Skip to content
Legal

Privacy policy

Last updated 20 August 2026

This policy covers www.mapsfordevelopers.com and the tile and API services at tiles.mapsfordevelopers.com. The service is operated by Houston IT Developers LLC, Houston, Texas, USA, which is the controller of the personal data described here.

The short version: we collect what the contact form asks for, we run basic web analytics, we keep server logs for security, and we do not sell any of it or use it for advertising.

What we collect

When you submit the contact form

Your name, email address, and — if you choose to provide them — your company, the use case you selected, and the message you wrote. We also record the IP address the submission came from, which is used to detect automated abuse.

When you use the map, the site or the API

Standard server and edge logs: IP address, timestamp, the resource requested, response status and bytes served. Tile access is governed by a short-lived signed token and a per-client byte budget, which requires counting request volume against the requesting IP address.

Analytics

We use Google Analytics 4 (provided by Google LLC) to understand which pages are used and how people arrive. It records pages viewed, referring site, approximate location derived from your IP address, and general device and browser characteristics.

How it is configured here, deliberately:

  • Google Analytics 4 does not log or store IP addresses. Your IP is used transiently to derive a coarse location and is then discarded by Google.
  • Google Signals is switched off, and the tag sends allow_google_signals: false and allow_ad_personalization_signals: false. No cross-device profile is built and nothing is fed to advertising products.
  • Cookies: first-party _ga and _ga_<stream>, used to tell repeat visits from new ones. We cap their lifetime at 13 months rather than Google's two-year default.
  • Retention: event and user data expire after 14 months and the clock is not reset by a later visit, so data genuinely ages out.

You can opt out entirely with Google's browser opt-out add-on, or with any content blocker — the site works normally without it.

Bot protection

Cloudflare Turnstile runs on the contact form and on map tile access. Turnstile is designed not to require personal data or to track users across sites, but it does process your IP address and browser signals in order to decide whether a request is automated.

Why we are allowed to do this

Where the UK or EU GDPR applies, we rely on: legitimate interests for security logging, bot protection and analytics (running a service that is not abused, and understanding whether it is useful); and taking steps at your request prior to entering into a contract for handling your contact-form enquiry. You can object to processing based on legitimate interests at any time — see Your rights.

What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California and Texas law.
  • We do not add you to a marketing list because you used the contact form. It is used to answer you.
  • We do not set advertising or cross-site tracking cookies.
  • We do not use your data to train machine-learning models, and we do not provide it to anyone else who does.

Who processes data on our behalf

  • Vercel Inc. — application hosting and request logs.
  • Cloudflare, Inc. — DNS, the tile gateway, R2 object storage, and Turnstile bot protection.
  • Resend — delivery of the email generated by the contact form.
  • Google LLC — Google Analytics 4, as described above.

Each processes data under its own terms and only to provide the service to us. We are a US company using US-based providers; if you contact us from outside the United States, your data will be processed in the US.

How long we keep things

  • Contact enquiries — for as long as we are talking to you, and afterwards for our business records. Ask and we will delete yours.
  • Analytics — 14 months, then automatic expiry.
  • Server and gateway logs — short-lived, retained only for security, abuse prevention and debugging.

Security

Traffic is encrypted in transit with TLS. The tile storage bucket is private and reachable only through a gateway that requires a short-lived signed token. API keys are stored as hashes, never in plaintext. Access to production systems is limited to the people who operate them. No system is perfectly secure, and we will not claim otherwise — if we become aware of a breach affecting your data we will notify you and the relevant regulator as required by law.

Your rights

Wherever you live, you can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted, and we will action it. We will not treat you differently for asking.

Depending on where you live you may have specific statutory rights — for example under the California Consumer Privacy Act (as amended by the CPRA), the Texas Data Privacy and Security Act, or the UK/EU GDPR. These typically include the right to know, access, correct, delete, obtain a portable copy, and to appeal a refusal. An authorised agent may make a request on your behalf. To exercise any of these, use the contact form and say what you need — we do not require a particular form of words, and we will respond within the period the applicable law requires.

If you are in the UK or EU and are unhappy with how we have handled a request, you also have the right to complain to your local data protection authority.

Children

This is a service sold to businesses and developers. It is not directed at children, and we do not knowingly collect data from anyone under 16.

Changes

If this policy changes materially we will update the date at the top of this page. Continued use after a change means you accept the revised policy.

Contact

Use the contact form for any privacy request and say what you need — it reaches us directly.