Legal

Privacy Policy

Last updated: 11 July 2026

DropMaps is a browser-based mapping application. This policy explains what personal information we collect, why, and the choices you have. It covers the marketing site (dropmaps.net) and the application (app.dropmaps.net).

The short version

  • Your map data stays on your device by default. The free in-browser editor stores files locally — they are not uploaded to us.
  • We collect an email address and account identifier only if you create an account.
  • We use Cloudflare Web Analytics for anonymous usage statistics. It does not use cookies and does not track individuals, so there is no cookie banner.
  • Map data you save to the cloud is encrypted in transit and at rest by our hosting provider, but it is not end-to-end encrypted — our systems can access it in order to provide sync and sharing. We never see or store your password; sign-in is handled by Google Firebase Authentication.
  • We do not sell your personal information.

Information we collect

Account information

If you sign in or subscribe, our authentication provider (Google Firebase Authentication) processes your email address and a unique user ID. We store this together with your subscription tier and storage quota in order to provide the service.

Map and file data

Files you open in the free editor (shapefiles, KML, CSV, GeoTIFF, PMTiles, etc.) are processed entirely in your browser and stored locally on your device. They are only sent to our servers if you explicitly use a paid “save to cloud” or “share” feature, in which case they are stored to provide that feature to you.

Usage and analytics data

We use Cloudflare Web Analytics to understand how the site is used. It collects aggregate, anonymous data such as pages visited, referring sites, country (derived from IP), and general device and browser type. It does not use cookies, does not store anything on your device, and does not fingerprint or track you across sites or over time. Because of this there is no analytics cookie and no consent banner.

Payment data

Paid subscriptions are processed by our payment provider [CONFIRM — e.g. Lemon Squeezy / Stripe]. Payment card details are handled by that provider and are not stored by us. We receive only the information needed to manage your subscription (e.g. tier, status, renewal date).

Cookies and similar technologies

We do not use any analytics or advertising cookies. We use browser local storage only for essential functionality, such as keeping you signed in and storing your map data on your device in the editor. Cloudflare, our hosting provider, may set strictly-necessary cookies for security and bot protection; these are required for the site to operate and do not track you for advertising or analytics.

How we use your information

  • To provide, maintain and secure the service;
  • To manage your account and subscription;
  • To understand usage and improve the product;
  • To respond to your support requests;
  • To comply with legal obligations.

How your data is stored and secured

On your device

Map data you work with in the editor is stored in your browser’s built-in storage (such as the Origin Private File System, IndexedDB and local storage) on your device. The application does not add its own layer of encryption to this local data, so its protection depends on your device’s security — your operating system account, and whether your device uses disk encryption. Anyone with access to your device and browser profile could access it, so use a device you trust and keep it secured.

In the cloud

If you use a paid “save to cloud”, “sync” or “share” feature, that data is stored on Cloudflare’s infrastructure. It is encrypted in transit (HTTPS/TLS) and encrypted at rest by Cloudflare’s standard server-side encryption. It is not end-to-end encrypted: you do not hold a private key, and our systems are able to read the data in order to operate features such as sync, sharing and shared-map viewing. We do not access your map data except as needed to operate the Service, investigate abuse, provide support you have requested, or comply with the law. If you need end-to-end encryption for sensitive data, do not store that data in the cloud features.

Login credentials

Sign-in is handled by Google Firebase Authentication. If you use a password, it is sent only to Google and is stored by them salted and hashed — never in plain text, and never on our servers. If you sign in with Google or an email link, no password exists at all. We store only your email address, a unique user ID, and your subscription details.

Third-party services

We rely on the following providers, each with its own privacy policy:

  • Google Firebase — authentication. Policy
  • Cloudflare — hosting, our API backend, and cookieless web analytics. Policy
  • Our payment provider [CONFIRM] — billing.

Data retention

We keep account and subscription data for as long as your account is active and as required to meet legal and accounting obligations. You can ask us to delete your account at any time (see below).

Your rights

Depending on where you live, you may have rights to access, correct, delete or export your personal information, and to object to or restrict certain processing. To exercise any of these, contact us at the address below. If you are in the EU/UK, our legal basis for our cookieless analytics is our legitimate interest in understanding and improving the site, and for account data it is performance of our contract with you.

International transfers

Our providers may process data outside your country, including in the United States. Where required, we rely on appropriate safeguards offered by these providers for such transfers.

Children

DropMaps is not directed at children under 16, and we do not knowingly collect their personal information.

Changes to this policy

We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, provide a more prominent notice.

Contact us

Questions or requests about your data? Get in touch via our contact form.