Our commitment to data protection
At a glance
As a German business, founded and run by EU (German) citizens who value privacy, we are fully committed to GDPR and to data protection best practices.
The essentials:
- Your data stays in the EU. Our website and geocoding servers are hosted in the EU.
- Geocoding queries are deleted after six months and are never used to train AI or machine learning systems.
-
You can opt out of query logging entirely
using the
no_recordparameter — we then keep no record of your query. - We do not sell your data, ever.
- You can delete your account and billing details at any time from your dashboard.
- Business customers: our Data Processing Agreement is linked below.
On this page
What data do we collect?
What we store depends on how you use OpenCage. Find the description that fits you below.
If you are a visitor to our website
Our website (as opposed to our geocoding API) is hosted by Heroku, a division of SalesForce, in Europe.
We use Fathom Analytics to understand, in anonymized form, how the site is being used. Fathom does not track or store any personal data and has a privacy-first focus, and our account is configured so that all data collected stays entirely in the EU. To display maps on our geocoding demo page we use map tiles from Thunderforest.
Occasionally people try to abuse our demo page or to sign up for many accounts to exploit our free trial. In those cases we may use hCaptcha to verify that requests come from a real person and prevent abuse. See our blog post to learn more.
If you are a free trial user
When registering for our service you provide an email address, which we confirm by emailing you a link. We need it so we can contact you about changes to our service or to this policy. Confirmation and service emails are sent via Postmark, operated by ActiveCampaign.
We store the IP address you used when you register, so we can detect when people try to abuse the service by registering multiple accounts.
At registration we optionally ask for (but do not require) a few other details such as your name, how you discovered us, and which programming languages you use, so we can better help you get started. Your answers are stored in a database within Heroku, are accessible to our employees, and are visible to you on your account dashboard. Our user database is encrypted and regularly backed up to rsync.net in Switzerland, which has no ability to decrypt this information.
Registering requires acceptance of our publicly available terms and conditions. Our public status page is hosted by Instatus.
If you are an API or geosearch user
Our geocoding and geosearch servers are leased from Hetzner, and are physically located at multiple sites in the EU (Germany and Finland). All of Hetzner's datacenters are certified in accordance with DIN ISO/IEC 27001, an internationally recognized standard for information security.
When you send us a geocoding API request we send you a response and then
log the request.
While you should only ever be sending us
geographic data and NOT personal data, if you use
the optional
no_record
parameter
when calling the geocoding API, we will not store your query when we log the request.
In this case we have no record of what the query was.
We encourage you to use this parameter.
We may later analyze the logs to see how we can improve our service. All logs are deleted after six months.
For the avoidance of any doubt, user queries (free trial or paying customers) are not used to train AI or machine learning (ML) systems in any way.
If you are a paying customer
If you become a paying customer (as opposed to just testing our free trial) you provide us and our payment partners with valid billing information. Billing is handled by Stripe and invoicing by Quaderno. We can see your name, billing address, email address, and VAT number (if provided). We cannot see your credit card number — only Stripe has access to that. Once you are no longer a customer you can delete your billing information with a single click in your account dashboard.
As you would expect of any business, we share transaction data with our accountants and the relevant tax authorities so that we can pay VAT and file our annual tax return. We also use the business analytics service Baremetrics for internal analysis; it holds details of customer purchasing history.
Third-party subprocessors
The services below help us operate OpenCage. Each is described in the relevant section above.
| Service | Impacts | Purpose | Location | Privacy / GDPR policy |
|---|---|---|---|---|
| Heroku (Salesforce) | Website visitors | Hosting (website) | EU | Policy |
| Fathom Analytics | Website visitors | Site analytics | EU | Policy |
| Thunderforest | Website visitors | Map tiles (on demo page) | EU | Policy |
| hCaptcha | Website visitors | Abuse / bot prevention | US | Policy |
| Postmark (ActiveCampaign) | Registered users | Transactional emails | US | Policy |
| rsync.net | Registered users | Database backups, encrypted | CH | Policy |
| Instatus | Website visitors | Hosting (status page) | EU | Policy |
| Hetzner | geocoding API & geosearch users | Hosting | EU | Security (pdf) |
| Stripe | Customers | Payment processing | EU / US | Policy |
| Quaderno | Customers | Invoicing | EU | GDPR |
| Baremetrics | Customers | Business analytics | US | GDPR |
Data Processing Agreement
By becoming a customer of our service, you agree to our Data Processing Agreement, unless otherwise explicitly agreed with us in writing.
Data deletion & retention
Any user (paid or free trial) can request to have their account deleted at any time, from your account dashboard or by contacting us. Beyond that, here is how long each type of data is kept:
| Data | Retention |
|---|---|
|
Geocoding query logs
See note above about use of no_record
parameter.
|
Deleted after six months |
| Inactive free trial accounts | Deleted automatically after three months |
| Uploaded spreadsheets / CSV files (free trial) | Deleted after 3 days |
| Uploaded spreadsheets / CSV files (paying customers) | Deleted after 30 days |
| Completed transaction records | Retained as required by tax law |
A free trial account is considered inactive if it has made no API request and no dashboard login during the retention period above.
Technical & organisational measures (TOMs)
In line with Art. 32 GDPR ("Security of processing"), we maintain the technical and organisational measures below to protect personal data. They are reviewed regularly and updated as our service evolves.
Confidentiality
- Physical access control. Our servers are hosted by Hetzner in data centres in the EU (Germany and Finland) that are certified to DIN ISO/IEC 27001. Physical access is controlled by the data centre operator via access control systems, video surveillance, and 24/7 monitoring.
- Logical access control. Access to production systems requires individual, named accounts, strong authentication, and SSH keys rather than passwords. Two-factor authentication is enforced on the critical third-party services we rely on.
- Authorisation control. Access to personal data follows the principle of least privilege: employees are granted only the access needed for their role. Administrative access is limited to a small number of authorised staff.
- Data minimisation. We collect only the data we need. Customers can use the optional no_record parameter so that geocoding queries are never stored at all.
- Separation control. Test, development, and production environments are kept separate. Different customers' data is logically separated within our systems.
Integrity
- Encryption. All traffic to our website is encrypted in transit via TLS/HTTPS. User database backups are encrypted before leaving our systems.
- Transfer control. Backups are stored with rsync.net in Switzerland, which has no ability to decrypt them. Payment card data is handled exclusively by Stripe; we never see or store card numbers.
- Input / accountability control. Access to and changes within production systems are logged, allowing us to trace relevant activity.
Availability & resilience
- Backups. Our user database is regularly and automatically backed up to an encrypted, geographically separate location.
- Redundancy. Our geocoding infrastructure runs across multiple sites in the EU to provide resilience and continued availability.
- Monitoring. Systems are continuously monitored, with a public status page for service availability.
- Deletion & retention. Personal data is deleted according to our published retention schedule — for example, geocoding query logs are deleted after six months. Queries are never used to train AI or machine learning systems.
Regular review, assessment & evaluation
- Vulnerability management. We publish our security policy, accept security reports at security @ opencagedata.com, and run a security bounty program.
- Subprocessor management. We select subprocessors that offer sufficient guarantees under the GDPR, and list them transparently in the subprocessors table above.
- Data protection by design and by default. Privacy considerations are built into how we design and operate our service, including offering opt-out query logging and keeping data within the EU.
- Ongoing review. These measures are reviewed periodically and whenever our infrastructure or processing activities change materially.
Reporting issues
We make every effort to keep your data secure. If you find a vulnerability please report it to security @ opencagedata.com, we will follow up with you promptly. You can find our public key on our security.txt. Thank you.
We welcome vulnerability reports via our security bounty program.
Stay informed
Meaningful changes to this document will be announced on our Mastodon account and our blog.
Have questions?
Should you have any questions about this topic feel free to write to us at dataprotection @ opencagedata.com or via our contact form.
Change history
This document was last edited on 13 July 2026. Show full history.
| 13 July 2026 | Added explicit list of TOMs. |
| 3 July 2026 | Page reformatted to improve readability, no content changes. |
| 4 May 2026 |
|
| 20 July 2025 | Removed mention of Reform.app, we no longer use it. |
| 18 Feb 2025 | Our legal headquarters has moved to Berlin: blog post |
| 23 Jan 2025 | Add mention of how long spreadsheets are kept in Data Deletion section. |
| 15 Sep 2024 | Inactive free trial accounts are now deleted after three months (previously six). |
| 13 Sep 2022 | Add that servers are within the EU but not only Germany. There are servers in Finland. |
| 13 Nov 2021 | Note that our Fathom Analytics account is now set such that all data is collected and stays within the EU. |
| 16 Oct 2021 | Our legal headquarters has moved to Hannover: blog post |
| 15 Sep 2021 | Added mention of using Reform for early access lists. |
| 23 Jan 2021 | Remove reference to map view as it was turned off in Sept. 2020 |
| 15 Dec 2020 | Make it clear card details can be deleted once no longer a customer |
| 2 June 2020 | Minor design tweak, added mention of CAPTCHAs in sign up process |
| 30 Apr 2020 | Added link to our security bounty program |
| 1 Oct 2019 | Added link to Hetzner's security certification |
| 12 Jul 2019 | Service is now operated by OpenCage GmbH, Brexit section removed |
| 29 May 2019 | Added link to blog post with details of transition of operations to OpenCage GmbH |
| 11 Apr 2019 | OpenCage Data Ltd is now 100% subsidiary of OpenCage GmbH |
2,500 geocoding API requests/day - No credit card required