1. Scope and controller
Draft — controller details required.Before this Policy becomes effective, this paragraph must identify the controller's full legal name, legal form, NIF/VAT number, registered address, and any applicable registry details. Tileflow currently expects the controller to be established in Madrid, Spain. Until those details are completed, do not create an account or submit business data.
This Privacy Policy applies to tileflow.dev, Tileflow accounts, the dashboard, API, CDN, static-map service, CLI authorisation, SDK telemetry, and support communications (collectively, the Service). Once identified above, that provider will be the controller for account, website, security, and commercial data described in this Policy.
Questions and privacy requests can be sent to hello@tileflow.dev. Tileflow does not currently publish a separate data protection officer contact.
This Policy does not cover Customer's own website or application, Google's services, or another third party's service, each of which has its own privacy terms.
2. Our privacy roles
Tileflow handles data in different roles:
- Controller. Tileflow decides how to use account details, support and commercial communications, security records, credential administration, and limited operational logs needed to run and protect the Service.
- Processor.If a later approved use case involves personal data in Customer Content, Tileflow will process it on Customer's documented instructions under an executed data processing addendum. Customer remains responsible for its lawful basis, notices, and end-user choices.
- Customer.A Customer embedding Tileflow maps normally decides why its own end users' map and location data are processed and is usually the controller for that activity.
During the private preview, Customer must not upload personal data or identifiable precise locations unless Tileflow has approved the use case in writing and the parties first execute an appropriate data processing addendum. Special-category, highly sensitive, or regulated personal data remains prohibited unless a later written agreement expressly authorises it.
3. Data we process
Account and authentication data
When you sign in with Google, Tileflow receives your name, email address, email-verification status, profile image, Google account identifier, and the authorisation tokens and scopes needed to complete sign-in. OAuth tokens are encrypted at rest. Tileflow does not receive or store your Google password.
We also process session tokens, session expiry, IP address, browser user-agent, login times, and temporary OAuth verification data to authenticate you and secure the account. Session and OAuth records can retain IP and user-agent information in the primary database.
Workspace and Customer Content
We process project and style names, slugs, map configurations, style JSON, deployment history, PMTiles archives, tileset metadata, attribution, overlays, markers, coordinates, static-map parameters and images, and other content you submit. This content can contain personal or precise-location data depending on what Customer chooses to upload.
Credentials and developer activity
For API keys, Tileflow stores a key prefix and one-way hash, label, scopes, expiry, revocation status, last-used time, a user-agent truncated to 240 characters, and a pseudonymous hash of the last-used IP address. The complete secret is shown only when created. CLI authorisation records include hashed device and user codes, a PKCE challenge, device name, requested permissions, account and project identifiers, status, and timestamps.
Map, API, and delivery telemetry
Depending on the request and feature, Tileflow may process:
- project, map, style, tileset, deployment, and session identifiers;
- requested path, tile zoom and version, response status, cache result, and duration;
- country inferred by the edge network, referrer, origin, and browser user-agent;
- SDK version, integration source, random map-session ID, event timestamp, and optional customer-supplied session metadata;
- static-map camera, bounds, coordinates, markers, lines, polygons, dimensions, and content hash;
- custom usage-event names, units, idempotency identifiers, and up to 32 fields of customer-supplied scalar metadata; and
- daily project-level counts for tiles, styles, SDK events, and static maps, which remain linked to Customer and project identifiers.
IP hashes and random identifiers are pseudonymous, not necessarily anonymous. A referrer URL can contain information placed there by Customer or its end user, so applications should not put secrets or personal data in URLs. Customers must not place personal data, secrets, or identifiable precise locations in optional session or usage metadata during the private preview.
Website, communications, and commercial data
Edge infrastructure receives normal HTTP data such as IP address, request time, URL, user-agent, response status, and security signals. If you contact us, we process your message, contact details, and related support history. For a paid pilot, we process organisation, billing-contact, order, invoice, tax, and payment-status information. Tileflow does not currently collect payment-card details directly.
4. Where data comes from
We receive data:
- directly from you when you contact us, configure a project, or use the Service;
- from Google when you choose Google sign-in;
- from Customer when it provisions your access or submits Customer Content;
- automatically from browsers, SDKs, CLIs, servers, and edge infrastructure when a request reaches Tileflow; and
- from service providers when they report delivery, security, or payment status.
5. Purposes and legal bases
Provide the Service
We use account, project, content, credential, delivery, and support data to authenticate users, compile and deploy styles, serve maps, render images, provide documentation and support, and administer a pilot. For an individual account user, the basis is performance of a contract or steps requested before a contract. For Customer Content, we act on Customer's documented instructions where Tileflow is a processor.
Security, reliability, and abuse prevention
We use session, request, credential, device, rate-limit, and diagnostic data to detect abuse, investigate errors, secure accounts, prevent cross-tenant access, and maintain availability. The basis is Tileflow's and its customers' legitimate interest in a secure and reliable service. We balance that interest by limiting application logs, hashing certain identifiers, and restricting administrative access.
Usage and service improvement
We use request and aggregate usage data to understand feature operation, capacity, cache behaviour, and account usage. As of this draft, Tileflow does not use advertising pixels or third-party product-analytics scripts on its website and does not use Service data for targeted advertising. Project-level aggregates may remain linked to Customer and project identifiers and are not described as anonymous.
Billing, compliance, and legal claims
We use order, invoice, account, usage, and communication records to administer payments, comply with tax and accounting duties, respond to lawful requests, enforce agreements, and establish or defend legal claims. The basis is contract, legal obligation, or legitimate interests, depending on the activity.
Consent and automated decisions
If Tileflow later introduces optional non-essential cookies or direct marketing requiring consent, we will ask first and allow withdrawal. Tileflow does not currently make decisions producing legal or similarly significant effects about people solely by automated means.
6. Hosted-map viewers
When an end user opens a Customer application containing a Tileflow-hosted map, the end user's browser requests styles, tiles, fonts, sprites, or images from Tileflow. Tileflow and Cloudflare therefore receive normal network metadata. The Tileflow SDK may also attach a random session ID and map/style identifiers to delivery requests and send a session-start beacon containing the SDK version, source, timestamp, and page referrer.
Customers can disable SDK session telemetry with analytics.enabled = false, but Tileflow still processes ordinary network and delivery logs needed to serve and secure the map. Customer must describe this processing in its own privacy notice and obtain any consent its use case requires. Tileflow does not use map-viewer telemetry to build advertising profiles.
9. International transfers
Tileflow expects to operate from Spain and configures the static renderer with Paris as its primary compute region, but some providers and their subprocessors are established in or can access data from countries outside the European Economic Area. We therefore cannot promise that all data remains in the EU.
Before this draft becomes effective, Tileflow must verify and document the data processing agreement, subprocessor chain, destination, and lawful transfer mechanism that applies to each provider account, such as an adequacy decision or approved Standard Contractual Clauses. This draft does not yet represent that every required safeguard has been completed. Once verified, you may request the applicable information at hello@tileflow.dev.
10. Retention
Current implementation does not yet automate deletion for most database and object-storage records. Unless a period is stated below, data persists until an operator deletes the relevant category, subject to provider backups, caches, legal holds, and records that must be retained by law. Before this Policy becomes effective, Tileflow must adopt and implement a production retention schedule.
| Data | Retention |
|---|---|
| Map-session deduplication records | Scheduled for deletion after seven days. |
| Cloudflare Analytics Engine telemetry | Up to three months under the current provider limit. |
| Workers and renderer logs | Cloudflare Workers Logs are retained for three days on a Free plan or seven days on a paid plan; the production plan must be confirmed before this draft becomes effective. Fly.io searchable logs are generally available for approximately seven days under the current provider service. |
| Accounts, OAuth and session records, projects, credentials, usage records, and Customer Content in PostgreSQL | No general automatic expiry. This includes expired verification and session rows, OAuth/account records, CLI authorisations, raw usage events, daily aggregates, API-key audit data, styles, configurations, and deployment history. Each category persists until manually deleted by an operator. |
| Deployments, PMTiles, static images, and public caches | R2 origin objects have no automatic expiry and remain until manually deleted. Browsers, CDNs, Customer applications, or other recipients may retain downloaded copies; static-map responses can instruct those recipients to cache an asset for at least one year. |
| Invoices, orders, and tax records | For the period required by applicable accounting and tax law. |
Tileflow does not yet provide self-service account deletion or a fully automated DB-to-R2 deletion workflow. Send a verified request to hello@tileflow.dev. An operator will review and delete applicable categories from systems Tileflow directly controls and explain records retained temporarily or by law. Tileflow cannot promise immediate or complete erasure from provider backups, Analytics Engine, expired provider logs, third-party caches, or copies already downloaded by another recipient.
11. Public map assets
Published styles, tiles, sprites, glyphs, and static-map images are designed for public map delivery and can be cached by Tileflow, Cloudflare, browsers, Customer applications, or other recipients. A static-map URL may be content-addressed, public, and immutable for its cache period. The R2 origin object has no automatic expiry and remains until manually deleted; downstream copies can remain for at least their one-year cache lifetime. Domain allowlists do not make an asset confidential.
Do not include secrets, sensitive personal data, private coordinates, or confidential material in public map assets. Once another party has downloaded an asset, Tileflow cannot delete that party's independent copy.
12. Security
Tileflow uses measures intended to protect Service data, including HTTPS, encrypted OAuth tokens, one-way API-key hashing, scoped credentials, tenant checks, rate limits, restricted production secrets, non-root rendering, and controls against server-side request forgery. Access to production systems is limited to people and providers who need it.
No system is perfectly secure. Customer must secure its Google account, servers, devices, API keys, repositories, and applications. Please report a suspected Tileflow security or privacy incident immediately to hello@tileflow.dev. We will investigate and provide legally required notifications without undue delay.
13. Your rights
Depending on your location and our role, you may have rights to access, correct, delete, restrict, or object to processing of your personal data; receive portable data you supplied; and withdraw consent without affecting earlier lawful processing. You may also ask about the safeguards used for an international transfer.
Email hello@tileflow.dev with the subject Privacy request. Describe your request and the account or application involved. We may request proportionate information to verify identity and authority. We will respond without undue delay and within one month where GDPR requires, subject to any legally permitted extension.
If Tileflow processes data solely for a Customer, we may refer the request to that Customer and assist it as processor. You can complain to the supervisory authority where you live or work. In Spain, that is the Agencia Española de Protección de Datos (AEPD). We ask that you contact us first so we have an opportunity to address the issue.
You can also revoke Tileflow's Google access in your Google Account settings. Revocation stops future Google authorisation but does not by itself delete your Tileflow account or data.
14. Children
Tileflow is a business developer service. Accounts are intended only for adults acting in a professional capacity; the current preview does not operate a separate age-verification system. Contact us if you believe a child's personal data has been submitted without proper authority.
15. Changes to this Policy
We may update this Policy as the Service, providers, or law changes. The version and status at the top identify the current draft. Once effective, a material change affecting an active account will receive reasonable notice through email, the dashboard, or a prominent website notice before it takes effect, unless an urgent legal or security reason requires faster action.
16. Contact
Privacy questions, requests, or complaints can be sent to hello@tileflow.dev. For a paid pilot, you may also use the legal-notice address and provider details in the applicable order form or invoice. Before this Policy becomes effective, this section must include the controller's full legal identity and postal address.