Privacy policy

Last updated 2026-08-23

This policy explains what personal data MapRouter collects and what we do with it. MapRouter is the data controller for that data.

What we collect

  • Account details. The email address you contact us from and any name or company you give us, so we can issue your key and reach you about your account.
  • API key records. A hash of your key, your credit balance, your rate limit, and the date it was issued. We never store the key itself.
  • Usage records. A ledger of billable requests — timestamp, operation, and amount debited — because it is what makes your balance auditable and refunds checkable.
  • Operational logs. Request metadata such as endpoint, response status, timing, and edge location, used to run and debug the Service.
  • Payment records. What you bought and when. Card details go directly to our payment processor and never reach our systems.

What we do not do

We do not sell or rent your personal data, and we do not share it with anyone for advertising. This website carries no advertising trackers, no third-party analytics, and no cookies used for tracking or profiling.

We do not use the contents of your queries — the places and areas you look up — for any purpose other than serving and billing the request itself.

Why we are allowed to hold it

We process account, key, and usage data because it is necessary to perform our contract with you. We process operational logs on the basis of our legitimate interest in keeping the Service secure and working. We keep payment and tax records because the law requires it.

Who else processes it

We use a small number of service providers, each processing data only to provide their service to us:

  • Cloudflare — hosting, edge delivery, and storage of account, key, and usage data.
  • Upstash — the key and balance datastore.
  • Our payment processor — payment handling. Your card details are held by them under their own privacy policy, not by us.
  • Fastmail — email correspondence with you.

Some of these operate infrastructure outside your country. We rely on their standard contractual protections for such transfers.

How long we keep it

Account and key records are kept while your account is active and for twelve months after you stop using the Service. Billing ledger and payment records are kept for seven years, as tax law requires. Operational logs are kept for thirty days.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it, and you can object to processing based on legitimate interest. Depending on where you live, you may have further rights under the GDPR, the UK GDPR, or US state privacy laws.

Email support@maprouter.ai and we will respond within thirty days. There is no charge. Note that we cannot delete billing records we are legally required to retain, and deleting your account data means revoking your API key.

If you are unhappy with how we have handled a request, you may complain to your local data protection authority.

Security

All traffic is encrypted in transit. API keys are stored only as SHA-256 hashes, so a breach of our datastore does not expose usable keys. Access to production systems is limited to the operator.

Children

The Service is intended for use by businesses and developers. It is not directed at children and we do not knowingly collect their data.

Changes

If this policy changes materially we will update the date above and notify account holders by email. Contact: support@maprouter.ai.