Privacy Policy
Last updated: June 21, 2026
1. Who We Are & Scope
GISDeploy is the data controller for personal data processed about your account and use of the Service. For data you upload and publish, you are the controller and we act as a processor on your behalf. This policy covers our website, dashboard, APIs, and map services. It does not cover third-party sites or services we link to.
2. Information We Collect
- Account information — your name, email address, and a securely hashed password.
- Content you upload — geospatial files and datasets, their metadata, and any maps or stories you create. These may contain location data and, depending on what you upload, personal data for which you are responsible.
- Billing information — plan and subscription details. Where payments are processed, card numbers are handled by our payment processor; we do not store full card numbers.
- Communications — messages you send us, including via the contact form (name, email, organization, and message).
- Usage & technical data — log data such as IP address, browser/device information, requests made, and timestamps, used for security and to operate the Service.
- Cookies — we use a single essential session cookie (
geodeploy_session) to keep you signed in. See section 5.
3. How We Use Information
- To provide, operate, and maintain the Service, including processing and serving your maps;
- To authenticate you and secure your account;
- To manage subscriptions, billing, and plan limits;
- To respond to your requests and provide support;
- To monitor, debug, and improve the Service and prevent abuse;
- To comply with legal obligations and enforce our terms.
4. Legal Bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you sign up for;
- Legitimate interests — to secure, maintain, and improve the Service and prevent abuse;
- Legal obligation — to meet accounting, tax, and other legal requirements;
- Consent — where we ask for it; you may withdraw consent at any time.
5. Cookies
We use only strictly necessary cookies. The geodeploy_session cookie keeps you authenticated. We do not use advertising or cross-site tracking cookies. Because these cookies are essential to the Service, they are not used for profiling and do not require consent under most frameworks. Blocking them may prevent you from signing in.
6. Sharing & Subprocessors
We do not sell your personal data. We share data only with service providers (“subprocessors”) that help us run the Service, under appropriate confidentiality and data-protection terms:
- Hosting & infrastructure — cloud and server providers that store and serve your data;
- Email delivery — to send transactional and support emails;
- Geocoding — when you create a map from an address, the address query is sent to a geocoding provider (by default OpenStreetMap / Nominatim);
- AI assistant — if you use AI features, your prompts and the relevant context are sent to a third-party large language model provider (e.g., DeepSeek or Anthropic) to generate responses;
- Legal & safety — we may disclose data if required by law or to protect rights, safety, and the integrity of the Service.
We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
7. International Data Transfers
We and our subprocessors may process data in countries other than your own. Where required, we use appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) to protect personal data transferred across borders.
8. Data Retention & Deletion
We retain personal data for as long as your account is active or as needed to provide the Service, and afterward only as required for legitimate business or legal purposes. When you delete content or close your account, we delete or anonymize the associated data within a reasonable period, except where retention is required by law.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data; to restrict or object to certain processing; and to withdraw consent. California residents may request to know and delete personal information and to opt out of its sale or sharing (note: we do not sell or share your personal information).
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law and will not discriminate against you for exercising your rights. You may also have the right to lodge a complaint with your local data-protection authority.
10. Children’s Privacy
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
11. Security
We use technical and organizational measures — including encryption in transit, hashed passwords, access controls, and per-customer data isolation — to protect personal data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-app) and update the “Last updated” date above.
13. Contact
For privacy questions or requests, contact us at [email protected].