Front Carbon
AdvisoryOur PlatformCCS MapAbout
Talk to us
AdvisoryOur PlatformCCS MapAbout
Sign in
PlatformClient sign inMapExplorerTalk to us
Legal

Privacy Policy

Front Carbon CCS Map·Version 3·Last updated 02.07.2026·Front Solutions AS
Contents
1. Who is responsible for your data (controller)2. What this policy covers3. What personal data we process4. Why we process it and the legal basis5. Cookies and similar technologies6. Who we share data with (processors and recipients)7. How long we keep it8. Your rights9. Security10. Children11. Changes to this policy12. Contact

1. Who is responsible for your data (controller)

Front Solutions AS, organisation number 933 375 250, Agnes torg 18, 3290 Stavern, Norway, is the data controller for personal data processed through Front Carbon CCS Map (the “Service”). Privacy contact: post@frontcarbon.com.

We have assessed that we are not required to appoint a Data Protection Officer under GDPR Article 37, because our core activities do not consist of large-scale, regular and systematic monitoring of individuals, nor large-scale processing of special-category data.

This policy explains what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and your rights under the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

2. What this policy covers

This policy concerns personal data about you as a user of the Service — free-tier visitors, registered account holders, and subscribers.

It is separate from the CCS and emissions information shown in the product, which describes industrial facilities and is compiled from public sources. Where that information includes the name of an operator who is a natural person (for example a sole proprietorship taken from a public register), that limited personal data is addressed in section 3.5.

3. What personal data we process

  • 3.1 Account data — email address; password (stored only as a secure hash, never in plain text); account status and tier; and, if you choose to add them to your profile, your full name and phone number (both optional).
  • 3.2 Subscription and billing data — subscription status, entitled region(s), seat count, and billing records. Card and payment details are processed by Stripe; we do not store full card numbers.
  • 3.3 Usage data — events such as login, region views, and feature use, and a last-active timestamp on your profile, used for product analytics, security, and abuse detection (for example detecting credential sharing or scraping).
  • 3.4 Technical data — IP address, browser/device information, and similar data generated when you use the Service, processed for security, operation, and abuse prevention. For aggregate visitor statistics we derive only a coarse country from the IP address; the IP address itself is not stored for that purpose.
  • 3.5 Operator data in the product — the facility dataset may incidentally include the name of an operator who is a natural person, obtained from public registers. We process such data on the basis of our legitimate interest in providing an accurate market dataset (section 4). Because we obtain it from public sources rather than from the individual, individual notice would in most cases involve disproportionate effort (GDPR Article 14(5)(b)); the source categories are listed in our Terms of Use.
  • 3.6 Team invitations— if an account holder invites a colleague, we store the invitee’s email address, the inviter, and the invitation status. If you were invited but never created an account, we hold your email address only to manage the invitation.
  • 3.7 Communications — messages you send us (for example support emails).

We do not intentionally collect special categories of personal data, and you should not submit them.

4. Why we process it and the legal basis

PurposeLegal basis (GDPR Art. 6)
Provide the Service; create and manage your accountPerformance of a contract – Art. 6(1)(b)
Process subscriptions and grant accessPerformance of a contract – Art. 6(1)(b)
Security, abuse detection, protecting the ServiceLegitimate interests – Art. 6(1)(f)
Product analytics and improvementLegitimate interests – Art. 6(1)(f) (or consent where required)
Manage team invitationsLegitimate interests – Art. 6(1)(f)
Operator names that are personal data in the product datasetLegitimate interests – Art. 6(1)(f) (see 3.5)
Comply with legal and accounting obligationsLegal obligation – Art. 6(1)(c)
Respond to your enquiriesLegitimate interests – Art. 6(1)(f)

We do not make decisions producing legal or similarly significant effects about you that are based solely on automated processing.

5. Cookies and similar technologies

We use only cookies and similar technologies that are strictly necessary to operate the Service; these do not require consent. We do not use advertising cookies, third-party analytics cookies, or cross-site tracking. The complete list:

NameWhat it doesLifetime
Authentication cookie (Supabase)Keeps you signed in. HttpOnly.7 days, refreshed while you use the Service
fc_geoThrottles an anonymous daily per-country visit counter. Stores only today's date. HttpOnly.1 day
fc_anon_* (sessionStorage)Limits anonymous funnel events to once per session. Never sent to third parties.Cleared when the tab closes

The map is rendered with Mapbox GL JS. We have disabled Mapbox's optional performance telemetry; the library still sends a minimal map-load event to Mapbox that is required for Mapbox's usage counting and billing (see section 6). If we introduce any non-essential analytics or tracking in the future, we will ask for your consent first and you will be able to withdraw it at any time.

6. Who we share data with (processors and recipients)

We share personal data only as needed to run the Service, with providers acting as our processors under data-processing agreements (DPAs):

  • Stripe — payments and subscription management.
  • Supabase — authentication, database, and file-storage hosting.
  • Vercel — application hosting.
  • Resend — transactional email delivery (welcome emails, team invitations, account notices).
  • Mapbox — map tiles, styles, and fonts for the map display; the map library sends a minimal map-load event to Mapbox for usage counting and billing (optional performance telemetry is disabled).
  • Cloudflare (Turnstile) — bot protection on sign-up and sign-in.

Some providers may process data outside Norway/the EEA (for example in the United States). Where they do, transfers are safeguarded by appropriate mechanisms, such as the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

We do not sell your personal data. We may disclose data where required by law or to establish, exercise, or defend legal claims.

7. How long we keep it

  • Account data — for as long as your account is active; deleted or anonymised within 30 days after account closure, except where retention is required below.
  • Billing and accounting records — five (5) years after the end of the relevant financial year, as required by the Norwegian Bookkeeping Act (bokføringsloven).
  • Usage and technical logs — 12 months, then deleted or anonymised by an automated retention routine.
  • Support communications — 12 months.

We delete or anonymise personal data when it is no longer needed.

8. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent at any time. Exercise these rights by contacting post@frontcarbon.com. We respond without undue delay and within one month, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), or with the supervisory authority in your EEA country of residence or work.

9. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, role-based access controls, and row-level access restrictions. No system is completely secure and we cannot guarantee absolute security. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours where required, and inform affected users without undue delay where the breach is likely to result in a high risk to them, in line with GDPR Articles 33 and 34.

10. Children

The Service is intended for use by adults (business and individual subscribers) and is not directed at children. We do not knowingly collect personal data from anyone under 18.

11. Changes to this policy

We may update this policy. We will post the updated version with a new “last updated” date and, for material changes, provide reasonable notice.

12. Contact

Front Solutions AS, Agnes torg 18, 3290 Stavern, Norway · post@frontcarbon.com · organisation number 933 375 250.

This Privacy Policy applies to Front Carbon CCS Map. Customers will be notified of material changes.

Front Carbon

Front Carbon is an independent advisory for CCS logistics. Our platform is the engine behind our work; the Map is open to all.

Platform

OverviewCapabilities

Map

OverviewWhat you’ll seeOpen the map

Company

AdvisoryAboutLegal

Get in touch

Contactpost@frontcarbon.comSign in
© 2026 Front Solutions AS, trading as Front Carbon. All rights reserved. Org. nr. 933 375 250.