Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how RedMapForge (“we”, “us”) collects and processes personal data when you use the browser-based map editor at redmapforge.com (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

The controller responsible for the processing described here is the company identified in our Imprint:

Dietrich Development GmbH
Alemannenstraße 14
72393 Burladingen
Germany
Email: info@dietrich-development.com

2. What data we process

We process the following categories of personal data:

  • Account data: your email address, display name and avatar URL, plus the identifier from the sign-in provider you use (Discord, Google, or email magic link). We do not use or store passwords.
  • Project content: the projects and map edits you create, and any fonts (.ttf) and images you upload to use in the editor.
  • Billing state: plan and subscription information received from our payment processor Paddle via webhooks — your plan, subscription status, and Paddle customer/subscription identifiers. We do not receive or store your card or payment data; that is handled entirely by Paddle.
  • Community templates: if you publish a template to the community template store, that template becomes public user-generated content.
  • Technical data: data necessarily processed to deliver the Service, such as your IP address and request metadata in server logs, used for security and to operate the Service.

3. Cookies

We use only functional cookies that are necessary to provide the Service. We do not use advertising or tracking cookies, and we do not currently run any web analytics.

  • Session cookie — keeps you signed in.
  • rmf.locale — remembers your language preference.
  • rmf.theme — remembers your light/dark theme preference.

4. Purposes and legal bases

We process your personal data for the following purposes and on the following legal bases:

  • Providing the Service (account creation and sign-in, storing and rendering your projects, generating exports, enabling collaboration and the template store) — performance of a contract with you, Art. 6(1)(b) GDPR.
  • Billing and subscription management (processing plans via Paddle, applying entitlements) — performance of a contract, Art. 6(1)(b) GDPR, and compliance with legal (e.g. tax/accounting) obligations, Art. 6(1)(c) GDPR.
  • Security, abuse prevention and operating our infrastructure (server logs, rate-limiting, moderation of public templates) — our legitimate interests in a secure and functioning Service, Art. 6(1)(f) GDPR.

We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects, and we do not use your data for advertising.

5. Recipients and processors

We use carefully selected service providers who process personal data on our behalf as processors under Art. 28 GDPR, or who act as independent controllers where noted:

  • Paddle (Paddle.com Market Ltd / Paddle Payments Ltd) — our merchant of record and payment processor. Paddle acts as an independent controller for payment and tax processing; see Paddle’s own privacy policy for details.
  • Our hosting / infrastructure provider — operating the application servers, the PostgreSQL database and the S3-compatible object storage in which your account data and project content are stored.
  • Authentication providers — Discord and Google, when you choose to sign in with them (they process the sign-in you initiate), and our email delivery for magic links.

Where a processor is located outside the EU/EEA, any transfer is safeguarded by an adequacy decision or by EU Standard Contractual Clauses.

6. Where your data is stored

Account data and billing state are stored in a PostgreSQL database; your project content and uploaded files are stored in S3-compatible object storage. Both are operated through our infrastructure provider.

7. How long we keep your data

We keep your account and project data for as long as you have an account. When you delete a project it is removed from active systems; when you delete your account we delete or anonymise your personal data, except where we must retain certain records to comply with legal obligations (for example, billing records for statutory retention periods) and except for limited backups that are overwritten in the ordinary course. Published community templates may remain available as public content even after the related project is deleted, unless you remove them.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data rectified (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing based on our legitimate interests (Art. 21); and
  • withdraw any consent you have given, with effect for the future, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at info@dietrich-development.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or of the alleged infringement.

9. Changes to this policy

We may update this Privacy Policy as the Service evolves or for legal reasons. The “Last updated” date above reflects the current version, and we will provide notice of material changes where required.