Privacy Policy
Effective: October 3, 2026. This policy explains what personal information Atmos Data Labs ("we", "us") collects through the Weather Trading Intelligence website and API (the "Service"), and how we use it.
1. What we collect
- Account data: the email address and password you provide at signup (we store a bcrypt hash of your password, never the plaintext), and your current plan.
- API keys: we store a one-way hash and a short prefix of each API key for lookup/display purposes, plus a label and timestamps (created, last used, revoked). The plaintext key itself is shown to you once at creation and is not stored by us.
- Billing data: if you subscribe to a paid plan, billing and card details are collected and processed directly by Stripe, our payment processor — we receive and store only Stripe's customer and subscription identifiers, not your card number.
- Enterprise inquiries: if you submit the Enterprise contact form, we store the company name, your name, email, optional message, and requested seat count you provide.
- Usage events: for quota enforcement and abuse prevention, we log API requests and downloads tied to your account and API key (event type, dataset table/version, response status, and timestamp).
- IP addresses: used transiently, in memory, to rate-limit signup and login attempts and prevent abuse. We do not persist IP addresses in our database.
2. What we don't do
- We don't use cookies, browser local storage, or any third-party analytics, advertising, or tracking scripts on the website — there is nothing of that kind on this site today.
- We don't sell your personal information to anyone.
3. How we use your information
- To create and operate your account and API keys;
- To enforce plan quotas and detect abuse of the API;
- To process subscription payments and manage billing, via Stripe;
- To respond to enterprise inquiries and send related invoices;
- To send transactional emails relevant to your account (e.g. billing or enterprise-inquiry notifications) — we don't send marketing email today.
4. Third-party processors
We share the minimum information necessary with these service providers to operate the Service:
| Provider | Purpose | What they see |
|---|---|---|
| Stripe | Payment processing & billing | Your billing details, email, and subscription status |
| Render | Application hosting | Standard web server access logs |
| Our email/SMTP provider | Transactional email delivery | Recipient address and message content for emails we send |
5. Data retention
We retain account, API key, billing-reference, and usage-event data for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, and dispute-resolution obligations. You can request deletion of your account data at any time (see §7); some records (e.g. billing records Stripe is legally required to retain) may persist with our payment processor independently of our own deletion.
6. Security
Passwords are hashed with bcrypt; API keys are stored only as one-way hashes. We use HTTPS in production and standard security response headers. No method of transmission or storage is perfectly secure, and we can't guarantee absolute security.
7. Your rights
You can access, correct, or delete your account data, or ask what we hold about you, by emailing contact@atmosdatalabs.com. You can revoke individual API keys yourself from your account page at any time.
8. Governing law
This policy is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, consistent with our Terms of Service.
9. Changes to this policy
We may update this policy from time to time; we'll update the effective date above when we do.
10. Contact
Questions about this policy? Email contact@atmosdatalabs.com.
See also: Terms of Service · Data License.