Privacy Policy
Easy Territory, Inc. (“EasyTerritory”, “EZT”, “we”, “us”)
2910 Kerry Forest Pkwy, D4-282, Tallahassee, FL 32309, USA
Effective date: October 9, 2026
Last updated: October 9, 2026
1. Scope
This policy explains how we collect, use, store, and share information when you:
- visit www.easyterritory.com (the “Website”);
- request a free trial or demo, or contact us;
- use our hosted services, including Territory Designer, EasyMap for Dynamics 365, the Territory Visual for Power BI, and the EasyTerritory MCP Server at https://mcp.easyterritory.ai/ (together, the “Services”).
If your organization has a subscription, your use of the Services is also governed by the EasyTerritory Terms of Service and any data processing terms your organization has signed with us. If this policy conflicts with a signed agreement, the agreement controls.
Under the Terms of Service, data your organization submits to the Services (“Subscriber Data”) belongs to your organization. For Subscriber Data, EasyTerritory acts as a service provider (processor) on your organization’s behalf. For account, billing, website, and marketing information, EasyTerritory acts as the controller.
2. Information we collect
2.1 Information you give us
- Free-trial requests. Our free-trial form asks for your name, business email, phone number, company name, address (street, city, state or province, ZIP or postal code, and country), the number of map users, and your primary platform integration (for example Excel, Power BI, MCP Server, Dynamics 365, or another CRM). When you submit a form, our website also records your IP address, browser user agent, and the page you submitted it from.
- Demo and contact requests. Similar contact details and the message you send us.
- Account and billing information. Name, email, company, address, and the billing contact and invoice records needed to administer a subscription. Subscriptions are billed by invoice.
- Support communications. What you send us by email, by phone, or through our support channels.
2.2 Information collected automatically on the Website
- Analytics. www.easyterritory.com uses Google Analytics (the Google tag,
gtag.js) to measure site traffic. Google may set cookies and receive your IP address, browser details, and page-view data. - Spam protection. Forms on www.easyterritory.com use Google reCAPTCHA, which sends information about your browser and your interaction with the form to Google.
- Server logs. Standard web-server and hosting logs, such as IP address, user agent, requested URL, and time.
2.3 Information processed by the EasyTerritory MCP Server
The MCP Server lets an AI assistant (an “AI host”) such as Claude, ChatGPT, Microsoft Copilot, Grok, or Cursor call EasyTerritory territory-planning tools for you. It processes:
| Data | What it is | How it is stored |
|---|---|---|
EZT MCP API key (ezt_…) |
The key EasyTerritory issues to each seat | Stored only as a one-way SHA-256 digest plus a short prefix for identification. The full key is shown once when it is created and is never stored in plain text. |
| OAuth records | When an AI host connects through OAuth, you paste your ezt_ key on our consent page. We then issue the host an access token and a refresh token tied to that key. |
Authorization codes, access tokens, refresh tokens, and client secrets are stored only as SHA-256 digests. We also store the host’s registration record (client name and redirect URLs). |
| Tool inputs and your data | What the AI host sends in a tool call: account or location rows (for example names, addresses, coordinates, and any columns you include, such as revenue or rep name), territory assignments, GeoJSON, routing stops, and instructions | Processed to perform the requested operation and kept in short-lived working storage (Section 4). |
| Territory Solutions and map sessions | The working map, territories, points, and routes you build | Kept in a per-user map workspace that expires about one hour after it was last used. You can save a permanent copy of your work with export_geojson. |
| Usage metering | Per-seat counts of geocoding, routing, and drive-time calls, used to enforce plan and trial quotas | Tenant and seat identifiers and counts only. No addresses or coordinates. |
| Audit records | Which tool was called, when, by which customer and seat, whether it succeeded, the error code, and the source IP address | Metadata only. No tool inputs or outputs. |
| Feedback | Short text an AI host may send through submit_feedback describing a problem or a missing capability |
Before storage we strip bearer tokens, key and password values, and email addresses, and we cap the text length. Readable only by EasyTerritory administrators. |
| Operational logs | Request ID, method, path, status, and timing | Logs never include API keys, bearer tokens, raw account rows, full address lists, Territory Solution payloads, or alignment files. Map-link tokens in URLs are redacted. |
What the MCP Server doesn’t receive: your full conversation with the AI host. We receive only the arguments the AI host puts in each tool call.
No AI training. We do not use Subscriber Data, MCP tool inputs, or other customer data to train AI models.
3. How we use information
- To provide, maintain, secure, and support the Services, including authenticating seats, running the operations you request, and showing results on the map.
- To meter usage, enforce plan and trial quotas, and bill where applicable.
- To respond to trial, demo, and support requests.
- To improve the Services, using aggregated usage, audit metadata, and feedback. Under the Terms of Service, Subscriber Data is used only to provide, maintain, support, and improve the Services.
- To send service communications and, where permitted, marketing communications. Every marketing email includes an unsubscribe link.
- To comply with law and protect our rights.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. Retention
| Data | Retention |
|---|---|
| MCP working data (job inputs and results, Territory Solution handles, map sessions, and selections) | Short-lived: about 1 hour after last use. Expired records are deleted by an automatic cleanup that runs about every hour. CSV upload links are valid for 15 minutes. |
| OAuth authorization codes | 5 minutes |
| OAuth access tokens | 1 hour |
| OAuth refresh tokens | 30 days. They are rotated on each use, and reuse of an old refresh token revokes the whole grant. |
| Expired or revoked OAuth tokens | Deleted about one hour after they expire or are revoked |
| Inactive OAuth client registrations | Deleted after 90 days without use and with no live token |
| API key digests | Kept while the key exists. Revoking a key changes its status rather than deleting the record, so historical usage stays attributable for billing. Trial keys expire automatically after 14 days. |
| MCP audit records, usage metering, and operational logs | 1 year |
| Feedback | Only as long as needed to investigate and address the reported issue |
| Website free-trial form entries | Deleted from our website after 1 day |
| Trial, demo, and contact emails | 3 years |
| Account and billing records | 7 years, for tax and accounting purposes |
| Subscriber Data after a subscription ends | Destroyed within 14 business days after termination, per the Terms of Service (§7.2) |
5. AI hosts (Claude, ChatGPT, Microsoft Copilot, Grok, Cursor, and others)
When you connect the MCP Server to an AI host:
- You choose what the AI host sends. Data you give the AI host (for example a spreadsheet) may be passed to EasyTerritory tools as tool arguments. Tool results (territory summaries, analysis numbers, map links, and GeoJSON) return to the AI host and may appear in your conversation.
- The AI host is a separate company. Anthropic, OpenAI, Microsoft, xAI, Anysphere (Cursor), and other hosts process your conversation and the tool results under their own terms and privacy policies, not this one. EasyTerritory doesn’t control and isn’t responsible for how an AI host stores or uses your conversation.
- Map links. Tools may return a link to a live EasyTerritory map. Anyone who has the link can view that map while the session is active, so share it only with people who should see the data.
- Disconnecting. Removing the connector in the AI host revokes its tokens. Revoking your
ezt_key revokes every token issued from it.
6. How we share information
We share personal information only with:
- Service providers (subprocessors) that host or operate the Services and our business systems for us (Section 7);
- Your organization, which controls your seat and its Subscriber Data;
- Authorities, when required by law or to protect rights and safety;
- A successor, in a merger, acquisition, or sale of assets, subject to the protections in this policy.
7. Subprocessors
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Microsoft Azure | Hosting for the MCP Server (Azure Container Apps, US East 2 region), its managed PostgreSQL database in the US, and secret storage (Azure Key Vault) | All MCP Server data described in Section 2.3 |
| Microsoft Azure Maps | Geocoding, routing, and drive-time (isochrone) calculations | Addresses to be geocoded, and route stop and origin coordinates |
| Microsoft Dynamics 365 | Customer relationship management (trial and contact lead records) | Contact details and request details from trial, demo, and contact requests |
| Microsoft 365 (Exchange Online) | Business email, including trial and support notifications | Contact details and messages |
| Mailchimp (Intuit) | Marketing email | Name, email, and subscription preferences |
| Google (Analytics and reCAPTCHA) | Website analytics and form spam protection on www.easyterritory.com | Website visitor data (Section 2.2) |
| WP Engine | Hosting for www.easyterritory.com and its forms | Form submissions and server logs |
| AI embedding service (for example, the Google Gemini API) | Ranking results for the MCP Server’s search over EasyTerritory’s own help content (ep_search) |
Only the search text the AI host sends to ep_search |
8. Where data is processed
EasyTerritory is based in the United States, and we process and store information in the United States. If you access the Services from outside the US, your information will be transferred to and processed in the US.
9. Security
- Encryption in transit (HTTPS/TLS) for the Website and the MCP Server.
- API keys, OAuth tokens, and client secrets stored only as one-way digests. Revoking a key takes effect on every token derived from it at the next lookup.
- OAuth 2.1 with PKCE (S256). Tokens issued to AI hosts can’t reach administrator tools.
- Production secrets kept in Azure Key Vault.
- Logging rules that exclude keys, tokens, raw account rows, and address lists.
- See also our Security Statement.
No system is perfectly secure. Report suspected vulnerabilities to [email protected].
10. Your choices and rights
- Access, correction, deletion, and portability. Contact us (Section 13). If your data was submitted by your employer under a subscription, we may refer your request to that organization, which controls the data.
- Disconnect an AI host. Remove the EasyTerritory connector in the AI host’s settings.
- Revoke a key. Ask your EasyTerritory administrator, or contact us, to revoke an
ezt_key. Every OAuth token issued from it stops working. - Marketing. Use the unsubscribe link in any marketing email.
- Cookies and analytics. Block or delete cookies in your browser, or use Google’s Analytics opt-out browser add-on.
- Additional rights. Depending on where you live, you may have additional rights under applicable privacy laws. We won’t discriminate against you for exercising your privacy rights.
11. Children
The Services are for businesses and aren’t directed to children under 16. We don’t knowingly collect their personal information.
12. Changes
We’ll post changes on this page and update the “Last updated” date. If a change is material, we’ll give notice by email or in the Services before it takes effect.
13. Contact
Easy Territory, Inc.
2910 Kerry Forest Pkwy, D4-282, Tallahassee, FL 32309, USA
Phone: +1 (850) 629-4274
Privacy requests: [email protected]