Skip to main content

Privacy Policy

How Tilery.eu collects, uses, and protects your personal information.

Last updated 9 Aug 2026

Who We Are

Tilery.eu is operated by Tilery AS (org. nr. 837 547 652), a Norwegian company. In GDPR terms, Tilery AS is the "data controller" for the personal data described on this page — the company that decides why and how your data is used, and the one responsible for it. For any questions or requests about your data, email support@tilery.eu.

Three other companies help us run the service, in different roles:

  • Creem, our payment provider and merchant of record, is a separate data controller: when you buy credits you give your payment details directly to Creem, and Creem is responsible for them under its own privacy policy (see Payment Information).
  • Scaleway, our hosting provider, is our "data processor": it stores and handles data only on our instructions and may not use it for its own purposes (see Third-Party Services).
  • Proton, our support-inbox provider, is also our data processor: when you email support@tilery.eu, Proton handles your message on our behalf (see Third-Party Services).

Our service runs entirely on servers in the EU, and your personal data is processed only in the EU and in Switzerland — a country the European Commission recognizes as providing adequate data protection.

Data We Collect

We collect minimal personal information necessary to provide the service, and all of it comes directly from you. Here is everything at a glance — the sections below give the detail:

WhatWhy we have itLegal basisKept for
Email addressSign-in, password resets, billing notificationsContractUntil account deletion (60-day grace period)
NameYour profile and Creem billing accountContractUntil account deletion
API keys & CORS originsAuthenticating your tile requestsContractUntil you delete them, or account deletion
Sign-in IP & browserYour active-sessions list, spotting intrudersSecurity (legitimate interest)With the session — 7 days idle, 90 days max
Login-attempt IPsBrute-force protectionSecurity (legitimate interest)Deleted on login; expired entries purged every 30 minutes
Tile usage (coordinates, country)Metering and billingContract1 day raw; 60 days hourly; 2 years daily
Purchase & spend recordsBookkeepingLegal obligation (accounting law)5 years, pseudonymous after account deletion

Email Address

We collect your email address when you create an account — it is the one piece of personal data you cannot sign up without. It is used for authentication, account management, and service notifications such as billing confirmations and password resets. We do not share your email with third parties for marketing. You can change your email through your account settings; removing it entirely means deleting your account.

Account Information

We store your name, API key configurations, and allowed CORS origins. API keys are cryptographically hashed before storage — only the first eight characters are stored in plaintext as a visual prefix.

Usage Data

We track tile request counts per user account for usage-based billing. Each tile request records the tile coordinates, whether it was served from cache, and country-level location derived from the requesting IP address. The IP address itself is not stored in our analytics database — only the two-letter country code. You can view your usage statistics in your dashboard.

IP Addresses

We store IP addresses in limited, specific contexts to protect the service and your account (in GDPR terms: our legitimate interest in keeping the service secure):

  • Session records: Your IP address and browser user agent are recorded when you sign in, so you can review active sessions and detect unauthorized access.
  • Authentication rate limiting: IP addresses are stored in the database to enforce rate limits on login attempts and prevent brute-force attacks. Records are deleted immediately on successful login and any remaining expired entries are purged by a background job every 30 minutes.
  • Tile server rate limiting: IP addresses are held in server memory (not written to disk) to enforce per-request rate limits. They are purged periodically and lost on server restart.

We do not use IP addresses for tracking, profiling, or marketing. IP addresses are not shared with third parties except as required by law.

Passwords and Authentication

Passwords are hashed with modern algorithms before storage — we never store plaintext passwords. Session tokens and API keys are also hashed. If you enable two-factor authentication, your secrets are encrypted at rest.

Cookies

We use a small number of strictly functional cookies. We do not use any advertising or analytics cookies.

  • Session cookie ("tilery.session_token"): Keeps you signed in. HttpOnly, expires after 7 days of inactivity.
  • MFA challenge cookie ("tilery.mfa_challenge"): Used during two-factor authentication at login. HttpOnly, expires after 5 minutes.
  • Password-reset MFA cookie ("tilery.reset_mfa_challenge"): Used during two-factor authentication when resetting your password. HttpOnly, expires after 5 minutes.
  • Flash message cookie ("tilery.flash"): Displays one-time feedback messages (e.g., "Settings saved"). HttpOnly, removed after a single page load.

Payment Information

Payments are handled by Creem, our merchant of record. When you purchase credits you enter into a customer relationship with Creem: the purchase is made from Creem, and Creem issues your invoice.

To set this up, we share your email address and name with Creem so they can create your billing account, and we tag their record with your Tilery account ID so payments can be matched to your account. In return we receive only confirmation of payment status and the resulting credit purchase amount.

For the information you provide at checkout — card details and billing address — Creem is an independent data controller, and its processing is governed by the Creem Privacy Policy. Payment credentials never reach our systems: we do not store card numbers or bank account details.

Data Retention

We retain data only as long as necessary for its stated purpose.

Account Data

Your account information is retained while your account is active. If you delete your account, it is scheduled for permanent deletion with a 60-day grace period — you can log back in during that time to cancel. After the grace period we remove your email, name, password, API keys, sessions, and two-factor authentication data.

Records of credit purchases and spending are kept for 5 years because Norwegian accounting law requires it (a legal obligation). After account deletion these records are pseudonymous — they no longer contain your name, email, or any other direct identifier.

If a payment is disputed through your bank (a chargeback), we keep the account and its records while the dispute is open, and afterwards for as long as we may need them to establish, exercise or defend legal claims — rather than deleting them on the usual schedule. That is a legitimate interest, and it is the only case in which an account is kept beyond the periods above.

Usage Data

  • Individual tile request events: retained for 1 day
  • Hourly usage aggregates: retained for 60 days
  • Daily usage aggregates and billing summaries: retained for 2 years

Session and Security Data

  • Sessions expire after 7 days of inactivity, and always after 90 days
  • Authentication rate-limit records are deleted on successful login and expired entries are purged every 30 minutes
  • In-memory tile server rate-limit data is purged periodically and does not survive server restarts

Third-Party Services

Creem (Payments)

Creem (operated by Armitage Labs OÜ, an Estonian company) processes all payments and handles your billing information. See the Creem Privacy Policy.

Scaleway (Hosting and Email)

Our service runs on infrastructure from Scaleway (a French company), in EU data centers. We also use Scaleway's transactional email service to send account-related emails such as verification links, password reset links, and billing notifications.

This means the personal data described on this page is stored on Scaleway servers, and account emails are delivered through their email service. Scaleway handles this data only on our behalf and on our instructions — in GDPR terms it is our "data processor", bound by a data processing agreement. See the Scaleway Privacy Policy.

Proton (Support Inbox)

Our support inbox (support@tilery.eu) is hosted by Proton (a Swiss company), so when you email us, your address and whatever your message contains are handled by Proton on our behalf. Switzerland is not in the EU/EEA, but the European Commission has formally recognized it as providing an adequate level of data protection — this is the one place your data can leave the EU/EEA. See the Proton Privacy Policy.

Tracking and Analytics

We count visits to this website with a self-hosted instance of Umami, an open-source, privacy-focused analytics tool, so we can see which pages are useful (our legitimate interest). It uses no cookies and stores nothing that can identify you: we see page views, referrers, browser and device types, and countries — never who you are. Your IP address is used only for a moment to derive the country and a short-lived anonymous identifier, and is never stored. It runs on our own servers in the EU/EEA, and the data is shared with no one.

Beyond that there is no tracking — no advertising pixels, no cross-site tracking, no analytics cookies.

Our servers keep internal technical logs of requests (the URL, response status, and browser user agent — not your IP address) so we can fix problems and keep the service healthy. These logs stay on our own EU infrastructure.

Your Rights

Under applicable data protection law (including the GDPR), you have the right to access, correct, delete, and export your personal data, as well as to object to or restrict certain processing.

  • Access and portability: View your account information and usage statistics in your dashboard at any time. For a machine-readable copy of your personal data, email us and we will send you one.
  • Correction: Update your email, name, and account settings through your dashboard.
  • Deletion: Delete your account at any time from your profile page (60-day grace period — see Data Retention above). Personal data will be removed from our systems, except where retention is required by law.
  • Objection and restriction: You can object to the processing we base on legitimate interest (the security measures above). The data we do collect and process is necessary to run the service, so objection will in practice mean closing and deleting the account.

If you think we are handling your data wrong and we cannot resolve it together, you have the right to complain to Datatilsynet (the Norwegian Data Protection Authority) or the data protection authority in the country where you live.

Contact

If you have questions about this privacy policy or wish to exercise your data protection rights, email support@tilery.eu. We aim to reply within a few days, and always within one month as the GDPR requires.

Tilery AS · Org. nr. 837 547 652 · Norway

Changes to This Policy

We may update this policy to reflect changes in our practices or for legal and regulatory reasons. Material changes will be posted on this page with an updated date. We encourage you to review this policy periodically.