Legal
Privacy Policy
Last updated: March 7, 2026
Overview
MapToArt (“we,” “us,” or “our”) generates custom map posters from real city geometry. This policy explains what data we collect, why, and how we protect it. We keep things simple: we collect only what we need to deliver your posters and process your payment.
Data We Collect
Information you provide
- Email address — used to deliver your order confirmation and download links. We do not use your email for marketing.
- Poster configuration — city name, coordinates, theme, dimensions, and other design choices you make when creating a poster.
Information collected automatically
- IP address — used temporarily for rate limiting to prevent abuse. IP addresses are not stored permanently or linked to your account.
- Browser locale — detected from your browser settings to display prices in your local currency. Not stored on our servers.
How We Use Your Data
- Generate and deliver your poster renders
- Process payments securely through Stripe
- Send transactional emails (order confirmations and download links)
- Provide order lookup so you can access past purchases
- Rate-limit API requests to maintain service stability
We do not send marketing or promotional emails. All emails you receive from us are directly related to your orders.
Third-Party Services
Stripe (Payments)
We use Stripe to process payments. When you purchase a poster, your payment information (card details) is handled entirely by Stripe. We never see, store, or have access to your full card number. Stripe’s privacy policy governs how they handle your payment data.
OpenStreetMap / Nominatim (Map Data)
We use OpenStreetMap data to render posters and the Nominatim geocoding service for city search. When you search for a city, your query is sent to the Nominatim API. Map data is licensed under the Open Database License (ODbL).
Sentry (Error Tracking)
We may use Sentry to track application errors. If enabled, Sentry may collect technical information about errors you encounter (browser type, error messages, stack traces). This data is used solely to fix bugs and improve reliability.
Google Customer Reviews
After a purchase we show an optional survey from Google Customer Reviews on the order confirmation page. If you opt in, we share your email address, order number, delivery country and estimated delivery date with Google so it can email you a review request later. The module only loads once you have accepted analytics cookies, and you can decline the survey itself.
Cookies and Local Storage
Cookies
- NEXT_LOCALE — stores your language preference so the site displays in your chosen language on return visits. This is a functional cookie, not used for tracking.
Local Storage (Browser)
- Saved designs — your poster configurations are saved locally in your browser so you can resume editing. This data stays on your device and is never sent to our servers unless you generate a preview or place an order.
- Form state — the poster creation form auto-saves your progress in your browser’s local storage.
- Theme preference — your choice of light or dark mode is stored locally.
We do not use advertising cookies, analytics trackers, or any third-party tracking cookies.
Data Retention
- Orders and email addresses — kept indefinitely so you can access your download links at any time.
- Preview renders — temporary low-resolution previews are cleaned periodically and not kept long-term.
- High-resolution renders — stored as long as the order exists so you can re-download your posters.
- IP addresses — used only in-memory for rate limiting and not stored permanently.
Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Deletion — request that we delete your personal data. Note that this will also remove access to your purchased posters.
- Portability — request your data in a machine-readable format.
- Objection — object to certain types of processing.
To exercise any of these rights, contact us at the email address below. We will respond within 30 days.
Data Security
We protect your data using industry-standard security measures including encrypted connections (HTTPS), secure payment processing via Stripe, and access-controlled download tokens with time-limited expiration. However, no method of electronic transmission or storage is 100% secure.
Children’s Privacy
MapToArt is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated “last updated” date. Continued use of MapToArt after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions or to exercise your data rights, email us at info@maptoart.com.