Who this notice covers
This notice applies to mapscale.io, MapScale documentation, dashboards, APIs, map tiles, static maps, support and integrations that link to it (together, the “Services”). It does not cover a customer’s own website or app merely because that customer uses MapScale.
The data controller for MapScale’s own website, sales, accounts and business operations is [LEGAL ENTITY NAME], trading as MapScale, at [REGISTERED OFFICE ADDRESS]. Contact: [PRIVACY EMAIL]. If a data protection officer has been appointed, their contact is [DPO CONTACT].
When a business customer sends personal data through an API, the customer normally decides why and how that data is used. MapScale may then act as its data processor under the service agreement and data processing agreement. The final allocation of roles depends on the service and contract.
Data we collect
The data depends on how you use MapScale.
- Website and network data: IP address, user agent, requested host and path, date and time, referrer, response status, request identifiers, and security or diagnostic information.
- Contact and sales data: work email, company name if supplied, use case, message, language, form placement and source. We also use network information to prevent spam and abuse.
- Account and billing data: name, work email, organisation, role, plan, service status, billing contact and invoicing information, and contract or purchase-order details.
- Credentials and settings: API-key hash and public prefix, key type, environment, allowed origins or app identifiers, enabled products, rate tier, expiry, revocation and last-used time. MapScale stores a hash rather than the full secret key after creation.
- Service and usage data: product or endpoint used, account and key identifiers, request timing, outcome or status class, and aggregated hourly or monthly usage counts for operations, limits and billing.
- Support data: the content of messages, files and troubleshooting details you choose to send us.
Location and API request data
MapScale processes the API input needed to answer a request. Depending on the product, this can include an address, place name, coordinates, route waypoints, search bounds, map style parameters, markers or paths. An address or precise location can identify or relate to a person and should be treated accordingly.
We use request data to return the requested result, protect the service, diagnose failures and meet contractual obligations. We do not intentionally put raw address queries, coordinates, free-text messages, emails or API secrets into product-analytics events.
Customers are responsible for having a lawful basis and giving any required notice before sending personal data to MapScale. Customers should not send special-category or highly sensitive personal data unless the contract expressly allows it and suitable safeguards are in place.
Why we use personal data
| Purpose | Typical data | Proposed legal basis |
|---|---|---|
| Provide APIs, accounts, support and billing | Account, request, usage, support and billing data | Contract; steps requested before a contract |
| Answer sales or contact requests | Contact form and correspondence | Steps requested before a contract; legitimate interests |
| Secure, rate-limit and troubleshoot the Services | Network, request, device and diagnostic data | Legitimate interests; legal obligations where applicable |
| Measure and improve the website and docs | Consented analytics data | Consent |
| Keep tax, accounting and compliance records | Contract, billing and transaction records | Legal obligation; contract |
Analytics, cookies and local storage
MapScale uses a basic-consent model. Google Analytics and any configured product-analytics tool are not loaded or contacted until you select “Yes, help improve MapScale”. If you select “No, thanks”, optional analytics stays off and the site continues to work.
When you consent, analytics may collect a random browser identifier, page path and title, referrer, language, browser and device information, screen information, approximate location derived by the provider, and interactions such as page views, demo use and button clicks. We configure analytics without advertising features and sanitise event properties to avoid direct identifiers, query strings, free text and secrets.
If session replay is enabled in a configured product-analytics tool, text, form inputs, known result areas and elements marked private are masked or blocked. Recording console logs and automatic exception capture are disabled in the current client configuration.
- mapscale_analytics_consent: remembers accepted or rejected for up to 12 months; necessary to remember your choice.
- _ga and related analytics identifiers: set only after consent when Google Analytics is active.
- mapscale-theme: local-storage preference for light or dark appearance; not used for analytics.
Who receives data
We disclose data only where needed to operate the Services, fulfil a contract, obtain professional advice, complete a business transaction, or comply with law. Access should be limited to authorised people and providers under appropriate obligations.
- Cloud and delivery providers, including Cloudflare, for DNS, network security, content delivery and request handling.
- Google Analytics, only after consent, for website and documentation measurement.
- PostHog, when configured and only after consent, for privacy-restricted product analytics.
- Sentry and observability infrastructure, where configured, for service errors, traces, metrics and operational diagnosis.
- Payment, accounting, legal, audit and other professional providers where relevant to an account or legal obligation.
- Authorities, courts or counterparties when disclosure is required by law or necessary to establish, exercise or defend legal claims.
International transfers
MapScale and its providers may process data in Thailand, Singapore, the United States and other countries where the provider or its subprocessors operate. Privacy protections can differ between countries.
Before a restricted international transfer, we will use a mechanism required by applicable law, such as an adequacy decision, appropriate contractual terms, another permitted safeguard or explicit consent where that is the lawful option. Customers can request relevant transfer information through the privacy contact above.
How long we keep data
We aim to keep personal data only while it is needed for the purposes above, then delete or anonymise it unless law or a dispute requires longer. The schedule below is provisional.
| Data | Proposed period | Review needed |
|---|---|---|
| Analytics consent choice | Up to 12 months | Implemented in the consent cookie |
| Google Analytics data | 14 months | Confirm the GA4 property setting |
| PostHog analytics, if enabled | 12 months | Confirm project retention and replay settings |
| Contact and sales enquiries | 24 months after the last meaningful contact | Confirm CRM and deletion process |
| Routine security and application logs | 90 days | Confirm each production log store and incident exception |
| Account, contract, billing and usage records | For the account term plus the applicable statutory period | Insert the Thai tax, accounting and claims period |
| Backups | According to the documented backup cycle | Insert cycle and prove expiry |
Your choices and rights
Depending on the law and circumstances, you may ask to access or receive a copy of your data, correct it, erase it, restrict or object to processing, receive portable data, or withdraw consent. You may also complain to Thailand’s Personal Data Protection Committee or another competent regulator.
Send a request to [PRIVACY EMAIL]. We may need to verify your identity and clarify the request. Some rights have exceptions—for example, we may need to retain transaction records required by law or data needed for legal claims. If MapScale processes data only for a customer, we may direct you to that customer.
How we protect data
We use technical and organisational safeguards proportionate to the risk. Current examples include encrypted transport, hashed API secrets, origin or app restrictions for publishable keys, access controls, rate limiting, masked analytics capture, sanitised analytics events, and separation of PII-bearing sales records from analytics views.
No internet service can guarantee absolute security. Please do not send customer records, API secrets or unnecessary personal data through the public contact form. If you believe data or credentials are exposed, contact [SECURITY EMAIL] promptly.
Children
MapScale is a business and developer service and is not directed to children. We do not knowingly ask children to create accounts or submit personal data. If you believe a child has provided personal data directly to MapScale, contact us so we can investigate and take appropriate action.
Changes and contact
We may update this notice when the Services, providers or law change. We will change the date above and provide a more prominent notice where a change materially affects your privacy choices.
Questions, requests or complaints: [LEGAL ENTITY NAME], [REGISTERED OFFICE ADDRESS], [PRIVACY EMAIL], [TELEPHONE IF USED], and [DPO CONTACT IF APPLICABLE]. General product enquiries can be sent through the contact form on the MapScale home page.
Before publication
Counsel and operator checklist
This block is intentionally visible while the notice is a draft. Remove it only after the policy and production systems agree.
- Insert the legal entity, registered address, privacy, security and DPO contacts.
- Confirm controller/processor roles and attach the customer DPA and subprocessor list.
- Verify every active provider, processing region and cross-border safeguard.
- Approve and implement the retention schedule in each production system.
- Confirm the lawful bases, child-user position, rights workflow and breach-response contacts under Thai PDPA and any other applicable law.
- Remove noindex and the draft banner only after legal sign-off.