How the application handles data.
This page describes information processed by The Elevator Database website and API. It also explains the difference between application activity data and the public records displayed by the service.
Last updated August 4, 2026Public-record information
The core datasets are obtained from government or other public-record sources. Depending on the jurisdiction, a record may include property addresses, owner or business names, permit and inspection information, equipment details, service-company information, and contact fields supplied by the source agency. The Elevator Database is not the original collector or issuing authority for those records.
Accounts and security
When an account is created, the application stores account information such as username, email address, role, access status, and assigned API jurisdictions. Passwords, API client secrets, authenticator recovery codes, and password-reset tokens are stored as hashes rather than readable values. TOTP authenticator seeds and optional SMTP passwords must be recoverable by the server to perform verification or delivery, so they are encrypted at rest using the application’s protected Data Protection key ring instead of being stored as plaintext.
Search, report, and API activity
The application records certain website searches and report actions for diagnostics, usage analysis, and service administration. Depending on the dataset, logs may include submitted filters, search terms, record identifiers, and timestamps. API and token logs can include the account or client identifier, endpoint, state or AHJ, response status, returned-record count, duration, IP address, user agent, grant type, and error details.
Map geocoding
To prepare state and AHJ maps, the application sends public property-address text to the configured geocoding service and stores the returned latitude and longitude with the related dataset and conveyance identifier. Geocoding runs as a background server process rather than in the visitor’s browser. The public address itself may therefore be processed by the configured OpenStreetMap-compatible geocoding provider under that provider’s terms.
Analytics, sponsorships, and ad tracking
The site uses Google Analytics across its pages to measure page views and selected interactions such as searches, record opens, favorites, and outbound links. Google Analytics may process browser, device, referral, approximate-location, and interaction information under Google’s own terms. The application also records sponsored-banner clicks using the banner name, click time, and associated sponsor/client identifier. External sponsor and LinkedIn links take you to third-party services with their own privacy practices.
How information is used and shared
Application data is used to operate accounts, enforce access, deliver records, calculate quotas, troubleshoot errors, measure performance, review searches, and report sponsor clicks. The application is not designed to sell account, search, or API-log data. Information may be processed by hosting, analytics, or infrastructure providers, or disclosed when required for security, legal compliance, or protection of the service.
Retention, corrections, and questions
Different account, search, API, and ad-click tables may have different retention needs, and the current application does not apply one automatic deletion period to every log. Public-record corrections should normally be directed to the agency that issued the source data. For questions about an account or application activity, contact the project directly.
Contact The Elevator Database