THS2 · Legal
Privacy Policy
Version dated 2 August 2026
1. General information
This policy describes personal data processing on ths2.ru, the THS2 API, and related mobile application features.
Controller: Azat Maratovich Akhmetshin, Ufa, Republic of Bashkortostan, Russian Federation. Privacy contact: akhmetshin.azat@gmail.com.
2. Data we process
- account data: email, optional first and last name, interface language, password hash, registration and login dates;
- user maps and related data: PMTiles files, titles, descriptions, sizes, checksums, technical and geographic metadata;
- library and store records: map access rights, product actions, and access-grant history;
- rights complaints: name, email, claimant role, description, and evidence URL; the sender IP is retained only as a protected anti-spam hash;
- technical data: IP address, user-agent, request time and path, login, upload, download, deletion, generation, and administrative audit events;
- information voluntarily sent to support.
THS2 does not request payment credentials. Payments are not implemented in the current service version.
3. Purposes and legal grounds
We use data to create and secure accounts, store and deliver maps, operate the library and API, restore access, handle requests, comply with law, prevent abuse, and maintain security. Processing is based on performing the user agreement, taking requested pre-contractual steps, legal obligations, and consent where requested separately.
Personal data is not sold, used for advertising profiles, or supplied for marketing mailings.
4. Cookies and external resources
The site uses only essential cookies for authenticated sessions, CSRF protection, and service messages. Advertising and analytics cookies are not installed by THS2.
Interactive maps cause the browser to contact OpenStreetMap directly. Some interface libraries are loaded from the unpkg CDN. Those providers receive normal network request data, including IP address and user-agent, under their own privacy terms.
5. Retention and security
Primary account and file data is stored on service infrastructure in the Russian Federation. Passwords are stored only as strong hashes; connections use HTTPS; map files are isolated by owner; downloads and APIs enforce access control.
Account data is retained until account deletion or service termination; user files until deletion or another lawful ground applies; closed complaints and audit events for up to three years unless longer retention is required by law or to establish or defend claims. Deleted data may remain in rotating backups for up to 14 days.
6. Data disclosures
Access is limited to the controller and providers needed for hosting, databases, backups, and email. Data may be disclosed to public authorities upon a lawful request. Publishing a map does not make its owner's contact details public.
7. Your rights
You may request access, correction, restriction, or deletion of your data, withdraw consent, and challenge processing. Send requests from the account email to akhmetshin.azat@gmail.com. Reasonable identity verification may be required to protect the account.
Withdrawal does not affect prior lawful processing or processing required by contract or law. Removing required data may make continued account use impossible.
8. Policy changes
The current version is always available at this address. The version date is updated for material changes.