Draft for legal review
This is not the final privacy notice.

It reflects MapScale’s current product and code as closely as possible. The highlighted operator details, retention periods, international-transfer terms and controller/processor roles must be confirmed before this notice is published as final.

Privacy / plain language

What MapScale collects, and why.

We collect only what we need to run, secure and improve MapScale. Optional website analytics stays off unless you choose to allow it. We do not sell personal data or use it for targeted advertising.

Drafted
18 August 2026
Status
Legal review required
01

Who this notice covers

This notice applies to mapscale.io, MapScale documentation, dashboards, APIs, map tiles, static maps, support and integrations that link to it (together, the “Services”). It does not cover a customer’s own website or app merely because that customer uses MapScale.

The data controller for MapScale’s own website, sales, accounts and business operations is [LEGAL ENTITY NAME], trading as MapScale, at [REGISTERED OFFICE ADDRESS]. Contact: [PRIVACY EMAIL]. If a data protection officer has been appointed, their contact is [DPO CONTACT].

When a business customer sends personal data through an API, the customer normally decides why and how that data is used. MapScale may then act as its data processor under the service agreement and data processing agreement. The final allocation of roles depends on the service and contract.

02

Data we collect

The data depends on how you use MapScale.

  • Website and network data: IP address, user agent, requested host and path, date and time, referrer, response status, request identifiers, and security or diagnostic information.
  • Contact and sales data: work email, company name if supplied, use case, message, language, form placement and source. We also use network information to prevent spam and abuse.
  • Account and billing data: name, work email, organisation, role, plan, service status, billing contact and invoicing information, and contract or purchase-order details.
  • Credentials and settings: API-key hash and public prefix, key type, environment, allowed origins or app identifiers, enabled products, rate tier, expiry, revocation and last-used time. MapScale stores a hash rather than the full secret key after creation.
  • Service and usage data: product or endpoint used, account and key identifiers, request timing, outcome or status class, and aggregated hourly or monthly usage counts for operations, limits and billing.
  • Support data: the content of messages, files and troubleshooting details you choose to send us.
03

Location and API request data

MapScale processes the API input needed to answer a request. Depending on the product, this can include an address, place name, coordinates, route waypoints, search bounds, map style parameters, markers or paths. An address or precise location can identify or relate to a person and should be treated accordingly.

We use request data to return the requested result, protect the service, diagnose failures and meet contractual obligations. We do not intentionally put raw address queries, coordinates, free-text messages, emails or API secrets into product-analytics events.

Customers are responsible for having a lawful basis and giving any required notice before sending personal data to MapScale. Customers should not send special-category or highly sensitive personal data unless the contract expressly allows it and suitable safeguards are in place.

04

Why we use personal data

Purposes and proposed legal bases for counsel to confirm
PurposeTypical dataProposed legal basis
Provide APIs, accounts, support and billingAccount, request, usage, support and billing dataContract; steps requested before a contract
Answer sales or contact requestsContact form and correspondenceSteps requested before a contract; legitimate interests
Secure, rate-limit and troubleshoot the ServicesNetwork, request, device and diagnostic dataLegitimate interests; legal obligations where applicable
Measure and improve the website and docsConsented analytics dataConsent
Keep tax, accounting and compliance recordsContract, billing and transaction recordsLegal obligation; contract
05

Analytics, cookies and local storage

MapScale uses a basic-consent model. Google Analytics and any configured product-analytics tool are not loaded or contacted until you select “Yes, help improve MapScale”. If you select “No, thanks”, optional analytics stays off and the site continues to work.

When you consent, analytics may collect a random browser identifier, page path and title, referrer, language, browser and device information, screen information, approximate location derived by the provider, and interactions such as page views, demo use and button clicks. We configure analytics without advertising features and sanitise event properties to avoid direct identifiers, query strings, free text and secrets.

If session replay is enabled in a configured product-analytics tool, text, form inputs, known result areas and elements marked private are masked or blocked. Recording console logs and automatic exception capture are disabled in the current client configuration.

  • mapscale_analytics_consent: remembers accepted or rejected for up to 12 months; necessary to remember your choice.
  • _ga and related analytics identifiers: set only after consent when Google Analytics is active.
  • mapscale-theme: local-storage preference for light or dark appearance; not used for analytics.
06

Who receives data

We disclose data only where needed to operate the Services, fulfil a contract, obtain professional advice, complete a business transaction, or comply with law. Access should be limited to authorised people and providers under appropriate obligations.

  • Cloud and delivery providers, including Cloudflare, for DNS, network security, content delivery and request handling.
  • Google Analytics, only after consent, for website and documentation measurement.
  • PostHog, when configured and only after consent, for privacy-restricted product analytics.
  • Sentry and observability infrastructure, where configured, for service errors, traces, metrics and operational diagnosis.
  • Payment, accounting, legal, audit and other professional providers where relevant to an account or legal obligation.
  • Authorities, courts or counterparties when disclosure is required by law or necessary to establish, exercise or defend legal claims.
07

International transfers

MapScale and its providers may process data in Thailand, Singapore, the United States and other countries where the provider or its subprocessors operate. Privacy protections can differ between countries.

Before a restricted international transfer, we will use a mechanism required by applicable law, such as an adequacy decision, appropriate contractual terms, another permitted safeguard or explicit consent where that is the lawful option. Customers can request relevant transfer information through the privacy contact above.

08

How long we keep data

We aim to keep personal data only while it is needed for the purposes above, then delete or anonymise it unless law or a dispute requires longer. The schedule below is provisional.

Proposed retention schedule for operational and legal confirmation
DataProposed periodReview needed
Analytics consent choiceUp to 12 monthsImplemented in the consent cookie
Google Analytics data14 monthsConfirm the GA4 property setting
PostHog analytics, if enabled12 monthsConfirm project retention and replay settings
Contact and sales enquiries24 months after the last meaningful contactConfirm CRM and deletion process
Routine security and application logs90 daysConfirm each production log store and incident exception
Account, contract, billing and usage recordsFor the account term plus the applicable statutory periodInsert the Thai tax, accounting and claims period
BackupsAccording to the documented backup cycleInsert cycle and prove expiry
09

Your choices and rights

Depending on the law and circumstances, you may ask to access or receive a copy of your data, correct it, erase it, restrict or object to processing, receive portable data, or withdraw consent. You may also complain to Thailand’s Personal Data Protection Committee or another competent regulator.

Send a request to [PRIVACY EMAIL]. We may need to verify your identity and clarify the request. Some rights have exceptions—for example, we may need to retain transaction records required by law or data needed for legal claims. If MapScale processes data only for a customer, we may direct you to that customer.

10

How we protect data

We use technical and organisational safeguards proportionate to the risk. Current examples include encrypted transport, hashed API secrets, origin or app restrictions for publishable keys, access controls, rate limiting, masked analytics capture, sanitised analytics events, and separation of PII-bearing sales records from analytics views.

No internet service can guarantee absolute security. Please do not send customer records, API secrets or unnecessary personal data through the public contact form. If you believe data or credentials are exposed, contact [SECURITY EMAIL] promptly.

11

Children

MapScale is a business and developer service and is not directed to children. We do not knowingly ask children to create accounts or submit personal data. If you believe a child has provided personal data directly to MapScale, contact us so we can investigate and take appropriate action.

12

Changes and contact

We may update this notice when the Services, providers or law change. We will change the date above and provide a more prominent notice where a change materially affects your privacy choices.

Questions, requests or complaints: [LEGAL ENTITY NAME], [REGISTERED OFFICE ADDRESS], [PRIVACY EMAIL], [TELEPHONE IF USED], and [DPO CONTACT IF APPLICABLE]. General product enquiries can be sent through the contact form on the MapScale home page.

Before publication

Counsel and operator checklist

This block is intentionally visible while the notice is a draft. Remove it only after the policy and production systems agree.

  • Insert the legal entity, registered address, privacy, security and DPO contacts.
  • Confirm controller/processor roles and attach the customer DPA and subprocessor list.
  • Verify every active provider, processing region and cross-border safeguard.
  • Approve and implement the retention schedule in each production system.
  • Confirm the lawful bases, child-user position, rights workflow and breach-response contacts under Thai PDPA and any other applicable law.
  • Remove noindex and the draft banner only after legal sign-off.