Cirrosense Privacy Policy
Effective Date: October 8, 2025
1. Introduction
Cirrosense (“Company,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you access or use our software-as-a-service (“SaaS”) REST API that provides weather forecasts (the “Service”).
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service.
2. Scope
This Privacy Policy applies to personal information collected from users located in the United States and Canada, including information collected through our website, API endpoints, and related services.
The Service is intended and offered only for residents of the United States and Canada. It is not directed to, or intended for use by, individuals located in the European Union, the United Kingdom, or the European Economic Area, and we do not market or offer the Service to such individuals. If you are located outside the United States or Canada, please do not use the Service or provide us with personal information.
3. Information We Collect
We collect only the information necessary to operate and maintain the Service, as described below:
- Account Information: When you register for an account, we collect your email address.
- Billing Information: When you subscribe to a paid plan, our payment processor (Stripe) provides us with limited billing details, including your billing name, email address, card type, the last four digits of your payment card, and your subscription status. We use this information solely to manage billing and subscriptions; we never sell it or use it for any other purpose.
- Cookies and Session Data: We use session cookies to maintain user authentication and access control.
- Network Data: We collect IP addresses for rate limiting and abuse prevention purposes.
- Usage Logs: We collect logs containing request timestamps, API endpoints accessed, and performance metrics for security, diagnostics, and system maintenance.
We do not collect payment card numbers or unnecessary personal data.
4. Use of Information
We use the information described above for the following purposes:
- To provide, operate, and maintain the Service;
- To authenticate and manage user sessions;
- To monitor and prevent fraudulent or abusive activity;
- To analyze usage for reliability, performance, and troubleshooting;
- To process payments and subscriptions via third-party payment processors (Stripe); and
- To comply with applicable legal obligations.
We do not sell, rent, or use personal information for advertising or marketing purposes.
5. Payment Processing
Payments are processed by Stripe, Inc. (“Stripe”). When you make a payment, Stripe collects and processes your payment information on our behalf in accordance with its Privacy Policy.
6. Service Providers
We may engage third-party service providers to facilitate our operations. These include:
- Amazon Web Services (AWS): For hosting and infrastructure; and
- Stripe: For payment processing.
Each third-party provider is contractually obligated to protect the confidentiality and security of personal information and to use it only for the purposes specified by Cirrosense.
7. Data Retention
We retain personal information only as long as necessary to fulfill the purposes described in this Policy or as required by law.
Usage logs and related technical data are typically retained for up to ninety (90) days for debugging, performance, and security purposes, unless longer retention is required to investigate or resolve service issues.
8. Data Security
We employ administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit (TLS/HTTPS), role-based access controls, and continuous system monitoring.
While we strive to use commercially reasonable means to protect your personal information, no method of transmission or storage is completely secure.
9. International Data Transfers
Your information may be processed and stored in data centers located in Canada and the United States.
These jurisdictions may have data protection laws different from those of your region. Where your consent is required for such transfers, we will obtain it; otherwise, we rely on this notice and applicable legal bases to process and transfer your information.
We take appropriate steps to ensure that personal information is treated securely and in accordance with this Policy and applicable laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and relevant U.S. state privacy laws such as the California Consumer Privacy Act (CCPA) where applicable.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- The right to access and obtain a copy of your personal data;
- The right to request correction of inaccurate or outdated information;
- The right to request deletion of your personal data, including your account information, subject to applicable legal exceptions;
- The right to withdraw consent to processing where consent was provided;
- The right not to receive discriminatory treatment for exercising any of these rights; and
- The right to file a complaint with a regulatory authority.
Requests to exercise these rights may be submitted by contacting us at support@cirrosense.com.
11. Cookies
We use minimal session cookies strictly necessary for authentication and access control. You may disable cookies in your browser; however, doing so may limit functionality of the Service.
12. Disclosure of Information
We may disclose personal information:
- To comply with a legal obligation, subpoena, or lawful request by public authorities;
- To protect the rights, property, or safety of Cirrosense, our users, or the public; or
- In connection with a merger, acquisition, or sale of assets, provided that appropriate confidentiality and data protection safeguards are in place.
13. Children's Privacy
The Service is not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we become aware that a child has provided us personal data, we will take steps to delete it promptly.
14. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. The “Effective Date” at the top of this document indicates when the latest version took effect. Material changes will be communicated via email or a prominent notice on our website.
15. Contact Information
If you have any questions or concerns regarding this Privacy Policy, please contact us at: