Privacy · draft for launch review
Privacy Policy
Effective August 1, 2026. EveryCityMap processes only the information needed to deliver the service, prevent abuse, and complete purchases.
Who operates EveryCityMap
EveryCityMap is an independent-developer product, not a registered company name. Before public account or payment launch, this policy will identify the individual operator by their legal name and country or region and publish a private support address. The operator is the controller of first-party account and product data.
Anonymous use
Browsing and editing can remain anonymous. Approximate location headers may be used to suggest a city; precise location is not requested. A first-party functional cookie remembers the last confirmed city for up to 30 days so later visits can render immediately. It is not used for advertising or cross-site tracking.
Email and accounts
An optional free-export email is used to deliver that attachment. Marketing consent is separate and unchecked. Paid accounts store identity, order, entitlement, and project-snapshot metadata.
Payments and files
When paid checkout is enabled, the selected provider processes payment details on its secure checkout page; EveryCityMap does not receive or store full card numbers. Paddle acts as merchant of record when Paddle checkout is active. When Stripe checkout is active, Stripe processes payment for the independent operator. Each provider processes payment data under its own privacy terms. Free and initial paid raster files render in the browser and are not stored in first-party object storage.
Public share cards
When you choose Share, EveryCityMap stores a branded 2400 by 1260 pixel preview image and the map style needed to reopen it. The public link expires after 90 days. Shared payloads do not include raw city source data.
Minimal product analytics
EveryCityMap records a limited set of product events, such as a failed map load, export, checkout, or share. It does not send search text, map projects, payment details, IP addresses, or user agents in these events. The browser identifier exists only for the current page session, events expire after 90 days, and Do Not Track or Global Privacy Control disables submission.
Deletion and retention
Account deletion removes sign-in providers and sessions, revokes remaining export access, and anonymizes the account. Paid order records and frozen purchase snapshots may remain as required for commerce, support, and tax obligations. A signed-in user can download the account, provider, order, entitlement, frozen-project, and linked product-event data stored by EveryCityMap. Canceled checkout snapshots are removed after 24 hours. Expired purchase payloads are cleared after the support window while required commerce records remain.
This draft requires the operator's legal name, country or region, support address, and jurisdiction review before public account registration or live payment is enabled.