Legal · Sightfield Maps
Sightfield Maps Privacy Policy
Last updated September 3, 2026
This policy explains what Sightfield Maps — the product at maps.sightfield.co, made by Sightfield, Inc. (“Sightfield”, “we”, “us”) of Dublin, Ohio, USA — collects and how it is used. It covers two groups of people: publishers, who create an account and upload data to build maps, and visitors, who see a published map embedded on a website or on its share page.
The short version
- A publisher account is an email address plus an optional display name and avatar. There is no password.
- The files you upload are stored for you and processed to build your map. We do not sell them, and the AI services we use may not train on them.
- A published map is public. Anyone with its link or embed can view it.
- Visitors to a published map are counted, never identified: no cookies, no device identifiers, no per-visitor records.
- You can delete your account and everything under it yourself, at any time, from Settings.
Part 1 — Publishers
Your account
Signing in is passwordless: you enter your email address and we email you a six-digit code. We store your email address, the display name and avatar you choose to add, and, for sign-in security, a hash of each code (valid for ten minutes and one use) with attempt and rate-limit counters keyed on a hash of your email. A signed-in browser holds one cookie, __session, which keeps you signed in for up to fourteen days and is removed when you sign out. Your browser also keeps your theme preference and a few editor conveniences locally.
What you upload and build
When you import a file we keep the original file as you sent it, the rows we parsed from it, any cell edits you make in the dataset editor, and everything you build on top: maps, card layouts, styles, cover images, logos, embed instances, and the published snapshot of each map. All of it is stored in Google Cloud in the United States and is readable only by your account, except the published snapshot, which is public by design.
You are responsible for what is in your files. A map of restaurants or trails is what Maps is for; a spreadsheet of private individuals is not, and you must have the right to publish whatever you upload. See the Maps Terms of Service.
AI processing
Maps uses a large-language-model service — Anthropic’s or OpenAI’s, chosen by us — to understand your columns and design your cards. This runs on our servers when you import or redesign, never when a visitor views the map. What is sent is bounded:
- a profile of each column — its name, how full it is, its range, and up to eight sample values shortened to 120 characters, or the full list of values for columns with few distinct ones;
- for datasets of up to 500 rows, each row’s name and up to three descriptive columns shortened to 200 characters, so places can be sorted into categories;
- eight sample rows, to draft a map description and a cover-photo search;
- a rendered preview of real rows when the layout is critiqued, and the unparseable values of an opening-hours column when they are normalized.
Coordinates are never sent to the AI service. We use both providers through their business API terms, which do not allow the content of requests to be used to train their models. The results — field types, categories, a layout, a description — are stored with your map.
Geocoding
Addresses in your rows are sent to Geoapify, our geocoding provider, to find coordinates. The results are kept in a shared address cache — address in, coordinates out — so the same address is never looked up twice. That cache holds facts about places, not about you, and it is not deleted with your account.
Maps, photos, and email
- Mapbox draws the map. While you edit, your browser fetches map tiles from Mapbox directly, so Mapbox receives your IP address and browser details. When you publish, our servers request a static image of the map area from Mapbox for the fast-loading first view.
- Unsplash receives the search terms you type when you look for a cover photo. Photos you choose are served from Unsplash’s CDN and credited to their photographers, as Unsplash’s terms require.
- Resend delivers our email: sign-in codes from auth.sightfield.co, and service messages such as a welcome note or a warning that a plan quota is nearly used up. We do not send marketing email from the sign-in address, and we do not share your address with anyone for their own marketing.
Paid plans and Stripe
If you subscribe to a paid plan, payment is handled by Stripe. We give Stripe your email address and your account identifier; Stripe collects your card and billing details itself and keeps them — we never see or store card numbers. We keep only what we need to run your plan: your Stripe customer and subscription identifiers, the plan you are on, its status, and the current billing period.
Error monitoring and logs
We use Sentry to learn about errors in the app. It records the error and technical context only: no performance tracing, no user profile, and cookies, tokens, and email addresses are stripped before a report leaves the app. Our hosting provider, Google Cloud, keeps standard request logs — IP address, browser, page requested — that we use to operate and secure the service.
Usage counters
We keep counts — loads, interactive opens, shares — per embed and per month, both to show you how your maps are doing and to apply your plan’s monthly quota. The same counts, plus the hostnames of the sites an embed appears on, feed an internal dashboard that shows daily totals. None of it describes an individual visitor.
Part 2 — Visitors to published maps
If you are looking at a Sightfield map on someone’s website, in the map’s share page, or in Sightfield Go, this is what happens:
- No cookies, no storage. The embed sets no cookies and writes nothing to your browser. It does not know who you are.
- Counting, not tracking. Loading the embed adds one to that map’s load count; opening the interactive map adds one to its opens; sharing adds one to its shares. Your IP address is used for a few minutes to stop the counters being spammed and is not stored. We record the hostname of the page the map is embedded on — the site, not the page or you.
- Services your browser contacts. The map tiles come from Mapbox once you activate the map, and photos come from the host the publisher chose, often Unsplash. Each receives the standard technical details of your request. Until you touch the map, it is a static image served by us.
- Error reports. The embed loads our error-monitoring code only if something breaks, and then sends the error and the map’s identifier — nothing about you.
The website the map sits on, and its owner, may collect information under their own policies. The share page on sightfield.co is covered by our website privacy policy; Sightfield Go by its own.
Published maps are public
Publishing makes a map public at its share link and embed. Anyone with the link can view it, share it, open it in Sightfield Go, and — unless you restrict the embed to your domains — embed it. Your display name, or the publisher name and logo you set for the map, appears on it. Unpublishing removes the map from new loads; copies already cached in a visitor’s browser or saved in Go may persist until they refresh.
How we use information
We use the information above to provide Maps — sign you in, build and host your maps, serve embeds, bill your plan — to keep it secure, to support you, and to understand aggregate usage. We share it only with the providers named here, each acting on our instructions, or when the law requires. We do not sell or rent personal information and we do not use your data for advertising.
Retention and deletion
Your account and everything under it are kept until you delete them. Delete account in Settings removes your maps and their published snapshots, datasets and uploaded files, embed instances, usage counters, avatar, billing record, and sign-in identity, cancels any subscription, and clears the published pages on sightfield.co. Three things remain: the shared address cache (not personal data), sign-in rate-limit counters keyed on a hash of your email, which expire within days, and the billing records Stripe must keep by law. Sign-in codes expire after ten minutes.
Your rights
You can see and change your profile, maps, and data in the app, and delete your account yourself. For anything else — a copy of the data we hold, a correction, or a question — email info@sightfield.co from the address on the account. Depending on where you live you may have further rights under laws such as the GDPR or US state privacy laws, and we will honor them.
Where data is stored
Sightfield is a US company. Your data is stored on Google Cloud infrastructure in the United States and processed by the providers above, some of which operate elsewhere. If you use Maps from outside the US, your information is transferred to and processed in the US.
Children
Maps is a publishing tool for businesses and adults. It is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email info@sightfield.co and we will delete it.
Changes
If this policy changes, the new version appears at this address with the date above. A material change to what Maps collects or shares will be announced in the app before it takes effect.
Contact
Sightfield, Inc. · Dublin, Ohio, USA · info@sightfield.co