Privacy notice
Last updated 4 October 2026
This notice says what personal data gis.dhanypedia.com handles, why, and who else receives it. The site is run by Dhany Yudi Prasetyo, in Indonesia, who is responsible for that data.
What is collected
If you only visit the public pages: nothing is stored about you by the application. The server and the network in front of it record technical data of each request (address, browser, page) to keep the site running and safe.
If you have an account:
- your name, email address and role, and the invitation that created the account;
- your password, stored only as a hash;
- your sessions: when you signed in, from which address and with which browser;
- your access keys, stored only as a hash, and when each was last used;
- what you upload and make (datasets, maps, analyses, dashboards) and who created or changed each item.
If you write to me about access or a trial, I keep that email to answer it.
The site has no advertising and no analytics that follow visitors.
Cookies and browser storage
- A session cookie keeps you signed in. Without it the workspace does not work.
- A language cookie and a language entry in the browser’s storage remember English or Indonesian.
- A theme cookie remembers light or dark.
There are no tracking cookies.
Who else receives data
Some parts of a map are loaded by your browser straight from other providers, who then see your address and the area you look at:
- background maps from CARTO, OpenStreetMap and, for satellite imagery, Esri;
- map fonts and city buildings from OpenFreeMap (the buildings pass through this site’s server);
- relief (elevation tiles) from the Terrain Tiles open data set on Amazon Web Services;
- place search: the text you type goes to the Photon search service of komoot.
Other services work for this site:
- Cloudflare carries all traffic to the site;
- the map server and the routing service are run by me; a route request sends its start and destination to the routing service;
- invitations and password emails are sent through Google’s mail service.
I do not sell personal data and I do not give it to anyone else, unless a law requires it.
Where the data lies and for how long
The application and its database run on a server I operate in Indonesia.
Account data is kept while the account exists. Sessions end when you sign out or expire by themselves. When a trial ends or you ask me to, I delete the account and what it uploaded from the running system.
Your rights
Under Indonesian Law No. 27 of 2022 on Personal Data Protection you can ask what I hold about you, have it corrected or deleted, and withdraw a consent you gave. Write to the address at the foot of this page; I answer within the time the law sets.
Security
Connections are encrypted, passwords are stored as hashes, accounts are by invitation and uploaded data is closed until its owner opens it. No system is free of risk; if personal data is exposed, I tell the people affected as the law requires.
Changes
When this notice changes, the date at the top changes with it.