LEGAL

Mapbox is going to serve and protect your maps. For details, read our terms of service, service level agreement, privacy policy, & law enforcement guidelines.

Privacy

Download

Privacy

Privacy policy

This Privacy Policy applies to information that Mapbox, Inc. and/or its affiliates (“we”) collect (A) when you use any of our websites, APIs or other online services (collectively, our “Services”), including third-party products and services that integrate with our Services, and (B) when you use third-party websites and applications that cite this privacy policy to provide us with feedback, event or shipping-related information (collectively, our “Vendors”).

This Privacy Policy is intended to help you understand what data we collect, why we collect it, what we do with it, and your options regarding our collection and use of that data.

Corporate Accounts: If your account with us lists a corporate email address (a “Corporate Email”), then all references to “you” in this Privacy Policy shall also include the person or legal entity that controls the Corporate Email (for example, a person whose email is name@mapbox.com would be considered a Corporate Account of Mapbox). If you don’t want your account to be a Corporate Account, you should use a personal non-corporate email address. For clarification, commonly known personal email account services (e.g., Gmail, Yahoo, Outlook) are not Corporate Email.

Information We Collect

  1. Account Information: If you sign up for an account with us, we may collect information that you provide to us in connection with setting up the account, such as your username, name and email address. Further, in the course of using your account, you may provide us with additional information through your communications with us.
  2. Payment Information: Payment is required for some of our Services, and we may ask you to provide certain information, including your name, address, email, and credit card information (collectively, “Payment Information”), in connection with processing your transactions. You may update your Payment Information through your account.
  3. All credit card processing for our Services is handled directly by our third-party PCI-certified payment provider, Stripe (and any information you provide to them is governed by their privacy policy). Your Payment Information is encrypted and transmitted directly and securely to Stripe via HTTPS, and is not stored on our systems.
  4. Information from Our Vendors: We may receive information related to your use of our Vendor websites and services, including your username, name, email address, shipping address and your interaction with our Vendor. Common examples include signing up for an event or requesting shipment of a product from us.
  5. Website Logs and Cookies: Whenever you visit or interact with our website, we automatically collect certain information about your browser and your interaction with our website, including (a) IP address, (b) browser and device type, (c) operating system, (d) referring web page, (e) the date and time of page visits, and (f) the pages accessed on our websites. We also use cookies and similar technologies to recognize and improve your use of our websites, and you will not be able to access certain parts of our websites, including those that require a login, unless your device accepts cookies from us.
  6. APIs and Mobile SDKs: We automatically collect certain technical information whenever requests are made to our APIs, including (a) IP address, (b) device and browser information, (c) operating system, (d) the content of the request, (e) the date and time of the request, and (f) limited location and usage data. We delete IP addresses after 30 days. In addition, when a mobile application uses our SDKs to access our APIs, it may send us certain limited location and usage data along with an ephemeral ID. We delete this ephemeral ID within 24 hours and do not associate it or the unprocessed mobile location data with any personally identifying information, including names, permanent IDs, email addresses, IP addresses, or phone numbers. We also collect randomly-generated IDs for the limited purpose of analyzing the use of our APIs, including the number of active users. We will delete the randomly generated IDs and the content of requests made to our APIs after 36 months.
  7. Vision SDK: We automatically collect certain information whenever the Vision SDK is in use, including (a) IP address, (b) device and browser information, (c) operating system, (d) the content of the API requests, (e) the date and time of the request, (f) limited location and usage data, (g) limited front-facing camera imagery and video, (h) a randomly generated ID, (i) accelerometer data and (j) detected road feature data.
  8. Hosted Data: In using your account, you may upload data to us via Mapbox Studio, Mapbox Studio Classic, our Dataset API or our Upload API ("Hosted Data") so that Mapbox can host it for you as part of providing our Services. We delete Hosted Data upon your request, however, due to our highly available, distributed implementation of our hosting solution, artifacts of Hosted Data may remain on Mapbox systems after you delete the file in your account. We will delete those artifacts in accordance with our standard platform maintenance practices after we either receive a specific request from you to delete the Hosted Data artifacts (along with sufficient information to identify which data you want to ensure are deleted) or we receive a request from you to delete your account.
  9. Feedback: You and/or your end users may provide us with feedback regarding our Services (e.g., in the form of email, suggestions for how to improve our maps, etc). We do not delete this information.

How We Use the Information We Collect

  1. Account Information: We use the account information we collect to provide our Services to you, to maintain your accounts, and to process your transactions. This information is necessary for us to provide the Services to you. We may combine account information with data we receive from other sources. We also may use certain information, such as your email address, to help you by telling you about new Mapbox products or features that may be of interest to you and by providing you with examples of how Mapbox products and services can be used. We have a legitimate interest in improving and marketing our Services. If you receive promotional emails from Mapbox, you can opt out by following the instructions in those emails.
  2. Payment Information: We use payment information solely for billing purposes, which is necessary to provide the Services.
  3. Information from Our Vendors: We may use the information you provide to our Vendors in connection with the event or transaction (including shipments and deliveries), to improve our Services, and to provide you with information about our Services and/or the event or transaction. We have a legitimate interest in improving and marketing our Services and certain data collection is necessary in order to provide the Services. You may opt out of receiving promotional communications from us at any time.
  4. Website Logs and Cookies: We use cookies, website logs and other similar data and technologies (i) to preserve information so you will not have to re-enter it during your visit or on subsequent visits to our site; (ii) to maintain sessions for authenticated users; (iii) to monitor metrics about our site such as the number of visitors and pages viewed; (iv) for internal diagnostic and analytic purposes (v) to improve our website and the services we provide, and (vi) to market our Services to you. We may combine this data with information we receive from other sources. We have a legitimate interest in improving and marketing our Services and certain data collection is necessary in order to provide the Services.
  5. APIs and Mobile SDKs: We use the data collected through our APIs and SDKs (1) for internal diagnostic and analytic purposes (2) to improve our mapping products and services (3) to provide our Services to end users of our customers and (4) to generate aggregated and anonymized usage statistics. We have a legitimate interest in improving our Services and certain data collection is necessary in order to provide the Services. You can find more information specifically about how we secure and use location data on our telemetry page.
  6. Vision SDK: We use the data collected from Vision SDK (a) for internal diagnostic and analytic purposes, (b) to improve our mapping products and services, (c) to provide our Services to end users of our customers and (d) to generate aggregated and anonymized usage statistics. We have a legitimate interest in improving our Services and certain data collection is necessary in order to provide the Services.
  7. Hosted Data: We use Hosted Data to provide our Services to you.
  8. Feedback: We may use the feedback that you provide for any purpose, including improving our Services. We have a legitimate interest in improving our Services for the benefit of all of our users.

When We Share the Information We Collect With Third Parties

  1. In General: We are a global company and may transfer your information outside of the country where you live. However, we will not transfer personal information outside of the European Union unless the recipient complies with the Privacy Shield Principles (see “U.S.-EU Privacy Shield and Swiss-U.S. Privacy Shield” below) or is subject to suitable contractual safeguards to ensure that the personal information is processed in accordance with EU law. For more information, please email us at privacy@mapbox.com.
  2. Account Information and Information from our Vendors: We may share your account information and information we receive from our Vendors with our Vendors and other service providers who need access to such information to carry out work on our behalf.
  3. Payment Information: We may disclose Payment Information to (a) our payment provider, Stripe, as described above in the “Information We Collect” section, (b) billing and accounting service providers acting on our behalf and (c) in connection with “Rare and Limited Disclosures” described below.
  4. Website Logs and Cookies: We share information about your device and interaction with our website with our service providers that host our website and provide marketing and analytics services to us. The marketing and analytics services that integrate directly into our website include AdRoll, Customer.io, Facebook, Google Analytics, LinkedIn, and Marketo. These and other third parties that we use may collect information about your device and interaction with our websites (including by using cookies and similar technologies). We do not control how these third parties use or share this information, which is subject to their privacy policies.
  5. APIs and Mobile SDKs: We only share raw location data with our hosted infrastructure service providers. We share other data collected through your use of our APIs and SDKs with our hosted infrastructure and internal analytics service providers. In limited situations, we may also share API log data associated with a specific customer's account with that customer for the purpose of resolving billing questions. We also may share aggregated and anonymized usage statistics with other third parties.
  6. Vision SDK: We share data collected through your use of Vision SDK with our hosted infrastructure and internal analytics service providers. In addition, we may share Vision SDK data with the person or entity that controls the account associated with the data. We also may share aggregated and anonymized usage statistics with other third parties.
  7. Hosted Data: We use third parties to store, process and deliver the Hosted Data as directed by you (e.g., AWS and Cloudfront). We may share the Hosted Data with such service providers subject to obligations consistent with this Privacy Policy and any other appropriate confidentiality and security measures. We do not otherwise disclose Hosted Data except as directed by you or as described below in “Rare and Limited Disclosure”.
  8. Feedback: We may share your feedback with third parties, including our third-party suppliers and partners who help us provide the Services.
  9. Rare and Limited Disclosures: We may share information in our possession in response to a request if we believe disclosure is in accordance with, or required by, any applicable law, regulation or legal process. For more information, see “Law Enforcement and Transparency,” below.
  10. Furthermore, we may share information in our possession if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to enforce our terms of service, detect, prevent, or otherwise address threats to our platform, or protect against harm to the rights, property or safety of Mapbox, our users, or the public as required or permitted by law.
  11. Finally, we may also share the information we collect in connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company. We may also share information among our current and future parents, affiliates, subsidiaries and other companies under common control and ownership.

Your Choices About What We Do With the Information We Collect

  1. Account and Payment Information: Certain account information is optional, and you may choose not to provide it to Mapbox. Note that some of this account and payment information is necessary for related Services to function properly – for example, if you do not provide payment information, you cannot take advantage of features that require payment.
  2. Website Logs and Cookies: You may delete cookies from your computer, and most browsers provide the option to block cookies. Note that if you block cookies placed by us (first party cookies), portions of our Services, including our website, may not work as intended. However, your access to our websites should not be affected if you disable third-party cookies placed by third parties that manage marketing and analytics aspects of our website.
  3. APIs and Mobile SDKs: If you are an end user of a product or service that integrates our Services, your privacy options will be largely determined by the developer of the product or service. In addition to any privacy options that the developer may have provided you with, you may also be able to control the applications that can collect information about your precise location by using the settings available on your device.

Your Access to and Control of the Information We Collect

  1. In General: If you believe that we hold information that would allow us to correct, amend, or delete inaccurate information about you or if you believe that information about you has been processed in violation of this privacy policy or the Privacy Shield Principles (see “Privacy Shield” below), please email us at privacy@mapbox.com.
  2. Account Information, Hosted Data, and Payment Information: You may correct or change certain account information in the account pages we’ve made available to you, and you may update, correct or delete other Account Information, Hosted Data or Payment Information that you have provided to us at any time by emailing us at privacy@mapbox.com. If you wish to delete or deactivate your account, please email us at privacy@mapbox.com, but note that we may retain certain information as required by law or to protect our rights and property.
  3. Website Logs, Cookies, APIs and Mobile SDKs: We temporarily retain IP addresses for security and accounting purposes. Given the temporary nature of this storage, it is generally not feasible for us to provide access to IP addresses or the logs associated with them.
  4. Feedback: You may request that we update, correct or delete any feedback that you have provided to us by emailing us at privacy@mapbox.com, however we may have deleted or anonymized the feedback you had previously provided to us in a way that makes it infeasible for us to associate a particular piece of feedback with a particular user.

Law Enforcement and Transparency

  1. In General: Although we acknowledge that government sometimes must act to protect citizens' safety and security, we strongly believe that current laws regulating surveillance of individuals and access to user information need to be reformed. We have signed the Stop Watching Us petition and supports the principles of the Reform Government Surveillance open letter to Congress.
  2. We post anonymized information about all law enforcement requests in our transparency report. Mapbox has never received a national security letter, FISA court order, or any other classified request for user information. If we ever receive such a request, we will review it carefully and make sure it follows the law (including the Fourth Amendment). If we believe a request is overly broad, we will seek to narrow it.
  3. If we have a good faith belief that there is an emergency involving the danger of death or severe physical injury, we may disclose limited information necessary to prevent that harm.
  4. Account Information, Hosted Data, Store Data and Payment Information: We require a subpoena or court order to provide information about your account, such as the name associated with the account, means of payment, and length of service. If we are ever forced to share identifiable information about you, we'll notify you with the full details of the request before we disclose it unless we are legally prohibited from doing so by law or court order.
  5. Website Logs, Cookies, APIs and Mobile SDKs: We will only disclose information collected through our Services, including maps and associated data and location information, in response to a subpoena or court order.

U.S.-EU Privacy Shield and Swiss-U.S. Privacy Shield

  1. We (Mapbox, Inc. and Mapbox International, Inc.) comply with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. We have certified to the Department of Commerce that we adhere to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/welcome.
  2. In compliance with the Privacy Shield Principles, we are committed to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us using the information in the "Contact Us" section below. We have further committed to refer unresolved Privacy Shield complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint. The services of JAMS are provided at no cost to you.
  3. Under certain conditions, you may be able to invoke binding arbitration to resolve your complaint. Mapbox is subject to the investigatory and enforcement powers of the Federal Trade Commission.
  4. If we share personal data transferred to the U.S. under the Privacy Shield with a third-party service provider that processes such data on our behalf, then we will be liable for that third party’s processing in violation of the U.S. Privacy Shield Principles, unless we can prove that we are not responsible for the event giving rise to the damage.

MAPBOX.CN

This privacy policy does not cover APIs and other services available on Mapbox.cn, which are instead governed by the privacy policy, if any, available therein.

Contact Us

We'd love to hear any questions, concerns or feedback you might have about this privacy policy. If you have suggestions for us, let us know at privacy@mapbox.com.

Changelog

  • June 19, 2019: Minor changes to the privacy shield section.
  • March 4, 2019: Updates to SDK collection provisions.
  • February 21, 2019: Added language providing more clarity on our right to use information in the event of a dispute under the "Rare and Limited Disclosure" section.
  • November 16, 2018: Added language describing information practices specific to Vision SDK.
  • October 30, 2018: Added language clarifying limited use of randomly-generated IDs and sharing API logs for the purpose of resolving billing questions.
  • August 13, 2018: Added language clarifying when this privacy policy applies to information received from Vendors.
  • June 22, 2018: Added additional marketing and analytics services that integrate directly into our website.
  • May 17, 2018: Added additional clarification as to how deletion of Hosted Data works.
  • May 14, 2018: Added language to distinguish between website logs and API logs; added more information about cookies and similar technologies; updates to comply with GDPR disclosure requirements.
  • November 16, 2017: Added clarifying language regarding corporate emails, removed online merchandise store, and updated policy to cover information submitted to Our Vendors.
  • May 12, 2017: Added language regarding data collected through our soon to be launched online merchandise store.
  • May 2, 2017: Updated the Privacy Shield certification language.
  • April 14, 2017: Re-wrote the policy for the purposes of Privacy Shield certification.
  • January 20, 2016: Updated to reflect EU Safe Harbor invalidation.
  • July 24, 2015: We now participate in the EU Safe Harbor program.
  • July 6, 2015: Added clarification regarding third party services, mobile data collection and user age requirements.
  • March 27, 2015: Added guarantee that we will require a warrant for access to location information. Added exception to legal process requirements for life-threatening or similarly dire emergencies.

Want to receive updates on our sub-processors?

Please subscribe below:

Stay tuned for updates!
Please enter an email address that includes @.