Privacy notice
TerraNova measures which places people are interested in. It is built so that it cannot measure which people are interested in them.
Last updated 2026-07-30.
What we measure, and what we don't
TerraNova records which places people are interested in — aggregated. We do this so we can tell which towns and regions our readers actually care about, and improve the data and the coverage where the interest is.
We record, per visit:
- the municipality or region a page was about;
- whether the visit came from a map view, a list filter, a region page or a report;
- which scoring profile the ranking was set to (for example “lifestyle” or “investment”), when you have chosen one;
- the language the site was being read in;
- your country, only if the network in front of our servers tells us — see below.
With these interest records we do not:
- store your IP address alongside them;
- look up your location from your IP address;
- set any tracking cookie, or use any third-party analytics or advertising script on these pages;
- build a profile of you, or link your activity across visits;
- record anything that identifies you personally.
The quiz
If you complete the location quiz, we record the answers you chose and the priority profile they produce, so we can see which priorities visitors actually have and which questions are worth asking. The answers are recorded as the choices you clicked — there is no free-text field in the quiz, and nothing you could type is stored.
If you leave the quiz part-way, we record how far you got and nothing else — not your partial answers, and not a guess at what your result would have been. That tells us which question is losing people, which is the only reason we measure it.
Searches
When you use the search box we record what you typed and how many places matched it. Searches that match nothing are the ones we most want to see: they tell us about places or spellings we do not cover yet.
Search terms are shortened and normalised before they are stored, and they are stored against no identity — there is no way to see “what this person searched for”, only “how many people searched for this”. Please don't type personal information into a search box on any website, including this one.
How “country” works
Where a visit came from is recorded at country level only, and only when the network in front of our servers reports it to us. When it does not, we record nothing rather than guessing. We never derive your location from your IP address, because that would mean keeping the address long enough to look it up.
Sessions, cookies and server logs
The site uses one functional session cookie so it can work at all. To count “how many people looked at this town” rather than “how many page loads”, we store a one-way cryptographic digest of that session identifier alongside the interest record. It cannot be reversed, it is not linked to any account or to any other visit, and it becomes meaningless as soon as the session ends. Clearing your cookies produces an entirely new, unconnected value.
Two other cookies exist and neither tracks you: one carries a short-lived, rotating token that lets the map and list views call our own data endpoints (it is derived from a server secret and a time window — it contains nothing about you), and one remembers whether you chose light or dark appearance.
Being honest about the boring part: the session record itself, which the web framework keeps so it can expire stale sessions, holds your IP address and browser user-agent string. It is deleted when the session expires. Our web server also writes ordinary access logs — the requested URL, time, status, IP address and user agent — which is how any web server on the internet works, and which we keep short-term for security and debugging. One consequence worth knowing: the single-listing report puts the pin's coordinates and the asking price you entered into the page's URL, so those values appear in those access logs. The browser bookmarklet deliberately hands its data over in the part of the URL that is never sent to a server, precisely to keep a specific property out of them.
When you buy a report
Payment runs on Stripe's hosted checkout page. Your card details go to Stripe and never to us — we could not store them if we wanted to. Stripe handles that data under its own privacy policy (stripe.com/privacy).
What we keep is the purchase record: what was bought, the amount, the scope you paid for, the email address Stripe collected, and a one-way digest of the download token (so a leak of our database yields no working download links). We keep it as long as tax and dispute rules require, because it is also the proof that you are entitled to the document you paid for.
When you write to us
The “something wrong on this page?” form on a town or region page sends us your name, email address, message, and which page you wrote from, so we can check the correction and reply. Alongside it we keep the submitting IP address and user agent, used for nothing but stopping abuse of the form.
If you give us your email address for updates, we store the address, the language you were reading in, and where you signed up — and nothing else. Every message we send you will let you unsubscribe.
Addresses you look up
To turn an address into a point on the map we ask OpenStreetMap's Nominatim service, which means the address text you type is sent to that third party under its own terms. The answer is cached on our side, keyed by the search text, so the same address is not asked twice — that cache holds the text you searched for, not who searched for it.
Stopping abuse
The site's data is the product, and automated harvesting is a real problem for it (see the terms). Our own detector scores the shape of requests — how fast, how sequential, whether cookies and JavaScript work — and only when a client crosses a threshold does it write an audit record: the IP address, the path, the user agent, and the reasons it scored. Normal browsing never reaches that threshold and never gets a record. Those records are deleted after 14 days.
If you create an account
An account is optional and not needed to buy anything. If you make one, we store your email address, a hash of your password (never the password), any two-factor or passkey credentials you set up, and the sessions your account is signed in on — which, as above, include the IP address and user agent of each sign-in.
How long we keep things
| What | How long |
|---|---|
| Individual place-interest records | 6 months, then deleted |
| Daily aggregate counts (“this many sessions looked at this province on this day”) | Kept indefinitely — they contain no session identifier and no visitor-level detail |
| Abuse-detection audit records | 14 days |
| Session records and access logs | Short-term: the session expires, the logs rotate |
| Geocoding cache | About a month per entry |
| Purchase records | As long as tax and dispute rules require |
| Corrections you send us, newsletter address, account | Until the matter is closed, you unsubscribe, or you ask us to delete the account |
Why we are allowed to do this (GDPR)
- Legitimate interest (Art. 6(1)(f)) for the place-interest records: understanding which regions our readers are interested in, in order to improve and prioritise the data we publish. The processing is aggregate by design, uses no personal identifiers, and sets no cookie beyond the functional session cookie the site needs to operate. No consent banner is required for it.
- Legitimate interest for keeping the site available and unharvested — the session records, access logs and abuse-detection records.
- Performance of a contract (Art. 6(1)(b)) for a purchase: without the record there is no way to deliver or re-deliver what you bought.
- Consent (Art. 6(1)(a)) for the newsletter, withdrawable at any time.
None of this data is sold, and none of it is shared with anyone except the service providers named above who need it to do their job.
Your rights
You have the rights the GDPR gives you: access, correction, deletion, restriction, objection, and portability.
For the place-interest records there is an honest limit: we hold nothing that identifies you, so we cannot locate “your” data — there is no key to look you up by. That is a design choice rather than an evasion; the pipeline was built so the question does not arise. If you would prefer not to be counted at all, any standard tracking-protection setting that blocks the session cookie will exclude you.
For anything keyed to your email address — a purchase, a correction you sent, the newsletter, an account — we can find it and act on it. You may also complain to your national data-protection authority.
Changes to this notice
When what we collect changes, this page changes with it and the date at the top moves. The promises above are enforced in code, not policy — which is the only reason we are comfortable writing them this precisely.