Legal

Privacy Policy

Last updated: May 6, 2026

This policy describes how Mapsmith, a product of Strode Media Co ("we," "us"), handles personal data and other information collected through the Mapsmith WordPress plugin and the mapsmith.app website. It covers two surfaces: the marketing/account website at mapsmith.app, and the Mapsmith WordPress plugin you install on your own site.

Information We Collect on the Website

When you create an account on mapsmith.app, we collect your email address and a bcrypt hash of your password. When you purchase a license, Stripe processes your payment information directly — we never see or store your credit card details, and we receive only a Stripe customer ID and the line items you purchased.

Information Sent by the WordPress Plugin

The Mapsmith WordPress plugin connects to mapsmith.app for two specific reasons. Both are documented in the plugin's readme; this section describes them in full.

License key validation (only if you enter a Pro license key)

If you choose to enter a Mapsmith Pro license key under Mapsmith → Settings → License, the plugin sends a request to https://mapsmith.app/api/license/validate. Each request includes only:

  • The license key you entered
  • Your site URL (so we can scope activations to one or more sites per your plan)

These requests are sent when you click "Activate License," when you click "Deactivate License," and once every five days while a key is stored, to confirm the key has not been revoked. We retain the license activation record (key + site URL + last-checked timestamp) for as long as the key is active. Deactivating a license removes the activation record from our server.

The license-key field has no effect on the WordPress.org plugin's behavior — every feature in the plugin is fully available regardless of whether a key is entered. The key only prepares your site for the optional Mapsmith Pro companion plugin (sold separately).

Anonymous usage telemetry (opt-in, off by default)

If — and only if — you opt in under Mapsmith → Settings → Other, the plugin sends a small anonymous usage report to https://mapsmith.app/api/telemetry/ping once per day, plus immediately after a successful license activation. Telemetry is disabled by default and you can disable it again at any time from the same screen. The telemetry payload contains:

  • Plugin version, WordPress version, PHP version
  • Locale and server timezone
  • Whether the site is part of a multisite network
  • Stored license plan (free / pro / agency)
  • Counts of businesses, locations, and maps configured on the site (numbers only — no names, no addresses, no business or location content of any kind)
  • Your site URL (to identify the source)

We use telemetry to understand which WordPress and PHP versions to support, how widely the plugin is used, and whether features are being adopted. We never collect map content, business or location details, end-user (visitor) data, IP addresses beyond the source of the request, or any other personally identifying data through telemetry. Telemetry records are retained for analytics for up to 24 months.

Google Maps Platform

Mapsmith renders maps using the Google Maps JavaScript API and provides address autocomplete via the Places API. These libraries are loaded directly from Google's servers into your visitors' browsers (and into the WordPress admin when you use the location editor). No data is sent to Mapsmith as part of this. Google's terms and privacy policy apply directly to that traffic — see Google Maps Platform Terms and Google's Privacy Policy.

How We Use Your Information

We use your email address to manage your account, deliver license keys, send password reset and account notification emails, and provide product support. We do not sell, rent, or share your personal information with third parties for their marketing purposes. License-activation records are used solely to enforce per-site license limits and to power your account dashboard. Telemetry data, when enabled, is used solely for product analytics in aggregate.

Cookies

We use a single HTTP-only session cookie (mapsmith_session) to keep you logged into your mapsmith.app account. We use Google Analytics (GA4) to understand how visitors interact with the marketing pages of mapsmith.app; GA4 sets its own cookies for usage measurement and collects anonymized data (pages visited, referral source, device type). You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on. We do not use advertising or cross-site tracking cookies.

Transactional Email

We use Amazon Web Services Simple Email Service (AWS SES) to send account-related emails such as welcome messages, password reset links, license activation notices, and purchase confirmations. Your email address is shared with AWS solely to deliver these messages.

Payment Processing

Payments are processed by Stripe. When you make a purchase, you are subject to Stripe's Privacy Policy. We store a Stripe customer ID associated with your account for order management and support purposes.

Data Retention

We retain account data for as long as your account is active. License activation records are retained while a key is active. Telemetry records are retained in aggregate for up to 24 months. If you delete your account, we will remove your personal information and revoke all associated licenses; some data may be retained briefly in encrypted backups before being purged.

Your Rights

You may request access to, correction of, or deletion of your personal data at any time by emailing [email protected]. If you are in the European Union or the United Kingdom, you have additional rights under the GDPR / UK GDPR including the right to data portability and the right to lodge a complaint with a supervisory authority. If you are a California resident, you have rights under the CCPA including the right to know what personal information we collect about you and to request deletion.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the email address on your account, and the "Last updated" date at the top of this page will be revised.

Contact

Questions about this privacy policy? Contact us at [email protected].