Privacy

Privacy policy.

Plain-language summary first; the formal terms follow. Last updated 14 May 2026.

Plain-language summary

We do not set third-party cookies on visitors who load a VelMap iframe. We log the bare minimum required to serve tiles and bill accounts: timestamp, the embed identifier, a truncated IP for abuse detection, and the requested tile coordinates. We never sell data.

What we collect from account holders

When you create a VelMap account we store your email address, a hashed password (or your SSO identifier), the billing details required by our payment processor, and the embed configurations you create. You can export or delete this data from the account settings at any time.

What we collect from end visitors

When a visitor loads a page that contains a VelMap iframe, our tile servers receive a request that includes their IP address, the User-Agent header, the embed ID, and the tile coordinates. We truncate the last octet of the IP address before writing it to logs, and we discard the raw request after 30 days.

Cookies and storage

VelMap iframes do not set cookies. The interactive map uses sessionStorage to remember the pan and zoom state during a single visit; sessionStorage is cleared when the tab is closed.

Subprocessors

We use Cloudflare for edge delivery, Stripe for payments, and Postmark for transactional email. We will update this section before adding any new subprocessor.

Your rights

If you are in the EU, UK, or California, you have the right to access, correct, export, and delete your personal data. Email privacy@velmap.com from the address on file and we will respond within 30 days.

Contact

Privacy questions: privacy@velmap.com.