This Privacy Policy explains how PlacemarkLens collects, uses, discloses, and retains information when you use the PlacemarkLens service on supported smart glasses hardware. It applies to:
Both platforms are covered by a single policy. Where practices differ by platform, differences are noted explicitly.
By using PlacemarkLens, you agree to this Privacy Policy. If you do not agree, do not use the service.
Mitchell Innovations, LLC is a limited liability company organized under the laws of the State of New Jersey, United States. PlacemarkLens is a spatial anchor advertising platform that delivers location-aware merchant offer cards to smart glasses wearers when they are near participating merchant locations.
For purposes of the General Data Protection Regulation (GDPR), Mitchell Innovations, LLC is the data controller for personal data processed by the PlacemarkLens service.
For purposes of the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Mitchell Innovations, LLC is the business responsible for the personal information described in this policy.
The following table describes every category of data the PlacemarkLens service collects or processes, organized by platform. "Processed" means the data is used at query time but not persisted to our database. "Stored" means the data is written to our database and retained subject to the retention schedule in Section 5.
| Data Category | Meta Ray-Ban Track | Android XR Track | Stored? |
|---|---|---|---|
| Anonymous session UUID | Collected on first load, persisted in localStorage |
Collected on first launch, persisted in device storage | Yes — retained per retention schedule |
| GPS coordinates (latitude / longitude) | Used to query nearby anchors; never written to database | Used to query nearby anchors; never written to database | No — processed at query time only |
| Device heading (compass bearing from IMU) | Used to determine facing direction at query time | Used to determine facing direction at query time | No — processed at query time only |
| Walk speed (derived from GPS delta) | Used to suppress offer delivery when the device is traveling at vehicle speed; not stored per session | Used to suppress offer delivery when the device is traveling at vehicle speed; not stored per session | Yes — stored on impression record as walk_speed_ms (numeric value, not a location trace) |
| Impression events (anchor ID + timestamp) | Logged when an offer card has been displayed for a qualifying duration | Logged when an offer card has been displayed for a qualifying duration | Yes |
| Dwell time (seconds card was viewed) | Logged per impression | Logged per impression | Yes |
| Action taken (e.g., "claimed," "dismissed") | Logged per impression | Logged per impression | Yes |
Platform identifier (meta_raybans / android_xr) |
Stored on each session and impression record | Stored on each session and impression record | Yes — used for per-platform analytics |
| User agent / device metadata | HTTP User-Agent header stored on session creation | Captured at session creation | Yes — stored on session record |
| Camera frames | Not accessed or processed by PlacemarkLens | Processed by Google's ARCore Geospatial API for device positioning only; not stored by PlacemarkLens — see Section 2.2 | No (PlacemarkLens) / Google's policies apply |
What we do not collect: We do not collect your name, email address, phone number, physical address, payment information (for wearers), government identifiers, biometric data, or any information that directly identifies you as an individual. Session UUIDs are randomly generated and not linked to any identity.
What merchants do not see: Merchants on the PlacemarkLens platform receive aggregate analytics — impression counts, average dwell times, and action rates — keyed to anonymous session UUIDs. Merchants never receive individual session data, location traces, or any information that could identify a specific wearer.
On the Android XR platform, PlacemarkLens uses Google's ARCore Geospatial API to determine device position and orientation. As part of this process, ARCore may capture and process camera frames to compute position via Google's Visual Positioning System (VPS). These camera frames are processed by Google's systems; they are not transmitted to or stored by PlacemarkLens.
Google's handling of data processed through ARCore is governed by the Google Privacy Policy and the ARCore Additional Terms of Service. We encourage you to review those documents.
When you use PlacemarkLens, our backend infrastructure (hosted on Amazon Web Services) automatically receives standard server logs, including your IP address, request timestamps, HTTP method, and response codes. These logs are used for security monitoring, abuse detection, and operational health. They are not linked to your session UUID and are not used for advertising targeting.
If you are a merchant (not a wearer), we collect business information necessary to operate your account, including your business name, contact information, payment details (processed by Stripe, Inc. — see Section 4), anchor configuration data, and offer card content. This policy section primarily addresses wearer data; a separate merchant data addendum is available upon request.
We use the data described above for the following purposes and legal bases:
| Purpose | Data Used | Legal Basis (GDPR) | CCPA Category |
|---|---|---|---|
| Deliver location-aware offer cards to your glasses | GPS coordinates, device heading (both processed but not stored) | Legitimate interests (core service delivery) | Geolocation data |
| Prevent vehicle-speed false triggers | Walk speed | Legitimate interests (service quality) | Inferred data |
| Measure and bill advertising impressions | Session UUID, anchor ID, timestamp, dwell time, action taken | Legitimate interests (billing and platform integrity) | Commercial information |
| Per-platform analytics and service improvement | Platform identifier, user agent | Legitimate interests (product improvement) | Internet or other electronic network activity |
| Security monitoring and abuse prevention | Server logs (IP address, timestamps) | Legitimate interests (security) | Internet or other electronic network activity |
| Compliance with legal obligations | Any data required by applicable law | Legal obligation | N/A |
We do not use your data for behavioral advertising, cross-context behavioral profiling, or sale to third parties.
We share data only in the following circumstances:
Service providers. We use the following sub-processors to operate the service:
| Provider | Purpose | Data Shared | Privacy Reference |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (Lambda, API Gateway, S3, CloudFront) | All data transiting or stored in the service | AWS Privacy |
| Neon, Inc. | Serverless PostgreSQL database | Session UUIDs, impression records, merchant anchor data | Neon Privacy |
| Google LLC (ARCore) | Device positioning on Android XR platform | Camera frames (processed by ARCore, not PlacemarkLens) | Google Privacy Policy |
| Stripe, Inc. | Payment processing for merchants | Merchant payment information only; not wearer data | Stripe Privacy Policy |
Legal requirements. We may disclose data if required to do so by law, subpoena, court order, or other governmental request, or when we believe disclosure is necessary to protect our rights, the safety of users, or the public.
Business transfers. If Mitchell Innovations, LLC is acquired, merged, or its assets are transferred, user data may be transferred as part of that transaction. We will provide notice before your data is subject to a materially different privacy policy.
Aggregated, anonymized data. We may share aggregated, de-identified analytics (e.g., foot traffic patterns by neighborhood, platform-level impression volumes) that cannot reasonably be used to identify any individual. This is not a "sale" of personal information under CCPA.
We do not sell personal information, share it for cross-context behavioral advertising, or disclose it to data brokers.
We retain data according to the following schedule:
| Data Category | Retention Period | Rationale |
|---|---|---|
| GPS coordinates / device heading | Not stored — discarded after query response | Minimization by design |
| Session UUIDs | 90 days from last activity | Analytics window; rolling deletion |
| Impression records (anchor ID, timestamp, dwell, action, walk speed, platform) | 90 days | Analytics window; rolling deletion via scheduled process |
| Server logs (IP address, request metadata) | 30 days | Security monitoring; standard log rotation |
| Merchant account data | Duration of account + 7 years | Tax, accounting, and legal obligations |
| Billing records | 7 years | Accounting and legal obligations |
Impression records older than 90 days are deleted via an automated scheduled process (AWS EventBridge + Lambda). Billing records are retained separately and do not include location-inferable impression detail beyond the anchor identifier.
PlacemarkLens applies the following security measures:
No method of transmission or storage is 100% secure. If you believe a security incident has occurred, contact us immediately at security@placemarkLens.com.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the GDPR:
Because PlacemarkLens wearers are identified only by anonymous session UUIDs, exercising some rights (such as access or portability) may require you to provide your session UUID so we can locate your records. If you do not have your session UUID, we may be unable to retrieve data associated with your use of the service.
If you are a California resident, you have the following rights:
To exercise CCPA/CPRA rights, submit a verifiable consumer request to privacy@placemarkLens.com. We will respond within 45 days, with one 45-day extension where reasonably necessary.
All rights requests (GDPR or CCPA/CPRA) should be submitted to:
Email: privacy@placemarkLens.com
Subject line: "Privacy Rights Request"
Include your session UUID if available (found in the app's debug panel or device storage) and specify the right you wish to exercise. We will respond within 30 days for GDPR requests and 45 days for CCPA requests.
PlacemarkLens is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has used the service, contact us at privacy@placemarkLens.com and we will promptly delete any associated data.
If you are between 13 and 16 years of age and located in California, we will not sell or share your personal information without your affirmative authorization.
PlacemarkLens is operated from the United States. If you are located outside the United States, your data is transferred to and processed in the United States, where data protection laws may differ from those in your country.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following transfer mechanisms:
For questions about our transfer mechanisms, contact privacy@placemarkLens.com.
Meta Ray-Ban web app: The web app uses browser localStorage
(not cookies) to store your anonymous session UUID and your acceptance of this Privacy
Policy and Terms of Service. No third-party tracking cookies are used. No advertising
pixels or cross-site tracking scripts are embedded in the app.
Android XR app: The native app uses Android's DataStore and SharedPreferences (or equivalent) to persist your session UUID and ToS acceptance state locally on your device. No third-party SDKs with tracking capabilities are included in the app.
Offer cards displayed by PlacemarkLens may contain content provided by participating merchants, including business names, promotional descriptions, and imagery. PlacemarkLens does not endorse merchant content and is not responsible for the privacy practices of merchant businesses. If you visit a merchant's physical or online storefront, that merchant's own privacy practices apply.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by applicable law, provide additional notice (such as an in-app notification on next launch). Continued use of PlacemarkLens after the effective date of a revised policy constitutes acceptance of the updated terms.
We encourage you to review this policy periodically. Previous versions are available upon request.
For privacy-related questions, requests, or concerns:
Mitchell Innovations, LLC — PlacemarkLens
Privacy Inquiries
Email: privacy@placemarkLens.com
Web: https://placemarkLens.com/privacy
For security vulnerability disclosures:
Email: security@placemarkLens.com
For general support:
Web: https://placemarkLens.com/support
This Privacy Policy was drafted to address the requirements of the General Data Protection Regulation (EU) 2016/679, the UK General Data Protection Regulation, the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act, and applicable FTC guidance on advertising disclosures. It is provided for informational purposes and does not constitute legal advice. You should consult a licensed attorney before relying on this document for legal compliance purposes.