Appearance
Privacy Policy
Effective Date: 2026-07-09 · Document ID: PP-MMA-001 · Contact: info@mapsted.com · Contact UsVersion: 1.0
Plain-language summary (non-binding): The Mapsted Maps JavaScript API embeds a map into your Licensee's website or application using an iframe. When you use the map, Mapsted's servers receive your IP address, user-agent, and API key to serve map data. Navigation actions you take inside the map (selecting a POI, changing floors, entering a search term, clicking a promotion) travel only between the map iframe and the embedding page via browser postMessage — they are not transmitted to Mapsted's servers. If you are using an application built by one of Mapsted's Licensees, the Licensee's own privacy policy governs how your data is used. You may submit privacy requests to privacy@mapsted.com.
1. Introduction
Mapsted Corp. ("Mapsted", "we", "us", "our") is committed to protecting the privacy of individuals who interact with the Mapsted Maps JavaScript API (the "Software") and this documentation site. This Privacy Policy explains what data is collected, why, on what legal basis, how it is used, and what rights you have.
This policy applies to:
- End users of Licensee applications that embed the Software (via the Software's iframe and postMessage architecture).
- Visitors to this documentation site (
docs.mapsted.com/maps-js-api). - Developers and Licensees who register for API keys or sign Commercial Agreements with Mapsted Corp.
2. Data Controllers and Processors
Mapsted Corp. as data controller: Mapsted Corp. determines the purposes and means of processing data it directly collects through the backend services (maps.mapsted.com, deploy.mapsted.com, filer.mapsted.com) and this documentation site.
Licensee as independent data controller: The Licensee (the organisation embedding the Software in their application) is an independent data controller for the data it collects from its end users. The Licensee is responsible for its own privacy policy and for obtaining any consents required from its end users.
Mapsted Corp. as data processor: To the extent Mapsted Corp. processes personal data on behalf of a Licensee under a Commercial Agreement (for example, by serving map sessions to the Licensee's end users), Mapsted Corp. acts as a data processor. The terms of that processing are governed by the Data Processing Addendum incorporated into the Commercial Agreement. Licensees may request a copy of Article 28 GDPR processor information from privacy@mapsted.com.
Notice at collection: The Licensee's own notice at collection is operative for end users of Licensee applications. This Privacy Policy is a transparency supplement that describes Mapsted Corp.'s direct processing. End users of Licensee applications should consult the Licensee's privacy notice as the primary statement of their rights.
3. Data Collected During a Map Session
When an end user loads a page embedding the Software, the following data may be processed by Mapsted's backend services:
| Data category | Source | Purpose |
|---|---|---|
| IP address | HTTP request headers | Routing, fraud prevention, regional compliance |
| User-agent string | HTTP request headers | Compatibility, debugging |
API key (?key= query parameter or authentication header) | Request authentication | Licence validation, quota enforcement. Note: the API key is passed as a URL query parameter (?key=…) in certain request paths, which may be visible in server access logs, browser history, and network proxies. Licensees should treat the API key as a credential and avoid logging or caching the full request URL. |
| Property ID and building ID | init() call parameters | Serving the correct map data |
| Crash telemetry (stack traces, error codes) — capability not currently implemented | Planned opt-in error reporting for a future release | Quality improvement |
Navigation events are client-side only — not transmitted to Mapsted's backend: User interactions inside the map iframe (including entity selections via selectEntity, floor changes, routing requests, map-centre and zoom changes, search queries captured by the searchText event, promotion interactions captured by the promotionClick and promotionDetails events, and navigation lifecycle events captured by the navigationStart event) travel exclusively between the map iframe and the embedding Licensee page via the browser's window.postMessage API. These events are dispatched to a client-side in-memory event emitter (DocumentFragment) and are not relayed to, stored by, or transmitted to any Mapsted backend service. Any analytics the Licensee chooses to build on top of these events are governed by the Licensee's own privacy policy.
What is not collected by Mapsted's backend: The Software does not transmit end-user names, email addresses, passwords, payment information, navigation event payloads, search terms, or any direct personal identifier from end users to Mapsted's servers. The Licensee's authentication system and user accounts are entirely outside the Software's scope.
Crash telemetry is not currently implemented in the Software — the current version transmits zero crash reports, stack traces, or error codes to Mapsted's backend. Should Mapsted add crash telemetry in a future release, it will be opt-in only, scoped to stack traces and error codes, and processed solely for quality improvement under the consent basis described in §5. No analytics platform is wired to Mapsted's backend services for the Software.
4. Data Collected on the Documentation Site
When you visit docs.mapsted.com/maps-js-api, we may collect:
- Server access logs (IP address, request path, timestamp, user-agent, referrer) for security monitoring and performance tuning.
- Preferences stored in browser
localStorage(e.g., dark/light theme, selected code language). These are not transmitted to Mapsted servers. - Search queries entered into the documentation site's local search.
The storage inventory above reflects the Software's current disclosed behaviour for the outer-page wrapper and the inner map iframe at the date of publication. Mapsted reviews and updates this inventory as part of its ongoing compliance process; Licensees may request the latest inventory from privacy@mapsted.com.
5. Lawful Bases of Processing
Where Mapsted Corp. acts as data controller (controller mode):
| Processing activity | Lawful basis (GDPR Art. 6) | Notes | Equivalent Canadian basis (PIPEDA) |
|---|---|---|---|
| Serving map tiles and building data | Contract performance (Art. 6(1)(b)) — performance of the service agreement with the Licensee | — | Contractual necessity |
| API key validation and quota enforcement | Contract performance (Art. 6(1)(b)) | — | Contractual necessity |
| IP logging for security and fraud prevention | Legitimate interest (Art. 6(1)(f)) — Mapsted's interest in protecting the integrity of its services and preventing abuse | A Legitimate Interests Assessment (LIA-MMA-001) has been conducted and supports this basis; a summary is available to Licensees upon written request to privacy@mapsted.com. End users retain the right to object under Art. 21 GDPR. | Legitimate business purpose |
| Crash telemetry — planned future capability | Consent (Art. 6(1)(a)) — opt-in only when and if introduced | Not currently implemented; see §3 | Express consent |
| Documentation site server logs | Legitimate interest (Art. 6(1)(f)) — security monitoring and performance tuning | Covered by the same LIA as IP logging above. | Legitimate business purpose |
Where Mapsted Corp. acts as data processor (processor mode):
When processing personal data on behalf of a Licensee under a Commercial Agreement, the Licensee (as data controller) determines the lawful basis for that processing. Mapsted Corp. processes such data only on documented instructions from the Licensee, as set out in the Data Processing Addendum.
DPIA: Mapsted Corp. has assessed whether a Data Protection Impact Assessment (DPIA) is required under GDPR Art. 35. Given that the Software processes location-adjacent data (property ID, building ID, floor) potentially at scale across multiple Licensees, Mapsted Corp. will conduct a DPIA where the applicable risk threshold is met and will make a copy available to Licensees upon written request to privacy@mapsted.com.
6. Retention
| Data category | Retention period |
|---|---|
| Server access logs (IP, user-agent) | Thirty (30) days |
| Navigation event logs | Not retained beyond session (events are client-side postMessage only) |
| Crash telemetry (opt-in) — if and when implemented | Twelve (12) months (planned) |
| API key audit logs | Twelve (12) months |
| Vulnerability-report data | Thirty-six (36) months post-closure |
| Commercial Agreement records post-term | Seven (7) years (or longer where legal-hold obligations apply) |
| Data subject rights (DSR) response records | Three (3) years from date of response |
Note: The Software does not retain navigation event logs on Mapsted's backend (see §3).
7. Data Subject Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the data Mapsted holds about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your data, subject to Mapsted's legal obligations and to technical constraints: certain data categories (e.g., immutable security audit logs and aggregated billing records) may not be individually erasable. Where full erasure is not technically feasible, Mapsted Corp. will take proportionate steps to restrict further use of the data, and will document the technical limitation in its response.
- Restriction — request that processing be limited while a dispute is resolved.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Opt-out of sale/sharing (California CCPA/CPRA) — Mapsted does not sell or share personal information as defined under CCPA/CPRA. To submit a California privacy request, email privacy@mapsted.com. Mapsted Corp. will respond within 45 days of receipt, extendable by a further 45 days with notice.
- GPC signal (California CCPA Regulations §7025) — Mapsted Corp. honours Global Privacy Control (GPC) signals to the extent applicable to first-party processing.
- Shine the Light (California Civil Code §1798.83) — California residents may request information about disclosures of personal information to third parties for direct marketing purposes during the preceding calendar year. Submit requests to privacy@mapsted.com.
Mapsted Corp. will respond within the time periods required by applicable law. Under GDPR, responses are due within one month; this period may be extended by a further two months for complex or numerous requests, with notice provided within one month of receipt. Under CCPA, responses are due within 45 days, extendable by a further 45 days with notice. Under PIPEDA (Canada), responses are due within thirty (30) days, extendable by a further thirty (30) days where necessary with notice.
To exercise any right, contact privacy@mapsted.com. Mapsted Corp. has designated a Privacy Lead accountable for privacy compliance under PIPEDA. For GDPR / UK GDPR enquiries and data-subject rights, contact privacy@mapsted.com. Mapsted will appoint a formal Data Protection Officer where required under GDPR Art. 37 and will update this contact accordingly.
Note for end users of Licensee applications: If you are an end user of an application built by a Licensee (not Mapsted Corp. directly), you should direct privacy requests to the Licensee first, as the Licensee is the data controller for your data in that context.
8. Cookies and Similar Technologies
See the Cookie Policy for a full inventory of cookies, localStorage, and similar technologies used by the Software and this documentation site.
The Software's outer-page bundle is stateless and sets no cookies in the embedding page. The inner maps.mapsted.com iframe may set cookies or use sessionStorage within the iframe's own origin. Licensees are responsible for ensuring their consent mechanism covers the Mapsted iframe.
9. International Transfers
Mapsted Corp. is a Canadian company. Personal data may be processed on infrastructure operated by Mapsted's subprocessors, which may be located in the United States or other jurisdictions outside Canada or the European Economic Area.
EEA and UK transfers: Where personal data is transferred from the EEA or UK to a country without an adequacy decision, Mapsted Corp. relies on Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2 (Controller-to-Processor)), and the UK International Data Transfer Addendum (IDTA), version B1.0 for UK transfers. A Transfer Impact Assessment (TIA) has been completed and is available to Licensees upon written request to privacy@mapsted.com.
Canada-to-EEA transfers: Where personal data is transferred from Canada to the EEA, Mapsted Corp. relies on PIPEDA Schedule 1 Principle 7 (comparable protection by contract) and contractual safeguards with the relevant subprocessors.
A full list of subprocessors and their locations is maintained in the Subprocessor List.
10. Subprocessors
Mapsted Corp. uses third-party subprocessors to deliver the Service. The current list is maintained in the Subprocessor List. Mapsted Corp. will provide notice of material changes to the subprocessor list to Licensees under a Commercial Agreement within thirty (30) days of the change taking effect.
11. Children's Data
The Software is not directed at children. Mapsted Corp. does not knowingly collect personal data from children under the age of 13 (or 16 in jurisdictions where a higher minimum age applies under applicable law, such as under the GDPR where member state law sets a higher age). If you believe a child has provided personal data through a Licensee application embedding the Software, please contact the Licensee in the first instance, and privacy@mapsted.com if the concern involves Mapsted Corp.'s own processing.
12. Jurisdiction-Specific Notices
Canada — PIPEDA and Québec Law 25
This policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation, including PIPEDA's Schedule 1 accountability principles (Principle 1: Accountability — Mapsted Corp. is accountable for personal data under its control and has designated an individual responsible for compliance).
Québec — Law 25 (Act respecting the protection of personal information in the private sector) and Bill 96:
Québec's Law 25 applies to Mapsted Corp.'s processing activities where personal information of Québec residents is involved. The following obligations are addressed:
- Privacy Impact Assessment (PIA) (s.70.1 Law 25): A PIA for cross-border transfers has been completed; a summary is available to affected Licensees upon written request to privacy@mapsted.com.
- French-language version (Bill 96 / Charter of the French Language): A French-language version of this Privacy Policy will be maintained for Québec residents where required under Law 25 / Bill 96 and will be made available at https://www.mapsted.com/legal/privacy-policy (fr-CA locale). En cas de divergence, la version française prévaudra pour les résidents du Québec.
- Privacy Officer: The individual designated under PIPEDA also serves as the person responsible for the protection of personal information under Law 25. Contact: privacy@mapsted.com.
- Automated decision-making: Routing and distance calculations performed by the Software are deterministic algorithmic outputs and do not constitute automated decision-making producing legal or similarly significant effects on individuals within the meaning of Law 25 s.12.1.
Breach Notification — PIPEDA and Québec Law 25
Mapsted Corp. will notify affected individuals and the relevant regulator(s) of a breach of security safeguards involving personal data as follows:
- PIPEDA (Canada-wide): Where a breach creates a real risk of significant harm, Mapsted Corp. will notify the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible after determining that the breach creates such a risk, and will notify affected individuals directly in accordance with the Breach of Security Safeguards Regulations (SOR/2018-64).
- Québec Law 25: Where a breach involves personal information of a person residing in Québec that presents a risk of serious injury, Mapsted Corp. will notify the Commission d'accès à l'information (CAI) promptly upon becoming aware of the breach, and will notify affected individuals without delay.
- GDPR / UK GDPR: As applicable, Mapsted Corp. (in its controller capacity) will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
- Processor obligations: Where Mapsted Corp. acts as a data processor, Mapsted Corp. will notify the Licensee (as data controller) of a personal data breach without undue delay and within the breach notification SLA specified in the Data Processing Addendum, to enable the Licensee to fulfil its own notification obligations.
European Economic Area and United Kingdom — GDPR / UK GDPR
Individuals in the EEA and UK have the rights described in §7. If you are not satisfied with Mapsted Corp.'s response to a privacy request, you have the right to lodge a complaint with your local supervisory authority (for example, the supervisory authority of the EU member state where you reside or work, or the Information Commissioner's Office (ICO) in the UK).
Data Protection Officer (DPO): Mapsted Corp. has designated a Privacy Lead accountable for privacy compliance under PIPEDA. For GDPR / UK GDPR enquiries and data-subject rights, contact privacy@mapsted.com. Mapsted will appoint a formal Data Protection Officer where required under GDPR Art. 37 and will update this contact accordingly.
EU/UK Representative (Art. 27 GDPR / UK GDPR Art. 27): Mapsted Corp. will appoint an EU representative and/or UK representative under Art. 27 where required. Enquiries may be directed to privacy@mapsted.com pending appointment of a designated representative.
Records of Processing Activities (RoPA): Mapsted Corp. maintains a Record of Processing Activities as required by GDPR Art. 30, covering both controller-mode and processor-mode processing activities.
UK GDPR — International Data Transfer Addendum (IDTA): Where personal data is transferred from the UK, Mapsted Corp. relies on the UK International Data Transfer Addendum (IDTA), version B1.0 (ICO-approved).
California — CCPA/CPRA
California residents have the right to know what personal information is collected, to request deletion, and to opt out of the sale or sharing of personal information. Mapsted Corp. does not sell or share personal information as defined under CCPA/CPRA.
To submit a California privacy request, email privacy@mapsted.com. Mapsted Corp. will respond within 45 days of receipt, extendable by a further 45 days with notice.
Shine the Light (California Civil Code §1798.83): See §7 above.
Global Privacy Control (GPC): See §7 above.
13. Security
Mapsted Corp. implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. All data in transit between the end user's browser and Mapsted's backend services is encrypted using TLS 1.3 preferred; TLS 1.2 minimum. TLS 1.0 and 1.1 are not supported. Data at rest on Mapsted-operated infrastructure is encrypted using AES-256 via the Google Cloud Platform default encryption service.
Origin validation: The Software validates the origin of postMessage events received from the map iframe against the expected Mapsted domain. However, during CDN-mode initialisation, there is a brief window before the iframe's actual origin is known during which postMessage origin validation uses a wildcard (*). This window is bounded by the iframe load event and is documented in the Software's security architecture (see emitter.ts, CHL4-08).
Mapsted Corp. uses the OWASP Top 10 as an internal reference framework for web application security development and review. Mapsted Corp. maintains an Incident Response Plan covering vulnerability triage, containment, remediation, and post-incident review.
See the Security Policy for further information.
14. Changes to This Policy
Mapsted Corp. may update this Privacy Policy from time to time. Material changes will be announced on this documentation site and, where required by applicable law, by direct notice to affected Licensees. The "last updated" date will be revised with each material change.
15. Contact
For privacy questions, requests to exercise data subject rights, or to report a privacy concern:
- Email: privacy@mapsted.com
- Web: https://www.mapsted.com/contact-us
- Mapsted Corp., registered office address available upon written request to info@mapsted.com.
Related documents
- Cookie Policy — CP-MMA-001
- Subprocessor List — SL-MMA-001
- Terms of Service — TOS-MMA-001
- Security Policy — SP-MMA-001
- Legal Hub