BarrioRadar BarrioRadar ← Back to App

Privacy Policy

Last updated: September 10, 2026 • Compliant with GDPR (Regulation EU 2016/679) & Spanish Organic Law 3/2018 (LOPDGDD)

1. Data Controller

This Privacy Policy applies to the location intelligence platform accessible at barrioradar.com ("BarrioRadar", "we", "us").

Data Controller: Martin Wells, operating BarrioRadar in Spain.

Privacy Contact: For privacy inquiries, data subject requests, or to exercise your statutory rights, contact: info@barrioradar.com.

We process personal data in accordance with the European General Data Protection Regulation (Regulation EU 2016/679 — GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).

2. Personal Data We Collect

We apply strict data minimization principles and only collect information necessary to provide property location analysis, manage purchase credits, and maintain server security:

A. Account & Sign-In Data

  • Email Address: When you sign in to BarrioRadar, you provide your email address to receive a secure, passwordless sign-in link (magic link).
  • Session Authentication Token: Upon verifying a sign-in link, a secure authentication token is generated and stored locally in your browser to maintain your sign-in state and authorize your requests. We do not use or store passwords.
  • Temporary Sign-In Links: When requesting a sign-in link, a cryptographically secure token hash is stored with an expiry time of 15 minutes.

B. Orders & Entitlement Records

  • Credit Packs: When you purchase analysis credit packs (Single Property, Property Hunter, or Professional), we record the transaction amount, currency, order reference, and your remaining analysis credits.
  • Permanently Unlocked Properties: When you unlock a full property analysis using an available credit or direct purchase, we record the property coordinates and verified address associated with your account. Once unlocked, the analysis remains permanently unlocked for your account and can be viewed or re-downloaded at any time without using additional credits.
  • Payment Details: Payments are processed directly by Stripe. BarrioRadar never receives, processes, or stores your credit card numbers, expiration dates, security codes (CVV), or bank details.

C. Search & Technical Logs

  • Public Address Searches: Public address searches entered into the search bar are resolved in real time against official Spanish cartographic data. Search query strings are processed in memory and are not saved to our database.
  • Security & Rate-Limiting Logs: We log client IP addresses and timestamps when sign-in links are requested or authenticated endpoints are accessed, strictly to enforce rate limiting and protect against automated abuse.

3. Lawful Bases for Processing (GDPR Art. 6)

Purpose Categories of Personal Data Lawful Basis
Account sign-in & session management Email address, session token, temporary sign-in link hash Performance of a Contract (Art. 6(1)(b))
Delivering credit packs & maintaining unlocked property dossiers Order references, credit balance, unlocked property coordinates, address Performance of a Contract (Art. 6(1)(b))
Commercial accounting & tax records Transaction amounts, currency, payment provider transaction IDs, timestamps Legal Obligation (Art. 6(1)(c))
Rate limiting, API security & abuse prevention Client IP address, request timestamps Legitimate Interests (Art. 6(1)(f))
Optional audience measurement analytics Pseudonymous analytics client identifier (GA4) Consent (Art. 6(1)(a))

4. Cookies & Browser Storage

  • No Server Cookies: Our web server sets zero HTTP cookies.
  • Browser Local Storage: We use your browser's local storage solely for functional operation:
    • barrioradar_lang: Your interface language preference (English, Spanish, German, or French).
    • barrioradar_consent_choice: Your cookie banner selection (granted or denied).
    • barrioradar_auth_session: Your signed-in user session token and account state.
  • Google Analytics (Opt-In Only): We use Google Analytics 4 to measure website usage and performance. By default, the Google Analytics script is completely absent and not loaded on the page. No analytics cookies are set and no data is transmitted unless you click "Accept" on our consent banner. If accepted, Google Analytics sets cookies (_ga, _ga_*) to distinguish unique visits. All advertising features, remarketing, and ad personalization are disabled. You can revoke consent at any time.

5. Service Providers & Data Processors

We work only with technical service providers necessary to operate the platform:

  • Hosting & Infrastructure: BarrioRadar's application and database servers are hosted in Paris, France by Hostinger.
  • Transactional Email: Hostinger International Limited (European infrastructure). Used exclusively to deliver 15-minute sign-in magic links.
  • Payment Gateway: Stripe Payments Europe, Ltd. (Ireland). Processes payment card transactions. Stripe acts as a processor for checkout services and an independent controller for fraud prevention and financial compliance. Any onward transfer to Stripe, Inc. (USA) is governed by the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs).
  • Analytics (Opt-in): Google Ireland Limited. Used only upon explicit affirmative consent under the EU-U.S. Data Privacy Framework (DPF).

6. Data Retention & Automatic Cleanup

  • Security & Technical Logs: IP rate-limiting logs and expired/used sign-in link records are automatically purged after 90 days by an automated cleanup mechanism.
  • Temporary Sign-In Links: Become unusable and expire after 15 minutes.
  • Unlocked Property Analyses: Retained for the duration of your account so that the property remains unlocked for your account.
  • Commercial & Transaction Records: In accordance with the Spanish Commercial Code (Código de Comercio, Art. 30.1), commercial transaction documentation and order records are preserved for 6 years.
  • Account Profiles: Retained until you request account deletion, subject to statutory preservation requirements for financial records.

7. Your Rights Under GDPR

Under the GDPR and Spanish LOPDGDD, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate information.
  • Right to Erasure (Art. 17): Request deletion of your account and personal data, subject to legal record-keeping obligations.
  • Right to Restriction of Processing (Art. 18): Restrict the processing of your data under statutory conditions.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Revoke analytics consent at any time.

To exercise your rights or request account deletion, contact us at: info@barrioradar.com.

Right to Lodge a Complaint: You have the right to lodge a complaint with the Spanish Data Protection Agency: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid (www.aepd.es).

8. Chrome Extension Privacy Practices

Our browser extension (BarrioRadar — Idealista Location Intelligence) adheres to strict privacy standards:

  • Permitted Domains: The extension operates only on property listing pages on Idealista (idealista.com) and official Spanish Cadastre portals (sedecatastro.gob.es). It does not function on other portals.
  • Listing Location Extraction: Reads only the visible property listing location text or map coordinates on the active page to query BarrioRadar's public autocomplete API.
  • No Personal Data or Browsing History: The extension does not collect, record, or transmit user identity, account tokens, cookies, form inputs, or browsing history. API queries sent to BarrioRadar are completely anonymous.
  • In-Memory Caching: Official Cadastral References (RC) resolved during browsing are cached strictly in memory for the duration of the active page session and are not stored in permanent storage. chrome.storage.local is used only for optional developer base URL overrides.
  • Zero Data Monetization: No extension data is ever sold, transferred, or monetized.