MyMaps - Privacy Policy
Version: 2.0
Effective Date: August 14, 2026
Supersedes: Version 1.0 (June 10, 2025)
Plain-Language Summary
MyMaps is a web-based GIS and mapping platform operated by Momentum CE Inc. ("Momentum CE," "we," "us," or "our"). Most of the data in MyMaps does not belong to us — it belongs to the tribal government, special district, or business that hired us.
Here's what that means in practice:
- We collect very little about you personally. To run your account we need your name, email, and organization. That's it.
- We do not run advertising or marketing analytics, and we do not sell personal information.
- Field apps capture location. If you use a MyMaps field data collection tool, it records GPS coordinates, and photos you attach may carry embedded location and device metadata. Your browser or device will ask before sharing precise location.
- Your organization's data belongs to your organization. We hold it and process it on their instructions. Requests to see, correct, or delete it go to them, not to us.
- Tribal clients keep full data sovereignty. We do not disclose culturally sensitive, sacred site, or trust land data without the tribe's explicit authorization.
- Public map viewers don't need an account. If you're just looking at a public map, we don't ask who you are.
The full policy below explains each of these in more detail. If anything below conflicts with this summary, the formal terms control.
1. Scope of This Policy
This Privacy Policy explains how Momentum CE Inc. collects, uses, discloses, and protects information in connection with the MyMaps platform (the "Service"), including its custom map applications, data portals, dashboards, and field-data tools.
This Policy applies to all users of the Service, including tribal government staff, special district and small business clients and their employees, contractors and consultants, and members of the public with access to publicly available map content. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
This Policy does not apply to:
- Information collected by a client organization through its own separate systems;
- Information collected by third-party map data, imagery, or basemap providers whose content appears in the Service (those services are governed by their own privacy policies); or
- Information you provide directly to a client organization outside of the Service.
Capitalized terms used but not defined in this Policy have the meanings given in the MyMaps Terms of Use.
For tribal government clients, we recognize that data sovereignty and the protection of culturally sensitive information are of particular importance. We handle such data with heightened care and in accordance with any applicable tribal data governance requirements and the terms of your Service Agreement. See Section 11.
2. Our Role: Controller and Processor
Our role differs depending on the information involved:
- We act as a controller for account information, authentication records, and technical and device data described in Sections 3.1, 3.2, and 3.4 — the information we need to operate the platform itself.
- We act as a processor (service provider) for Client Data as described in Section 3.3 and Section 5 — we process it only on the instructions of the client organization that owns it.
If you are an individual whose information appears within Client Data — for example, as a respondent to a field survey or as a property owner in a parcel record — the client organization, not Momentum CE, is the controller of that information. Direct your privacy requests to that organization. See Section 10.
3. Information We Collect
3.1 Account Information
When you register for a MyMaps account, we collect:
- Full name
- Email address
- Organization name and affiliation
- A hashed password, or an identifier from your organization's sign-in provider if single sign-on is used
This information is used to create and manage your account and to assign you to your organization within the Service once your setup has been completed by Momentum CE.
3.2 Authentication and Activity Records
To secure the Service and maintain accountability for changes to client data, we record:
- Sign-in and sign-out timestamps, and failed sign-in attempts
- The account and organization associated with each session
- Records of who created, edited, or deleted content within a portal, and when
These records exist for security, troubleshooting, and audit purposes, and may be provided to the client organization that owns the affected data.
3.3 Field-Collected Data
Certain MyMaps applications include field data collection features that allow users to submit information directly from the field. This may include:
- Form submissions and survey responses
- GPS coordinates and precise location captured at the time of a field observation
- Photos, notes, sketches, or other media attached to field records
About location. Field applications request precise location through your browser or device, and your device will prompt you before granting that permission. You can decline, though some field features will not work without it. Location is captured when you actively record an observation; we do not track your device's location continuously in the background.
About photos. Photographs you upload may contain embedded metadata (EXIF), which can include the coordinates where the photo was taken, the time, and the device used. This metadata travels with the file. If your work requires that such metadata be removed, strip it before uploading.
Field-collected data is submitted on behalf of the client organization and is treated as Client Data (see Section 5). You are responsible for ensuring you have the authorization and any necessary consents to collect and submit such data, particularly where it concerns individuals, private property, cultural resources, or protected sites.
3.4 Technical and Device Data
When you access the Service, we may automatically collect certain technical information about your device and connection, including:
- IP address and the general geographic region derived from it
- Browser type and version
- Device type and operating system
- Pages and portals accessed, and time spent within the Service
- Error and diagnostic information
This data is collected to maintain Service performance and security and to diagnose technical issues. It is not used to build advertising or marketing profiles, and it is not used to identify or track individual users beyond what is necessary for these purposes.
3.5 Public Map Viewers
Where a client organization has made map content publicly available, you can view it without creating an account, and we do not ask for your name, email, or any other identifying information. We receive only the technical data described in Section 3.4 and any strictly necessary session cookies described in Section 4. If a public map offers a "find my location" feature, your browser will ask permission first, and the resulting location is used to center the map — it is not stored on our servers.
3.6 Support and Correspondence
If you contact us for support or with a question, we retain your message and our reply, along with your contact details, so we can assist you and maintain a support history.
4. Cookies and Similar Technologies
The Service uses cookies and equivalent browser storage for the following purposes:
| Purpose | Description | Can you refuse? |
|---|---|---|
| Authentication | Keeps you signed in as you move between pages and portals | No — the Service cannot function without it for signed-in users |
| Security | Protects against cross-site request forgery and abusive traffic | No |
| Preferences | Remembers settings such as active map layers, basemap choice, and display options | Yes, with reduced convenience |
We do not use advertising cookies, cross-site tracking pixels, third-party marketing analytics, or social media trackers within the Service.
Third-party basemap, imagery, or geocoding providers whose content is displayed in a map may set their own cookies or receive your IP address when their tiles load. See Section 6.
You can block or delete cookies through your browser settings. Blocking authentication or security cookies will prevent you from signing in.
5. Client Data
Data submitted to the Service by or on behalf of a client organization — including field-collected data, map layers, parcel and asset records, uploaded documents, and any other organizational content ("Client Data") — belongs to that client.
We process Client Data only as directed by the client and as necessary to provide, secure, support, and maintain the Service. We do not access, use, or share Client Data for any purpose beyond delivering and supporting the Service, except as required by law. Our personnel access Client Data only where needed to deliver support, investigate a technical or security issue, or perform the setup and configuration work the client has requested.
Retention and deletion of Client Data is governed by the client's instructions and the terms of the applicable Service Agreement. Following termination, the export and deletion process described in Section 13.3 of the Terms of Use applies.
Tribal clients retain full data sovereignty over their Client Data, including any culturally sensitive, sacred site, trust land, environmental, or sovereign information submitted through the Service. See Section 11.
6. How We Use Information
We use the information we collect for the following purposes:
- To create and manage user accounts and assign users to their organization within the Service
- To authenticate users and secure the Service against unauthorized access
- To provide, operate, maintain, and improve the Service and its features
- To communicate with users regarding their account, access status, support requests, or service updates
- To monitor the security, integrity, availability, and performance of the Service
- To diagnose and resolve technical issues
- To produce aggregated, de-identified statistics about how the Service is used
- To comply with applicable legal obligations and enforce our Terms of Use
Aggregated and de-identified data. We may generate aggregated statistics about use of the Service — for example, feature usage counts, performance metrics, and error rates — to operate, secure, and improve it. Such information does not identify you, your organization, or any individual, and does not include Client Data in identifiable form, culturally sensitive content, trust land information, or parcel- or site-level records.
We do not use your personal information for advertising, for marketing to third parties, to train machine learning models on Client Data, or for any purpose unrelated to the delivery of the Service.
7. How We Share Information
We do not sell, rent, or trade personal information or Client Data. Information may be disclosed only in the following limited circumstances:
7.1 With Your Organization
Account information, authentication records, and activity records associated with your account are available to the administrators of the client organization to which your account is assigned.
7.2 Service Providers and Infrastructure
We use third-party providers to operate the Service. These providers process data on our behalf under contractual data protection obligations and are not permitted to use it for their own purposes.
| Category | Role | What it receives |
|---|---|---|
| Cloud hosting and infrastructure | Runs the application servers and stores the database and uploaded files | Account information, Client Data, technical logs |
| GIS and mapping services | Provides basemaps, imagery, tile services, and geocoding | Map view requests, coordinates, IP address |
| Email delivery | Sends account, access, and notification emails | Name and email address |
| Error monitoring and diagnostics | Reports application errors so we can fix them | Technical and device data, error context |
A current list of the specific providers we use is available on request at privacy@momentumce.com. Where a Service Agreement requires advance notice or approval of subprocessors, those terms govern.
7.3 Legal Requirements
We may disclose information if required to do so by law, court order, subpoena, or governmental authority, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Momentum CE, our users, or the public. We will make reasonable efforts to notify the affected client of any such request before responding, where we are legally permitted to do so, so that the client may seek to object or limit the request. Where a request seeks tribal Client Data, we will notify the tribal government where legally permitted.
7.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, user information and Client Data may be transferred as part of that transaction. We will provide notice to affected clients and users and will ensure the receiving party is bound by privacy obligations no less protective than those in this Policy. Any transfer of tribal Client Data remains subject to the applicable Service Agreement and tribal data governance requirements.
7.5 We Do Not Sell Personal Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under applicable state privacy laws. We have not done so in the preceding twelve months.
8. Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. These include:
- Encryption of data in transit (HTTPS)
- Hashed storage of passwords — we do not store plain-text passwords
- Role- and organization-based access controls that limit each account to its authorized scope
- Restriction of administrative access to authorized Momentum CE personnel
- Monitoring for unauthorized access and abnormal activity
- Regular updates to underlying software and infrastructure
No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Users are responsible for maintaining the security of their own account credentials and for promptly notifying us of any suspected unauthorized access.
Security incidents. If a security incident occurs that materially affects information described in this Policy, we will notify affected client organizations without undue delay, and affected individuals where required, consistent with applicable law and the terms of the applicable Service Agreement.
9. Data Retention
We keep information only as long as needed for the purpose for which it was collected.
| Category | Retention |
|---|---|
| Account information | For as long as your account is active, plus a reasonable wind-down period after your organization's access ends |
| Authentication logs | Typically one (1) year, or as required by applicable security or audit obligations |
| Activity and audit records | For the duration of the client's Service Agreement; provided to the client on termination if requested |
| Technical and diagnostic logs | Typically ninety (90) days or less |
| Support correspondence | Up to twenty-four (24) months after our last correspondence with you, or until you ask us to delete it |
| Client Data, including field-collected data | Per the client's instructions and the applicable Service Agreement; see Section 13.3 of the Terms of Use for the post-termination export window |
| Aggregated, de-identified statistics | Indefinitely, as they no longer identify any individual |
If you request deletion of your account, we will remove your personal information within a reasonable timeframe, except where we are required to retain it by law, or need it to resolve a dispute, enforce our agreements, or preserve the integrity of an audit record that a client organization is obligated to keep. Specific retention windows may vary based on legal obligations, security needs, or the written agreement with a particular client.
10. Your Privacy Rights
Depending on where you live and applicable law, you may have rights with respect to the personal information we hold about you — the account, authentication, technical, and correspondence information described in Section 3. Subject to applicable law and verification of your identity, you may request to:
- Know and access the personal information we hold about you
- Correct inaccurate personal information
- Delete your personal information
- Obtain a portable copy of information you provided to us
- Opt out of the sale of personal information or of targeted advertising — neither of which we engage in
- Appeal a decision we make on your request, where applicable law provides for an appeal
To exercise any of these rights, contact us at privacy@momentumce.com. Because our access management processes are handled manually, email is the most reliable route. We will respond within the period required by applicable law. We will not discriminate against you for exercising a privacy right. If we deny a request, we will explain why and how to appeal. You may use an authorized agent where applicable law permits; we may ask for proof of authorization.
Requests concerning Client Data. Rights with respect to Client Data — including field-collected data, survey responses, parcel records, and any personal information contained within them — are governed by the applicable Service Agreement and are exercised through the client organization that owns the data, not through us. We act only as a processor for that data (see Section 2). If you send us such a request directly, we will refer you to the client organization, or forward the request to them where we can reasonably identify the right recipient.
11. Tribal Data Sovereignty and Culturally Protected Data
We recognize that tribal government clients may use the Service to manage information that carries cultural, legal, or sovereign significance — including data related to sacred sites, cultural resources, natural resources, trust lands, environmental conditions, and community health. We treat such information with the highest level of care and discretion.
Information generated by or about a tribal client through the Service — including Client Data, field records, configuration data, and audit trails — belongs to and is subject to the governance of that tribal government. We do not share, publish, or disclose tribally sensitive data without explicit authorization from the relevant tribal government.
Where a tribal data governance policy, data sharing agreement, or Service Agreement is in place, those terms govern our handling of such data and take precedence over the general provisions of this Policy. Nothing in this Policy asserts any Momentum CE ownership interest in tribal data, or limits or waives the sovereign rights of any tribal government.
12. Children's Privacy
The Service is intended for use by professional and organizational users and by members of the public viewing map content. It is not directed at children, and accounts may only be created by individuals 18 or older. We do not knowingly collect personal information from children under 13.
We recognize that field surveys and program records submitted by a client organization may themselves contain information about minors — for example, a household health survey. Such information is Client Data, held under the client organization's control and governance, and that organization is responsible for handling it in accordance with applicable law. If you believe a child has provided personal information to us directly, contact us using the information in Section 15 and we will take appropriate steps.
13. International Users and Data Transfers
We are based in the United States, and information described in this Policy is stored and processed in the United States by us and our providers. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
We offer the Service to clients in the United States. We do not target our offering to individuals in the European Economic Area or the United Kingdom. If that changes, we will update this Policy before doing so.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we do, we will increment the version number and update the Effective Date above, and publish the revised Policy at momentumce.com/web-based-mapping/privacy-policy.
For material changes — including any change that expands what we collect or how we use it — we will provide notice by reasonable means, which may include in-Service notice, notice at your next sign-in, or email to the address associated with your account, before the change takes effect. Where the change requires your consent under applicable law, we will obtain it before the change applies to you. Material changes affecting Client Data will also be communicated to the affected client organization.
We encourage you to review this Policy periodically. The version and effective date at the top indicate when it was last revised.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your information, please contact us at:
Momentum CE Inc.
320 E Vine Dr #316 Fort Collins, CO 80524
privacy@momentumce.com