1. This website (www.mapalizer.com)

This section covers www.mapalizer.com. Separate sections below cover the interactive tool pages, the Mapalizer® Toolbar and Widget, and the Customer Portal (portal.mapalizer.com).

✓ No website analytics   ✓ No cross-site tracking

We do not use website analytics or cross-site tracking on www.mapalizer.com.

The website itself does not set cookies or create visitor profiles. Our hosting infrastructure processes technical request data, including IP address, user agent, requested URL, and timestamp, to deliver and protect the site. Optional Google and Mapbox services are explained separately below.

No global analytics or advertising consent banner is used. The separate controls described below apply only when you choose to enable an interactive Google or Mapbox service.

2. Interactive tool pages (Demo, Configurator, API Examples, Toolbar Themes & Score Widget)

The Demo, Configurator, API Examples, Toolbar Themes, and Score Widget pages can use the Google Maps JavaScript API (and, on some pages, Mapbox). These third-party SDKs are not loaded automatically: a service-specific notice is shown first, and that service is contacted only after you enable it. Google Maps, Google Places address search, and Mapbox each have a separate choice; enabling one does not enable either of the others.

Leaflet is served locally by Mapalizer and Leaflet itself does not set cookies. Leaflet examples use map tiles from tile.openstreetmap.org without a consent gate. Loading those tiles sends technical request data such as your IP address, browser information, tile coordinates, and timestamp to the OpenStreetMap tile service. See the OpenStreetMap Foundation Privacy Policy and Tile Usage Policy.

Some pages additionally offer an address search powered by the Google Maps Places API. The search box is likewise disabled until you enable it; once enabled, addresses you type are sent to Google's Places Autocomplete service.

After you give consent, Google Maps JS API and Places API may collect and process:

  • Your IP address
  • Browser and device information
  • Map interaction events (pan, zoom, click)
  • User-typed address queries submitted to Places Autocomplete

Google processes this information under its own terms. Mapalizer does not receive or store Google's request and interaction data. Please refer to Google's Privacy Policy and Google Maps Platform Terms.

After you specifically enable Mapbox, its SDK and map resources are loaded from api.mapbox.com. Mapbox may process your IP address, browser/device data, requested map resources, and interaction data under the Mapbox Privacy Policy.

Your Google Maps, Google Places address search, and Mapbox choices are stored separately in your browser's local storage so the site can remember which services you enabled. These preferences are used only for this purpose. You can withdraw any choice below. If a service is already loaded on the current page, reload the page after withdrawing; it will remain disabled on future page loads.

3. Mapalizer® Toolbar and Widget (when you integrate them on your website)

The Mapalizer® Toolbar (map overlay) and Widget (standalone score badge embed) are distributed as the same JavaScript SDK. Both share an identical Mapalizer-side privacy profile when integrated on a customer website.

If you are a developer integrating the Mapalizer Toolbar or Widget on your own website, here is what the SDK does with data:

  • No personal user data is collected. The Toolbar and Widget do not read, store, or transmit any personally identifiable information about your website's visitors.
  • CDN and data requests. The SDK fetches its JavaScript, CSS, locale files, and category metadata from cdn.mapalizer.com, and score tiles from data.mapalizer.com. All requests are made with credentials: 'omit', which means no cookies or authentication headers are sent by the browser as part of these fetch requests. As with any web request, technical request data such as IP address may still be processed at the network level. The CDN pipeline records only aggregate request counts per registered domain. Individual visitor IP addresses or session data are not stored in the final analytics dataset.
  • API call counting. The number of Toolbar or Widget loads is counted in aggregate per registered domain. This aggregate count is used solely for billing and license compliance monitoring. Individual visitor data is never extracted or stored.
  • No cookies. The Toolbar and Widget set no cookies on your visitors' browsers.
  • No third-party sharing. Mapalizer does not sell, share, or transfer any data to third parties.

Integrating the Mapalizer Toolbar or Widget does not require you to add a cookie consent banner specifically for the SDK. However, you should review your own website's data practices independently.

4. Customer Portal (portal.mapalizer.com)

If you create an account on the Mapalizer Customer Portal at portal.mapalizer.com, the following data processing applies:

  • Account data. When you sign up, we store your email address, a Cognito-issued user identifier, and (if you sign in with Google) the unique provider sub-identifier returned by Google. We use this data to authenticate you, to provision your customer record and API tokens, and to send transactional emails (verification codes, password resets, billing-related notifications).
  • Authentication. The portal authenticates you using Amazon Cognito. Cognito stores the standard authentication tokens (ID token, access token, refresh token) in the browser's localStorage. These are not third-party cookies and are not used for cross-site tracking.
  • Google sign-in (optional). If you choose “Continue with Google”, you are briefly redirected to Google so they can verify your identity. Google's processing during sign-in is governed by Google's Privacy Policy. We receive only your verified email address and a stable Google sub-identifier.
  • Bot protection. The native sign-up and sign-in forms use Cloudflare Turnstile, an invisible CAPTCHA, to block automated abuse. The Turnstile script is loaded only when you open the sign-up or sign-in form, and no other portal page contacts Cloudflare. Turnstile may process technical request data (IP address, browser characteristics) as an independent data processor, potentially on servers in the United States; Cloudflare participates in the EU-US Data Privacy Framework and uses Standard Contractual Clauses for such transfers. See Cloudflare's Privacy Policy.
  • No tracking cookies. The portal sets no advertising or analytics cookies. The only browser storage is authentication state required for Cognito.
  • Account deletion. You can permanently delete your account and all associated data at any time from https://portal.mapalizer.com/accountDanger zoneDelete my account. The deletion is immediate: your sites and API tokens are removed, your profile is purged, and your Cognito identity is deleted. Usage records are anonymized (the link to your identity is removed) but the anonymized counters are retained for the billing-audit period required by EU tax law. If you cannot sign in to use the self-serve flow, email info@mapalizer.com from the address registered to your account and we will process the deletion within 5 business days.

Account data is stored in Amazon DynamoDB in the EU (eu-central-1) region, with server-side encryption at rest. Transactional emails are sent via Amazon SES from the mapalizer.com domain.

5. Contact

For any privacy-related questions or requests, please contact:

Emre Dagli
Manteuffelstraße 46, 12103 Berlin, Germany
info@mapalizer.com