Mapbox Legal Portal
U.S. Government Terms of Service
Applicability
This Exhibit applies to all instances where the ultimate end user(s) of any Service is an agent or employee of the U.S. Government.
Flow Up
If you are a prime contractor or subcontractor that is using the Services to provide products or services to or for the U.S. Government, you must flow this Agreement to your U.S. Government customer and all U.S. Government users, account holders, and subscribers who use or access the Services on behalf of a U.S. Government agency (“U.S. Government End User”). You will indemnify and hold us harmless from any and all claims, liabilities, damages, losses, or costs (including reasonable attorneys’ fees) based on or arising out of your failure to comply with this Section.
U.S. Government End User Rights:
- The Services and any derivatives thereof are “commercial items” as defined in 48 C.F.R. 2.101 (“Commercial Items”). The use, duplication, reproduction, release, modification, disclosure or transfer of the Atlas Software or any Services-related software and any associated documentation and technical data by a U.S. Government End User is restricted in accordance with 48 C.F.R. §12.211; 48 C.F.R. §12.212, 48 C.F.R. §227.7102-2, and 48 C.F.R. §227.7202, as applicable. You may resell the Services to a U.S. Government End User, if and only if, (a) the U.S. Government End User is specified in your Order and (b) the Services are licensed to the U.S. Government End User subject to the terms of this Agreement.
- Consistent with 48 C.F.R. §12.211, 48 C.F.R. §12.212, 48 C.F.R. §227.7102-1 through 48 C.F.R. §227.7102-3, and 48 C.F.R. §§227.7202-1 through 227.7202-4, as applicable, the Services are provided to U.S. Government End Users: (i) only as Commercial Items, (ii) with only those rights as are granted to all other users pursuant to our standard terms of use (except as otherwise noted herein), and (iii) the terms of this Exhibit are incorporated into any reseller, prime contractor, or subcontractor’s contract with the U.S. Government or otherwise agreed to by the U.S. Government customer in a way that legally binds the U.S. Government to these terms. This U.S. Government Rights clause is in lieu of, and supersedes, any Federal Acquisition Regulations (“FAR”), the Defense FAR Supplement (“DFARS”), or other clause or provision that addresses U.S. Government rights in computer software or technical data.
Superseding Provisions
- In recognition of the fact that certain provisions of the Master Services Agreement are inapplicable or unenforceable where U.S. Government End Users are involved, Mapbox and you agree that modifications to the Master Services Agreement are appropriate. Provisions concerning the following subject matter that are included in the Master Services Agreement do not apply, and, where relevant, are superseded by the applicable provision of FAR 52.212-4 or other applicable law, such as the Contracts Disputes Act:
- Changes and payment
- Account cancellation or suspension
- Changes to service or terms
- Indemnification
- Limitation of liability
- Any provision concerning choice of law and/or venue for dispute resolution
No Endorsement
We agree that any U.S. Government seals, trademarks, logos, service marks, trade names, and the fact that you use the Services, shall not be used by us in such a manner as to state or imply that our products or services are endorsed, sponsored or recommended by any entity of the U.S. Government, or are considered by the U.S. Government as superior to any other company's products or services. We agree not to display any U.S. Government seal or logo on our homepage or elsewhere on our website, unless permission to do has been granted by the relevant U.S. Government authority. We may list the U.S. Government customer’s name in a publicly available user list so long as the name is not displayed in a more prominent fashion than that of any other third-party name, and reference the U.S. Government customer as our user.
Permanent Geocodes:
- For the purpose of U.S. Government End Users, use, duplication, reproduction, release, modification, disclosure or transfer of Permanent Geocodes and Atlas Geocoding Data is restricted in accordance with the LIMITED or RESTRICTED rights as described in any applicable DFARS or FAR. In case of conflict between any of the FAR and/or DFARS that may apply to Permanent Geocodes or Atlas Geocoding Data, the construction that provides greater limitations on the Government’s rights shall control. For purpose of any public disclosure provision under any federal, state or local law, it is agreed that certain Permanent Geocodes and parts of the Atlas Geocoding Data are a trade secret and a proprietary commercial product and not subject to disclosure.
- U.S. Government End Users hereby agree to protect Permanent Geocodes and Atlas Geocoding Data from public disclosure and to consider the Permanent Geocodes and Atlas Geocoding Data exempt from any statute, law, regulation, or code, including any Sunshine Act, Public Records Act, Freedom of Information Act, or equivalent, which permits public access and/or reproduction or use of the Permanent Geocodes and Atlas Geocoding Data. In the event that such exemption is challenged under any such laws, this agreement shall be considered breached and any and all right to retain any copies or to use of the Permanent Geocodes and Atlas Geocoding Data shall be terminated and considered immediately null and void, and any copies of Permanent Geocodes and Atlas Geocoding Data held by a U.S. Government End User at that time shall immediately be destroyed. If any court of competent jurisdiction considers this clause void and unenforceable, in whole or in part, for any reason, this agreement shall be considered terminated and null and void, in its entirety, and any and all copies of Permanent Geocodes and Atlas Geocoding Data shall immediately be destroyed.
Privacy & Security FAQ
Last Updated: Aug 22, 2023
Mapbox provides a location data platform that powers maps and location services. Mapbox provides SDKs (software development kits) and APIs (application programming interfaces), which businesses and developers use to incorporate Mapbox mapping and navigation technologies into the licensed applications and websites they make. The SDKs contain libraries of software code which are incorporated into a customer’s licensed application or website. These libraries of software code facilitate API requests to Mapbox’s location data platform (which is a backend data server, hosted in the cloud (AWS-US)) which then responds with map and location content to the customer’s application or website.
In addition, Mapbox offers an on-premise version of its location data services, called Atlas.
No. Mapbox does not sell personal data.
No. For customers on a monthly active user (“MAU”) billing model, Mapbox maintains counts of MAUs for billing purposes only. Mapbox does not (and cannot) track an end user’s activity across billing cycles and does not build targeted profiles with the data processed through its products/services.
Mapbox applies the principle of data minimization to product development and operations in an effort to collect only limited data from the outset. Mapbox operates a number of technical and organization measures regarding the limited personal dataset that we process, such as strict access controls and prompt deletion of raw log files that contain IP addresses and billing IDs. Mapbox deploys regular ID rotation and 1-way hashing for billing IDs, which must be retained for accounting and billing purposes, to minimize the ability to track user requests over time. Billing IDs are not transmitted with unrelated events, further reducing the feasibility of correlating a user’s activities over time. In addition, Mapbox operates strict anonymization procedures, such as clipping traces, for telemetry events that send location data.
Communication through the Internet requires the presence of IP addresses, which specify each transmission’s origin and destination. When end users engage with applications that access Mapbox products/services through the Internet, the end user necessarily discloses their current IP address to one or more Mapbox servers. IP addresses are retained in cloudfront logs for 30 days for billing and customer usage reporting, unless involved in an ongoing security, anti-fraud, or misuse investigation.
Mapbox receives location data when a Mapbox customer’s end users uses a licensed application that incorporates Mapbox mobile SDKs and the end user has authorized the licensed application’s use of the end user’s device location via their mobile phone or device operating system.
Location data includes fields such as latitude and longitude, altitude, horizontal and vertical accuracy, a session ID rotating every 24 hours, and origin IP address (as would any Internet communication). The IP address that accompanies location data is retained at the load balancer (where it is used for security and PUBLISHED: Aug 22, 2023https://www.mapbox.com/legal/legal-faq Mapbox Customer FAQ, Page 3billing purposes and discarded after 30 days). This IP address is not forwarded to the location telemetry processing pipeline. Location data is encrypted in transit and at rest, and is subject to the principle of least access, with the minimal number of personnel and processes having access to it in its pre-aggregated form.
In the location data anonymization pipeline, the location data is then anonymized by clipping off the origin and destination of the trip and further dividing the trip into segments, which cannot be reassembled. The anonymized location data is then used to improve Mapbox mapping products, including the Traffic and Movement data products.
In AWS in the United States. However, for performance purposes, Mapbox regularly caches content on its AWS content delivery network (“CDN”) located in various regions. Mapbox employees who work for Mapbox wholly-owned subsidiaries may access personal data from the countries where they work in order to support, develop and provide Mapbox products/services.
No. Mapbox’s products/services store and serve source data from an AWS primary region in the US. As noted above, data is cached and served out of various regions outside the US for performance reasons, however Mapbox cannot serve its data from one limited geographic region. To comply with GDPR and safeguard transfers to the US and other countries, please see Mapbox's DPA, Schedule C, which includes the Standard Contractual Clauses released in 2021 by the European Commission.
Yes. Mapbox carefully scrutinizes the personal data it processes within its engineering lifecycle, which includes conducting a privacy review for new (or changed) processing activities. Mapbox follows privacy-by-design principles and works diligently to limit the personal data it processes from the outset. A DPIA is conducted in any situation in which processing of personal data may be considered high risk and not able to be accomplished in a lower risk manner.
Mapbox runs a global data protection program designed to operate in compliance with applicable global privacy laws, including: VCDPA (Virginia, USA), UCPA (Utah, USA), UK-GDPR (UK), TIPA (Tennessee, USA), TDPSA (Texas, USA),PIPEDA (Canada), MTCDPA (Montana, USA), LGPD (Brazil),IDPL (Iowa, USA), ICDPA(Indianna, USA), GDPR (Europe), CTDPA (Connecticut, USA), CCPA and its implementing regulations including CPRA (California, USA), CPA (Colorado, USA), and APPI (Japan), among many other important jurisdictions.
Mapbox’s privacy program is based on privacy by design, which includes monitoring for upcoming privacy laws and regulations to assess whether its practices may need to be adjusted to maintain compliance; product/service privacy reviews; data breach response processes; and operationalized technical and organizational measures designed to ensure the security of the personal data it receives including: security audits and SOC2 certification; anonymization & pseudonymization of personal data (where applicable); strict access control with logging; limited data retention periods.
Yes. Mapbox is SOC2 Type 2 certified with a summary SOC3 report available for customer review. In addition, Mapbox earned and maintains Trusted Information Security Assessment Exchange (“TISAX”) and ISO 9001 certifications. Upon request and execution of an NDA, Mapbox may share a copy of its latest SOC2 report.
Mapbox welcomes any further questions you may have regarding its ongoing commitment to privacy and data security. Please contact Mapbox’s privacy office at privacy@mapbox.com.
Want to receive updates on our sub-processors?
Please subscribe below: