Legal

Terms, privacy, accessibility, and cookies

Privacy Policy

Draft — pending legal review. This is a good-faith placeholder reflecting what Marco Map actually collects and stores. Formal policy language will replace this page after legal review.

Effective date: 2026-04-23 (draft)

What we collect

Account data

  • Email address
  • Username (display name)
  • Hashed password (bcrypt; we never see your plain-text password)
  • Account creation and last-login timestamps

Usage data

  • Search queries typed into the global search bar, stored in app.searched_address
  • API request logs (URL path, response status, duration), stored in app.apirequestlog
  • Client IP address, captured on each request for rate-limiting and abuse detection

User-generated content

  • Custom regions you draw or save (app.saved_regions)
  • Composite Index definitions and results
  • Map Builder projects and uploaded geometry files
  • Feedback you submit via the in-app feedback form

Authentication cookies

  • jwt — session token, set by the LB4 auth backend after login
  • agent_key — optional API-key cookie used by automated testing agents

What we don't collect

  • Browsing activity outside Marco Map
  • Third-party marketing trackers or pixels
  • Device fingerprinting beyond standard HTTP headers
  • Data from social logins (Marco Map does not support social login)

How we use your data

  • Providing the Service (authentication, saving your work, rendering analyses)
  • Debugging and performance tuning (looking at logged API latency, error rates)
  • Preventing abuse (rate-limiting, identifying scraping activity)

We do not sell your data, license it to advertisers, or share it with third parties except as required by law.

Retention

  • Account data is kept for the life of your account.
  • API request logs are retained for 90 days then aggregated into anonymized summary metrics.
  • Search history is retained for 365 days unless you request deletion sooner.
  • Exported ZIPs and Map Builder uploads are retained for 30 days after last access.

Your rights

Under CCPA (California), GDPR (EU/UK), and comparable regimes, you can:

  • Access — request a copy of the data we hold about you
  • Port — receive it in a machine-readable format (JSON / ZIP)
  • Correct — ask us to fix inaccuracies
  • Delete — ask us to erase your account and associated data

To exercise any of these rights, email [email protected] with the email address on your account. We will respond within 30 days.

Note

the in-app /account page will automate these requests once its backend endpoints land. Until then, email is the canonical channel.

Security

Passwords are hashed with bcrypt. Sessions use HTTP-only, secure cookies. All traffic is served over TLS. Staff access to production data is restricted and audit-logged.

Despite these precautions, no system is perfectly secure. If you believe your account has been compromised, email [email protected] immediately.

Children

Marco Map is not directed at children under 13. We do not knowingly collect data from children.

Changes to this policy

Material changes will be announced on /changelog and reflected in the Effective date above.

Contact

Privacy questions or data-subject requests: [email protected].


See also: Terms of Service · Accessibility Statement · Cookie Policy