1. Information we process
Subscription information: email address, internal customer and subscription references, plan, billing status, invoice references, entitlement state, and support correspondence.
Account information: normalized email address, verification time, organization memberships, and one-way keyed hashes of short-lived verification tokens and browser sessions. We do not store a website password or send API keys by email.
API access information: a one-way keyed hash of each API key, its display prefix and last four characters, creation and revocation times, plan ownership, and security audit events. We cannot retrieve a plaintext key after it is shown to you.
Usage information: key reference, timestamp, route, method, result, HTTP status, duration, response size, quota period, and request ID. We do not store raw Overpass QL, request bodies, URL credentials, or full query results in usage records.
Connection information: Cloudflare processes IP address, device, request, and security signals while delivering and protecting the site. We use approximate IP-derived location to initialize regional terrain and the documentation map. We resolve coordinates using Cloudflare location headers or a local DB-IP database; local lookups do not send visitor IPs to DB-IP. When configured, ip-api processes the visitor IP to return city-level coordinates. Mapsource does not persist the returned coordinates or full visitor IP in terrain records, map state, usage records, or cache keys.
2. Payments
Stripe processes payment details, billing addresses, tax information, fraud signals, and transaction data for checkout, recurring billing, invoices, refunds, and payment support. Payment-card numbers are entered into Stripe-controlled fields and are not stored by Mapsource.
We retain only the provider references and billing facts needed to operate your subscription, provide access, reconcile payments, prevent fraud, meet accounting obligations, and resolve disputes. Stripe processes information under its own privacy terms.
For x402 machine payments, we retain payment amounts, public wallet addresses, authorization nonces, transaction hashes, timestamps, and reconciliation status. When Stripe settlement is enabled, we also retain the associated PaymentIntent reference and status. We do not retain wallet private keys, payment signatures, or query contents in payment records. The configured facilitator processes payment authorizations, and confirmed blockchain transactions are public.
3. How information is used
We use information to provide and secure the service, authenticate keys, enforce plan limits, maintain subscriptions and entitlements, deliver transactional messages, answer support requests, diagnose incidents, prevent abuse, reconcile billing, comply with law, and improve reliability.
Where applicable, processing is based on performing our contract with you, legitimate interests in operating and protecting the service, compliance with legal obligations, or consent when specifically requested. We do not sell personal information or share it for cross-context behavioral advertising.
4. Service providers and transfers
We disclose the minimum necessary information to service providers that operate the product, including Stripe for payments, Cloudflare for network delivery and security, ip-api for approximate map initialization when enabled, infrastructure and backup providers, and the transactional email provider used for access and billing notices.
These providers may process information in countries other than your own. Where required, transfers are handled through recognized legal mechanisms and provider data-protection commitments. We may also disclose information when required by law, to protect customers or the service, or as part of a business transfer subject to appropriate safeguards.
5. Retention and security
Account, subscription, and transaction records are retained while access is active and afterward for applicable security, tax, accounting, dispute, fraud-prevention, and legal periods. Email challenges expire after 15 minutes and authenticated browser sessions after 30 days, though bounded security records may remain for abuse prevention. Raw usage metadata is retained for no more than 90 days. Security, support, key-claim, and event diagnostics are retained only for their operational or legal purpose and are then deleted or de-identified.
We use access controls, encryption where appropriate, keyed one-way credential storage, secret separation, audit records, backups, and monitoring. No internet service is risk-free; report suspected unauthorized access promptly.
6. Cookies and local storage
Mapsource uses essential browser storage and cookies for checkout state, verified-account sessions, security, recovery, and authenticated billing controls. Stripe and wallet providers may use cookies or similar technology to provide checkout, remember eligible payment methods, and prevent fraud. We do not use advertising cookies.
7. Your choices and rights
You may update billing information through the billing portal and rotate or revoke API keys through the control surface. Depending on where you live, you may request access, correction, deletion, restriction, objection, or portability of personal information, and may appeal or complain to an applicable regulator.
Send a request from the subscription email address to [email protected]. We may verify your identity before acting. Some information may be retained where required for legal obligations, security, fraud prevention, disputes, or the exercise of legal claims. We do not discriminate against users for exercising applicable privacy rights.
8. Children and policy changes
The service is intended for businesses and developers and is not directed to children. Do not provide personal information if you are not old enough to consent to online services in your jurisdiction.
We may update this policy as the service or legal requirements change. The effective date above identifies the current version, and material changes will be communicated through the site or subscription contact where appropriate.
9. Regional privacy rights
Policy shown for Global
You may request access, correction, deletion, or a portable copy where applicable. Mandatory privacy and consumer protections in your location remain available even when they differ from this global summary.
Region is reduced from edge-provided location and is not retained for this selection. If the label is wrong, rights granted by applicable law still apply.
10. Contact
Mapsource, operating from Indiana, United States, is responsible for the Mapsource information described here. Privacy and data requests can be sent to [email protected].