FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. Mapbox
M

Mapbox

Preferences

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Mapbox do?

Mapbox is a leading commercial provider of vector maps, geocoding and navigation. The Mapbox GL JS SDK transmits the visitor IP and an anonymised telemetry signal to Mapbox US servers. Consent is required in the EU; the SDK telemetry can be disabled.

What Mapbox is

Mapbox is a leading commercial provider of vector maps, geocoding, navigation and location based developer services. The product line covers Mapbox GL JS (web map SDK), Mapbox Studio (visual style editor), Mapbox Geocoding API, Mapbox Directions API, Mapbox Map Matching, Static Images, Navigation SDK for mobile, Search Box and the Boundaries tilesets. Mapbox vector tiles render server side from OpenStreetMap, OpenAddresses and proprietary datasets combined.

What data the SDK transmits

At map initialisation, Mapbox GL JS sends the visitor IP, the user agent, the referrer URL, the access token and the requested tile coordinates to api.mapbox.com. By default the SDK also sends anonymised telemetry data (movement samples, viewport changes) to events.mapbox.com to improve the Mapbox products. The telemetry can be disabled with map.setConfigProperty(basemap, telemetry, false) or by setting the EventManager to disabled. Local storage is used to remember the user choice of opting out from the Mapbox attribution telemetry.

GDPR consent and ePrivacy

Loading the Mapbox SDK with default telemetry requires prior consent under GDPR art. 6(1)(a) and ePrivacy art. 5(3) because the SDK writes a local storage entry, sends anonymised telemetry and transfers the IP to the United States. When telemetry is disabled and only tiles are fetched, legitimate interest can be argued for the map necessary to deliver the requested service, but the Munich Google Fonts ruling logic applies because the IP still goes to a US server. A click to load wrapper is the recommended pattern.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data residency and US transfers

Mapbox runs the api.mapbox.com endpoint from the US by default. EU customers on enterprise plans can request EU tile delivery, but the account API, the events API and the Mapbox Studio remain US based. Mapbox is certified under the EU US Data Privacy Framework with 2021 SCCs as fallback. A Transfer Impact Assessment must be on file. Mapbox publishes its sub processor list and an audit report (SOC 2 type II).

Compliant integration pattern

Disable the Mapbox telemetry at SDK initialisation, use a click to load wrapper, integrate with a TCF v2.2 CMP, request EU tile delivery on the enterprise plan, list Mapbox as a sub processor in the privacy notice, sign the Mapbox DPA, mention the Data Privacy Framework certification, and consider migrating to MapLibre GL JS with an EU tile provider (Stadia, MapTiler) for full EU residency.

GDPR consent category

Preferences

Websites using Mapbox must obtain user consent under GDPR regulations.

Legal basisConsent under GDPR art. 6(1)(a) and ePrivacy art. 5(3) for the Mapbox GL JS map because the SDK telemetry collects anonymised location samples by default and the visitor IP is transferred to the United States. The mapbox-telemetry flag can be disabled at SDK initialisation, reducing the data flow to the tile request itself; in that case legitimate interest plus a click to load wrapper can be defended. The Munich Google Fonts ruling logic applies given the US infrastructure.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidance on web maps, EU US Data Privacy Framework, Munich Google Fonts ruling logic, German TTDSG, AEPD geolocation guidelines

DPIA considerations

A DPIA is recommended for any Mapbox deployment in the EU because the SDK transmits the visitor IP, the access token and the anonymised telemetry signal to Mapbox US infrastructure. The DPIA should cover the Mapbox SDK telemetry toggle, the use of the Mapbox Geocoding or Directions API (which may contain freeform addresses), the EU tile delivery option, the integration with a CMP and the Mapbox Data Privacy Framework certification.

Sample consent text

Our website displays maps powered by Mapbox, operated by Mapbox Inc. (United States). When the map loads, the Mapbox GL JS SDK transmits your IP address, your user agent and the access token to Mapbox servers in the United States and sends anonymised telemetry to improve the service. With your consent we activate the map; refusing displays a static fallback image. Data is processed under the EU US Data Privacy Framework.

Technical details

Tracking methodcommercial_map_service_with_javascript_sdk_vector_tiles_geocoding_and_analytics_telemetry
Server locationMapbox is operated by Mapbox Inc., a US company headquartered in Washington DC. The Mapbox platform runs on Amazon Web Services with primary regions in the United States (us-east-1) and Europe (eu-west-1 Ireland). Vector tile delivery uses a global CDN with European edge nodes. The Mapbox Account API, the Mapbox Studio editor and the Map Matching API run from the US data centres; EU customers can request EU residency for tile delivery but not for the corporate control plane.
Data transferred outside the EUMapbox Inc. is US headquartered. Every Mapbox GL JS or Mapbox SDK request transmits the visitor IP, the user agent and the access token to Mapbox servers in the United States. Mapbox is certified under the EU US Data Privacy Framework and uses the 2021 Standard Contractual Clauses as fallback. Telemetry data (anonymised aggregate movements when the Mapbox SDK telemetry is enabled) is processed in the US to improve the Mapbox products.

Third-party domains contacted

api.mapbox.comevents.mapbox.coma.tiles.mapbox.comb.tiles.mapbox.comc.tiles.mapbox.comd.tiles.mapbox.commapbox.com

Cookies placed

NameTypeDurationPurpose
mapbox.attribution.show (Local Storage)First party (Mapbox GL JS local storage)PersistentStores the visitor choice to dismiss the Mapbox attribution telemetry banner
mapbox.eventData.uuid (Local Storage)First party (Mapbox GL JS local storage, when telemetry enabled)PersistentStores a UUID used by the Mapbox SDK to deduplicate anonymous telemetry events; only present when telemetry is enabled

Mapbox uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Mapbox set?

Mapbox does not set classic cookies. Mapbox GL JS stores a local storage entry for the attribution telemetry opt out. The map sends the IP and an anonymised telemetry signal to events.mapbox.com unless telemetry is disabled at SDK initialisation.

Is consent required for Mapbox?

Yes with default settings, because the SDK telemetry transmits anonymised location samples and the IP to Mapbox US servers. If telemetry is disabled and only tiles are fetched, the Munich Google Fonts ruling logic still suggests consent because the IP goes to a US server.

What is the legal basis for Mapbox?

Consent (GDPR art. 6(1)(a)) for the default SDK with telemetry. Legitimate interest (art. 6(1)(f)) is defensible only when telemetry is disabled, the map is essential to the service, a balancing test is documented and Data Privacy Framework is in place.

Are data transferred to the United States?

Yes by default. api.mapbox.com and events.mapbox.com are operated from the US. EU tile delivery is available on enterprise plans but the account and events endpoints remain US. Mapbox is certified under the EU US Data Privacy Framework with SCCs 2021 fallback.

Do I need a DPIA for Mapbox?

Recommended in most cases because of the persistent US transfer and the telemetry. The DPIA should document the SDK telemetry toggle, the use of Geocoding or Directions APIs that may contain freeform addresses and the EU tile delivery option.

How do I implement Mapbox compliantly?

Disable telemetry at SDK initialisation, use a click to load wrapper, integrate with a TCF v2.2 CMP, request EU tile delivery on enterprise, sign the Mapbox DPA, list Mapbox in the privacy notice, and consider migrating to MapLibre GL JS with an EU tile provider for full EU residency.

What are the alternatives to Mapbox?

MapLibre GL JS (open source fork of Mapbox GL JS) with EU tile providers like Stadia Maps, MapTiler, Geoapify or CARTO Madrid. Other EU options: Leaflet with OpenStreetMap tiles, OpenLayers. For commercial parity in the US camp: Google Maps Platform, Apple MapKit JS, Microsoft Azure Maps.

How do I update my cookie policy after adding Mapbox?

List Mapbox Inc. as a sub processor, declare the local storage entry for telemetry opt out, mention the IP transfer to api.mapbox.com and events.mapbox.com in the United States under the Data Privacy Framework, link to the Mapbox Privacy Policy and provide a DSAR contact.