DoMaps

Privacy Policy

Last updated: 6 October 2026

The short version.

1. Who is responsible

The controller of your personal data is Kirill Grabar, a sole trader (autónomo) established in Spain; the full details are in the legal notice. In this policy "DoMaps", "we" and "us" mean him. For anything about your data, write to hello@domaps.app. We have no data protection officer, as the law doesn't require one for a service of this kind.

This policy covers domaps.app, the map editor and maps at map.domaps.app, and the API at api.domaps.app.

2. What we collect and why

DataWhyLegal basis (GDPR)
Your email address, plan, the date your account was made, and when you accepted which version of the Terms To log you in by email link, keep your maps in your account, apply your plan, and show which Terms you accepted Contract, art. 6(1)(b)
Login links and login sessions, stored only as one-way hashes To log you in safely Contract, art. 6(1)(b)
Your maps: name, places and addresses with their coordinates, colors, pin and view settings, and the websites you allow a map on To show your map wherever you embed it Contract, art. 6(1)(b)
View counts per map and per day, and the website addresses (hostnames) a map was shown on To apply your plan's limits, show you where your map is used, and warn you before a limit Contract, art. 6(1)(b), and our legitimate interest in preventing abuse, art. 6(1)(f)
A website address you paste into DoMaps, and what we read from that page (see section 3) To style your map from that site Contract, art. 6(1)(b)
Addresses you type or that we find on a site To find their coordinates (see Geoapify in section 5). The coordinates are stored with the map Contract, art. 6(1)(b)
The emails we send you: login links, and notices about your maps (paused for the day, 80% of the month's views, a grace month) To run your account. These are service messages, not marketing Contract, art. 6(1)(b)
What you write to us by email To answer you, and to set up and bill a paid plan Steps before or under a contract, art. 6(1)(b); legal obligations for billing records, art. 6(1)(c)
Technical logs: errors and events with map or account ids, and the address of a website that could not be read. They contain no IP addresses and no email addresses To keep the service working and secure Legitimate interest, art. 6(1)(f)

You don't need an account to make a map. If you want to save one or log in, we need your email address; without it we can't create the account.

We don't sell personal data, show ads, build profiles, or make automated decisions that have legal or similar effects on you. We send no marketing emails.

3. Reading a website

When you paste a website address, our server fetches that one public page (and, where needed, its icon, web app manifest and style sheets) to read the brand colors, the site's name, the name of its font and any postal addresses. It reads nothing else and follows no other links. What you then keep in your map is stored with the map; everything else is discarded straight away.

A page can contain personal data about someone else, for example a sole trader's name and business address. We process it only to make the map you asked for, based on our and your legitimate interest (art. 6(1)(f)), and we keep only what ends up in a map. Telling everyone named on a page individually would take disproportionate effort (art. 14(5)(b)), so this section is how we inform them. If your details were taken into a DoMaps map without your agreement, email us and we will look at it (see "Reporting content" in our Terms).

4. People who view a map

When someone opens a page with a DoMaps map, their browser loads the map from map.domaps.app and asks api.domaps.app for the map's settings. Like any server, ours receive the visitor's IP address with each request. We use it in memory, for at most a day, to limit abusive traffic; it is never written to our database or logs. The map also tells us the address (hostname) of the website it is on, so we can count the view for the right map and plan. We store view counts per map and day, not per person.

We also use the IP address and the browser's user agent at the moment of the view to note the visitor's country and whether they use a phone or a computer. Only daily totals per map are stored (for example "Portugal: 41 views"); the IP address and user agent are never stored.

The visitor's browser also loads map tiles and terrain directly from OpenFreeMap and Mapterhorn (see section 5), which receive the IP address to deliver them. The map sets no cookies and stores nothing on the visitor's device. Our legal basis for this processing is our legitimate interest in delivering and protecting the service, art. 6(1)(f).

A line for your privacy policy, if you embed a DoMaps map and list embedded services

"Our map is provided by DoMaps (domaps.app). When you view it, your browser connects to DoMaps and its map providers, which receive your IP address to deliver the map. The map sets no cookies. See https://domaps.app/privacy."

The Terms say who does what between you and us for these visitors.

5. Who processes data for us

We use these providers, each under a data processing agreement where it acts on our behalf:

ProviderWhat forWhere
Cloudflare, Inc.Delivers our websites, protects them from attacks, and connects our server to the internetGlobal network; US company
DigitalOcean, LLCRuns our serverAmsterdam, Netherlands; US company
Supabase, Inc.Hosts our databaseIreland; US company
Mailjet SAS (part of Sinch)Sends our emails, with open and click tracking switched offEU; company in France
Zoho (Zoho Mail)Our mailbox: emails you send to usEU data centres (Netherlands, Ireland)
Geoapify (KEPTAGO Ltd)Turns addresses into coordinates. It receives the address text onlyEU servers (Germany, Finland); company in Cyprus

These services are loaded directly by the browser of anyone viewing a map. They act on their own behalf, under their own privacy policies:

6. Transfers outside the EU

Our server, database, emails and address lookups are in the EU. Cloudflare, DigitalOcean and Supabase are US companies, and Cloudflare's network is global, so personal data may be accessed from or pass through the United States. Cloudflare and DigitalOcean are certified under the EU-US Data Privacy Framework (adequacy decision (EU) 2023/1795); Supabase's transfers are covered by the European Commission's Standard Contractual Clauses in its data processing agreement. Zoho's support staff may access our mailbox from India under Standard Contractual Clauses.

7. How long we keep data

DataKept for
Your account and saved maps, with their view counts and website addressesUntil you delete them or ask us to close your account
Unsaved maps never shown on a website, and map links never openedDeleted after 30 days
Unsaved maps that are in useUntil you ask us to delete them, or we delete them under the Terms
Login linksWork once for 15 minutes; deleted after one day
Login sessionsUntil you close the browser (our record lasts one day), or 30 days if you chose "Keep me logged in"; logging out ends it at once
Visitor IP addressesIn memory only, at most one day; never stored
Emails with us about a paid plan, and billing recordsAs long as Spanish tax and commercial law requires (up to six years)
Other emails with usUntil the matter is closed, then up to one year
Technical logsOverwritten as new logs come in; they hold no IP or email addresses

When we delete data, it is removed from our database straight away.

8. Cookies and storage on your device

DoMaps stores only what the service needs to do what you ask. That's why there is no cookie banner.

NameWhereWhat forHow long
domaps_session (cookie)Set by api.domaps.app after you log inKeeps you logged inUntil you close the browser, or 30 days if you choose "Keep me logged in"
Unsaved map (session storage)map.domaps.app editor and save pageKeeps the map you're making if you reload the pageUntil you close the tab
Code tab (local storage)map.domaps.app editorRemembers which embed code tab you last pickedUntil you clear your browser data

This website (domaps.app) and the maps embedded on other websites store nothing on your device. Cloudflare, which protects our sites, may set a short-lived security cookie when it needs to check that a visitor is not a bot.

9. Your rights

You can ask us to:

Email hello@domaps.app, from the address on your account if you have one, so we know it's you. We answer within one month (art. 12(3)). It's free.

You can also complain to the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, at aepd.es, or to the data protection authority where you live.

10. Security

All connections use HTTPS. Login links, sessions and save keys are stored only as one-way hashes. Our server accepts no direct connections from the internet; traffic reaches it only through Cloudflare. Only the operator has access to the server and the database.

11. Business use

DoMaps is a service for businesses and professionals, not for children. If you think a child has given us personal data, email us and we will delete it.

12. Changes

If we change this policy, we update the date at the top. If a change affects how we use your data in a significant way, we tell account holders by email before it applies.