1. Who is responsible for your data (controller)
Front Solutions AS, organisation number 933 375 250, Agnes torg 18, 3290 Stavern, Norway, is the data controller for personal data processed through Front Carbon CCS Map (the “Service”). Privacy contact: post@frontcarbon.com.
We have assessed that we are not required to appoint a Data Protection Officer under GDPR Article 37, because our core activities do not consist of large-scale, regular and systematic monitoring of individuals, nor large-scale processing of special-category data.
This policy explains what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and your rights under the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
2. What this policy covers
This policy concerns personal data about you as a user of the Service — free-tier visitors, registered account holders, and subscribers.
It is separate from the CCS and emissions information shown in the product, which describes industrial facilities and is compiled from public sources. Where that information includes the name of an operator who is a natural person (for example a sole proprietorship taken from a public register), that limited personal data is addressed in section 3.5.
3. What personal data we process
- 3.1 Account data — email address; password (stored only as a secure hash, never in plain text); account status and tier; and, if you choose to add them to your profile, your full name and phone number (both optional).
- 3.2 Subscription and billing data — subscription status, entitled region(s), seat count, and billing records. Card and payment details are processed by Stripe; we do not store full card numbers.
- 3.3 Usage data — events such as login, region views, and feature use, and a last-active timestamp on your profile, used for product analytics, security, and abuse detection (for example detecting credential sharing or scraping).
- 3.4 Technical data — IP address, browser/device information, and similar data generated when you use the Service, processed for security, operation, and abuse prevention. For aggregate visitor statistics we derive only a coarse country from the IP address; the IP address itself is not stored for that purpose.
- 3.5 Operator data in the product — the facility dataset may incidentally include the name of an operator who is a natural person, obtained from public registers. We process such data on the basis of our legitimate interest in providing an accurate market dataset (section 4). Because we obtain it from public sources rather than from the individual, individual notice would in most cases involve disproportionate effort (GDPR Article 14(5)(b)); the source categories are listed in our Terms of Use.
- 3.6 Team invitations— if an account holder invites a colleague, we store the invitee’s email address, the inviter, and the invitation status. If you were invited but never created an account, we hold your email address only to manage the invitation.
- 3.7 Communications — messages you send us (for example support emails).
We do not intentionally collect special categories of personal data, and you should not submit them.
4. Why we process it and the legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|
| Provide the Service; create and manage your account | Performance of a contract – Art. 6(1)(b) |
| Process subscriptions and grant access | Performance of a contract – Art. 6(1)(b) |
| Security, abuse detection, protecting the Service | Legitimate interests – Art. 6(1)(f) |
| Product analytics and improvement | Legitimate interests – Art. 6(1)(f) (or consent where required) |
| Manage team invitations | Legitimate interests – Art. 6(1)(f) |
| Operator names that are personal data in the product dataset | Legitimate interests – Art. 6(1)(f) (see 3.5) |
| Comply with legal and accounting obligations | Legal obligation – Art. 6(1)(c) |
| Respond to your enquiries | Legitimate interests – Art. 6(1)(f) |
We do not make decisions producing legal or similarly significant effects about you that are based solely on automated processing.
5. Cookies and similar technologies
We use only cookies and similar technologies that are strictly necessary to operate the Service; these do not require consent. We do not use advertising cookies, third-party analytics cookies, or cross-site tracking. The complete list:
| Name | What it does | Lifetime |
|---|
| Authentication cookie (Supabase) | Keeps you signed in. HttpOnly. | 7 days, refreshed while you use the Service |
| fc_geo | Throttles an anonymous daily per-country visit counter. Stores only today's date. HttpOnly. | 1 day |
| fc_anon_* (sessionStorage) | Limits anonymous funnel events to once per session. Never sent to third parties. | Cleared when the tab closes |
The map is rendered with Mapbox GL JS. We have disabled Mapbox's optional performance telemetry; the library still sends a minimal map-load event to Mapbox that is required for Mapbox's usage counting and billing (see section 6). If we introduce any non-essential analytics or tracking in the future, we will ask for your consent first and you will be able to withdraw it at any time.
6. Who we share data with (processors and recipients)
We share personal data only as needed to run the Service, with providers acting as our processors under data-processing agreements (DPAs):
- Stripe — payments and subscription management.
- Supabase — authentication, database, and file-storage hosting.
- Vercel — application hosting.
- Resend — transactional email delivery (welcome emails, team invitations, account notices).
- Mapbox — map tiles, styles, and fonts for the map display; the map library sends a minimal map-load event to Mapbox for usage counting and billing (optional performance telemetry is disabled).
- Cloudflare (Turnstile) — bot protection on sign-up and sign-in.
Some providers may process data outside Norway/the EEA (for example in the United States). Where they do, transfers are safeguarded by appropriate mechanisms, such as the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
We do not sell your personal data. We may disclose data where required by law or to establish, exercise, or defend legal claims.
7. How long we keep it
- Account data — for as long as your account is active; deleted or anonymised within 30 days after account closure, except where retention is required below.
- Billing and accounting records — five (5) years after the end of the relevant financial year, as required by the Norwegian Bookkeeping Act (bokføringsloven).
- Usage and technical logs — 12 months, then deleted or anonymised by an automated retention routine.
- Support communications — 12 months.
We delete or anonymise personal data when it is no longer needed.
8. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent at any time. Exercise these rights by contacting post@frontcarbon.com. We respond without undue delay and within one month, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), or with the supervisory authority in your EEA country of residence or work.
9. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, role-based access controls, and row-level access restrictions. No system is completely secure and we cannot guarantee absolute security. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours where required, and inform affected users without undue delay where the breach is likely to result in a high risk to them, in line with GDPR Articles 33 and 34.
10. Children
The Service is intended for use by adults (business and individual subscribers) and is not directed at children. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy. We will post the updated version with a new “last updated” date and, for material changes, provide reasonable notice.
12. Contact
Front Solutions AS, Agnes torg 18, 3290 Stavern, Norway · post@frontcarbon.com · organisation number 933 375 250.