Privacy Policy
Last updated:
1. Introduction
Thorpe Land Services ("we," "our," or "us") operates the Ironwood Terminal platform and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
2.1 Information You Provide
- Name, email address, phone number
- Commission information (notary commission number, expiration date)
- Payment information (processed securely through Stripe)
- Profile information and preferences
- Session recordings and journal entries (for notarization services)
2.2 Automatically Collected Information
- Device information and IP address
- Browser type and version
- Usage data and analytics
- Cookies and similar tracking technologies
2.3 Location Information and Privacy Protection
Privacy-First Directory Design: We implement location fuzzing to protect your privacy while maintaining directory functionality.
- Public Directory Listings: We only display county and a fuzzed ZIP code prefix (first 3 digits, e.g., 78700 instead of 78701). Full street addresses are never shown in public listings.
- Private Storage: Full addresses are stored securely in our database with restricted access (admin-only) and are never exposed in public APIs or directory searches.
- Location Fuzzing: ZIP codes are automatically fuzzed to protect approximately 100 addresses per ZIP prefix, preventing precise location tracking while maintaining sufficient granularity for local searches.
- Opt-Out Available: Officers can opt out of public directory listings entirely if desired.
This privacy-first approach protects officers from doxxing, stalking, and unwanted visitors while still allowing clients to find notaries in their general area.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and manage subscriptions
- Send you service-related communications
- Comply with legal obligations and notary regulations
- Prevent fraud and ensure security
- Analyze usage patterns to improve user experience
4. Data Sharing and Disclosure
We do not sell your personal information.
We may share your information only in the following circumstances:
4.1 Service Providers and Data Processors
We use the following third-party service providers who process your data on our behalf:
- Supabase (Supabase, Inc.) - Data storage, authentication, and database services. Data is stored in the United States. See Supabase Privacy Policy: https://supabase.com/privacy
- Stripe (Stripe, Inc.) - Payment processing. Payment information is processed directly by Stripe and never stored on our servers. See Stripe Privacy Policy: https://stripe.com/privacy
- OpenAI (OpenAI, L.L.C.) - AI/ML processing for content analysis and parsing. Data may be processed in the United States. See OpenAI Privacy Policy: https://openai.com/privacy
- Resend (Resend, Inc.) - Email delivery services. Data processed in the United States. See Resend Privacy Policy: https://resend.com/privacy
- Vercel (Vercel, Inc.) - Hosting and infrastructure services. See Vercel Privacy Policy: https://vercel.com/legal/privacy-policy
- BlueNotary (BlueNotary, Inc.) - Remote Online Notarization (RON) platform services for video sessions, identity verification, and session recording. Data processed in the United States. See BlueNotary Privacy Policy: https://www.bluenotary.us/privacy-policy
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.2 Legal Requirements
When required by law, court order, or government regulation, including but not limited to:
- Compliance with Texas Government Code and notary regulations for record-keeping
- Responding to valid legal process (subpoenas, court orders)
- Protecting our rights, property, or safety, or that of our users or others
- Investigating fraud, security issues, or violations of our Terms
4.3 Notary Compliance
As required by Texas Government Code and notary regulations for record-keeping and audit purposes.
4.4 Business Transfers
In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
4.5 With Your Consent
When you explicitly authorize us to share your information with third parties.
5. Data Security
We implement industry-standard security measures to protect your information:
- AES-256 encryption for data at rest
- TLS/SSL encryption for data in transit
- Access controls and authentication
- Regular security audits and monitoring
- Compliance with Texas Government Code requirements for electronic notarization
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6. Your Rights and Choices
You have the right to:
- Access and receive a copy of your personal data
- Correct inaccurate or incomplete information
- Request deletion of your account and data (subject to legal retention requirements)
- Opt-out of marketing communications
- Disable cookies through your browser settings
To exercise these rights, contact us at daniel@thorpeland.com. You can also export your data directly from your account settings.
6A. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about categories and specific pieces of personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information (subject to legal exceptions)
- Right to Opt-Out: Opt-out of the sale of personal information (we do not sell your information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, contact us at daniel@thorpeland.com. We will respond within 45 days.
In the past 12 months, we have collected the following categories of personal information: Identifiers (name, email, phone), Commercial information (subscription data), Internet activity (usage data), and Professional information (notary commission data).
7. Data Retention
We retain your information for different periods depending on the type of data:
- Account Information: Retained while your account is active and for 90 days after account deletion (for fraud prevention and legal compliance)
- Notary Journal Entries and Session Records: Retained permanently in accordance with Texas Government Code § 406.014 and notary record-keeping requirements
- Financial Records: Retained for 7 years as required by tax and accounting regulations
- Cookie Consent Records: Retained for 2 years
- Analytics Data: Retained for 2 years in aggregated, anonymized form
- Legal Acceptance Records: Retained indefinitely for legal compliance and audit purposes
After the retention period, we securely delete or anonymize your information, except where legal requirements mandate longer retention.
7A. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users within 72 hours of discovery (or as required by applicable law)
- Provide clear information about what data was affected
- Explain steps we are taking to address the breach
- Offer guidance on protective measures you can take
- Report to relevant authorities as required by law (including Texas Attorney General for breaches affecting 250+ Texas residents)
Notifications will be sent via email to the address associated with your account. We will also post notices on our website for significant breaches.
8. International Data Transfers
Our Service is operated from the United States. If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where our servers are located and our central database is operated.
By using our Service, you consent to the transfer of your information to the United States and processing in accordance with this Privacy Policy and applicable U.S. laws.
We implement appropriate safeguards to protect your information during transfer, including encryption and contractual protections with our service providers.
9. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically.
For material changes, we may also notify you via email or through a notice on our Service. Your continued use of the Service after changes become effective constitutes acceptance of the modified Privacy Policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us: