Skip to content

50,000 free calls a month, card-free. Get an API key →

Legal

Privacy policy

Last updated: 20 July 2026

We run a metered API, not an advertising business. We store what metering, billing and abuse prevention require, plus a de-identified log of where demand for routing is. Everything else we collect is opt-in, and all of it is aggregate-only (none of it includes your GPS positions or routes) and we never sell personal data.

1. What we store

We keep the minimum needed to run a metered API: your email address (lowercased, as the identity of record for keys, ledger and plan); API keys as cryptographic hashes only, never in plaintext; per-key usage counters (day, endpoint, count); your prepaid ledger and its credit history; your plan quota history; and a record of your terms acceptance, including the timestamp, IP address and user agent of the accepting request.

We do not store route coordinates against your identity for profiling. Request logs used for operations are short-lived and carry a request id, not a behavioural profile.

Separately from your account records, we keep a coarse demand log: one line per metered geospatial request recording the endpoint, whether it arrived from the API, an agent or an SDK, the territory, the pricing class, the billable units, and (where the request carried coordinates) the origin and destination truncated to a roughly 5 km cell, with the time floored to a five-minute bucket. The truncation happens before anything is written, and the line carries no API key, no key id, no account, no IP address and no search text, so it cannot be linked back to you or to a person. We use it to understand where demand for routing is, which is what tells us where to improve coverage.

The website sets no analytics or advertising cookies. We measure aggregate site traffic with Plausible and product usage (for example, how many visitors complete signup) with PostHog, both configured cookieless: they store no personal data, no persistent identifiers and nothing on your device, and cannot follow you across sites or visits. When you issue a key through the signup page, the key, its id and your email are saved in your own browser's localStorage so the account page and playground work without a login system; that data stays on your device and you can clear it from your browser at any time.

2. Why we store it

Service operation: issuing and authenticating keys, metering usage against quotas and credit, showing you your own account state, and billing through our payment processor.

Abuse prevention: issuance velocity limits per IP, key caps per identity, and disposable-email rejection all rely on the data above. The acceptance record (timestamp, IP, user agent) exists so that self-serve and agent-made acceptances are evidenced.

The lawful bases are performance of a contract (running the service you signed up for) and legitimate interests (keeping the service secure and abuse-free, and creating aggregated, de-identified insights that identify no one). Where we act as a fleet operator's processor for opt-in operational data, that operator sets the lawful basis as controller; see section 4.

3. Who else touches it

We do not sell personal data, full stop. We may create and commercialise aggregated, de-identified insights (data aggregated so that no person or customer is identifiable, which is not personal data), and the contractual basis for that is in the terms of service.

We use a small number of processors to run the service: Stripe (card payments and subscriptions; we never see card numbers), a transactional email provider for magic-link verification emails, Hetzner (the servers the API gateway runs on, located in the EU), Vercel (hosting for this website and its signup proxy), Plausible (cookieless aggregate web analytics; no personal data), PostHog (cookieless product analytics, hosted in the EU; no personal data), and Sentry (error and performance monitoring for this website; a crash report carries the page, the browser and the originating IP address). We will keep this list current here as providers change.

4. Contributed operational data (opt-in, off by default)

MapMap's SDK includes an optional fleet-telemetry module that is off by default and does nothing unless a fleet operator explicitly enables it. When switched on, it map-matches on the device and shares only aggregate road-segment statistics (mean and 85th-percentile speeds, stopped time, in day-of-week and time-of-day buckets) with the first and last stretch of every trip discarded and no location beyond a coarse (~5 km) origin/destination cell. Your GPS positions and your route never leave the vehicle; the module is architecturally incapable of uploading a trajectory. The same applies to any map-matched trace-analysis output a customer chooses to retain: matched segment data only, never the input trace. See /trust for the verifiable detail.

The demand log described in section 1 is the one collection surface that is not per-customer opt-in: it runs on the hosted API only, it is de-identified before it is written rather than afterwards, and it is never applied to self-hosted deployments, which report nothing to us at all. If you would rather your hosted traffic did not appear even in that form, tell us and we will exclude your key.

Where a fleet operator enables this, the operator is the data controller for its drivers and MapMap is its processor under a data processing agreement; the lawful basis is the operator's legitimate interest or contract, not driver consent. Where a consumer app embeds our SDK, the app developer is the controller and must obtain opt-in consent before any collection. We use the aggregated, de-identified result to improve routing and traffic products; because it identifies no one it is not personal data, and its commercial use is governed by the terms of service.

5. How long we keep it

Keys and identities persist while your account is active. Revoked keys and their usage counters are retained for up to twenty-four months for billing evidence and abuse forensics, then deleted or anonymised. Ledger and quota history are retained for six years in line with UK accounting requirements. Acceptance records are kept for as long as the agreement could be relevant. IP-based issuance counters expire within days. Contributed operational data is aggregated and de-identified at the point of collection; the de-identified aggregates are retained for as long as they are useful for the products they feed.

6. Your rights

Under the UK GDPR you have the right of access, rectification, erasure, restriction, portability and objection, and the right to complain to the Information Commissioner's Office (ico.org.uk). Email us and we will act on a verified request within one month. Note that erasing your identity necessarily revokes its keys.

7. Contact

Controller: MapMap AI Ltd, registered in England and Wales, trading as MapMap. For any privacy matter, including subject access requests, contact hello@mapmap.ai. We will update this page as the service evolves; material changes will be dated here.

The contractual side lives in the terms of service. Anything unclear: hello@mapmap.ai.