DOC · MW-PRIVACY SHEET 1 OF 1 REV. 2026.06 0.1807°S 78.4678°W

Legal

Privacy Policy

1. Scope & who we are

This Privacy Policy explains how Mapwright handles information across three distinct contexts, which differ significantly:

  • Website — the marketing pages at mapwright.io.
  • Managed cloud — the hosted service we operate for customers.
  • Self-hosted software — Mapwright running on your own infrastructure, which we cannot access (see §9).

For the website and the managed cloud, the controller is Mapwright. For managed-cloud customer content we generally act as a processor on your behalf; for account, billing and security data we act as a controller.

2. Definitions

  • Personal data — information relating to an identified or identifiable person.
  • Customer content — tilesets, styles, datasets and configuration you upload or create.
  • Usage data — request counts, quotas and operational logs generated when the Service is used.
  • Process — any operation performed on data (collection, use, storage, disclosure, deletion).
  • Sub-processor — a third party we engage to process data to operate the Service.

3. Data we collect

We collect the categories below. We aim to minimize what we collect and to keep it only as long as needed (§14).

Category Examples Purpose Legal basis Retention
Identity & contactName, email, organizationAccounts, support, communicationsContract; Legitimate interestsAccount life + 90 days
AuthenticationPassword hash, sessions, API keysSecure access to the ServiceContractAccount life
BillingPlan, transaction status, last-4Billing, fraud preventionContract; Legal obligation7 years (tax/accounting)
Usage dataRequest counts, quotas, operational logsMetering, security, reliabilityContract; Legitimate interestsRaw 30–90 days; aggregates longer
Map/API request contentCoordinates, search termsReturn results you requestedContractMinimized; transient logs only
Website & deviceIP, browser, pages viewedSecurity and aggregate analyticsLegitimate interests; Consent12 months

We may also receive limited data from third parties, such as our payment processor (transaction status) and infrastructure providers (abuse and security signals).

4. Cookies & similar technologies

The website and console use a small number of cookies. Where consent is required, we ask before setting non-essential cookies; you can withdraw consent or block cookies via your browser at any time.

Cookie Type Purpose Duration
mapwright_sessionEssentialConsole authenticationSession / up to 7 days
PreferencesFunctionalRemember settings (e.g. theme)12 months
AnalyticsAnalytics (if enabled)Aggregate, privacy-respecting usage12 months

5. How we use data

  • Provide, maintain, secure and improve the website and cloud.
  • Authenticate accounts and operate API keys.
  • Meter usage, enforce quotas, and bill where applicable.
  • Detect, prevent and investigate abuse, fraud and security issues.
  • Respond to requests and provide support.
  • Comply with legal obligations and enforce our terms.

We do not sell personal data, and we do not use it for advertising.

6. Legal bases (EEA/UK)

Where the GDPR/UK GDPR applies, we rely on contract, legitimate interests (operating, securing and improving the Service, balanced against your rights), consent (where required, e.g. some cookies and marketing), and legal obligation. You may withdraw consent at any time without affecting prior processing.

7. Marketing communications

We send service and transactional messages necessary to operate your account. We send marketing only where permitted, and you can opt out at any time via the unsubscribe link or by contacting us.

8. Automated decision-making

We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human involvement. Automated abuse and rate-limit controls protect the Service and do not profile you.

9. Self-hosted installs

When you run Mapwright yourself, your data — customer content, keys, and the map/geocoding/routing requests your users make — stays on your infrastructure. We receive no telemetry from self-hosted installs by default and have no access to that data. You are the controller for it; this Policy does not govern your own processing.

10. Cloud-customer responsibilities

If you use the managed cloud to process other people’s personal data, you are the controller for that data and are responsible for having a lawful basis, providing notices, and honoring data-subject requests. We will assist as your processor and, where applicable, under a data-processing addendum.

11. Sharing & disclosures

We disclose data only:

  • to sub-processors that help us run the Service (§12);
  • to comply with law or valid legal process, or to protect rights, safety and the integrity of the Service;
  • in a merger, acquisition or asset sale, subject to this Policy.

12. Sub-processors

We engage vetted providers and bind them by contract to appropriate protections. Our current sub-processors include:

Provider Purpose Location
Amazon Web ServicesHosting & computeus-east-1
Amazon CloudFrontContent delivery / edge cacheGlobal edge

We will update this list for material changes and, where required, offer a way to object.

13. International transfers

We may process data in countries other than yours. Where required, we use appropriate safeguards (such as Standard Contractual Clauses and, for the UK, the IDTA/UK Addendum) for cross-border transfers, and we make transfer details available on request.

14. Data retention

We keep personal data only as long as needed for the purposes above, to meet legal duties, or to resolve disputes — then delete or anonymize it. Indicative periods:

Data Retention
Account dataAccount life, then deleted within 90 days
Billing records7 years to meet legal/accounting duties
Operational logs30–90 days, then purged
Request-content logsMinimized; retained only transiently
BackupsRolling 35 days, then overwritten

15. Security

We use reasonable technical and organizational measures — encryption in transit, access controls, least-privilege credentials, network controls, and logging — to protect data. No method is perfectly secure; we cannot guarantee absolute security. We periodically review our controls.

16. Data breaches

We maintain procedures to detect and respond to security incidents. Where a breach is likely to affect you, we will notify affected users and, where required, regulators within the timeframes set by applicable law.

17. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, restrict or port your personal data, to object to certain processing, and to withdraw consent. To exercise them, contact us (§23); we may need to verify your identity and will respond within the period required by law (generally within 30–45 days). We do not charge for most requests, will not discriminate against you for exercising rights, and offer an appeal path if we decline. You may also complain to your supervisory authority.

18. Do Not Track & Global Privacy Control

Because there is no common standard, we do not respond to browser “Do Not Track” signals. Where required by law, we honor recognized opt-out preference signals such as Global Privacy Control (GPC).

19. Region-specific notices

EEA / UK

See §6 (legal bases), §13 (transfers) and §17 (rights). Our EU/UK representative and data-protection contact are listed in §23.

California (CCPA/CPRA)

We do not “sell” or “share” personal information as defined under California law. California residents may exercise rights to know, delete, correct and limit, and may use an authorized agent.

Other US states

Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah) may have similar rights to access, delete, correct and opt out; contact us to exercise them.

20. Children

The Service is intended for businesses and developers and is not directed to children under 16. We do not knowingly collect their personal data; contact us if you believe a child has provided data and we will delete it.

21. Third-party links

Our site and docs may link to third-party sites and services whose privacy practices are their own. Review their policies; we are not responsible for them.

22. Changes

We may update this Policy. We will post the new version and effective date here and, for material changes, provide additional notice where required. Your continued use after changes take effect constitutes acceptance where permitted by law.

23. Contact & complaints

Privacy questions or requests: privacy@mapwright.io. You may also lodge a complaint with your local supervisory authority.