ROUTEOGRAPH / PRIVACY POLICY

Effective 22 August 2026 · routeograph is operated by Westmidlanders LLC, a Wyoming (USA) limited liability company.

The short version

A GPS route is precise location history. That is sensitive data, and we treat it that way. Your uploaded file is processed in memory and never stored. What we keep is the rendered poster and its statistics, which delete within 30 days, or sooner if you ask. We count visits in totals that name nobody. If you agree to it, we also use Google Analytics, which sets cookies and is the only third party that measures your visit. Decline and it never loads. A feedback button on every page is drawn by another company, which sees your IP address in order to serve it and learns nothing more unless you open it and write to us. We run no advertising and we never sell data.

What we process, and why

Cookies and similar technologies

We set no cookies of our own. What we use is your browser's local storage, which does the same job and is covered by the same rules, so the notice on your first visit calls it what people expect to see it called. Cookies do get set on this site if you agree to analytics, but they are Google's rather than ours, and they are described below. There are three categories.

Strictly necessary. Your unsaved draft, your sign-in, and display settings such as units and theme. These are required for the site to work: without them your work is lost on every reload. They stay on your device, are not shared, and identify nothing about you to us. They cannot be disabled, and clearing your browser storage removes them. The one exception in this category sits here: the bot check on the sign-in form (Cloudflare Turnstile, described under service providers) may store a short-lived cookie or storage entry while it runs. It is there to tell a person from a script, it appears only if you use that form, and it is not used to identify or follow you.

Counts, which run for everyone. We keep daily totals of how many times a page was opened, a poster was drawn, or a checkout was started. A total is all it is: no name, no account, no address, no device identifier, nothing that could be traced to a person, and nothing written to or read from your device. These are counted on our server from requests it already handles and already logs, which is why they are not something we ask permission for. Without them we cannot tell whether the site works for the people who visit it.

Analytics, which you choose. This covers two things, and one answer turns both on or leaves both off. The first is what happens only inside your browser and never reaches us, such as finishing the introduction tour or trying a different colorway: we record that those happened, still as totals with nothing that identifies you. The second is Google Analytics, which we load only after you agree. It sets its own cookies, gives your browser a random identifier, and reports which pages you opened, roughly where you were, what device and browser you used, and which site sent you to us. That is more than the totals above, and it is why it sits behind a question. The notice offers I decline, I agree, and a preferences panel. Your choice is stored on your device, and if you decline, the Google script is never fetched at all rather than fetched and told to stay quiet.

What we do not do. No advertising and no ad technology. We have turned off Google's advertising features, its cross-device signals and its ad personalization, so your visit here is not used to target you elsewhere and does not feed an advertising profile. We do not sell your data or share it for anyone's advertising.

You can change your answer at any time: .

Retention and deletion

Rendered posters and their job records delete automatically within about 30 days, except posters you exported with a credit, which we keep so your re-downloads stay free. You can delete any poster yourself at any time from its job. No account or form needed. The shared cache of public map data (map coordinates for an area) is not tied to you and is kept to speed repeat renders. Account and purchase records, including print-order emails and the credit ledger, are kept while your account exists and as long as tax law then requires. Server logs follow our host's standard rotation. Google Analytics data, if you agreed to it, is kept by Google for 2 months, which is the shortest window it offers.

Security

We protect your data with reasonable safeguards, including encryption in transit and access controls, and we limit who can reach it. No system is perfectly secure, so we cannot promise absolute security.

Service providers

We rely on a few processors to run the service. We never sell or share personal information for advertising, and disclose data only if legally compelled.

Some providers are in the United States, so your data may be transferred internationally. Where it is, we rely on appropriate safeguards.

Your rights

You can delete any poster yourself, at any time, and the file goes with it rather than just the listing. Two cannot go: one another buyer has also bought, and one whose print has not shipped. Both still leave your list.

In your account panel, Download my data gives you everything held against your account as one file, and Delete account erases it without asking us.

Deleting removes your posters and your sign-in, and cannot be undone. Any unused credits are lost, and the confirmation says how many before you agree to it. Three things survive, and here is why. Purchase and print-order records are financial records we are required to keep, and your record of accepting these documents is our evidence that you did. Both are stripped of anything identifying you and kept under a random reference instead. If you asked us not to send you marketing, the record that you did is kept the same way, as evidence we honoured it. That setting does not follow your address: sign up again with the same one and you get a clean account, it included. A poster somebody else has also bought stays in their account: the file is the same file, and their copy is not yours to delete. Deletion is refused while a print is still in production, since it has to reach you first. We email you once to confirm, with that reference in it, and after that your address is gone from everything we hold.

Email hello@routeograph.com for anything the buttons do not cover. In the EEA/UK we process to provide the service you request (Art. 6(1)(b) GDPR), for our legitimate interest in running it securely (Art. 6(1)(f)), and, for analytics only, on your consent (Art. 6(1)(a)), which you can withdraw at any time using the link above. Withdrawing does not affect what was collected before you did. You have rights of access, rectification, erasure, restriction, portability, and complaint to your supervisory authority. Analytics data reaches Google in the United States, which is covered under the safeguards noted above. California residents have equivalent rights under the CCPA/CPRA. We do not sell personal information, and because Google's advertising features are switched off, we do not share it for cross-context behavioral advertising as defined there.

A practical note on route privacy

Routes often begin and end at home. Consider trimming the start and end of an activity in your tracking app before turning it into a poster you will display.

Children

The service is not directed at children under 13 and we do not knowingly process their data.

Changes and contact

We update this policy as the service changes, revising the effective date above. Questions or deletion requests: hello@routeograph.com.

← back to routeograph