Effective date: May 16, 2026. We may revise this policy from time to time; when we do we update this date and, for material changes, post a notice on the site.
This policy covers longislandpropertytax.com, operated by AI Laws by State LLC. Questions: read@longislandpropertytax.com.
1. What we collect
Information you give us directly
- Email address — when you subscribe to newsletter/assessment-alert updates. We may also store the parcel you searched for, your county, and your ZIP so we can send locally relevant content.
Information collected automatically
- Server log data — IP address, HTTP method, path visited, referring URL, browser user-agent string, and a timestamp. Retained for up to 30 days for security, debugging, and aggregate analytics. IP addresses are used for rate limiting and spam/abuse prevention; we do not build individual profiles from them.
- Search queries — the address or parcel text you type into our calculator, logged to improve fuzzy-match accuracy. Stored without linking to an identity unless you're a logged-in subscriber.
- Partner-link clicks — when you click an affiliate link we record which placement was clicked (e.g., "grievance-nassau-slot-A") alongside standard log data. We do not capture personal information beyond the log data above.
- GA4 page-view events — see the Cookies & Analytics section below.
What we do NOT collect
- Payment card or financial account data — we don't process payments directly.
- Government ID numbers or Social Security numbers.
- Precise geolocation beyond what's implied by an IP address.
- Data from third-party advertising networks or retargeting pixels — we use none.
2. Why we collect it
- Delivering the service — computing property tax estimates, returning search results, rendering pages.
- Sending the newsletter — assessment-change alerts, grievance deadline reminders, and occasional tax-related news you opted in to receive.
- Security and abuse prevention — IP-based rate limiting, detecting automated scraping, and investigating incidents.
- Aggregate analytics — understanding which pages and tools are useful so we can improve them. We look at aggregate trends, not individual sessions.
- Measuring partner-link engagement — so we can report to affiliate partners how many clicks each placement received. We do not share personal data with partners; we share only aggregate counts.
3. How we store it
Subscriber data (email addresses, parcel context, subscription status) is stored in a PostgreSQL database hosted on Neon (cloud Postgres). Neon encrypts data at rest (AES-256) and in transit (TLS). We access the database only from our application server and from our own administrative machines; no third party has direct read access.
Server logs rotate after 30 days. Subscriber records are retained as long as your subscription is active; if you delete your account or unsubscribe, we remove personally identifying fields within 30 days of your request.
4. Who we share it with
We do not sell, rent, or trade your personal information to data brokers or third parties for their own marketing purposes. The only service providers that touch personal data are:
- Neon — cloud Postgres hosting. Stores subscriber records on our behalf.
- Resend — transactional and newsletter email delivery. When we send you an email, Resend processes your address to route it. Resend's privacy policy is at resend.com/legal/privacy-policy.
- Railway / Cloudflare — application hosting and CDN. Cloudflare may log request metadata (IP, path, user-agent) for DDoS mitigation and performance.
- Google Analytics 4 — aggregate usage measurement, described in detail below. Google receives anonymized analytics events; it does not receive your email address or subscriber record.
If we are ever required by law, subpoena, or court order to disclose data, we will comply and, where legally permitted, notify affected users promptly.
5. Cookies and analytics
The admin_session cookie
We set one first-party cookie: admin_session. It is an HMAC-signed session token, marked HttpOnly and SameSite=Lax, that identifies our site administrator. It is only set on admin accounts — regular visitors and subscribers never receive this cookie.
Google Analytics 4 (GA4)
We use GA4 (measurement ID G-EDD24DR2ZR) to count page views and understand aggregate traffic patterns. Our implementation:
- IP anonymization is on — Google truncates the last octet of each IP before storing it.
- Google Signals and ad personalization are off — your data is not used to build advertising profiles.
- Do Not Track (DNT) and Global Privacy Control (GPC) are respected — if your browser sends a DNT or GPC signal we skip the GA4 script entirely; no network request is made and no
_ga cookie is set.
When GA4 is active it sets a first-party _ga cookie (and sometimes _ga_EDD24DR2ZR) in your browser. These are persistent cookies used to distinguish visitors in aggregate. You can opt out site-wide with the Google Analytics opt-out browser add-on, or by enabling DNT/GPC in your browser settings.
6. Your rights
You can:
- Unsubscribe at any time by clicking the unsubscribe link in any email or visiting /unsubscribe.
- Manage email preferences (choose which types of updates you receive) at /preferences (link included in every email).
- Request access, correction, or deletion of the personal information we hold about you by emailing read@longislandpropertytax.com from the address you signed up with. We honor reasonable requests within 30 days.
7. California residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:
- Right to know — you may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources we collected it from, and the business purpose.
- Right to delete — you may request deletion of personal information we hold, subject to certain exceptions (e.g., information needed to complete a transaction or comply with a legal obligation).
- Right to opt out of sale or sharing — we do not sell or share your personal information with third parties for cross-context behavioral advertising. There is nothing to opt out of, but you can confirm this in writing by emailing us.
- No discrimination — we won't deny service, charge different prices, or provide a lesser quality of service because you exercised a CCPA right.
To exercise a CCPA right, email read@longislandpropertytax.com with "CCPA Request" in the subject line. We will respond within 45 calendar days.
8. Children
This site is not directed at children under 13 and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it promptly.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date at the top and, for significant changes, by posting a notice on the site. Continued use of the service after a change constitutes acceptance of the updated policy.
10. Contact
Questions, concerns, or data requests: read@longislandpropertytax.com.