MetroMark · Privacy Policy
← Back to mapLast updated: September 9, 2026
This policy explains what information MetroMark ("we", "our", "us") collects, why we collect it, and the choices you have. This is a small hobby project; we collect as little as possible.
1. What we do not collect
- No advertising, marketing, or cross-site tracking.
- No third-party cookies.
- No sale or sharing of personal data with data brokers.
- We do not ask for or want sensitive personal data (health, financial, government identifiers).
2. Information you provide
- Account (optional): email address, optional display name, and a password. Passwords are never stored in plain text. An account lets your visited-station progress, filter preferences, and reviews sync across devices.
- Issue reports: when you use the map's "Report Issue" tool we receive the bounding box, zoom, center, and a screenshot of your map view, plus an optional description. If you are signed in, your account email is attached so we can follow up.
- Route reviews and ordering votes: if you review a route or vote on stop ordering while signed in, we store that with your account.
3. Information we collect automatically
- Server logs: standard web logs (IP address, timestamp, requested page) used to operate the service, diagnose faults, and guard against abuse. We do not use these logs to build profiles.
- Aggregate usage counters: anonymous totals (for example, number of requests per day) that cannot identify you.
4. Storage on your device
The map stores data in your browser's local and session storage so the app works like an installed app. This includes: your sign-in token (when you log in), your chosen theme, map/filter preferences, and cached data for offline use. Everything except data tied to your account (Section 2) stays on your device — we cannot read your local storage. If you decline the consent notice, we stop saving non-essential preferences going forward; you can also clear site data through your browser at any time.
5. Third-party services
- Transitland — route and stop data shown on the map. Your transit queries are sent to Transitland's servers.
- CARTO / OpenStreetMap — basemap tiles. Requests are made to their servers.
- Google Fonts — the site loads its fonts from Google's font servers, which receive your IP address. You can disable this by self-hosting the fonts.
- unpkg / MapLibre / PMTiles — the map library code is loaded from a public CDN.
- Supabase — your account (email, display name, password handled by Supabase Auth) and your synced progress/preferences are stored in a Supabase cloud project. Supabase is a third-party service; see supabase.com/legal. Your data there is subject to Supabase's hosting region and terms.
- Hosting and database — the map-data pipeline and its database run on the operator's own server in Seattle, Washington, United States, and are reachable through a Cloudflare Tunnel (Cloudflare Privacy Policy).
These providers have their own privacy policies and may be located outside your country.
6. Why we process data (legal bases)
- Performance of a contract / service: creating your account and saving your progress so it works across devices.
- Legitimate interest: operating the service, fixing data issues you report, and preventing abuse.
- Consent: storing non-essential preferences on your device, where required by law.
7. Retention
Account data is kept until you delete it or ask us to delete the account. Issue reports stay visible in the admin dashboard until resolved and removed. Server logs are kept for a limited period for operational purposes. The underlying map archive is rebuilt automatically from public transit data and is not derived from your personal information.
8. Your rights
Depending on where you live (including under the GDPR / UK GDPR and US state privacy laws), you may have the right to access, correct, export, or delete your personal data, and to withdraw consent. To exercise these, contact us using the details below. We will respond within a reasonable time.
9. Children
The Service is not directed at children under 13 (or the minimum age in your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it.
10. Security
We use HTTPS, never store passwords in plain text, and keep the map-data database on the operator's own hardware in Seattle, WA. User accounts and synced progress are stored by Supabase, a third-party cloud provider, under their security controls. No internet service is 100% secure; please do not store sensitive data here.
11. Contact & data controller
For privacy questions or requests, contact [email protected]. Operator: MetroMark by Zing, Seattle, Washington, United States.