Portal Privacy policy

Effective July 24, 2026

This policy covers the Zip Code Report subscriber portal — the account area operated by ALLTEK LLC. It explains what the portal collects about you, why, and who else sees it. The public website has its own privacy policy, which covers reading and buying reports without an account.

The short version: we collect what an account and a subscription need, and nothing for advertising. There are no trackers, no advertising networks, and no analytics JavaScript; your card details never reach us; and we do not sell your data.

What we collect

Your account. Your name, your email address, and your password — the password is stored only as a cryptographic hash, never in a form we could read. We also record whether the address has been confirmed and when the account was created and last updated.

Your sign-in sessions. For each active session we store a session token, its expiry, and the IP address and browser user-agent of the device that signed in. We use them to keep you signed in and to limit brute-force attempts on the sign-in form. Sessions expire on their own, and signing out or resetting your password ends them.

Your subscription — but not your card. Checkout and billing run on Stripe's own hosted pages. We never see, receive, or store a card number. What we keep is Stripe's references for your customer and subscription, the plan, the status, the date the current period ends, whether a cancellation is scheduled, and the date of a first failed payment (which drives the grace period).

Which ZIP codes were opened, per day. To count the fair-use allowance we record the ZIP codes opened on a subscription on a given day. It is tied to the subscription, and a team shares one counter.

Your branding. The contact card you fill in (name, brokerage, phone, email, website) and the logo image you upload, which we resize and store. You choose to provide this, and it exists to be shown on reports you prepare.

Your team. If you invite colleagues, we store the team, its members, and pending invitations — including the email addresses you enter to invite people. If you were invited to a team, the person who owns it can see your name and email address as a member.

Your purchases. Purchases made with your confirmed address — including ones made as a guest on the website before you had an account — are shown in the portal: the email address, the ZIP code, the amount, the date, and Stripe's reference for the payment. Those records are created by the website; the portal displays them.

Messages you send us. The support form emails your message, your address, your name, your account id and your plan to our support mailbox, so we can reply. The message is not stored in the portal's database — it lives in that mailbox, like any email you would have written yourself.

Product analytics — server-side, no trackers

We record a handful of account events so we know how the product is used: an account was created, someone signed in, a subscription started, was cancelled, or had a payment fail, branding was updated, a seat was invited, joined or removed, a checkout was started. Each event carries a one-way hash of the email address — never the address itself — and nothing else that identifies you; no IP address and no user-agent are recorded with it. All of it is written by our own server. There are no third-party analytics services and no analytics JavaScript in your browser.

Cookies

The portal sets exactly one cookie: better-auth.session_token, which is your signed-in session. It is marked httpOnly (scripts on the page cannot read it) and SameSite=Lax, it is sent only over https on the live service, and it lasts about a week unless you sign out sooner. There is no advertising, profiling or cross-site tracking cookie here and no third-party cookie at all, which is also why you are never asked to accept a cookie banner. Stripe's pages are on Stripe's own domain and set their own cookies under Stripe's privacy policy.

Nothing on a portal page is loaded from anyone else: the fonts, the logo and the styles all come from the portal itself, so no third party learns that you visited it.

What appears on reports you prepare

Reports opened or saved on a subscription carry a watermark with your name and email address, and, if you set one up, your “Prepared by” card and logo. That is the point of the feature — but it does mean anyone you hand a report to sees those details. A report you saved keeps whatever was frozen into it at the time.

Email we send you

Only transactional email — messages tied to something you or your team did: confirming your address, resetting your password, a team invitation, and an acknowledgement when you write to support. Receipts for purchases come from the website. There are no newsletters and no marketing campaigns, so there is no marketing list to unsubscribe from. Your address is never sold, rented, or shared for anyone else's marketing.

Who else sees your information

We do not sell personal information and never share it with advertising networks or data brokers. It reaches only the services needed to run the product:

  • Stripe — our payment processor: the checkout page, card details, subscriptions, renewals and refunds.
  • A transactional email delivery service — receives the address and the message so account email can be delivered.
  • Our hosting provider — operates the servers the portal runs on.

We may also disclose information if the law requires it, or where we must to establish or defend a legal claim.

How long we keep it

Account, subscription and branding records are kept for as long as your account exists, and payment records afterwards for accounting and tax purposes. Sessions expire on their own within about a week. The daily view counter is kept as product history. A cancelled subscription is not deleted: the record of what was charged is part of the accounting trail.

Your choices

You can change your name, branding and team membership in the portal at any time. Write to alltekmainbox@gmail.com to ask for a copy of the personal information we hold about you, to correct it, or to have it deleted — including closing your account, which is not yet a self-service button. Please write from the address on the account so we can tell which records are yours. We will not ask you to give a reason, and this applies wherever you live.

Two honest limits: deleting your data does not undo the payment records we are required to keep for accounting, and it does not reach Stripe's own records of a payment — for those, contact Stripe. Deleting purchase records also ends your access to the reports they cover.

Children

The portal is a professional tool, is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, write to alltekmainbox@gmail.com and we will delete it.

Changes to this policy

We may update this policy; the current version is always on this page, with its effective date at the top. Material changes will be reflected in that date, so it is worth a look if you are returning after a while.

Governing law & contact

This policy is governed by the laws of the State of Maryland, without regard to its conflict-of-laws principles — the same as the Portal Terms of Use. Questions about privacy, or a request about your data: alltekmainbox@gmail.com, ALLTEK LLC.

Zip Code Report · ALLTEK LLC