Privacy

OpenProperties publishes HM Land Registry's record of residential property sales in England and Wales. This page says what personal data that involves, what we collect when you visit, and what you can do about it.

Who we are

OpenProperties is part of OpenCommons. It is run by Jason Cartwright, an individual, who is the data controller for this site. To get in touch about anything on this page, use the contact details at jasoncartwright.com.

What this site publishes

Every sale HM Land Registry records in its Price Paid Data, from 1995 to the latest monthly release: the address, the price, the date, the type of property, whether it was new, and its tenure. The data does not name buyers or sellers. But an address and what was paid for it can still be about a person, so we treat it as personal data.

  • Where it comes from. HM Land Registry Price Paid Data, under the Open Government Licence v3.0. The location on a property page is the centre of its postcode, from Ordnance Survey's Code-Point Open. It is not the position of the building.
  • What we add. Nothing about people. We group sales at the same address into one property, and show addresses in title case. HM Land Registry also publishes UPRN and INSPIRE look-up files for recent sales. We store them, but no page, API or tool shows them.
  • Where it appears. Every property and sale with an address has its own page, the same data as JSON at the same address with .json on the end, and the MCP server for AI assistants. There is no key or sign-in.
  • Search engines. Property pages are listed in our sitemap, and our robots.txt lets search engines index everything but the admin area. So these pages can appear in search results.
  • Why we do it (lawful basis). Legitimate interests: making an official public dataset, which HM Land Registry already publishes openly, easier to search and use, which supports transparency about the housing market. We publish no more than HM Land Registry does.

Corrections and deletions

HM Land Registry's record is the authoritative one. If a sale is wrong, ask HM Land Registry to correct it.

Each month we apply HM Land Registry's update file, which adds new sales and changes or deletes earlier ones:

  • When HM Land Registry changes a sale, we change it here. If its address changes, the old link redirects to the new one.
  • When HM Land Registry deletes a sale, we delete it from our database. A property with no sales left is removed when the properties are rebuilt, in the same monthly run. Its pages then show "not found".
  • Copies held in caches and by search engines can take a little longer to go.

Objecting or asking for removal

You can object to us publishing data about you, or ask us to remove it. Get in touch and say which page it is. There is no automatic opt-out: we look at each request, weighing your circumstances against the value of the data being available. Removing something here does not change HM Land Registry's own record, which stays published by them.

What we collect when you visit

Cookies

This site sets no cookies for visitors, and stores nothing in your browser. The only cookies are for the admin area, which is for the people who run the site: signing in to it sets Django's session and security (CSRF) cookies.

Analytics

Every page loads two analytics services. Neither sets cookies.

  • Plausible, an EU-hosted service, counts visits to pages.
  • fivebar loads a small script from fiveb.ar. It sends the page's address, the page you came from, your window width, how long the page was on screen, how far down you read, how quickly it loaded, and clicks on links to other sites. Your browser's request also carries your IP address and user agent, as every request does. fivebar keeps only daily counts. It does not keep your IP address, user agent or the query string of the page's address, and it tells visitors apart with a code that changes every day.

A content blocker that blocks either service stops it altogether. The site works the same without them.

Searches

What you type into search goes into the page's address (for example /search?q=sw4). We use it to find results and do not save it.

Logs

The application does not keep a log of the pages people ask for. Like any website, the services that carry your request to us, Cloudflare and our server, see your IP address and the address of the page you asked for.

AI assistants (MCP) and the API

  • The JSON API and the MCP server need no key, account or sign-in. The MCP server is stateless: it sets no cookies and keeps no sessions.
  • The MCP server writes one line to the server's log for each request: the kind of request, the tool's name, how long it took, whether it worked, and the name the assistant gives itself. It never logs what was asked: no arguments, search text or addresses.
  • Feedback. An assistant can send us a short note about the tools with send_feedback, only once you've seen it and agreed. We keep the note, its kind, the tool it is about, the assistant's name and version, and when it was sent, for up to 365 days. A note that contains an email address, an IP address or a web address with a query string is refused. Your IP address is never stored, only a keyed hash of it (an HMAC), which limits how many notes one address can send in a day. The note itself is never written to a log.

Third parties and where data is processed

  • Hosting. The site and its database run on a Hetzner server in Falkenstein, Germany, managed with Coolify.
  • Cloudflare sits in front of the site and handles every request to it.
  • opencommons.uk, part of the same family of sites, serves the shared font and stylesheet on every page, and the chart and map code on property pages. Your browser fetches these from opencommons.uk.
  • Map tiles come from maptiles.opencommons.uk, our own proxy for OpenFreeMap, running on Cloudflare. It passes on only the address of the tile, so OpenFreeMap does not see your IP address.
  • Plausible and fivebar, as above.

We don't sell data or show adverts.

How long we keep it

  • Sales data: for as long as HM Land Registry publishes it. Changes and deletions are applied each month.
  • MCP feedback notes: up to 365 days, then deleted.
  • Searches: not kept.
  • Analytics: under Plausible's and fivebar's own policies.

Your rights

Under UK data protection law (the UK GDPR) you can ask us:

  • for a copy of the personal data we hold about you;
  • to correct it (for sales data, HM Land Registry is the place to correct it, and its corrections reach us in its monthly updates);
  • to delete it, or to restrict how we use it;
  • to stop using it: you can object to processing based on legitimate interests.

To use any of these, get in touch. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ICO).

Changes

When what this site collects or publishes changes, this page changes with it.

Last updated: 11 October 2026.