Legal
Privacy Policy
Last updated 18 July 2026.
This policy explains how Geo-Parity ("we", "us") handles personal data when you use https://geo-parity.com. It is written to comply with the UK GDPR and the Data Protection Act 2018. Geo-Parity is designed to be privacy-first: the calculators run in your browser, and we collect as little as possible.
1. Who we are (data controller)
The data controller is Adam Simmons Spaans (United Kingdom). For any privacy question or to exercise your rights, contact info@geo-parity.com.
Suite 657, 80a Ruskin Avenue, Welling, DA16 3QQ, United Kingdom2. What we collect, why, and our legal basis
a. Tool inputs — not collected
The numbers you type into the calculators (income, savings, itinerary, team timezones,
etc.) are processed in your browser and are not sent to
or stored by us, except when you deliberately call a JSON API endpoint (e.g.
/api/calculate.json), in which case the parameters travel in the request URL
so the result can be computed. Those requests are not tied to your identity.
b. Account data — only if you register
If you create an account, we store your name,
email address, a
securely hashed password (we never store the password
itself), and — if you sign in with Google — the account identifier they return.
We also store session records to keep you signed in. This is handled by the open-source
better-auth library in a Cloudflare D1 database.
Legal basis: performance of a contract (providing the account you asked for).
c. Payment data — only if you buy something
Purchases are processed by Polar, which acts as our
merchant of record — meaning Polar, not us, is the seller
on your receipt and the party that charges and remits your local VAT or sales tax. Your card
details go straight to Polar and are
never seen or stored by us. We keep only what's needed to
know what you've bought: your Polar customer and subscription identifiers, the plan and its
status, and a record of one-off purchases — linked to your account. Polar also collects the
billing address and any tax ID it needs to calculate that tax, and holds your invoices; see
Polar's privacy policy.
Legal basis: performance of a contract (supplying the plan you bought), and legal
obligation for tax and accounting records.
d. Email we send you
Account emails — password resets and address confirmation — are sent through
Zoho ZeptoMail, from its EU data centre.
We do not track them. There is no open-tracking pixel
and no click tracking: the messages are plain text, so there is nothing to load and no
rewritten links, and we do not know whether you opened one. Tracking is switched off
explicitly on every message we send, not merely left at its default. They also carry no
unsubscribe link, deliberately — these are security emails you asked for, and an
unsubscribe on a password reset would silently stop future resets reaching you.
This is why we changed provider in August 2026: the one before added a tracking pixel
and an unsubscribe link to every message and would not let us remove either.
Legal basis: performance of a contract (sending the email you asked for), and
legitimate interest in the security of accounts.
e. API keys — only if you create one
If you create an API key we store a hash of it (never the
key itself), its short visible prefix, and per-hour request counts used to apply your rate
limit. Anonymous API traffic is counted against your IP address for the same purpose.
Legal basis: performance of a contract, and legitimate interest in protecting the
service from abuse.
f. Analytics — aggregate and cookieless
We may use Cloudflare Web Analytics, which is
privacy-first and cookieless: it records aggregate page
views and performance without setting cookies, without fingerprinting, and without
tracking you across sites.
Legal basis: our legitimate interest in understanding, in aggregate, how the site
is used.
f2. The adviser
If you ask the adviser a question, the question and any optional details you give (home
country, monthly income, household) are sent to our /api/adviser endpoint and
passed to an AI model run by Cloudflare Workers AI, which calls this site's own calculators
to answer. We do not store your question, the answer, your IP
address or anything that identifies you. What we keep is a daily count of model
calls and the compute they used, held for 30 days, so the adviser can stop before it costs
anything. A short-lived per-address rate-limit counter, like the one on our API, is
discarded within the hour. Answers are generated automatically from published figures and
are not financial, legal, tax or immigration advice.
Legal basis: performing the service you asked for, and our legitimate interest in
keeping it within its free limits.
f3. TypeSafe (paid plans only)
On a paid plan, three features use a decision model run by TypeSafe AI (San Francisco,
USA): the adviser, which sends your question and the details you gave so the model can
choose which of our calculators to run; the "which country fits me" tool, which sends the
preferences you type so they can be turned into slider settings; and, for paid API keys,
the name of an MCP tool that does not exist, so we can suggest the nearest real one.
Separately, if you email support@help.geo-parity.com, the subject, the first
4,000 characters of your message and the domain of your address (never the address
itself) are sent to TypeSafe to label the email by kind, so it reaches the right place; the
email itself is forwarded to our inbox unchanged. Nothing else is sent: no account details,
no IP address. TypeSafe states it does not train its models on customer data.
We store none of this text ourselves — only a daily count
of calls and their size per feature, held for 30 days, to keep spending within a fixed
ceiling. Apart from support email, free visitors never reach TypeSafe: every tool works for
them without it.
Legal basis: performing the service you asked for.
g. Link-click and referral counts
When an outbound affiliate/sponsored link is clicked, the browser sends a minimal
fire-and-forget beacon to our /api/event endpoint recording the link's id and
the page path. It contains no cookies, no user identifier, and is
not stored in a database — it is an aggregate counter written to our server logs.
The banking tool holds a register of banks and money apps that is not published: a provider is shown only where we have a partner relationship with it, and none is shown today. Nothing about which countries or providers you look at is recorded.
If your browser exposes tools to an AI agent (the WebMCP browser API, currently a Chrome
and Edge trial), our pages register their calculators with it. When such an agent uses one,
the call goes to our /api/mcp endpoint exactly like any other API call, marked
with a request header so we can count it. What we keep is a
daily total of tool calls held for 90 days — no cookie, no
identifier, and nothing that could distinguish one visitor from another. The
registration itself sends one beacon per page saying how many tools were registered, which
is logged and not stored.
Separately, if you arrive from another site the same beacon reports the referring
website address only — never the full link, never a search
or conversation — together with the section of our site you landed on. We keep a count
only when the referrer is an AI assistant, so that we can
tell whether being read by AI systems actually sends anyone here; every other referrer is
discarded on arrival and never stored. What is kept is a daily total per assistant per
section (for example, “perplexity.ai → 4”), held for 90 days.
It contains no cookie, no identifier, and nothing that could distinguish one visitor from
another.
Legal basis: legitimate interest in measuring, in aggregate, which links and
sources are useful.
If you arrive by clicking one of our own adverts or a link we have tagged, the address you
land on carries labels such as utm_source=facebook. The same beacon reports
those labels and we keep a daily count per advert — the
source, the medium and the campaign name we chose, and nothing else. We do this because our
analytics provider cannot see them, so it is the only way to tell whether an advert we paid
for brought anyone here. Click identifiers that platforms add to identify one click
(fbclid, gclid and the like) are
never read or stored, nor is the page you landed on. A
visit with no such label sends nothing at all. Counts are held for 180 days and contain no
cookie and no identifier.
Legal basis: legitimate interest in knowing whether our own advertising works.
h. Server logs
Our host records standard technical request data (such as IP address, timestamp, and user
agent) transiently for security and to keep the service running.
Legal basis: legitimate interest in the security and integrity of the service.
3. Cookies & local storage
We use only strictly-necessary and functional storage — there are no advertising or cross-site tracking cookies, so no consent banner is required. Analytics, if enabled, is cookieless.
| Name | Type | Purpose |
|---|---|---|
| better-auth session | Cookie | Keeps you signed in after login. Only set if you have an account. |
theme | Local storage | Remembers your light/dark preference. |
geo-home | Local storage | Remembers your chosen home country and currency so tools default to them. |
4. Who processes your data (sub-processors)
- Cloudflare — hosting, the D1 database that stores accounts, and cookieless analytics.
- Google — only if you choose to sign in with it, to authenticate you.
- Zoho (ZeptoMail) — sending account emails (password reset, address confirmation), processed in the EU.
- Polar — merchant of record: payment processing, subscription billing, invoicing, and VAT/sales-tax calculation and remittance, only if you buy a plan.
We do not sell your personal data, and we do not share it for advertising.
5. International transfers
Geo-Parity runs on Cloudflare's global edge network, so data may be processed on servers outside the UK. Where that happens, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum / Standard Contractual Clauses.
6. How long we keep it
Account data is kept for as long as your account exists; if you delete your account, it is removed. Sessions expire automatically. Payment and invoice records are kept by Polar and by us for as long as tax and accounting law requires, even after an account is deleted. Rate-limit counters are discarded within a few hours. Aggregate analytics and log data are retained only for a limited period in line with our host's defaults.
7. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing;
- data portability; and
- withdraw consent where processing relies on it.
To exercise any of these, email info@geo-parity.com. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO).
8. Children
Geo-Parity is not directed at children under 13, and we do not knowingly collect their data.
9. Changes
We may update this policy; material changes will be reflected by the "last updated" date above. Continued use after an update means you accept the revised policy.
Related: Terms of Use · Affiliate & Sponsorship Disclosure · About.