auto-detect
- Save and display your measurements in your workspace
- Send transactional messages (account, billing, security, welcome / receipt)
- Monitor abuse, rate-limit shared resources (tiles, geocode, AI), and investigate incidents
- Improve product quality, tutorials, and reliability
- Comply with law and enforce our Terms
We do not sell your personal information, and we do not rent customer lists.
4. Legal bases (where applicable)
Where GDPR or similar laws apply, we process personal data on bases that may include: performance of a contract (providing the Service you requested); legitimate interests (security, product improvement, abuse prevention — balanced against your rights); consent (where required); and legal obligation (tax, accounting, responding to lawful requests).
Under PIPEDA, we collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, as described in this Policy.
5. How we share information
We share personal information only as needed to operate the Service, including with:
- Clerk — authentication and account management
- Stripe — payment processing, tax calculation, and billing portal
- Vercel — hosting, edge delivery, Analytics, and Speed Insights
- Database provider (e.g., Neon / Postgres host) — application data storage
- Google Maps Platform — map tiles / imagery related to locations you request
- Geocoding providers (for example LocationIQ / Nominatim / Photon, depending on configuration) — address lookup
- AI providers (e.g., Replicate) — only when you use AI auto-detect; image/prompt data needed to run detection may be processed by the provider under its terms
- Resend — transactional email delivery
- Professional advisors and authorities — where reasonably necessary for legal, tax, or security purposes, or where required by law
If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate confidentiality and notice where required.
6. International transfers
We and our providers may process data in Canada, the United States, the European Economic Area, and other countries. Where required, we rely on appropriate safeguards (such as contractual protections used by our providers) for cross-border transfers. By using the Service, you understand that your information may be processed outside your home province or country.
7. Retention
We retain account and measurement data while your account remains active and as needed to provide the Service. After deletion requests or account closure, we delete or anonymize personal data within a commercially reasonable period, except where we must retain limited records for:
- Tax, accounting, and audit obligations
- Fraud prevention, security, and dispute resolution
- Enforcing our Terms or complying with law
- Backup systems, which may take additional time to fully expire
Stripe and other processors may retain their own records according to their retention policies and legal obligations.
8. Account and data deletion policy
8.1 How to delete your account
You can request deletion by:
- Deleting your account through Clerk account settings (where available in the product experience), or
- Emailing generalinbox@overheadmeasure.comfrom the email address on your account with the subject line "Delete my account"
8.2 What we delete
When your Clerk user account is deleted, our systems are designed to delete the corresponding workspace and saved measurements from the application database (including via automated webhook handling when configured). Related application records tied solely to that workspace are removed through cascading deletes where implemented.
8.3 What may remain
After deletion, we may retain:
- Billing and invoice records required for tax/accounting (typically retained by Stripe and/or us for the legally required period)
- Minimal logs needed for security, fraud prevention, or legal claims (kept only as long as reasonably necessary)
- Aggregated/de-identified analytics that no longer reasonably identify you
8.4 Subscriptions before deletion
Deleting your account does not automatically issue a refund. Cancel any active subscription from the Billing page (or Stripe portal) before or when requesting deletion to stop future charges. If a subscription remains active in Stripe after account deletion, contact generalinbox@overheadmeasure.com so we can help cancel it.
8.5 Timing
We aim to complete deletion of application workspace data within thirty (30) days of a verified request (often sooner when automated). Backup expiration may take longer. We may request verification that you control the account email before processing a deletion request.
9. Your privacy rights
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Request deletion (see Section 8)
- Withdraw consent where processing is consent-based
- Object to or restrict certain processing, or request portability, where those rights apply (e.g., GDPR)
- Appeal a denial of a consumer rights request where required by U.S. state law
- Opt out of "sale" or "sharing" of personal information — we do not sell personal information; if our practices change, we will update this Policy
To exercise rights, email generalinbox@overheadmeasure.com. We will not discriminate against you for exercising privacy rights. You may also lodge a complaint with a data protection authority (in Canada, the Office of the Privacy Commissioner of Canada, or your provincial commissioner).
10. California and other U.S. state disclosures
If you are a California resident (or resident of another state with similar laws), categories of personal information we collect may include identifiers (email, account ID, IP), commercial information (subscription status), internet activity (usage logs), and geolocation related to addresses/maps you search. We collect these categories for the business purposes described above. We do not sell personal information as that term is commonly understood, and we do not use sensitive personal information for inferring characteristics about you.
11. Children's privacy
The Service is not directed to children under 16 (or under 13 where that is the applicable threshold), and we do not knowingly collect personal information from children. If you believe a child provided personal information, contact generalinbox@overheadmeasure.com and we will take appropriate steps to delete it.
12. Security
We use reputable providers (including Clerk, Stripe, and our hosting platform) that maintain their own security programs, transmit data over HTTPS, and restrict production access on a need-to-know basis. No method of transmission or storage is 100% secure; you use the Service at your own risk. Notify us promptly of any suspected vulnerability or unauthorized access at generalinbox@overheadmeasure.com.
13. Do Not Track
Some browsers send "Do Not Track" signals. There is no uniform industry standard for responding; our Service does not currently respond to DNT signals specifically, beyond the controls described in this Policy.
14. Third-party links and tools
The Service may link to third-party sites (for example Stripe-hosted invoices or Clerk-hosted account flows). Their privacy practices are governed by their own policies, not this one.
15. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date will change when we do. Material changes may also be communicated by email or in-product notice. Continued use after an update means you accept the revised Policy.
16. Contact
Privacy questions or requests: generalinbox@overheadmeasure.com.
Related documents: Terms of Service · Accessibility Statement.
This Policy is written to be thorough for a SaaS measurement product. It is not legal advice. Have a lawyer review it for your entity, jurisdictions, and processor list as you grow.