Privacy · effective August 8, 2026
Privacy Policy
This policy explains how EveryCityMap collects and uses information when you browse, create, share, export, or purchase a map. EveryCityMap is an independent-developer product operated under the EveryCityMap name. Questions and privacy requests can be sent to albertaz1992@gmail.com.
Information we collect
You can browse, search, and edit without an account. We may process an approximate country, region, city, or time zone supplied by the network or browser to suggest a starting city. We do not request precise device location.
If you create an account, we store your email address, sign-in provider, account identifiers, sessions, and security records. If you buy an export, we store order, payment-provider, entitlement, refund, dispute, and frozen-project metadata. We do not receive or store your full card number.
If you request a free export by email, we use the address only to deliver that file unless you separately opt in to product updates. Marketing consent is optional and unchecked. The generated attachment is sent directly and is not retained in EveryCityMap object storage.
How we use information
We use information to provide and secure the service, remember functional preferences, deliver requested emails and exports, process and reconcile purchases, prevent abuse, respond to support requests, comply with legal obligations, and understand a limited set of product events. We do not sell personal information or use it for cross-site advertising.
Service providers
Cloudflare hosts the application, security controls, and account database; AWS delivers the map assets needed to render the service; Resend sends transactional email; Google provides optional sign-in; and Paddle or Stripe processes payments when its checkout is selected. These providers process information under their own terms and may process it in countries other than yours.
Cookies and local storage
We use essential cookies for account sessions and abuse prevention. Browser storage and IndexedDB cache rendering assets, theme preferences, and the last confirmed city so return visits can load faster. These technologies are not used for third-party advertising.
Sharing and product events
Creating a public share link stores a branded preview and the style needed to reopen it. The link expires after 90 days and does not include the rendering assets used by the application. Limited product events, such as page views, city selection, map-load, export, checkout, share-template selection, or share outcomes, expire after 90 days. Security policy reports may record the blocked origin and affected page path so we can detect broken integrations or attacks. We review these signals in aggregate and do not place search text, full projects, payment details, IP addresses, or user agents in them; Do Not Track or Global Privacy Control disables product-event submission.
Retention, access, and deletion
Account deletion removes sign-in providers and sessions, revokes unused export access, and anonymizes the account. Required order and payment records may remain for tax, fraud, accounting, dispute, and legal obligations. Signed-in users can download the account and commerce data held by EveryCityMap. You may also email us to request access, correction, deletion, or another privacy right available where you live.
Security, children, and changes
We use access controls, signed downloads, rate limits, encryption in transit, and restricted provider credentials. No system is completely secure. EveryCityMap is not directed to children under 16, and we do not knowingly collect their personal information. Material policy changes will be posted here with a new effective date.