Privacy Policy

Last updated: September 5, 2026 (subject access and portability sections revised)

1. Controller and Contact

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Florian Rachmann
Bergstr. 25
52062 Aachen, Germany
Email: hello@openmapx.com

We are not legally required to appoint a Data Protection Officer and have therefore not designated one. For any data-protection matters, you can reach us at the email address above.

2. Overview of Data Processing

OpenMapX is an open-data mapping platform. We are committed to minimizing the personal data we process. We do not use any analytics, tracking, or advertising services. We do not sell or share your personal data with third parties for marketing purposes.

Data processing occurs in the following contexts:

  • Providing the mapping service (map tiles, search, routing, isochrones, elevation profiles)

  • Displaying third-party data layers (traffic, transit, air quality, natural disasters, hiking trails, street-level imagery, place photos, parking, fuel prices, EV charging, shared mobility)

  • User account management (if you create an account)

  • Publishing corrections you write to OpenStreetMap, if you use the contribution feature (see Section 7)

  • Optional, read-only display of personal location history from a Dawarich instance that you connect

  • Client-side storage of preferences and saved places on your device

  • Server-side caching for performance optimization

3. Hosting and Server Logs

When you visit OpenMapX, your browser automatically transmits certain technical data to our server. This may include:

  • IP address

  • Date and time of the request

  • Browser type and version

  • Operating system

  • Referrer URL

This data is processed to ensure the technical operation and security of the service. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing a secure and functional service). Persisted OpenMapX application logs are automatically deleted after 30 days. Reverse-proxy, container, and hosting logs follow the deployment operator's separately configured infrastructure policy.

4. Geolocation Data

OpenMapX may request your device's location only when you explicitly click the "My Location" button. Your browser will ask for permission before sharing this data. Location data is:

  • Used exclusively to center the map on your position

  • Processed only in your browser (client-side)

  • Not stored on our servers and not transmitted unless you actively use features that require coordinates (e.g., routing, nearby search, transit departures)

You can start an access request in your account settings. We provide a human-readable explanation together with a separate machine-readable portable copy where Article 20 applies. The archive is encrypted, available only after a fresh sign-in, and expires automatically. Connected Dawarich data is requested from that managed service when it is available; data held by independent controllers, off-host backups and browser-only data are explained separately rather than silently presented as complete.

The legal basis is Art. 6(1)(a) GDPR (your explicit consent via the browser permission prompt).

If you separately enable Personal Timeline, historical visits, journeys, bounds and route geometry from your Dawarich account are processed to display the day you select. This is independent of the browser's live-location permission and can reveal past locations and movement patterns.

The installed mobile app

The OpenMapX app for iOS and Android behaves differently from the website in one respect that matters: while a navigation session you started is running, it uses your location continuously, including when the screen is locked or the app is in the background. That is what lets it keep guiding you when the phone is in your pocket.

  • It is only ever active during a trip you started. Planning a route and pressing Start is a deliberate action. Arriving, or ending navigation, stops it.

  • Those fixes stay on your device. Progress along the route, when to speak the next instruction, and whether you have left the route are all computed on the phone, against the route captured when you started.

  • Coordinates leave the device only when you ask for a route — when you request directions, and once more each time a reroute or a transit replan is needed because you left the route or missed a connection. They are used to answer that request and are not retained.

  • There is no location history. The app keeps the current session and the latest accepted fix in local storage that is excluded from device backups, so a crash or a restart can resume the trip. Both are deleted when the session ends, and expire after 24 hours in any case.

  • There are no analytics, no advertising identifier, no crash-reporting SDK, and no tracking of any kind. The app also has no remote push: the get-off alert for public transit is scheduled locally by your phone.

You can grant foreground-only location instead. The app keeps working and tells you plainly that guidance pauses when the screen locks. You can revoke the permission at any time in system settings, and you can end navigation from the app at any time. Force- quitting the app also ends guidance — the operating system does not restart it for us.

For public transit, the app fetches each ridden leg's stop list once before the journey starts and then counts stops on the device, so it still knows when you should get off underground. Speech is produced by your phone's own text-to-speech engine; nothing is sent anywhere to be spoken.

Signing in with a third-party provider or a passkey opens your ordinary browser rather than an in-app one, so you can see the real address bar. The app never holds your session; it receives a single-use code, valid for two minutes, which is exchanged for a session inside the app.

5. User Accounts

You can use OpenMapX without creating an account. If you choose to register, we process:

  • Name and email address — for account identification and communication

  • Password — stored only as a cryptographic hash (never in plain text)

  • Passkeys (WebAuthn) — if you register a passkey, a public-key credential is stored on our server; the private key never leaves your device. A passkey authenticates you but does not encrypt your saved places, routes, vehicle, parking, or Personal Timeline data

  • Session data — authentication cookies to keep you signed in

  • Saved places — if you save places while signed in, the place name, coordinates, and associated metadata are stored in our database so they can be synchronized across devices

  • Vehicles and parked location — if you add a vehicle or save where you parked while signed in, the vehicle profile and the coordinates, address, note and expiry you entered are stored in our database so they synchronize across your devices. Nothing is recorded automatically; every entry is one you made. Only the current parked position per vehicle is kept — there is no parking history

  • Mangrove review keypair — if you opt in to the review feature, an ECDSA P-256 signing keypair is generated and stored for you. The public key is stored in cleartext on our server (it is, by design, public). The private key is stored according to the protection mode you choose:

    • Passphrase (recommended) — the private key is encrypted in your browser with a passphrase you choose, using the audited age encryption format (scrypt key-stretching plus ChaCha20-Poly1305). We only ever see the ciphertext.

    • Passphrase and/or WebAuthn passkey — you may additionally or alternatively unlock the private key with one or more registered passkeys (e.g. your phone's biometrics, a hardware security key). We store one age-plugin-fido2prf identity string per passkey. That string encodes the credential id, relying-party id and transport hint — it contains no secret material.

    • Unencrypted (explicit opt-in) — only if you actively choose this, the private key is stored in cleartext on our server. In this mode, anyone with access to the database (including the operator) could cryptographically sign reviews in your name. We show a warning before you make this choice.

  • Review content — if you submit a review, the content you provide (rating, free-text review, optional images, optional affiliations, optional experience context, place reference) is cryptographically signed in your browser and then forwarded by our server to the Mangrove.reviews network. See Section 6 below for the publication model.

You may also sign in via third-party OAuth providers (OpenStreetMap, Mapillary). In that case, we receive your public profile information (name, profile picture URL) from the respective provider. Your browser is redirected directly to the selected provider during authorization, so that provider may receive your IP address and browser request metadata. We do not receive or store your password for these providers.

The access and refresh tokens issued by these providers are stored encrypted at rest with this deployment's authentication secret and are refreshed as needed until you unlink the provider or delete your account. They are never sent to your browser. If you use the OpenStreetMap contribution feature, the linked OpenStreetMap account may additionally hold write permissions — see Section 7.

Personal Timeline (optional). If you opt in, you choose either an external Dawarich instance or the Dawarich service managed by this OpenMapX operator. We store the instance's public origin, safe connection metadata and your Dawarich API key; the API key is encrypted at rest. For each requested day, our backend temporarily processes the date, timezone, visits, journeys, bounds and route geometry and proxies the request to Dawarich. OpenMapX does not persist this fetched history, put it in a shared or browser-persistent cache, or include it in analytics. Disconnecting or deleting your OpenMapX account deletes the OpenMapX connection and encrypted credential.

The selected external Dawarich operator remains a separate controller or processor under that operator's terms and can receive requests from the OpenMapX server. For managed Dawarich, the instance is hosted by this OpenMapX operator. Browser SSO sends your stable account identifier (sub), name and email address to managed Dawarich; the separately supplied API key authorizes read-only history access. Dawarich retains its own account and history data according to the instance operator's settings and retention rules. You exercise Dawarich access, correction, deletion and API-key controls directly in that instance's account settings.

The feature is user-initiated and can be disconnected at any time. The project owner must confirm the applicable legal basis and any consent wording for the deployment before the optional feature is released; this implementation does not make that legal determination.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract / provision of the service you requested). You can delete your account at any time via the account settings.

The provision of personal data is neither a statutory nor a contractual requirement. You can use OpenMapX without providing any personal data. Creating an account requires an email address; without it, account-dependent features (such as saved places synchronization) cannot be provided.

6. Reviews (Mangrove Open Reviews Standard)

OpenMapX integrates the Mangrove.reviews decentralized review network (Open Reviews Standard, operated by the Open Reviews Association, Zürich, Switzerland). Using the review feature has privacy implications that go beyond our own servers, so please read this section carefully before submitting a review.

  • Reviews are public and permanent. When you submit a review, it is cryptographically signed with your keypair (see Section 5) and published to api.mangrove.reviews. From there it is mirrored and re-published by independent aggregators we do not control. Deletion of a review is a best-effort request to aggregators; we cannot guarantee removal from all copies already propagated.

  • Your public key is a persistent pseudonym. Every review you submit is signed with, and linked to, your public key. The public key is stored in cleartext by Mangrove and aggregators and ties all of your reviews together into a pseudonymous identity, even across sessions and devices. Anyone who learns a connection between your public key and your real-world identity can link it to all prior and future reviews you sign. The key is not a direct identifier (name, email, etc.), but treating it as anonymous would be misleading.

  • What is submitted. Each review submission contains: the subject identifier (for places this is a geo: URI with the place's coordinates and uncertainty radius), your rating, optional free-text opinion, optional experience tags, optional affiliation disclosures, optional uploaded images, your public key, and your signature.

  • Image uploads. Optional review images are uploaded to Mangrove's image service (files.mangrove.reviews). Images are served publicly once uploaded. Before your image leaves your browser, we re-encode it through an HTML canvas to strip EXIF, XMP, IPTC, GPS and similar embedded metadata that cameras often attach. The visible pixel content of the photo itself is retained and published as-is.

  • Reading reviews. When you view a place in OpenMapX, our backend fetches any existing reviews for that place from api.mangrove.reviews, forwarding the place's geo: URI (coordinates). Your IP address is not transmitted to Mangrove for read operations because these go through our server.

  • Editing and deleting your own reviews. Edits and deletions are themselves signed follow-up reviews. They are propagated in the same way as the original review and are subject to the same caveats about mirrors and retention by third parties.

The legal basis for the storage and signing of your keypair is Art. 6(1)(b) GDPR (performance of the review service you requested). The legal basis for the publication of review content to the Mangrove network is Art. 6(1)(a) GDPR (your explicit consent, given when you accept the in-app Terms/Privacy checkboxes in the review dialog and press “Publish”). You may withdraw future consent at any time by not publishing further reviews; already-published reviews cannot be unpublished unilaterally because of the decentralized design of the system. Where your review is thereby transferred to aggregators in countries outside the European Economic Area (EEA), that transfer is based on your explicit consent pursuant to Art. 49(1)(a) GDPR.

7. OpenStreetMap Contributions

If your instance has contributions enabled, you can correct a small set of facts on an existing OpenStreetMap place, or leave a public OpenStreetMap note, from inside OpenMapX. This is optional: you never have to use it, and nothing in this section applies unless you do.

Like reviews, contributing publishes content outside our servers and cannot be undone by us, so please read this section before you publish.

  • Additional OpenStreetMap permissions. Ordinary sign-in requests only the minimal openid read_prefs scopes. The first time you contribute, you are redirected to OpenStreetMap to grant write_api (for edits) or write_notes (for notes). You can revoke these at any time in your OpenStreetMap account settings.

  • Provider tokens. The access and refresh tokens issued by OpenStreetMap are stored on our server, encrypted at rest with this deployment's authentication secret, and refreshed as needed until you unlink the provider or delete your account. Tokens are never sent to your browser and never appear in our logs, metrics or error messages. Tokens stored before at-rest encryption was introduced remain readable and are re-encrypted when the account is next refreshed; in the rare case where such a legacy value cannot be read, you are simply asked to link the account again.

  • Requests we make on your behalf. When you open the editor, our server — not your browser — contacts OpenStreetMap to read the current element, your account details, your permissions and, on publication, to create the changeset and update the element. OpenStreetMap therefore sees our server's IP address for these calls, not yours. Your browser is redirected directly to OpenStreetMap only during the authorization step, so OpenStreetMap may receive your IP address and browser request metadata at that point.

  • What is sent to OpenStreetMap. For an edit: the element reference, the changed tags, the changeset comment you wrote, the source you selected, your interface language as a locale tag, a created_by tag identifying OpenMapX and its version, and an optional “review requested” marker. For a note: the text you wrote and coordinates our server computes from the element itself. We never upload values that came from our display enrichment providers as if they were your evidence.

  • It is public and tied to your OpenStreetMap identity. Your edit or note is published under your linked OpenStreetMap account. Your OpenStreetMap user name, the changeset, your comment, your stated source, the resulting tags, the note text and your contribution history become part of OpenStreetMap's public database and history. That database is operated by the OpenStreetMap Foundation and is governed by its own privacy policy and Contributor Terms, which you must accept before editing — not by us.

  • Deleting your OpenMapX account does not delete your OpenStreetMap history. Deleting your account here removes the stored provider tokens and the link to your OpenStreetMap account. It has no effect on contributions already published to OpenStreetMap; those are part of a public, permanently versioned database and are outside our control. Requests concerning them go to the OpenStreetMap Foundation.

  • Short-lived operational state. To stop a double click from publishing twice, we briefly store a submission lock and a record of the outcome. The keys are one-way HMAC digests of your user id, the element reference and a random submission id; the stored values contain only public result identifiers (changeset or note id), the resulting links and a timestamp. Locks expire after two minutes, successful results after 24 hours, and an unresolved ambiguous outcome after two minutes. Rate limiting keeps a similar short-lived, digest-keyed counter. We keep no database of contribution content: no tags, comments, note text or sources are stored here.

  • Logs and metrics are content-free. Operational telemetry records only which kind of operation ran, whether it succeeded, how long it took and a random request id. No element, tag, name, coordinate, comment, note text, source, account name or token is recorded. Server logs follow the normal retention described in Section 13.

The legal basis for storing and refreshing the OpenStreetMap tokens is Art. 6(1)(b) GDPR (performance of the contribution service you requested). The legal basis for publishing your contribution to OpenStreetMap is Art. 6(1)(a) GDPR (your explicit consent, given when you choose a source, write your own comment and press “Publish to OpenStreetMap” after being shown exactly what will be sent and that it will be public). You may withdraw future consent at any time by not publishing further contributions and by revoking the permissions in your OpenStreetMap account; contributions already published cannot be unpublished unilaterally, because OpenStreetMap is a public database with a permanent edit history. Insofar as your contribution is thereby transferred to recipients outside the European Economic Area (EEA), that transfer is based on your explicit consent pursuant to Art. 49(1)(a) GDPR.

8. Third-Party Services and Data Transfers

To provide its mapping features, OpenMapX sends requests to various third-party APIs. When you use a feature, certain data (typically map viewport coordinates, search queries, or route waypoints) is transmitted to the respective provider. Our backend server acts as a proxy for most of these requests, meaning third-party providers generally see our server's IP address rather than yours. Below is a comprehensive list of all external services:

A user-selected Dawarich origin is not included in the generated provider tables below because its operator and location are chosen by the user. Managed Dawarich is a first-party optional service of this deployment, not an integration provider. In both modes, Personal Timeline requests are proxied by OpenMapX as described in Section 5.

Air Quality
ServicePurposeData TransmittedData AccessCountryPrivacy Info
ECCC GeoMet AQHI observations and forecastsFind and preserve nearby official ECCC named-community air-quality observations and forecastsA server-derived bounding box around the requested coordinates and the requested forecast time windowServer-onlyCALink
UK-AIR current site pollution levelsFind a nearby official UK-AIR station and preserve its published current DAQINo user or location data; the server requests one fixed nationwide RSS feedServer-onlyGBLink
OpenAQAir quality monitoring locations and sensor-specific pollutant evidenceBounding box or radius coordinates; location and sensor IDs for latest and hourly measurementsServer-onlyUSLink
Open-Meteo Air QualityCurrent air quality index and pollutant concentrationsCoordinates (latitude, longitude)Server-onlyCHLink
Data Sources
ServicePurposeData TransmittedData AccessCountryPrivacy Info
CityBikesBike-sharing network and station data worldwideNo user data (network index with fields filter); per-network station data by network URLServer-onlyES

-

Donkey RepublicBike and e-bike hub locations and availability in European citiesBounding box coordinates (top-right and bottom-left corner lat/lng pairs)Server-onlyDKLink
NextbikeBike-sharing station locations and availability worldwideNo user data (fetches entire global dataset)Server-onlyDELink
Deutsche Bahn GBFSCall-a-Bike and StadtRad stations and free-floating bikes in German citiesNo user data (fetches full GBFS feeds per provider)Server-onlyDELink
GBFS Catalog (MobilityData)Discover GBFS-compliant bike-sharing systems worldwideNo user data (static catalog)Server-onlyCALink
Entur Mobility v2Enrich Norwegian bike-sharing stations and bikes with operator branding, pricing plans, rental apps and geofencing zones via the Entur Mobility APIGBFS station and vehicle identifiers (and system identifiers for geofencing) of items already found within the viewport. No user account or raw location dataServer-onlyNOLink
TransitousSupplementary bike-sharing stations and free-floating bikes from GBFS feeds aggregated by the Transitous (MOTIS) deploymentBounding-box coordinates (min and max latitude/longitude corners)Server-onlyDELink
Cambio CarSharingStation-based car sharing in Germany and BelgiumRegion code in URL path (matched by proximity to viewport center, up to 14 regions). No user location data sent directlyServer-onlyDELink
Stadt Münster Open DataCar sharing stations and vehicles in Münster (open data)No user data (static dataset, fetches all stations)Server-onlyDELink
Stadt Bielefeld Open DataCar sharing stations in Bielefeld (open data)No user data (static dataset, fetched in parallel with stations)Server-onlyDELink
Stadt Wuppertal Open DataCar sharing stations in Wuppertal from multiple operators (open data)No user data (static WFS query with fixed parameters for carsharing layer)Server-onlyDELink
GBFS Catalog (MobilityData)Discover GBFS-compliant car-sharing systems worldwideNo user data (static dataset, fetches all stations)Server-onlyCALink
Entur Mobility v2Enrich Norwegian car-sharing stations and vehicles with operator branding, pricing plans, rental apps and geofencing zones via the Entur Mobility APIGBFS station and vehicle identifiers (and system identifiers for geofencing) of items already found within the viewport. No user account or raw location dataServer-onlyNOLink
CommunautoStation-based car sharing across Canadian cities (Montréal, Toronto, Ottawa, Québec City, Calgary, Edmonton, Winnipeg, Halifax and more)City identifier and a fixed country-wide bounding box in the URL (matched by proximity to viewport center). No user location or account dataServer-onlyCALink
CoopStroomCooperative electric car sharing in Flanders, Belgium (CoopStroom)No user data (full fleet fetched once and filtered to the viewport server-side)Server-onlyBELink
DégageCooperative peer-to-peer car sharing in Flanders, Belgium (Dégage)No user data (full fleet fetched once and filtered to the viewport server-side)Server-onlyBELink
OpenChargeMapGlobal community-maintained EV charging station locations with connector details, power levels, operator info, and per-record data-provider/license attributionBounding-box coordinates (south, west, north, east), optional filters (connector type, usage type, status), and the OpenChargeMap API key — sent server-side per map requestServer-onlyAULink
NREL Alternative Fuel Stations (AFDC, US/CA)Official Alternative Fuel Stations dataset (US DOE / NREL) covering public electric charging stations in the United States and CanadaBounding-box centre latitude/longitude plus a derived search radius, the filters fuel_type=ELEC, country=all, status=E, access=public, and the AFDC/NREL API key (in an X-Api-Key header) — sent server-side per map requestServer-onlyUSLink
Bundesnetzagentur LadesäulenregisterOfficial German charging station registry (Bundesnetzagentur Ladesäulenregister) covering public charging infrastructure in GermanyNo query parameters — the full national CSV dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyDELink
OCPDB (MobiData BW) — German EV charging dataNationwide German charging data aggregated by MobiData BW (OCPDB) from the Bundesnetzagentur registry and charge point operators via Mobilithek, adding structured ad-hoc tariffs and live availabilityNo query parameters carrying user data — the full national OCPI dataset is paged server-side on a schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyDELink
Base nationale consolidée des IRVEFrench national consolidated EV charging dataset (Base nationale consolidée des IRVE) covering public charging points in FranceBounding-box coordinates as an in_bbox(point_geo, north, west, south, east) filter with pagination (limit/offset) — sent server-side per map request; no API keyServer-onlyFRLink
ESB ecars — Irish & Northern Ireland public charging networkESB ecars public charging network covering the Republic of Ireland and Northern IrelandNo query parameters — the full ESB ecars CSV dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyIELink
CYNAP — Cyprus public EV chargersCYNAP public EV charging point register for Cyprus, published by the Department of Electrical and Mechanical Services (EMS)No query parameters — the full CYNAP DATEX II dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyCYLink
Chargy — Luxembourg public charging networkChargy public charging network covering LuxembourgNo query parameters — the full Chargy KML dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyLULink
EVRoam — New Zealand charging network (Waka Kotahi)EVRoam public charging network for New Zealand, published by Waka Kotahi NZ Transport AgencyNo query parameters — the full ArcGIS FeatureServer dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyNZLink
DGT — Spanish national EV charging (NAP)Official Spanish national EV charging point registry (DGT National Access Point) covering public charging infrastructure in SpainNo query parameters — the full national DATEX II dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyESLink
PUN — Italian national EV charging (GSE)Italian national EV charging registry (PUN — Piattaforma Unica Nazionale, GSE/MASE); license terms are unconfirmed public-sector open data, included provisionallyNo query parameters — the full ArcGIS FeatureServer dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyITLink
Transport for NSW — EV charging locationsOfficial Transport for NSW register of public EV charging locations across New South WalesNo query parameters — the full NSW CSV dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyAULink
Department of Transport and Main Roads (Queensland) — EV charging locationsQueensland Department of Transport and Main Roads register of public EV charging sitesNo query parameters — the full Queensland CSV dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyAULink
State of Victoria (DEECA) — Destination Charger Program sitesVictorian Government (DEECA) Destination Charger Program register of public EV charging sitesNo query parameters — the full WFS GeoJSON dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyAULink
Vlaanderen — Flemish public EV charging (Laadpunten)Flemish public EV charging point register (Laadpunten) published by the Department of Mobility and Public WorksNo query parameters carrying user data — the full WFS dataset is paged server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyBELink
EPD — Hong Kong public EV chargersOfficial Hong Kong EPD dataset of public electric vehicle chargers covering car parks across Hong KongNo query parameters — the full territory-wide JSON dataset is downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyHKLink
Fintraffic Digitraffic — Finnish national EV charging network (AFIR)Finnish national EV charging network dataset (Fintraffic / Digitraffic AFIR Charging Network API) covering publicly accessible charging infrastructure in FinlandNo query parameters — the full national locations feed and its structured tariffs feed are downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyFILink
Via Lietuva — Lithuanian national EV chargingLithuanian national EV charging dataset (Via Lietuva OCPI) covering publicly accessible charging infrastructure in Lithuania, including structured tariffsNo query parameters — the full national OCPI locations and tariffs feeds are downloaded server-side on a daily schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyLTLink
Opendatasoft (France IRVE API platform)Opendatasoft (Opendatasoft SAS, France) is the API platform that hosts and serves the French national IRVE charging dataset; requests for French charging points are answered by this platformThe map-viewport bounding box (as an in_bbox(point_geo, north, west, south, east) filter with pagination) reaches the Opendatasoft platform server-side; no user identity, account, or API key is sentServer-onlyFRLink
Charging points for electric cars (SFOE)Swiss national charging station dataset (Swiss Federal Office of Energy SFOE) covering public charging infrastructure in SwitzerlandNo query parameters — the full national OICP dataset (and a 5-minute live-status feed) is downloaded server-side on a schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyCHLink
Publicly accessible charging points (DOT-NL / NDW)Dutch national charging point dataset (DOT-NL / NDW National Access Point) covering publicly accessible charging infrastructure in the NetherlandsNo query parameters — the full national OCPI locations feed (and its structured tariffs feed) is downloaded server-side on a schedule into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyNLLink
NOBILNordic EV charging station database (NOBIL) covering public charging stations in Norway and SwedenBounding box as type=rectangle with northeast=(north, east) and southwest=(south, west), plus the NOBIL API key — sent server-side per map requestServer-onlyNOLink
NAP Slovenija — Prometej IDACS Energy Infrastructure TableOfficial Slovenian national EV charging registry (NAP Slovenija / Prometej IDACS National Access Point) covering public charging infrastructure in Slovenia. Requires a business-entity registration and OAuth2 token; inactive until configuredNo query parameters from the map — the full national DATEX II dataset is downloaded server-side on a daily schedule using an OAuth2 bearer token exchanged from the configured refresh token, into the local database, then queried by bounding box locally; no user data reaches the provider per map requestServer-onlySILink
전국전기차충전소표준데이터 — Korea Environment Corporation (nationwide EV charging stations)Nationwide EV charging station standard dataset published by Korea Environment Corporation (한국환경공단) via data.go.krNo query parameters beyond the fixed column list — the full dataset is downloaded server-side on a daily schedule via data.go.kr's keyless standard-data endpoint into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyKRLink
EIPA (UDT) — Polish national alt-fuel/EV charging registerPolish national alternative-fuel/EV charging register (EIPA, run by UDT) covering publicly accessible charging stations in Poland, with live per-point availability and structured PLN pricingNo query parameters — the full national station/point/pricing feed is downloaded server-side on a schedule (authenticated from the environment) into the local database and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyPLLink
E-Control Ladestellenverzeichnis (AT)E-Control Austria's national Ladestellenverzeichnis — public EV charging stations across Austria with live per-connector status and structured ad-hoc pricingLatitude/longitude of the searched map area's center, plus the operator's API key and registered Referer domain — sent server-side per map request; no user data reaches the providerServer-onlyATLink
LTA DataMall — Singapore EV Charging PointsOfficial Singapore EV charging station dataset (LTA DataMall), covering charging point locations, connectors, and real-time availability by postal codeNo bounding-box or location parameters — the batch endpoint is called with only the AccountKey header, its pre-signed download link is fetched, and the full national result set is filtered by bounding box locally; a single-station lookup additionally sends the derived 6-digit postal codeServer-onlySGLink
TDX — Taiwan national EV charging stationsOfficial Taiwanese national EV charging station dataset (TDX — Transport Data eXchange, Ministry of Transportation and Communications) covering publicly accessible charging infrastructure by city/county, with live per-connector statusBounding-box coordinates matched against approximate city/county boundaries to pick which TDX city endpoints to query, plus an OAuth2 client-credentials bearer token (obtained server-side from the configured Client ID/Secret) — sent server-side per map requestServer-onlyTWLink
Service public de Wallonie (SPW) — public EV chargingPublic EV charging register for Wallonia, published by the Service public de Wallonie (SPW)No query parameters — the full regional CSV dataset is downloaded server-side on a daily schedule, reprojected from Belgian Lambert 72 to WGS84 into the local database, and then queried by bounding box locally; no user data reaches the provider per map requestServer-onlyBELink
OpenStreetMapEV charging station locations from OpenStreetMap via Overpass (secondary source, global fallback)An Overpass QL query for amenity=charging_station nodes within the bounding box (south, west, north, east) — sent server-side; no API keyServer-onlyUKLink
Tankerkoenig (MTS-K)German fuel station prices (E5, E10, Diesel)Center coordinates (latitude, longitude), search radius (max 25 km)Server-onlyDELink
E-Control SpritpreisrechnerAustrian fuel station prices (Diesel, Super 95)Center coordinates (latitude, longitude), search radius, fuel type (diesel and Super 95 queried separately)Server-onlyATLink
prix-carburants.gouv.frFrench fuel station prices (6 fuel types)Center coordinates (latitude, longitude), search radiusServer-onlyFRLink
Minetur (Spain)Spanish fuel station prices (5 fuel types)No user data (fetches entire national dataset)Server-onlyESLink
OpenStreetMapFuel station locations (global fallback, no prices)Bounding box coordinatesServer-onlyUKLink
ParkenDDReal-time parking lot availability across European cities (ParkenDD aggregator covering ~12 cities in Germany, Austria, Switzerland and neighbours)No user data; our server's data-manager fetches the full city catalogue and per-city lots on a scheduleServer-onlyDELink
MobiData BW (ParkAPI)German parking sites with real-time occupancy data (MobiData BW ParkAPI v3 aggregator spanning multiple Baden-Württemberg and federal operators)No user data; our server's data-manager fetches the entire parking-sites dataset on a scheduleServer-onlyDELink
DB BahnParkDeutsche Bahn station parking facilities across Germany (single operator)No user data; our server's data-manager fetches the entire facilities dataset on a schedule using subscription credentials (DB Client ID and API key)Server-onlyDELink
RDW Open Data (Netherlands)Netherlands parking garages, Park & Ride, and carpool facilities from the national RDW open-data registerNo user data; our server's data-manager fetches the full RDW datasets (specs plus the garage/P+R/carpool geo sets) on a scheduleServer-onlyNLLink
BNLS France (Opendatasoft)French parking facilities from the national BNLS register (Base nationale des lieux de stationnement aggregator)No user data; our server's data-manager fetches the entire BNLS GeoJSON export on a scheduleServer-onlyFRLink
Stad Gent (Belgium)Real-time parking garage occupancy in Ghent, Belgium (single-city open-data feed)No user data; our server's data-manager fetches the entire dataset on a scheduleServer-onlyBELink
Open Data Brussels (Belgium)Static parking facility data for Brussels, Belgium (single-city open-data portal)No user data; our server's data-manager fetches the entire dataset on a scheduleServer-onlyBELink
Kanton Basel-Stadt (Switzerland)Real-time parking garage occupancy in Basel, Switzerland (canton open-data portal)No user data; our server's data-manager fetches the latest dataset snapshots on a scheduleServer-onlyCHLink
Open data platform mobility Switzerland – Bike and car parkingBike and car parking facilities across Switzerland from the national open data platform mobility (opentransportdata.swiss aggregator)No user data; our server's data-manager fetches the entire bike-and-car-parking dataset on a scheduleServer-onlyCHLink
CITA Luxembourg parking DATEX IIParking facilities in Luxembourg from the CITA DATEX II feed (national mobility authority)No user data; our server's data-manager fetches the entire static DATEX II XML feed on a scheduleServer-onlyLULink
Comune di Firenze (Italy)Real-time parking availability in Florence, Italy (single-city open-data portal)No user data; our server's data-manager fetches the entire ParkFreeSpot dataset on a scheduleServer-onlyITLink
Ajuntament de Barcelona (Spain)Static parking facility data for Barcelona, Spain (single-city open-data portal)No user data; our server's data-manager fetches the entire dataset on a scheduleServer-onlyESLink
Stadt Wien (Austria)Static parking garages and P+R facilities in Vienna, Austria (single-city open-data WFS service)No user data; our server's data-manager fetches the entire WFS feature collection on a scheduleServer-onlyATLink
Københavns Kommune (Denmark)Static parking garage data for Copenhagen, Denmark (single-city open-data WFS service)No user data; our server's data-manager fetches the entire WFS feature collection on a scheduleServer-onlyDKLink
data.gov.sg (Singapore)Real-time car park availability across Singapore (national open-data portal aggregating HDB carparks)No user data; our server's data-manager fetches the entire availability and static datasets on a scheduleServer-onlySGLink
Ayuntamiento de Madrid (Spain)Static parking facility data for Madrid, Spain (single-city open-data portal)No user data; our server's data-manager fetches the entire dataset on a scheduleServer-onlyESLink
NE Travel Data (UK)Real-time car park data for Newcastle/Tyne & Wear, UK (NE Travel Data UTMC feed)No user data; our server's data-manager fetches the entire static and dynamic car-park feeds on a schedule using UTMC credentials (username/password)Server-onlyGBLink
Transport for NSW (Australia)Real-time Park & Ride car park data for Greater Sydney, Australia (Transport for NSW open data)No user data; our server's data-manager fetches the car-park list and per-facility occupancy on a schedule using the NSW Transport API keyServer-onlyAULink
NDW Open Data (Netherlands)Real-time truck parking availability along Dutch highways (NDW national open-data DATEX II feeds)No user data; our server's data-manager fetches the entire static table and dynamic status XML feeds on a scheduleServer-onlyNLLink
Autobahn GmbH (Germany)German Autobahn rest area and truck parking facilities (Autobahn GmbH national feed)No user data; our server's data-manager fetches the road list and per-road parking data on a scheduleServer-onlyDELink
Open Data Hub (South Tyrol, Italy)Parking stations in South Tyrol, Italy (Open Data Hub regional aggregator)No user data; our server's data-manager fetches the entire station list and latest measurements on a scheduleServer-onlyITLink
NRW.Mobidrom – Park+Ride NRWNRW.Mobidrom bundled Park+Ride data (VRR, Bielefeld, Bonn, Köln, Münster, Oberhausen) — regional Park+Ride aggregatorNo user data; our server's data-manager fetches the entire aggregate DATEX II Parking Light feed on a scheduleServer-onlyDELink
NRW.Mobidrom – Parken NRWNRW.Mobidrom bundled parking data (Düsseldorf, Köln, Bielefeld, Krefeld, Wuppertal, Aachen plus operator static data) — regional parking aggregatorNo user data; our server's data-manager fetches the entire aggregate DATEX II Parking Light feed on a scheduleServer-onlyDELink
APCOA Deutschland (via NRW.Mobidrom)APCOA Deutschland parking facilities via the NRW.Mobidrom exporter (single operator, openly licensed lineage)No user data; our server's data-manager fetches the operator feed on a scheduleServer-onlyDELink
APAG – Aachener ParkhausAPAG Aachener Parkhaus real-time garage data from the operator's own PMS API (single operator, Aachen)No user data; our server's data-manager fetches the operator's facilities feed on a scheduleServer-onlyDELink
APAG – Aachener ParkhausAPAG Aachener Parkhaus garage data via the NRW.Mobidrom exporter (single operator, Aachen; openly licensed backup lineage for the direct APAG feed)No user data; our server's data-manager fetches the operator feed on a scheduleServer-onlyDELink
GOLDBECK Parking Services (via NRW.Mobidrom)GOLDBECK Parking Services static garage data via the NRW.Mobidrom exporter (single operator)No user data; our server's data-manager fetches the operator feed on a scheduleServer-onlyDELink
Stadt Braunschweig — PULP parkingReal-time parking garage data for Braunschweig, Germany (city PULP feed, single city)No user data; our server's data-manager fetches the entire PULP GeoJSON feed on a scheduleServer-onlyDELink
VMZ Bremen — parking catalogueStatic parking catalogue for Bremen, Germany (VMZ Bremen city feed, single city)No user data; our server's data-manager fetches the entire parking GeoJSON catalogue on a scheduleServer-onlyDELink
Stadt Düsseldorf — VT-ManagerReal-time parking garage data for Düsseldorf, Germany (city VT-Manager WFS service, single city)No user data; our server's data-manager fetches the entire WFS feature collection on a scheduleServer-onlyDELink
Stadt Salzburg — parkplatz WFSParking facility data for the city of Salzburg, Austria (city WFS service, single city)No user data; our server's data-manager fetches the entire WFS feature collection on a scheduleServer-onlyATLink
Stadt Bielefeld — Parkplätze WFSParking facility data for Bielefeld, Germany (city WFS service with embedded PLS live counts, single city)No user data; our server's data-manager fetches the entire WFS feature collection on a scheduleServer-onlyDELink
Stadtwerke Bamberg — ParkenReal-time parking garage occupancy for Bamberg, Germany (Stadtwerke Bamberg carparkcounter feed, single operator)No user data; our server's data-manager fetches the entire status feed on a scheduleServer-onlyDELink
Stadtwerke Trier — ParkenReal-time parking garage occupancy for Trier, Germany (Stadtwerke Trier parken-v2 feed, single operator)No user data; our server's data-manager fetches the entire parken-v2 XML feed on a scheduleServer-onlyDELink
Stadtwerke Potsdam — ParkplätzeParking facility data for Potsdam, Germany (Stadtwerke Potsdam CSV feed, single operator)No user data; our server's data-manager fetches the entire parking CSV feed on a scheduleServer-onlyDELink
OpenStreetMapParking facilities from OpenStreetMap (global crowdsourced data, static, no real-time availability)An Overpass QL query containing the current map view's bounding-box coordinates (querying amenity=parking nodes and ways); OSM element type and ID for detail lookupServer-onlyUKLink
GBFS Catalog (MobilityData)Discover GBFS-compliant shared mobility systems worldwideNo user data (static catalog)Server-onlyCALink
FelyxFelyx moped/e-scooter positions (Netherlands, Belgium)No user data (fetches entire dataset, filtered server-side to bounding box)Server-onlyNLLink
Entur Mobility v2Enrich Norwegian e-scooter and moped vehicles with operator branding, pricing plans, rental apps and geofencing zones via the Entur Mobility APIGBFS station and vehicle identifiers (and system identifiers for geofencing) of items already found within the viewport. No user account or raw location dataServer-onlyNOLink
TransitousSupplementary e-scooter and moped vehicles from GBFS feeds aggregated by the Transitous (MOTIS) deploymentBounding-box coordinates (min and max latitude/longitude corners)Server-onlyDELink
NRW.Mobidrom E-Scooter SharingNRW.Mobidrom bundled e-scooter feed (Voi + Lime in North Rhine-Westphalia)OAuth2 client credentials (no user data; server-only)Server-onlyDELink
Windy WebcamsWebcam streams worldwide (tourism, weather, traffic)Bounding box coordinates via backend; browser loads Windy player/media directly when a live or timelapse embed is openedMixedCZLink
OpenStreetMapWebcam locations tagged in OpenStreetMapBounding box coordinates via Overpass APIServer-onlyUKLink
Caltrans CCTVCalifornia highway traffic cameras (Caltrans CCTV)No user data (fetches district datasets, filtered server-side to bounding box)Server-onlyUSLink
Transport for LondonLondon traffic cameras (TfL JamCams)No user data for catalog fetch; browser loads TfL video media directly when the video clip is displayedMixedUKLink
National Park Service WebcamsUS National Park webcams (NPS)No user data (fetches entire webcam catalog with pagination, filtered server-side to bounding box)Server-onlyUSLink
NYSDOT 511NYNew York State traffic cameras (511NY)No user data for catalog fetch; browser loads 511NY HLS media directly when the live stream is openedMixedUSLink
Oregon DOT TripCheckOregon highway traffic cameras (ODOT TripCheck)No user data (fetches entire camera inventory, filtered server-side to bounding box)Server-onlyUSLink
Georgia DOT 511Georgia traffic cameras (511GA)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Florida DOT 511Florida traffic cameras (FL511)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Arizona DOT 511Arizona traffic cameras (AZ511)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Idaho DOT 511Idaho traffic cameras (Idaho 511)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Utah DOT 511Utah traffic cameras (Utah 511)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Louisiana DOT 511Louisiana traffic cameras (511LA)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Pennsylvania DOT 511Pennsylvania traffic cameras (511PA)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
South Carolina DOT 511South Carolina traffic cameras (511SC)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Massachusetts DOT 511Massachusetts traffic cameras (Mass511)API key (fetches entire camera list, filtered server-side to bounding box)Server-onlyUSLink
Digitraffic Weather CamerasFinland road-weather cameras (Digitraffic)No user data; the server fetches active stations and proxies the selected still imageServer-onlyFILink
Trafikverket Traffic CamerasSweden traffic cameras (Trafikverket)Operator API key in a server-side XML requestServer-onlySELink
Norwegian Public Roads Administration CCTVNorway road cameras (NPRA DATEX)Operator DATEX credentials in a server-side HTTP Basic requestServer-onlyNOLink
Iceland Road Administration Web CamerasIceland road cameras (Road and Coastal Administration)No user data; the full public catalog is fetched server-side and filtered to the map areaServer-onlyISLink
DGT DATEX II Traffic CamerasSpain state-road traffic cameras (DGT DATEX II)No user data; the public DATEX catalog and displayed still images are fetched through the serverServer-onlyESLink
Ontario 511 Traffic CamerasOntario traffic cameras (Ontario 511)No user data; the public camera catalog and displayed still images are fetched through the serverServer-onlyCALink
Hong Kong Traffic Snapshot ImagesHong Kong traffic snapshot camerasNo user data; the public camera-location catalog and displayed still images are fetched through the serverServer-onlyHKLink
Live Traffic NSW CamerasNew South Wales live traffic camerasOperator API key in a server-side requestServer-onlyAULink
Taiwan Transport Data eXchange CCTVTaiwan road traffic cameras (TDX)Operator OAuth credentials are exchanged server-side; an external live stream is loaded only after user consentMixedTWLink
Flights
ServicePurposeData TransmittedData AccessCountryPrivacy Info
SkyscannerDeep link to search flights on Skyscanner for the chosen origin/destination airports, travel dates, passengers and cabinNone sent by OpenMapX — an outbound deep link to skyscanner.net is built locally and opened in your browser only when you click it. The URL carries the origin and destination IATA airport codes, the outbound (and optional return) date, the passenger counts (adults, children, infants), the cabin class and a direct-flights-only flag as path segments and URL parameters. If a Skyscanner affiliate mediaPartnerId is configured by the operator, it is added to the link so referrals can be attributed.Direct (browser)GBLink
Google FlightsDeep link to search flights on Google Flights for the chosen origin/destination airports and travel datesNone sent by OpenMapX — an outbound deep link to google.com/travel/flights is built locally and opened in your browser only when you click it. The origin and destination airport codes, the outbound (and optional return) date, cabin class, adult and child counts and a non-stop preference are encoded as a natural-language search phrase in the URL's q parameter.Direct (browser)USLink
KAYAKDeep link to search flights on KAYAK for the chosen origin/destination airports, travel dates, passengers and cabinNone sent by OpenMapX — an outbound deep link to kayak.com is built locally and opened in your browser only when you click it. The URL carries the origin and destination IATA codes, the outbound (and optional return) date, the cabin class and the adult passenger count as path segments, plus a sort order and a stops-only filter as URL parameters.Direct (browser)USLink
Kiwi.comDeep link to search flights on Kiwi.com for the chosen origin/destination airports and travel datesNone sent by OpenMapX — an outbound deep link to kiwi.com is built locally and opened in your browser only when you click it. The URL carries the origin and destination IATA airport codes and the departure (and optional return) date as URL parameters; passengers and cabin are not transmitted.Direct (browser)CZLink
momondoDeep link to search flights on momondo for the chosen origin/destination airports, travel dates, passengers and cabinNone sent by OpenMapX — an outbound deep link to momondo.com is built locally and opened in your browser only when you click it. The URL carries the origin and destination IATA codes, the outbound (and optional return) date, the cabin class and the adult passenger count as path segments.Direct (browser)USLink
SkiplaggedDeep link to search flights on Skiplagged for the chosen origin/destination airports and travel datesNone sent by OpenMapX — an outbound deep link to skiplagged.com is built locally and opened in your browser only when you click it. The URL carries the origin and destination IATA airport codes and the outbound (and optional return) date as path segments; passengers and cabin are not transmitted.Direct (browser)USLink
Food Delivery
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Uber EatsDeep link to order from Uber Eats for the selected restaurant, pre-filling its name and delivery location.Opening the delivery choices may send the restaurant name and delivery location to Uber Eats' store-feed endpoint from the OpenMapX server to resolve an exact store page. Selecting Uber Eats opens an outbound link in your browser carrying the restaurant name and, when known, coordinates/address/city/postcode.MixedUSLink
WoltDeep link to order from Wolt for the selected restaurant, scoped to its country and city.None sent by OpenMapX — an outbound deep link (carrying the restaurant name and the country/city as URL path or query parameters) is opened in your browser only when you click it.Direct (browser)FILink
LieferandoDeep link to Lieferando's delivery page for the selected city.None sent by OpenMapX — an outbound deep link (carrying the city as a URL path segment) is opened in your browser only when you click it.Direct (browser)DELink
DoorDashDeep link to search DoorDash for the selected restaurant.None sent by OpenMapX — an outbound deep link (carrying the restaurant name and city as the search term) is opened in your browser only when you click it.Direct (browser)USLink
DeliverooDeep link to Deliveroo's restaurant listing for the selected city.None sent by OpenMapX — an outbound deep link (carrying the city as a URL path segment) is opened in your browser only when you click it.Direct (browser)GBLink
Just EatDeep link to Just Eat's takeaway listing for the selected city.None sent by OpenMapX — an outbound deep link (carrying the city as a URL path segment) is opened in your browser only when you click it.Direct (browser)GBLink
GlovoDeep link to Glovo's restaurant listing for the selected country and city.None sent by OpenMapX — an outbound deep link (carrying the country and city as URL path segments) is opened in your browser only when you click it.Direct (browser)ESLink
foodpandaDeep link to foodpanda's restaurant listing for the selected country and city.None sent by OpenMapX — an outbound deep link (carrying the country host and city as a URL path segment) is opened in your browser only when you click it.Direct (browser)DELink
GrubhubDeep link to search Grubhub for the selected restaurant.None sent by OpenMapX — an outbound deep link (carrying the restaurant name and city as the search query) is opened in your browser only when you click it.Direct (browser)USLink
iFoodDeep link to search iFood for the selected restaurant.None sent by OpenMapX — an outbound deep link (carrying the restaurant name and city as the search query) is opened in your browser only when you click it.Direct (browser)BRLink
RappiDeep link to search Rappi for the selected restaurant in its country storefront.None sent by OpenMapX — an outbound deep link (carrying the restaurant name as the search query) is opened in your browser only when you click it.Direct (browser)COLink
PedidosYaDeep link to PedidosYa's restaurant listing for the selected city.None sent by OpenMapX — an outbound deep link (carrying the city as a URL path segment) is opened in your browser only when you click it.Direct (browser)UYLink
SwiggyDeep link to search Swiggy for the selected restaurant.None sent by OpenMapX — an outbound deep link (carrying the restaurant name and city as the search query) is opened in your browser only when you click it.Direct (browser)INLink
ZomatoDeep link to Zomato's brand or city restaurant page for the selected restaurant.None sent by OpenMapX — an outbound deep link (carrying the city and restaurant name as URL path segments) is opened in your browser only when you click it.Direct (browser)INLink
TalabatDeep link to Talabat's brand page for the selected restaurant in its country storefront.None sent by OpenMapX — an outbound deep link (carrying the country and restaurant name as URL path segments) is opened in your browser only when you click it.Direct (browser)AELink
Geocoding
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Deutsche Bahn RIS StationsForward/reverse geocoding of German railway stations, plus station detail lookupSearch query or coordinates (latitude, longitude, radius) for geocoding; EVA station number for detail lookupServer-onlyDELink
Entur Geocoder APISearch Norwegian places, addresses, POIs, and public-transport stops via Entur's geocoder; reverse geocode coordinates; preserve NSR stop identifiers for downstream transit flowsSearch query text or coordinates (longitude, latitude), language, optional Norway-first country filter, multimodal stop mode, ET-Client-Name headerServer-onlyNOLink
MapTilerForward geocoding and autocomplete — text search for places, addresses, POIs worldwide; reverse geocodingSearch query text or coordinates (longitude, latitude), language, result limitServer-onlyCHLink
TransitousForward geocoding and autocomplete for transit stops and addressesSearch query text, languageServer-onlyDELink
MOTIS (self-hosted)Forward and reverse geocoding via self-hosted MOTIS instanceSearch query text or coordinates (latitude, longitude), languageServer-onlyDE

-

Nominatim (OpenStreetMap)Forward geocoding, autocomplete, and reverse geocoding using OpenStreetMap dataSearch query text or coordinates (latitude, longitude), result limit, languageServer-onlyUKLink
Pelias (self-hosted)Forward geocoding, autocomplete, and reverse geocoding via self-hosted Pelias instanceSearch query text or coordinates (latitude, longitude), result limit, languageServer-onlyUS

-

Photon (Komoot)Forward geocoding, autocomplete, and reverse geocoding using Komoot's Photon (OSM-based)Search query text or coordinates (latitude, longitude), result limit, languageServer-onlyDELink
Hotels
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Booking.comDeep link to search the hotel on Booking.comNone sent by OpenMapX — an outbound deep link (with the hotel name, city, coordinates, check-in/check-out dates, and occupancy as URL parameters) is opened in your browser only when you click itDirect (browser)NLLink
ExpediaDeep link to search the hotel on ExpediaNone sent by OpenMapX — an outbound deep link (with the hotel name, city, check-in/check-out dates, and occupancy as URL parameters) is opened in your browser only when you click itDirect (browser)USLink
Hotels.comDeep link to search the hotel on Hotels.comNone sent by OpenMapX — an outbound deep link (with the hotel name, city, check-in/check-out dates, and occupancy as URL parameters) is opened in your browser only when you click itDirect (browser)USLink
AgodaDeep link to search the hotel on AgodaNone sent by OpenMapX — an outbound deep link (with the hotel name, city, check-in/check-out dates, and occupancy as URL parameters) is opened in your browser only when you click itDirect (browser)SGLink
Trip.comDeep link to search the hotel on Trip.comNone sent by OpenMapX — an outbound deep link (with the hotel name, city, check-in/check-out dates, and occupancy as URL parameters) is opened in your browser only when you click itDirect (browser)SGLink
LiteAPILive lowest nightly rate for the hotel (only when an operator LiteAPI key is configured)Place coordinates, search radius, check-in/check-out dates, occupancy, currency, guest nationality, and the operator's API key — sent server-side from OpenMapX, never from your browserProxied (server)IELink
Place Knowledge
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Open-Meteo MarineRender a wave/swell forecast widget on coastal place panels.Latitude/longitude (rounded to 2 decimals for caching).Server-onlyCHLink
NOAA Tides & Currents (CO-OPS)Resolve the nearest NOAA tide-prediction station to a place's coordinates and fetch the next ~24 hours of high/low tide predictions.Place latitude and longitude (rounded to 4 decimals) plus the resolved station ID. Sent to NOAA as `application=OpenMapX`.Server-onlyUSLink
OurAirportsMatch an OSM airport to its OurAirports record and render runway, frequency, and navaid detailNothing per-request — the integration mirrors public CSV dumps at startup and matches in memory by IATA/ICAO codeServer-onlyCALink
Sunrise-Sunset.orgSunrise, sunset, and twilight times for place detailsCoordinates (latitude, longitude rounded to 4 decimal places), date, timezone ID (auto-detected from coordinates)Server-onlyUnknownLink
Fisheries and Oceans Canada — CHS/IWLSTide predictions and high/low events for Canadian places near a CHS station.Latitude/longitude (rounded to 4 decimals) or station ID.Server-onlyCALink
IOC Sea Level Station Monitoring FacilityObserved water level + 24 h curve for global places near an IOC station.Latitude/longitude (rounded) or station code.Server-onlyFRLink
Kartverket SehavnivåTide predictions and high/low events for Norwegian places near a Kartverket station.Latitude/longitude (rounded) or station code.Server-onlyNOLink
WSV PegelonlineObserved water level + 24 h curve for German coastal places near a WSV station.Latitude/longitude (rounded) or station UUID.Server-onlyDELink
WikidataProvide structured facts (founding date, population, architect, etc.), description, Wikipedia link, and lead image for place detailsWikidata entity ID (QID from OSM tag), language preferenceServer-onlyUSLink
Wikimedia CommonsFetch metadata for the Wikidata main image (P18 claim)Image filename (from Wikidata P18 claim)Server-onlyUSLink
WikipediaShow Wikipedia description and lead image on place detail panelArticle title and language code (extracted from OSM `wikipedia` tag)Server-onlyUSLink
Wikimedia CommonsGet proper attribution and licensing for the Wikipedia article's lead imageImage filename (extracted from Wikipedia article thumbnail URL)Server-onlyUSLink
Live Transit
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Deutsche Bahn RIS MapsRealtime positions of Deutsche Bahn trains, shown as live vehicle markers on the mapNo user data or location is sent. The server requests journey positions for the configured administration IDs (default 80,81) using DB API credentials; the visible map area is applied as a local filter after the response.Server-onlyDELink
Entur Vehicle Positions v2Poll live positions of monitored Norwegian transit vehicles within the visible map area to animate them on the live-transit overlayA GraphQL query containing the map bounding-box coordinates, a maximum data-age window, and the ET-Client-Name header; no user dataServer-onlyNOLink
Entur Journey Planner SituationsFetch nationwide service alerts and disruption messages from the Journey Planner and show those affecting the visible map areaA GraphQL query for all national situations plus the ET-Client-Name header; no user data or location is sent (bounding-box filtering happens server-side after the fetch)Server-onlyNOLink
TransitousRealtime service alerts and trip updates for journeys served by the global Transitous network — used when a trip or stop comes from Transitous (a `mo:` id) rather than the self-hosted MOTIS instanceA stop ID (for alerts) or trip ID (for trip updates) for Transitous-served journeys is sent to api.transitous.org; no user or location data is included.Server-onlyDELink
MOTISRealtime service alerts and trip updates (delays, platform changes, cancellations) passed through from GTFS-RT feeds ingested by MOTISNothing is sent to a third party. Requests go to OpenMapX's own MOTIS deployment and carry only an internal stop ID (for alerts) or trip ID (for trip updates); no user or location data is included.Server-only—Link
Open data platform mobility Switzerland – SIRI Situation ExchangeRealtime SIRI-SX situation and disruption messages for Swiss public transport, surfaced as service alerts by stop, route, and map areaNo user data is sent. The complete and unplanned SIRI-SX feeds are polled server-side with an API key and a static requestor reference ("OpenMapX"); the requested stop, route, or bounding box is applied as a local filter on the cached feed and is never forwarded to the provider.Server-onlyCHLink
Public Transit
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Open data platform mobility Switzerland – Open Journey PlannerSwiss-wide transit data — stop search, departure/arrival boards, journey planning with intermediate stops and polylines, live trip updates, service alerts, optional itinerary fares and formation/composition infoStop names or coordinates with search radius; origin and destination stops, date and time for journey planning; trip ID for live updates; bounding box for service alerts; itinerary reference for fares; train number and date for formationServer-onlyCHLink
OpenStreetMap geometry used by Swiss OJP routing outputsOpenStreetMap-derived route geometry surfaced within the Swiss OJP routing output; provided only as attribution for OSM-backed leg polylinesNo data — OpenMapX never contacts OpenStreetMap for this; the geometry arrives inside the Swiss OJP journey response and OSM is credited only as the underlying sourceServer-onlyGBLink
Open data platform mobility Switzerland – GTFS static timetableGTFS static timetable for Switzerland — schedule, route, trip, shape and stop data used to reconstruct route patterns and stop sequencesNo user data — the published GTFS dataset is downloaded server-side as a scheduled bulk feed and imported into the database; no end-user query is forwardedServer-onlyCHLink
Open data platform mobility Switzerland – GTFS Realtime Service AlertsGTFS Realtime Service Alerts (-sa) — service disruption and alert messages mapped to affected stops and routesNo user data — the whole GTFS-RT Service Alerts protobuf feed is downloaded server-side using an API token; no end-user data is transmittedServer-onlyCHLink
Open data platform mobility Switzerland – GTFS Realtime Trip UpdatesGTFS Realtime Trip Updates — live delays, predicted arrival/departure times and schedule changes per tripNo user data — the whole GTFS-RT Trip Updates protobuf feed is downloaded server-side using an API token; no end-user data is transmittedServer-onlyCHLink
Open data platform mobility Switzerland – SIRI Situation ExchangeSIRI Situation Exchange (SIRI-SX) — planned and unplanned situation/disruption messages across the Swiss networkNo user data — the complete SIRI-SX XML feeds (planned and unplanned) are downloaded server-side using an API token; no end-user data is transmittedServer-onlyCHLink
Open data platform mobility Switzerland – OJP FareOJP Fare — optional price lookup for a planned itineraryAn API token plus the planned itinerary's trip and leg references (no personal data); the request is sent server-side at request time when a fare lookup is performedServer-onlyCHLink
Open data platform mobility Switzerland – Train formation serviceTrain formation / coach composition — sector positions, vehicle types, seat and accessibility details for a specific train runAn API token plus the operator code (EVU), operation date and train number for the journey being viewed (no personal data); the request is sent server-side at request timeServer-onlyCHLink
Open data platform mobility Switzerland – Occupancy forecast JSON datasetOccupancy forecast — expected first/second-class occupancy levels for upcoming train runsNo user data — the occupancy forecast JSON dataset is downloaded server-side as a scheduled bulk ZIP; lookups are resolved locally by operation date and operator within the downloaded fileServer-onlyCHLink
Open data platform mobility Switzerland – Business organisations with realtime dataBusiness organisations with realtime data — reference list used to label operators and detect which carriers provide real-time dataNo user data — the go-realtime reference CSV is downloaded server-side as a scheduled bulk feed; no end-user query is forwardedServer-onlyCHLink
Open data platform mobility Switzerland – Business organisations with SIRI-SX dataBusiness organisations with SIRI-SX data — reference list used to label operators and detect which carriers provide situation-exchange dataNo user data — the go-siri-sx reference CSV is downloaded server-side as a scheduled bulk feed; no end-user query is forwardedServer-onlyCHLink
Open data platform mobility Switzerland – Service and traffic pointsMaster/reference data — service points, traffic points, platforms, reference points, toilets, parking, contact points and relations used to enrich stops, platforms and infrastructureNo user data — the master-data CSV and ZIP datasets are downloaded server-side as scheduled bulk feeds; stop and infrastructure lookups are resolved locally from the downloaded filesServer-onlyCHLink
Deutsche Bahn (db-vendo-client)Deutsche Bahn transit data — stop search, departure boards, journey planning, live trip trackingCoordinates (latitude, longitude), search radius, stop ID, search query, origin and destination coordinates, departure/arrival time, trip IDServer-onlyDE

-

JSDelivr CDNLoad transit API provider definitions from the public-transport/transport-apis registryNo user data (static registry metadata)Server-onlyUKLink
GitHub APIFallback for loading transit registry when JSDelivr is unavailableNo user data (fallback registry source)Server-onlyUSLink
Regional public-transport operator APIs (transport-apis registry)Regional public-transport journey-planning APIs auto-discovered from the public-transport/transport-apis registry (~85 operators across many countries). Queried only when no hand-crafted provider covers your area.Your journey query — origin/destination coordinates and/or stop IDs — forwarded server-side to the matched regional operator's API (HAFAS mgate or OpenTripPlanner). No account or device identifier is included.Server-onlyVariousLink
Entur Journey Planner v3Search Norwegian transit stops, fetch stop boards, line details, route sequences, realtime journeys, service alerts, live vehicles, and stop-facility metadata via Entur's public APIsCoordinates, stop IDs, line IDs, service-journey IDs, time windows, optional Norway boundary filter, multimodal stop mode, ET-Client-Name headerServer-onlyNOLink
Entur Vehicle Positions v2Track live positions of monitored Norwegian transit vehicles, either for a single line or within the map view, to show them on the mapA GraphQL query containing either a line reference or bounding-box coordinates, a maximum data-age window, and the ET-Client-Name header; no user dataServer-onlyNOLink
Entur National Stop RegisterResolve detailed stop, quay, accessibility, facility, parking, and fare-zone metadata from Norway's National Stop RegisterA REST request containing the stop place or quay identifier in the URL path and the ET-Client-Name header; no user dataServer-onlyNOLink
HAFAS REST APIs (transport.rest)German transit data via community HAFAS REST wrappers (DB, VBB, BVG instances)Coordinates (latitude, longitude), search radius, stop ID, search query, origin and destination coordinates, departure/arrival time, trip ID, bounding box (for vehicle radar)Server-onlyDE

-

iRailBelgian railway data — stations, departure/arrival boards, journey planning, vehicle trackingStop ID, language; station IDs, date, time for connections; vehicle ID for trackingServer-onlyBE

-

MBTABoston metro transit data — stops, predictions, alerts, vehicles, routes, shapes, facilitiesCoordinates (latitude, longitude), search radius; stop ID; route ID; time windowServer-onlyUSLink
TransitousGlobal transit data — stops, departures, journey planning with fares, live vehicle radar, trip trackingStop ID, time window, search text, origin and destination coordinates, departure/arrival time, bounding box (for vehicle positions), trip IDServer-onlyDELink
MOTIS (self-hosted)Self-hosted transit data — same capabilities as Transitous, coverage depends on loaded GTFS/OSM dataStop ID, time window, search text, origin and destination coordinates, departure/arrival time, bounding box (for vehicle positions), trip IDServer-onlyDE

-

OpenTripPlanner (self-hosted)Multi-modal transit trip planning via self-hosted OpenTripPlanner. Coverage depends on loaded data.Origin and destination coordinates, time, date, travel mode, number of itineraries, optional arrive-by flagServer-onlyUS

-

OpenStreetMap (Overpass)Fallback transit stop discovery using OpenStreetMap when no other provider covers the areaBounding box coordinatesServer-onlyDELink
Overpass API (Kumi Systems mirror)Rate-limit fallback Overpass mirror (Kumi Systems e.U., Austria), used only when the primary Overpass endpoint is rate-limited or unavailableThe Overpass QL query containing the map-viewport bounding box, sent server-side only when the primary endpoint is unavailableServer-onlyATLink
Deutsche Bahn RIS RoutingDeutsche Bahn's official journey planner for multi-modal transit routing in GermanyOrigin and destination coordinates, departure or arrival time, languageServer-onlyDELink
Transport for LondonLondon transit data — stops, arrivals, alerts, line status, route stop sequencesCoordinates (latitude, longitude), search radius, stop types; line ID or mode filter; stop IDServer-onlyUKLink
Transitland (Interline)Global transit data — stops, routes, departures via Transitland aggregatorBounding box coordinates, optional route type filter; stop ID, time window for departuresServer-onlyUSLink
Map Overlays
ServicePurposeData TransmittedData AccessCountryPrivacy Info
USGS Earthquake HazardsEarthquake events displayed on the map, color-coded by depth/recency with magnitude-scaled circlesMagnitude threshold and time rangeServer-onlyUSLink
openSenseMapEnvironmental sensor stations (temperature, humidity, PM2.5, PM10, pressure, UV, noise)Bounding box coordinates, exposure filter (outdoor/indoor), dateServer-onlyDELink
Sensor.CommunityCitizen-driven air quality and environmental sensors (merged with openSenseMap, deduplicated)Bounding box coordinates, hardware sensor typeServer-onlyDELink
Waymarked TrailsHiking trail search, details, and tile overlaySearch query text or bounding box coordinates, result limitServer-onlyDE

-

Refuges.infoMountain shelters, refuges, water points, and cabinsBounding box coordinates, optional shelter type filterServer-onlyFRLink
OpenStreetMapFull hiking trail geometry with per-segment SAC difficulty gradingOSM relation ID for trail geometryServer-onlyUKLink
NASA EONETNatural events (volcanoes, storms, floods, landslides). Earthquakes and wildfires excluded (separate overlays).Event status filter, optional day range and categoryServer-onlyUSLink
GDACSDisaster events with alert levels; deduplicated against EONET (80km threshold)Event type filter, date range, alert level filterServer-onlyBELink
OpenSeaMapRender OpenSeaMap seamark tiles as a transparent overlay.Tile coordinates (z/x/y).Proxied (server)DELink
OpenStreetMapRender OpenSeaMap depth-contour and GEBCO bathymetry as raster tiles via WMS proxy.Tile bbox in EPSG:3857.Server-onlyUKLink
GEBCORender NOAA Maritime Chart Service tiles in US waters via WMS proxy.Tile bbox in EPSG:3857.Proxied (server)UKLink
NOAA Maritime Chart ServiceList OpenSeaMap harbours and marinas in the viewport, enrich the clicked harbour with seamark facilities via Overpass.Viewport bounding box, optionally harbour ID + coordinates for enrichment.Proxied (server)USLink
NOAA Tides & Currents (CO-OPS)Provide tide predictions and observed water levels at US coastal tide-gauge stations.A station ID and a date/time range (and a station-type filter when fetching the station catalog). No personal data.Server-onlyUSLink
Kartverket SjøkartRender official Norwegian nautical chart tiles for Norway and Svalbard via WMS proxy.Tile bounding box in EPSG:3857.Proxied (server)NOLink
Fisheries and Oceans Canada — CHS/IWLSProvide tide predictions and observed water levels at Canadian tide-gauge stations.A station ID and a from/to time range (and a time-series-code filter when fetching the station catalog). No personal data.Server-onlyCALink
Kartverket SehavnivåProvide tide predictions and observed water levels at Norwegian tide-gauge stations.A station's latitude/longitude and a from/to time range for the requested data. No personal data.Server-onlyNOLink
WSV PegelonlineProvide observed water levels at German coastal and estuarine tide gauges (North Sea and Baltic Sea).A station UUID for the measurement series (and a North Sea / Baltic Sea waters filter when fetching the station catalog). No personal data.Server-onlyDELink
IOC Sea Level Station Monitoring FacilityProvide observed sea-level data from the global IOC tide-gauge monitoring network.A station code and a time period in days for observations. No personal data.Server-onlyFRLink
EMODnet PhysicsSurface near-real-time sea-level monitoring stations across Europe as map markers.A request for the near-real-time sea-level station layer; no location or query parameters derived from the user are sent.Server-onlyBELink
OurAirportsRender airport markers on the map layer and resolve clicks to a place panel.Map viewport bounding box, optionally filtered by airport type.Server-onlyCALink
NASA GIBSSatellite imagery layers (MODIS, VIIRS, NDVI, Snow Cover, SST, etc.). Tiles and legends proxied via BFF.Layer identifier, date, tile coordinates (z/y/x); no user data for capabilitiesProxied (server)USLink
LOOM Transit Maps (University of Freiburg)Schematic transit-network map tiles for the map overlay.Map tile coordinates (zoom/x/y) and the selected network group and layout. Requests are made by the OpenMapX server, never directly by your browser.Proxied (server)DELink
timezone-boundary-builder (OpenStreetMap)Time zone boundary polygons rendered as a map overlayNothing — the boundaries are vendored and served from this instanceServer-onlyUSLink
Valhalla-compatible street isochrones (Stadia fallback)Visualize walking, cycling, and driving travel-time reachability from a point (street isochrone polygons only)Center coordinates (latitude, longitude), travel mode, contour time thresholds in minutesServer-onlyUSLink
TomTomReal-time traffic flow conditionsTile coordinates (z/x/y), traffic styleProxied (server)NLLink
RainViewerPrecipitation radar animation (metadata server-only, but radar TILES loaded directly by browser)No user data (static metadata feed)Proxied (server)USLink
OpenWeatherWeather parameter overlay tiles (temperature, clouds, wind, pressure, precipitation)Weather layer name, tile coordinates (z/x/y)Proxied (server)UKLink
NOAA Weather ServiceUS weather alerts (warnings, watches, advisories) with polygon boundariesNo user data (static active alerts feed)Server-onlyUSLink
ECCC (Environment Canada)Canadian weather alerts with polygon boundariesNo user data (static active alerts feed)Server-onlyCALink
DWD (Deutscher Wetterdienst)German weather warnings with municipality-level polygon boundariesNo user data (static active warnings feed)Server-onlyDELink
MeteoAlarm (EUMETNET)European weather alerts (24 countries, excl. Germany). No polygon geometry — country centroid used.Country code (per-country feed selection)Server-onlyBELink
NASA FIRMSActive wildfire/fire detections globally, sized by fire radiative power and colored by recencySatellite source (VIIRS or MODIS) and day range (1-3) only, sent server-side; no browser IP, identity, or exact device location is forwarded by OpenMapXServer-onlyUSLink
NIFC WFIGS Current Interagency Fire PerimetersBest-available current U.S. wildland-fire perimeters from WFIGS. Dynamic data are not legal documents and NIFC gives no warranty as to accuracy, reliability, or completeness.Generalized bounding-box coordinates (west, south, east, north) and a zoom-derived simplification offset, sent server-side; no browser IP, identity, or exact device location is forwarded.Server-onlyUSLink
EFFIS / Copernicus Emergency Management ServiceSatellite-derived weekly MODIS burned-area polygons for Europe, the Middle East, and North Africa; not an authoritative fire perimeter.Generalized bounding-box coordinates (west, south, east, north), sent server-side; no browser IP, identity, or exact device location is forwarded.Server-onlyBELink
NOAA Hazard Mapping System (HMS) Smoke DetectionObserved smoke plume polygons from NOAA's Hazard Mapping System (HMS), derived from satellite imagery; density is qualitative and not a measured smoke concentration.Source and time selection only, sent server-side; no browser IP, identity, or exact device location is forwarded.Server-onlyUSLink
OpenSnowMapSki piste overlay tiles and interactive piste/lift vector dataTile coordinates (z/x/y)Proxied (server)FR

-

Place Photos
ServicePurposeData TransmittedData AccessCountryPrivacy Info
OpenStreetMapPlace photos resolved from OpenStreetMap image tags (direct image URLs and Wikimedia Commons filenames)OpenStreetMap element reference (node/way/relation) or place name and coordinates, used to look up the element's tagsServer-onlyUKLink
Google PhotosLink-preview images for places whose OpenStreetMap image tag points to a Google Photos share linkThe Google Photos share URL taken from the place's OpenStreetMap image tag (no user or account data)Server-onlyUSLink
FlickrOpenly-licensed photos near a place for the place detail panelCoordinates (latitude, longitude), search radius (0.5 km), result limitServer-onlyUSLink
MapillaryStreet-level photos near a place for the place detail panelBounding box coordinates (~660 m around point), result limitServer-onlyIELink
PanoramaxOpen street-level imagery near a placeBounding box coordinates (~660 m around point), result limitServer-onlyFRLink
Wikimedia CommonsOpenly-licensed photographs near a place or from its Wikimedia Commons categoryCoordinates (latitude, longitude) with 500 m radius for geo-search; Wikimedia Commons filename or category name (from OSM wikimedia_commons tag) for tag-based lookupServer-onlyUSLink
Point of Interest Search
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Name Suggestion IndexCompile the brand/chain catalog used to recognise and suggest known businesses (e.g. Starbucks, Aldi) during POI searchNothing per-request — the catalog is compiled from the published dataset at build time and matched in memoryServer-onlyUSLink
Wikimedia Commons (brand logos)Resolve a brand's logo image for display in search suggestions and place detailsThe Wikimedia Commons filename referenced by the brand's catalog entry, requested through the image proxy so the browser never contacts Commons directlyServer-onlyUSLink
OpenStreetMap (Overpass)Category-based POI search (46 categories, e.g. restaurants, pharmacies, ATMs) using OpenStreetMap dataBounding box coordinates, POI category (OSM tag filters)Server-onlyDELink
Overpass API (Kumi Systems mirror)Rate-limit fallback Overpass mirror (Kumi Systems e.U., Austria), used only when the primary Overpass endpoint is rate-limited or unavailableThe Overpass QL query containing the map-viewport bounding box and POI category (OSM tag filters), sent server-side only when the primary endpoint is unavailableServer-onlyATLink
Restaurant Menus
ServicePurposeData TransmittedData AccessCountryPrivacy Info
OpenStreetMapProvides the venue's official website tag used to find menu, first-party order, and explicitly linked provider-order pagesNo request is made to OpenStreetMap. The OpenMapX server makes one robots-aware, byte-capped request to the contributed venue website (plus its robots.txt) and sends only normal HTTP request metadata. It does not submit forms or crawl provider sites.Server-onlyGBLink
Reviews
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Mangrove.reviewsReading, aggregating and submitting open, signed place reviews via the Mangrove.reviews networkOn read: a geo: subject URI with the place's coordinates and an uncertainty radius (no place name). On submit: a user-signed review JWT (rating, opinion, metadata). On image upload: the attached image fileServer-onlyCHLink
Ride-Hailing Apps
ServicePurposeData TransmittedData AccessCountryPrivacy Info
UberLink to open a ride request in Uber for the chosen pickup and destinationNone sent by OpenMapX — an outbound link to m.uber.com is built locally and opened in your browser only when you click it. When the operator has configured an Uber Client ID, the URL carries the pickup and destination latitude, longitude and formatted address, plus that Client ID so referrals can be attributed. Without a Client ID the web link is the plain Uber site and carries no trip data at all.Direct (browser)USLink
LyftLink to open a ride request in Lyft for the chosen pickup and destinationNone sent by OpenMapX — an outbound link to lyft.com is built locally and opened in your browser only when you click it. The URL carries the pickup and destination latitude and longitude, and their addresses when known. If the operator has configured a Lyft partner Client ID it is added so referrals can be attributed.Direct (browser)USLink
BoltLink to open the Bolt ride-hailing appNone sent by OpenMapX — an outbound link to bolt.eu is opened in your browser only when you click it. Bolt publishes no parameterised link format, so the URL carries no pickup, destination or address data.Direct (browser)EELink
FREENOWLink to open the FREENOW ride-hailing appNone sent by OpenMapX — an outbound link to free-now.com is opened in your browser only when you click it. FREENOW publishes no parameterised link format, so the URL carries no pickup, destination or address data.Direct (browser)DELink
YangoLink to open the Yango ride-hailing appNone sent by OpenMapX — an outbound link to yango.com is opened in your browser only when you click it. The URL carries no pickup, destination or address data.Direct (browser)NLLink
Registre des taxis de MontréalTaxi service areas, wait times and booking links for Montreal, when the operator of this deployment has configured a Registre des taxis API keyOnly when an API key has been configured, and requested by this OpenMapX server rather than your browser. Service areas and operating rules are downloaded and cached. When you open the ride mode with a pickup in Montreal, the pickup and destination coordinates (and their addresses, when known) are sent to the registry so it can return a wait time. Your identity is not sent, and the result is never cached or stored.Server-onlyCALink
Custom GOFS feed 1An additional GOFS on-demand feed chosen by the operator of this deployment, using the first API key slotOnly when the operator has configured a feed in this slot, and requested by this OpenMapX server rather than your browser. Service areas and operating rules are downloaded and cached. When you open the ride mode within that feed's service area, the pickup and destination coordinates (and their addresses, when known) are sent to it so it can return a wait time and price. Your identity is not sent, and the result is never cached or stored. Which feed this is, and the terms it operates under, are set by the operator of this deployment.Server-onlyXXLink
Custom GOFS feed 2An additional GOFS on-demand feed chosen by the operator of this deployment, using the second API key slotOnly when the operator has configured a feed in this slot, and requested by this OpenMapX server rather than your browser. Service areas and operating rules are downloaded and cached. When you open the ride mode within that feed's service area, the pickup and destination coordinates (and their addresses, when known) are sent to it so it can return a wait time and price. Your identity is not sent, and the result is never cached or stored. Which feed this is, and the terms it operates under, are set by the operator of this deployment.Server-onlyXXLink
Custom GOFS feed 3An additional GOFS on-demand feed chosen by the operator of this deployment, using the third API key slotOnly when the operator has configured a feed in this slot, and requested by this OpenMapX server rather than your browser. Service areas and operating rules are downloaded and cached. When you open the ride mode within that feed's service area, the pickup and destination coordinates (and their addresses, when known) are sent to it so it can return a wait time and price. Your identity is not sent, and the result is never cached or stored. Which feed this is, and the terms it operates under, are set by the operator of this deployment.Server-onlyXXLink
MobilityData GOFS registryThe community-maintained list of published GOFS on-demand feeds, so newly published systems become available without a configuration changeNone about you. This OpenMapX server downloads a public list of feed URLs from the GOFS repository on GitHub. The request carries no pickup, destination, account or device information of any kind, and is made whether or not anyone is using the ride mode.Server-onlyUSLink
GOFS on-demand feedsService areas, operating hours, service brands, wait times, fare estimates and booking links for on-demand transport covering your tripRequested by this OpenMapX server, not by your browser. Service areas, brands, calendars and fares are downloaded once and cached. When you open the ride mode, the pickup and destination coordinates (and their addresses, when known) are sent to the configured feed's wait-time and booking endpoints so it can return a wait time and price. The result is never cached or stored, and which feeds are contacted is set by the operator of this deployment.Server-onlyXXLink
YangoCredential storage for a future Yango fare and wait-time integrationNothing is sent. No request is made to Yango: this integration only holds the credential fields and their setup guide. Should an adapter be added later, this entry will be updated to describe exactly what it transmits before any request is made.Server-onlyNLLink
KarhooCredential storage for a future Karhoo quote, booking and tracking integrationNothing is sent. No request is made to Karhoo: this integration only holds the credential fields and their setup guide. Should an adapter be added later, this entry will be updated to describe exactly what it transmits before any request is made.Server-onlyGBLink
Routing
ServicePurposeData TransmittedData AccessCountryPrivacy Info
OSRMCar routing with turn-by-turn directions; waypoint optimization (Traveling Salesman)Route waypoint coordinates, optional avoidance options (motorway, toll, ferry)Server-onlyDELink
Valhalla (Stadia Maps)Multi-modal routing (walking, cycling, driving) with elevation profiles and localized instructions; waypoint optimizationRoute waypoint coordinates, travel mode, avoidance options (highways, ferry), unit preference, languageServer-onlyUSLink
Code and Alias Search
ServicePurposeData TransmittedData AccessCountryPrivacy Info
WikidataRank famous places above their namesakes in search, and find them by their names in other languagesNothing from searches — autocomplete queries stay on the OpenMapX server and use the local PostGIS index. The monthly refresh sends only fixed SPARQL queries to the configured Wikidata endpoint (QLever, University of Freiburg, by default)Server-onlyUSLink
OpenStreetMap contributorsFind a canonical place from an explicit OpenStreetMap alias, public reference, or conservative generated acronymNothing — autocomplete queries stay on the OpenMapX server and use the local PostGIS indexServer-onlyGBLink
Street-Level Imagery
ServicePurposeData TransmittedData AccessCountryPrivacy Info
PanoramaxStreet-level imagery. Coverage tiles, image metadata and the imagery itself are all fetched by the OpenMapX server; your browser never contacts the Panoramax instance.Only the OpenMapX server contacts Panoramax, sending the map area being viewed and the identifier of any image opened. Your IP address and browser details are not exposed to Panoramax.Server-onlyFRLink
Transit Data Catalogs
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Mobility DatabaseDiscover and download GTFS schedule feeds for import into the local GTFS catalog. Per-feed license metadata flows into the import pipeline.No user data (server-only catalog request)Server-onlyCALink
Weather
ServicePurposeData TransmittedData AccessCountryPrivacy Info
Bright Sky (DWD data)Current weather and forecasts for Germany (DWD data)Coordinates (latitude, longitude), date range for forecastsServer-onlyDE

-

MET NorwayCurrent weather, hourly, and daily forecasts. Global coverage.Coordinates (latitude, longitude)Server-onlyNOLink
Open-MeteoCurrent weather, hourly (up to 7 days), and daily (up to 16 days) forecasts. Global coverage.Coordinates (latitude, longitude), requested weather variables, unit preferencesServer-onlyCHLink
OpenWeatherCurrent weather and 3-hourly forecasts (up to 5 days). Global coverage.Coordinates (latitude, longitude), unit preference, language; interval count for forecastsServer-onlyUKLink
Core Map Rendering
ServicePurposeData TransmittedData AccessCountryPrivacy Info
MapTiler CloudBase map style, vector tiles, satellite tiles, and font glyphs when MapTiler is configured as the map providerMap asset requests and tile coordinates sent by our backend proxy; may reflect the visible map areaProxied (server)SwitzerlandLink
Authentication Providers
ServicePurposeData TransmittedData AccessCountryPrivacy Info
OpenStreetMap OAuth 2.0User sign-in via OSM account; optional contribution permissionsBrowser redirect to OSM authorization page; OAuth authorization flow (no password shared with us)Direct (browser)UKLink
OpenStreetMap API (contributions)Reading the live element and publishing your edit or note, if you use the contribution feature (Section 7)Server-side: element reference, your changed tags, your changeset comment and source, locale, created_by; or your note text and a server-computed location. Published publicly under your linked OSM account.Server-sideUKLink
Mapillary OAuth (Meta Platforms)User sign-in via Mapillary accountBrowser redirect to Mapillary authorization page; OAuth authorization flow (no password shared with us)Direct (browser)USALink
Software Registries and Catalogs
ServicePurposeData TransmittedData AccessCountryPrivacy Info
GitHub API (Microsoft)Fetching transit API registry and GTFS feed catalog from open-source repositories (server-side only)No user data (server-side repository file lookups)Server-onlyUSALink
Voice Search (Microphone)

The search bar offers an optional voice input button. It is never active until you press it. When you do, your browser asks for microphone permission and then uses your browser's own built-in speech recognition (the Web Speech API) to turn what you say into search text. Only the resulting text reaches our servers, as an ordinary search query — the audio itself is never sent to us and is never stored by us.

Where the speech recognition itself happens is decided by your browser, not by OpenMapX. Chromium-based browsers (Chrome, Edge and most derivatives) transmit the captured audio to their vendor's cloud speech service for transcription, under that vendor's own privacy policy; other browsers may transcribe on your device or may not offer the feature at all, in which case the button is hidden. If you do not want your audio processed by your browser vendor, do not use the voice button — typing your query has no microphone involvement.

Note on data flow: The "Data Access" column above indicates how each service is contacted. "Server-only" and "Proxied (server)" mean requests are routed through our backend server — the third-party provider only sees our server's IP address, not yours. "Direct (browser)" means your browser connects directly to the provider, exposing your IP address and browser fingerprint to them. "Mixed" means catalog or metadata requests are server-side or proxied, but specific media/player assets may be loaded directly by your browser after you take an explicit action, such as confirming a viewer notice or clicking "Load media". The vast majority of services are server-only or proxied. MapTiler map assets are routed through our API proxy by default. If an operator configures public map, style, or tile URL templates to point at external providers, your browser will contact those configured providers directly for those assets.

International transfers: Some of the above services are operated by entities in the USA or other countries outside the European Economic Area (EEA). A transfer of personal data to a third country only occurs where your data (such as your IP address or coordinates) actually reaches that provider:

  • Direct browser connections to media providers: Some webcam video or player providers may receive your IP address and browser/device request metadata when you click "Load media" or otherwise open live media. Street-level imagery coverage, metadata, and image assets are routed through our API proxy.

  • Proxied requests to non-EEA providers: MapTiler Cloud receives proxied map asset requests when it is configured as the map provider. MapTiler AG is based in Switzerland, which has an EU adequacy decision.

  • Server-proxied requests forwarding coordinates: For services like Flickr, Wikimedia Commons, TransitLand, and Link, our backend may forward map viewport coordinates (not your IP address) as part of the query. These coordinates reflect the area displayed on the map and are not inherently linked to your identity or physical location.

  • No personal data transferred: Several US-based services (NASA FIRMS, USGS, GitHub API) receive no user-related data at all. Our server fetches public data feeds or repository files without transmitting any coordinates, search queries, or user identifiers. No transfer of personal data occurs in these cases.

The legal basis for all third-party service requests is Art. 6(1)(f) GDPR (legitimate interest in providing the mapping service you are using).

9. Cookies and Local Storage

OpenMapX uses first-party storage mechanisms only. Storage that is necessary for the service is used without a consent banner. The optional recent map-data cache is disabled by default and is only enabled when you switch it on in Settings.

  • Session cookie — If you sign in, an HTTP-only session cookie is set to authenticate your requests. This cookie is essential for the login functionality and is deleted when you sign out or when it expires.

  • Language preference cookie (NEXT_LOCALE) — If you explicitly switch the interface language, your choice (e.g., "en" or "de") is stored in a first-party cookie (max-age: 1 year, SameSite: lax) so the interface remembers it across visits. This cookie is only set when you actively select a language. If you have not made an explicit choice, your browser's language setting is used automatically without storing a cookie.

  • View preferences — A small number of display settings (e.g., globe vs. flat map projection) are saved in localStorage so the interface restores your last-used view. No personal data is involved.

  • Service Worker cache — A Service Worker caches static assets (HTML, CSS, JavaScript), online map tiles, and versioned offline-package glyph assets using the browser's Cache Storage API. Offline map archives are stored in IndexedDB or the Origin Private File System and are verified before use. This enables offline functionality and faster loading. Cached entries expire automatically (static assets: 30 days; online map tiles: 3–7 days). Runtime API response caches for search, route, place, autocomplete, weather, and photo lookups are only written when you enable the recent map-data cache.

  • Browser memory cache — API responses are additionally cached in browser memory (via TanStack Query) during your session for performance. This data is discarded when you close the tab.

  • Optional recent map-data cache — If you enable "Remember recent map data on this device" in Settings, OpenMapX stores a curated set of recent map-related API responses in localStorage and Cache Storage. This can include typed search text, route waypoints, place details, weather lookups, photo lookup results, nearby results, and exact map coordinates. Entries expire automatically according to their cache type (usually within minutes to 24 hours; photo lookup caches can remain for up to 7 days). You can disable the setting or clear this data at any time in the Storage settings.

We do not use any tracking cookies, analytics cookies, or advertising cookies. No cookie consent banner is required for strictly necessary storage (§ 25(2) TDDDG, implementing Art. 5(3) ePrivacy Directive). The optional recent map-data cache is off by default and is controlled through an explicit first-party setting rather than a tracking banner.

10. Server-Side Caching and Databases

To improve performance and reduce load on third-party APIs, our server caches API responses in Redis (an in-memory data store). Cached data typically includes map search results, transit schedules, routing responses, and catalog data from external registries. Cache entries expire automatically (usually within minutes to 48 hours). These entries are not associated with your account and do not contain your IP address or authentication state. Search or routing inputs and results may nevertheless contain coordinates or place names that reveal a geographic area of interest.

Personal Timeline responses are specifically excluded from Redis, Service Worker, persisted query and browser-storage caches. Only a non-user managed-service health result may be held in server memory for up to 15 seconds; it contains no timeline, account, credential, hostname or request-date data.

We also operate a PostgreSQL database for user accounts, saved places, vehicles and parking positions, share payloads, and cached place knowledge data (e.g., Wikidata facts, Wikipedia summaries). The account and synchronized content is personal data and is server-readable. If GTFS transit feeds are imported, schedule data (stop names, routes, departure times) is stored in separate database schemas; cached public place knowledge and transit schedules are not account data.

If you use the OpenStreetMap contribution feature, a short-lived submission lock and outcome record are held (in Redis when configured, otherwise in memory) purely to prevent a double submission. Their keys are one-way digests and their values contain only public result identifiers and timestamps — never contribution content. See Section 7.

11. Email Communication

If you register an account, we may send transactional emails for:

  • Email address verification

  • Password reset requests

  • Two-factor authentication codes

These emails are sent via an SMTP server we operate or commission. They contain only information necessary for the respective action. We do not send newsletters or marketing emails. The legal basis is Art. 6(1)(b) GDPR (performance of a contract / provision of the service you requested).

12. Your Rights Under the GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — You can request information about which personal data we process.

  • Right to rectification (Art. 16 GDPR) — You can request correction of inaccurate data.

  • Right to erasure (Art. 17 GDPR) — You can request deletion of your data. You can also delete your account directly in the account settings.

  • Right to restriction of processing (Art. 18 GDPR) — You can request that we restrict the processing of your data.

  • Right to data portability (Art. 20 GDPR) — You can request to receive your data in a structured, commonly used, machine-readable format.

  • Right to object (Art. 21 GDPR) — You can object to processing based on legitimate interests at any time.

  • Right to withdraw consent (Art. 7(3) GDPR) — Where processing is based on consent (e.g., geolocation), you can withdraw it at any time by revoking the browser permission.

To exercise any of these rights, contact us at the email address listed above. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

No automated decision-making. We do not use your personal data for automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

13. Data Retention

We retain personal data only as long as necessary:

  • Account data — retained until you delete your account.

  • Saved places — retained until you remove them or delete your account.

  • Vehicles and parked location — retained until you clear the parked location, delete the vehicle, or delete your account. Deleting a vehicle also deletes where it was parked.

  • Personal Timeline connection — the encrypted API key and safe connection metadata are retained until you disconnect or delete your OpenMapX account. Fetched history is not retained by OpenMapX. Disabling managed Dawarich preserves its separate service volumes; retention and deletion of that Dawarich account and history are controlled by the instance operator and the direct Dawarich account settings.

  • Mangrove keypair — retained until you regenerate it or delete your account. Deleting the keypair on our servers does not retract previously published reviews from the Mangrove network.

  • Published review content — lives on the Mangrove network and its mirrors, outside our control. Within OpenMapX's own display, reviews can be hidden upon request; on external aggregators, retention is governed by their respective policies.

  • OpenStreetMap provider tokens — retained (encrypted) until you unlink the provider or delete your account.

  • Published OpenStreetMap contributions — part of OpenStreetMap's public database and permanent edit history, outside our control. Deleting your OpenMapX account does not remove them.

  • Contribution submission state — locks expire after two minutes, successful outcome records after 24 hours; neither contains contribution content.

  • Persisted application logs — automatically deleted after 30 days. Container/runtime logs follow the deployment operator's infrastructure policy.

  • Cache data — automatically expires within minutes to 48 hours.

  • Backups — account and synchronized content that existed when a database backup was created may remain until the configured backup retention period expires (30 days by default). Deleting live data does not rewrite an archive; a pseudonymous erasure journal is replayed during restore so a deleted account is not brought back.

  • Local storage and Service Worker cache — this browser's OpenMapX data is cleared after a successful account deletion. Other devices retain their local data until their browser/app data is cleared or cache entries expire.

14. Security

We implement appropriate technical and organizational measures to protect your data, including encrypted connections (TLS/HTTPS), hashed passwords (using modern key-derivation functions), secure session management, and parameterized database queries. However, no method of transmission over the Internet is 100% secure.

Ordinary synchronized content is not end-to-end encrypted. Saved places, shared route or list snapshots, vehicle profiles, parking positions, and Personal Timeline connection metadata must be available to the OpenMapX server for synchronization, sharing, or processing. They can therefore be accessed by the operator of this deployment and by a compromised application server. Encryption at rest for selected credentials and TLS in transit do not change that boundary.

Trust model for the Mangrove keypair (Section 5). In passphrase mode and passphrase + passkey mode, the private signing key never leaves your browser in cleartext. Even a full compromise of our database would only reveal age-encrypted ciphertext, which cannot be decrypted without your passphrase or a registered passkey. In contrast, the “unencrypted” opt-in mode stores the private key in cleartext; anyone with database access could therefore sign reviews in your name. We recommend choosing one of the encrypted modes and never sharing your passphrase. These modes protect the stored key against a database-only disclosure; they cannot prevent a compromised web application from targeting the key or review content after your browser unlocks it.

OAuth provider tokens. Tokens issued by OpenStreetMap and Mapillary are encrypted at rest with this deployment's authentication secret, so a database disclosure alone does not yield usable tokens. Because an OpenStreetMap token may carry permission to edit the public map on your behalf, the contribution boundary additionally re-checks your permissions against OpenStreetMap itself immediately before every write, rather than trusting what we have stored.

Personal Timeline credentials are encrypted before database storage, omitted from responses, logs, audit details and metrics, and sent only by the backend to the selected Dawarich API over its validated connection. The browser never calls the Dawarich API directly. A managed browser SSO session does not grant OpenMapX history access; the per-user API key remains a separate credential.

15. Children's Privacy

OpenMapX is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so we can delete it.

16. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at /privacy. Material changes will be indicated by updating the "Last updated" date.