Privacy Policy
Overview
This Privacy Policy explains how Seismocode Inc. (“Seismocode,” “we,” “us”) collects, uses, stores, and protects personal information in connection with MicSer, our cloud platform for HVSR (Horizontal-to-Vertical Spectral Ratio) ambient-noise seismic validation. It applies to account holders, organization members, and other individuals whose personal information passes through MicSer in the course of a customer using the platform. Our privacy practices are aligned with Canada’s federal private-sector privacy law (PIPEDA) — see “Your rights” below for what that means in practice.
Information we collect
We collect the following categories of personal information. Unless noted otherwise, each is provided directly by you or generated automatically as part of using MicSer:
Account & identity data. Your name, email address, and password when you create an account. Your password is never stored in plain text and is never viewable by Seismocode staff — it is stored as a salted cryptographic hash (Django’s standard PBKDF2 algorithm), which cannot be reversed back into the original password. This information is mandatory to create and sign in to an account; without it, you cannot use MicSer. If you sign in with Google instead, we receive your name and email address from Google and never receive or store a password at all.
Organization & role data. The organization(s) you belong to, and your role within each — Owner, Admin, Member, or Viewer. This determines what you can see and do inside that organization’s workspace; for example, only Owners and Admins can manage members or promote a dataset to Final, and only Owners can access billing. This is mandatory to use any organization-scoped feature of MicSer.
Billing metadata. If your organization is on a paid plan, we store Stripe’s own customer and subscription identifiers so we can associate your organization with its subscription. MicSer never stores your card number or other payment credentials — payment details are entered directly into Stripe’s own hosted checkout and billing portal, which Seismocode never sees. This is only collected for organizations on a paid plan; it is not required to use the Free plan.
IP address & user agent. We log the IP address and browser/device user agent associated with certain requests, primarily sign-in activity and policy acceptances (see “Retention & deletion” below). This is used for account security — detecting suspicious activity — and as evidence of when and how you accepted a given policy version. It is collected automatically and applies to every session; it cannot be opted out of while using the service.
Audit & login events. MicSer maintains an append-only audit log of account and organization actions — sign-ins, uploads, deletions, restorations, membership and role changes, and similar events — associated with the user who performed them. This exists for security, accountability, and so your organization’s Owners and Admins can review what happened, and when, within their own organization.
Uploaded file & report metadata that may identify a person. Beyond the geophysical measurement data itself (covered by the Data Upload & Processing Policy), some fields you or your organization enter can name a specific individual — for example, a station’s “Operator” field or a report’s “Prepared By” field. These are free-text fields you control, and the person named there is not necessarily the MicSer account holder; if you enter a colleague’s or another third party’s name in one of these fields, you are responsible for having an appropriate basis to do so.
Cookies. MicSer sets two cookies — sessionid and
csrftoken — both strictly necessary to keep you signed in and to protect
state-changing requests from cross-site request forgery. We do not use analytics, advertising, or
tracking cookies. Full detail, including retention periods and the browser storage MicSer uses
alongside cookies, is in our Cookie Notice.
How we use your information
We use the personal information above solely to operate, secure, and maintain the MicSer platform: to authenticate you, enforce your organization’s permissions and subscription limits, process billing through Stripe, investigate security incidents, and provide support. We do not sell, rent, or trade personal data to any third party. We do not use your personal information for advertising, and we do not currently use any analytics, advertising, or error-monitoring third-party service — none is integrated into MicSer. Aggregate, de-identified usage statistics may be used internally to improve the platform’s quality and reliability.
Third-party services
MicSer shares personal information with a small, fixed set of service providers, each engaged only to help operate the platform:
Amazon Web Services (AWS). Hosts our application infrastructure and stores uploaded files, reports, and database records. See “Cloud storage, security & data residency” below.
Stripe. Processes payments and manages billing for paid subscriptions. Stripe receives whatever billing and payment information is needed to process your transaction directly; MicSer only ever stores Stripe’s own customer and subscription identifiers, never card numbers.
Google. If you choose “Sign in with Google,” Google acts as your identity provider for that sign-in and shares your name and email address with MicSer; MicSer does not receive your Google password.
We do not share personal information with any other third party except as required by law, or as necessary to investigate fraud or a security incident.
Cloud storage, security & data residency
Account data is stored in a managed, access-controlled database. Uploaded files and generated
reports are stored in a private Amazon S3 bucket, encrypted at rest and not directly accessible to
the public. Both our application infrastructure and our S3 storage bucket are hosted entirely
within the AWS Canada (Central) region (ca-central-1) — your data is genuinely hosted
in Canada, with no cross-border replication in production. Access to customer data is restricted
to authenticated sessions and to authorized Seismocode personnel for support, security, and
maintenance purposes. Full detail on our hosting region and infrastructure is available on our
Data Residency page.
No AI training
We do not use your personal information, or any customer geophysical data, to train, fine-tune, or evaluate any artificial intelligence or machine learning model, ours or a third party’s. MicSer’s validation engine itself is a deterministic, fixed-formula implementation of the published SESAME (2004) methodology, not an AI or machine-learning system — see the Data Upload & Processing Policy for more detail. Uploaded files and project data are not sent to any third-party AI or analysis service unless you have explicitly authorized this in writing.
Retention & deletion
Project and organization data. Uploaded files, project and station records, validation results, and reports are retained for as long as the corresponding record exists in your organization’s workspace, identically across every subscription plan. Deleting a project does not erase it immediately — it moves to a self-service recycle bin, where an Owner or Admin on your team can restore it within 30 days; after that window, an automated process permanently purges it, including the underlying files. The Data Upload & Processing Policy sets out this lifecycle in full detail, including what happens to reports already issued from a purged project.
Account-level data. Your account and its associated personal information are retained for as long as your account remains active. MicSer does not currently offer a self-service “delete my entire account” option. To request deletion or anonymization of your account or other personal data beyond project-level deletion, contact privacy@seismocode.com; such requests are handled within a reasonable period, subject to legal, security, backup, billing, and operational requirements.
Consent records. A record of each policy you accept — which policy, which version, when, and the IP address/user agent used to accept it — is kept indefinitely as evidence of consent, even if your account is later closed. It is stored separately from your account data and is not editable by anyone, including Seismocode staff, once created.
Your rights
In line with PIPEDA, you have the following rights over your personal information, each grounded in a real, currently available mechanism — we would rather tell you plainly which of these is self-service and which requires an email request than imply a button that doesn’t exist:
Access. You can view your own data directly within MicSer — your projects, stations, datasets, and reports are browsable in the application. For a copy of personal information not otherwise visible in the product, email privacy@seismocode.com.
Correction. You can update your name and email yourself from the Account settings tab in the application. Other information, such as your organization’s role assignments, is corrected by your organization’s Owner or Admin.
Withdrawal of consent. You may withdraw consent to processing at any time by contacting privacy@seismocode.com. Because processing your account and organization data is necessary to provide MicSer, withdrawing consent generally means we can no longer provide the service to you and will proceed to close your account. Separately, whenever we materially update a policy, you are asked to review and re-accept it before continuing to use MicSer — you are never bound to updated terms without an affirmative, recorded acceptance.
Deletion. You can delete a project yourself at any time; it moves to the recycle bin and can be restored by an Owner or Admin for 30 days before automatic, permanent purge. There is currently no self-service option to delete your entire account — to request deletion or anonymization of your account and its associated personal data, email privacy@seismocode.com.
Changes to this policy
We may update this Privacy Policy as MicSer changes. Material changes update the version number above; you will be asked to review and re-accept an updated policy the next time you sign in, before continuing to use MicSer.
Contact
Privacy enquiries: privacy@seismocode.com
Legal matters: legal@seismocode.com