Privacy Policy
Your data is never shared with third parties. Not with Facebook, advertising networks, user trackers, or data aggregators.
Security
All data is encrypted in transit. MapStack is always served over HTTPS/SSL; only redirects to HTTPS are served over HTTP.
Passwords are stored only as salted bcrypt hashes, and never in the clear.
Third parties
We serve all our code from MapStack domains to avoid third-party tracking. We do not use Google Analytics, Cloudflare, or third-party content delivery networks, and we have no “partners” to flog your data to.
Analytics
We do not use third-party analytics. Usage metrics are collected in-house and aggregated, and a small set of anonymous counters (such as map view counts) is reported to our own servers.
Cookies
We do not serve any cookies by default to anonymous users. When you log in we set a single secure, HttpOnly session cookie for authentication, valid for up to 30 days.
Control over your data
You can:
- View and amend the data we hold about you on your account page.
- Export your data at any time, subject to reasonable bandwidth limits.
- Close your account at any time to delete your data. Data is immediately removed from live systems and completely removed from all backups within 14 days, and a record of the deletion request is kept for 14 days to allow for removal during any restore.
Data breaches
If you find or become aware of a data breach or leak, please report it to privacy@mapstack.org.
If there is a data breach, all affected users will be notified by email and notice will be posted on the website within 72 hours.
Please do not store highly sensitive or confidential information on MapStack. Contact us to discuss self-hosting or on-premises installation.