1. Information We Collect

We collect information you provide directly to us — account registration data (email address, name), billing information processed via Stripe, and API usage metadata (query strings, result counts, timestamps). We do not store the raw Google Maps results you extract via our API.

Automatically collected data includes: IP address, browser user-agent, referrer, and page-level analytics via Plausible (a privacy-first, cookieless analytics provider).

2. How We Use Your Information

We use collected data to:

  • Provide, operate, and improve the API service
  • Process payments and send billing receipts
  • Enforce rate limits and detect abuse
  • Send transactional emails (job completion, billing alerts)
  • Respond to support requests

We do not sell your data to third parties. We do not use your data for advertising targeting.

3. Data Retention

Account data is retained for the lifetime of your account plus 90 days after deletion. API access logs are retained for 30 days for abuse detection, then purged. Billing records are retained for 7 years as required by law.

4. Third-Party Processors

We use a small number of sub-processors: Stripe (payments), Postmark (transactional email), Cloudflare (CDN and DDoS protection), and Hetzner / AWS (compute and storage). Each is bound by a DPA.

5. Your Rights

Under GDPR and CCPA, you have the right to access, correct, export, or delete your personal data. Submit requests to privacy@mapsapi.dev. We respond within 30 days.

6. Cookies

We use one first-party cookie: a session token for dashboard authentication. We do not use advertising cookies or third-party tracking pixels. Our analytics provider (Plausible) is cookieless.

7. Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). API keys are stored as salted hashes — we cannot recover a lost key; you must rotate it. Production infrastructure runs in isolated VPCs with no public database endpoints.

8. Changes to This Policy

We will notify registered users by email at least 14 days before material changes take effect. Continued use of the service after the effective date constitutes acceptance.

9. Contact

Questions about this policy: privacy@mapsapi.dev. Postal address available on request for GDPR Article 27 purposes.