Last updated:
This Privacy Notice for Staked Maps, a product of Phi McRee Designs LLC ("we," "us," or "our"), describes how and why we access, collect, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
Questions or concerns? Contact us at info@phimcreedesigns.com. If you do not agree with our policies and practices, please do not use our Services.
Personal information you disclose to us
When you register an account, the only personal information we collect directly is your email address (used for account authentication, via our identity provider Supabase). We do not collect your name or billing address as part of account creation.
Payment Data. If you purchase a subscription, all payment handling — including any billing name, address, or card details — is collected and processed directly by our payment processor, Stripe, on its own systems. Staked Maps never receives, transmits, or stores your raw payment card number, billing address, or bank account details. From a completed checkout, our webhook integration with Stripe reads only the subscription tier and state selections you chose, plus an opaque Stripe customer reference ID — not a card number or other payment detail — which we retain so you can later manage or cancel your subscription through Stripe's own billing portal.
Information automatically collected
Like most web services, our server automatically logs standard technical/diagnostic information (IP address, browser type, general request metadata) for performance and security purposes. These logs are automatically deleted on a rolling 14-day cycle.
Location Data. Staked Maps uses your browser's HTML5 Geolocation API, with your explicit permission, to place a live position marker on the map and to determine which state's data to show you on our Free plan. This processing happens entirely within your own browser — your precise coordinates are never sent to or stored on our servers. If you decline location access, the map still loads normally; you simply won't see a live position marker, and Free-plan users will need to select a state manually if we're unable to resolve one.
Separately, if you use "Draft A Claim," the map coordinate you click (not your device's actual location) is sent to our server to look up parcel information. This is retained only in standard request logs for 14 days, the same as any other request.
Local Device Storage. To keep the app usable with a weak or absent cellular connection, we cache map data (claim boundaries and similar geographic data) and any custom pins you place directly inside your browser's local storage (IndexedDB). This data stays on your device and is not transmitted to us as part of this caching process. Downloading map data for offline use consumes data according to your device's connection type (Wi-Fi or cellular); an estimated download size is shown before you confirm an offline save.
We process your personal information only where we have a valid legal basis to do so, including: your consent (for precise geolocation); to perform our contract with you (providing the mapping features you've subscribed to); and to comply with legal obligations.
We do not sell your personal information. We share information only as needed to operate the Services:
The Service links out to official government resources (e.g. reports.blm.gov) in new browser tabs. We are not responsible for the privacy practices or content of these independent third-party sites.
We do not use cookies. Your signed-in session is kept using your browser's local storage, which keeps you signed in across visits. Map data and any pins you create are also cached in local storage (IndexedDB) as described in Section 1. We do not run advertising or behavioral tracking scripts of any kind.
We retain your account and subscription information for as long as you maintain an active account. Server request logs are automatically deleted on a rolling 14-day cycle.
Access to paid-tier map data (such as claim serial numbers and data quality scores) is verified on our server for every request based on your actual, current subscription status — not just hidden in the app's interface — so that data isn't sent to a device at all unless the associated account is entitled to it. That said, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Our Services are not directed to, and we do not knowingly collect personal information from, anyone under 18 years of age. If we learn an account belongs to someone under 18, we will deactivate it and delete the associated data.
Depending on your state or country of residence, you may have the right to access, correct, or request deletion of your personal information. To make such a request, email us at info@phimcreedesigns.com.
Because there is no accepted industry standard for how to respond to browser Do-Not-Track signals, our systems do not currently respond to them differently.
Categories of personal information we have processed in the past 12 months:
To exercise applicable state privacy rights (to know, access, correct, or delete your personal information), email info@phimcreedesigns.com.
Yes — we will update this notice as needed to stay current with our practices and applicable law. The "Last updated" date at the top of this page will always reflect the most recent revision.
If you have questions or comments about this Privacy Policy, contact us by email at info@phimcreedesigns.com or by post at:
Phi McRee Designs LLC
560 NE F Street, Ste A, PMB #322
Grants Pass, OR 97527
United States