Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains how RedMapForge (“we”, “us”) collects and processes personal data when you use the browser-based map editor at redmapforge.com (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for the processing described here is the company identified in our Imprint:
Dietrich Development GmbHAlemannenstraße 14
72393 Burladingen
Germany
Email: info@dietrich-development.com
2. What data we process
We process the following categories of personal data:
- Account data: your email address, display name and avatar URL, plus the identifier from the sign-in provider you use (Discord, Google (where offered), or email magic link). We do not use or store passwords. When you sign in with an OAuth provider, we also store the OAuth tokens issued by that provider for your linked account, which are needed to operate the sign-in link.
- Project content: the projects and map edits you create, and any fonts (.ttf) and images you upload to use in the editor.
- Uploaded map data (“hochgeladene Kartendaten”): the map tile files you upload from your own game copy, stored per account strictly separated from other users’ data, plus a validation manifest (tile names, checksums, your rights confirmation with timestamp).
- Billing state: plan and subscription information received from our payment processor Tebex via webhooks — your plan, subscription status, and Tebex customer/subscription identifiers. We do not receive or store your card or payment data; that is handled entirely by Tebex.
- Cfx.re account identifier: to buy a paid plan you sign in once with your Cfx.re account, because our payment provider identifies buyers on a RedM store that way. From that sign-in we store the account identifier and, where the provider supplies one, the display name — used to match your purchase to your account, to read your subscription state, and to show you which account is linked. We never receive your Cfx.re password. You can link or change the account under Account, and it is deleted with your account.
- Community templates and votes: if you publish a template to the community template store, that template becomes public user-generated content. If you vote on templates in the store, we store which templates your account has voted on (to count votes and prevent duplicate voting); your individual votes are not displayed publicly.
- Discord Founder role: if you hold the Founder Lifetime plan and have linked a Discord account, we store that linked Discord ID and use it for the Founder-role sync described in Section 5.
- Technical data: data necessarily processed to deliver the Service, such as your IP address and request metadata in server logs, used for security and to operate the Service. In addition to short-lived server logs, we record IP addresses of certain security-relevant actions in an internal audit database used for abuse prevention and investigating misuse. Server logs containing IP addresses are retained for a maximum of 14 days. Entries in the internal security audit database, including the IP address of the recorded action, are retained for 12 months from the date of the event and then deleted automatically, unless a specific entry is needed longer to investigate or pursue an identified case of abuse.
3. Cookies
We use only functional cookies that are necessary to provide the Service. We do not use advertising or tracking cookies, and we do not currently run any web analytics. These strictly necessary cookies are set without consent under § 25(2) no. 2 of the German TDDDG.
- Session cookie — keeps you signed in; stored for up to 30 days (the default lifetime of our authentication library).
- Sign-in helper cookies — short-lived cookies set by our authentication library (NextAuth) during sign-in: a CSRF-protection token, a callback-URL cookie, and a PKCE code-verifier cookie for OAuth sign-ins. They expire within a few minutes.
- rmf.locale — remembers your language preference; stored for 12 months.
Your light/dark theme preference (rmf.theme) and interface scale (rmf.uiScale) are stored in your browser’s localStorage, not in cookies; they never leave your device.
4. Purposes and legal bases
We process your personal data for the following purposes and on the following legal bases:
- Providing the Service (account creation and sign-in, storing and rendering your projects, generating exports, enabling collaboration and the template store) — performance of a contract with you, Art. 6(1)(b) GDPR.
- Billing and subscription management (processing plans via Tebex, applying entitlements) — performance of a contract, Art. 6(1)(b) GDPR, and compliance with legal (e.g. tax/accounting) obligations, Art. 6(1)(c) GDPR.
- Security, abuse prevention and operating our infrastructure (server logs, rate-limiting, moderation of public templates) — our legitimate interests in a secure and functioning Service, Art. 6(1)(f) GDPR.
- Backups and disaster recovery (encrypted backup snapshots as described in Section 6) — our legitimate interest in protecting the Service and your data against loss, Art. 6(1)(f) GDPR, and our security obligations under Art. 32 GDPR.
- Security audit logging (recording security-relevant account actions together with the acting IP address) — our legitimate interest in preventing and investigating abuse, Art. 6(1)(f) GDPR.
- Discord Founder-role synchronisation (transmitting your linked Discord ID to Discord for Founder benefits, see Section 5) — performance of the contract for the Founder Lifetime plan, Art. 6(1)(b) GDPR.
We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects, and we do not use your data for advertising.
5. Recipients and processors
We use carefully selected service providers who process personal data on our behalf as processors under Art. 28 GDPR, or who act as independent controllers where noted:
- Tebex (Tebex Limited, United Kingdom) — our merchant of record and payment processor. Tebex acts as an independent controller for payment and tax processing; see Tebex’s own privacy policy for details.
- Hetzner (Hetzner Online GmbH, Germany) — our hosting / infrastructure provider, operating the application servers, the PostgreSQL database and the S3-compatible object storage in which your account data and project content are stored.
- IONOS (IONOS SE, Germany) — email delivery for the one-time sign-in links (magic links).
- Cloudflare R2 (Cloudflare, Inc., USA) — stores our encrypted offsite database backups. Only encrypted database backups are transferred to Cloudflare; they are encrypted on our own infrastructure before upload, and Cloudflare cannot read their contents. This transfer is based on the EU-US Data Privacy Framework (Cloudflare, Inc. is certified under the DPF) and, in addition, on EU Standard Contractual Clauses.
- Discord and Google (where offered) — when you choose to sign in with them, they process the sign-in you initiate as independent controllers.
Discord Founder-role sync: if you hold the Founder Lifetime plan and have linked a Discord account, we transmit your linked Discord ID to Discord in order to assign the Founder role to your Discord account on our community server — and to remove it if the entitlement or the link ends. No other account data is shared with Discord for this purpose.
Where a recipient is located outside the EU/EEA, we transfer personal data only under an adequacy decision of the European Commission (Art. 45 GDPR - including the EU-US Data Privacy Framework for certified US recipients and the UK adequacy decision for Tebex Limited) or under EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can obtain a copy of the relevant safeguards by contacting us at info@dietrich-development.com.
6. Where your data is stored
Account data and billing state are stored in a PostgreSQL database; your project content and uploaded files are stored in S3-compatible object storage. Both are operated through our infrastructure provider.
Uploaded map data is stored in the same S3-compatible object storage, in per-user/per-tile-set prefixes that are never shared across accounts — except that collaborators you invite can render (not download) a set within a shared project. Transient upload archives used to process an upload are deleted once processing completes, and any orphaned archives are deleted automatically within about 48 to 54 hours.
We keep encrypted backups on a staggered schedule. Database backups (containing account, project and billing state data) are encrypted on our own infrastructure before upload and stored offsite with Cloudflare R2: daily snapshots for 14 days, weekly for 8 weeks, monthly for 12 months, and yearly snapshots for up to 3 years. Object-storage snapshots (containing project files and uploaded map data) are kept locally on our own infrastructure only, as weekly snapshots retained for 14 days; they are never transferred outside the EU. We regularly review whether shorter backup retention is sufficient for disaster recovery.
7. How long we keep your data
We keep your account and project data for as long as you have an account. When you delete a project it is removed from active systems; when you delete your account we delete or anonymise your personal data, except where we must retain certain records to comply with legal obligations (for example, billing records for statutory retention periods). Published community templates may remain available as public content even after the related project is deleted, unless you remove them. Deleting your account also deletes your uploaded map data, including tile objects and any derived render caches; copies of uploaded map data may persist in local encrypted backups for up to 14 days; copies of your account record may persist in encrypted database backups until those age out under the schedule in Section 6.
Backups: deleted data may persist in our encrypted backup snapshots until those snapshots expire under the retention schedule described in Section 6 (up to 3 years for yearly snapshots). Data is not selectively removed from individual backups; backups are only used to restore systems after data loss, and deleted data restored from a backup would be deleted again as part of the restore process.
7a. Children and minors
The Service is directed at persons aged 16 or over (or the minimum age required to consent to data processing in your country, if higher). We do not knowingly process personal data of children below this age; if you believe a child has created an account, please contact us and we will delete it.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21); and
- withdraw any consent you have given, with effect for the future, without affecting the lawfulness of prior processing.
Right to object (Art. 21 GDPR): where we process your personal data based on our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.
To exercise any of these rights, contact us at info@dietrich-development.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or of the alleged infringement. For us, the competent supervisory authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (www.baden-wuerttemberg.datenschutz.de); you may also complain to the authority of your habitual residence.
9. Changes to this policy
We may update this Privacy Policy as the Service evolves or for legal reasons. The “Last updated” date above reflects the current version, and we will provide notice of material changes where required.