Legal
Cookie Policy
Effective · Last updated
1.What this policy covers
“Cookies” is shorthand. This policy covers every technology that stores or reads something on your device: HTTP cookies, browser local storage, session storage and IndexedDB. The law treats them the same way, and so do we.
GetMap relies mostly on local storage rather than cookies. That is a deliberate choice — it keeps the data on your device instead of attaching it to every request — but it does not lower the bar: anything that is not strictly necessary still waits for your consent.
How this fits together with the rest: the Privacy Policy explains what personal data we process and why; this page lists the storage items behind it.
2.How your choice works
- On your first visit a banner asks you to decide. Accept all, Reject all and Manage preferences are equally available — rejecting is one click, exactly like accepting.
- Until you decide, nothing outside the strictly necessary category runs. No analytics script is loaded, no marketing identifier is created.
- Your decision is written to your browser's local storage under
gm.consent.v1. It stays on your device — it is not sent to us, and we do not set a cookie to remember that you refused cookies. - The choice lasts 12 months, after which we ask again. We also ask again if we materially change what we load.
- If your browser sends a Global Privacy Control signal, we keep the marketing category off and treat the signal as an opt-out of sharing for cross-context behavioural advertising.
3.Strictly necessary
These make the Service work at all. They cannot be switched off, and under the ePrivacy rules they do not require consent.
| Item | Type · set by | Purpose and lifetime |
|---|---|---|
| gm.consent.v1 | Local storage · GetMap | Remembers your cookie choice so we stop asking. 12 months. |
| firebaseLocalStorageDb | IndexedDB · Firebase Authentication (Google) | Keeps you signed in and holds the token that proves who you are. Until you sign out or clear site data. |
| Security and delivery cookies | Cookie · Vercel (our host) | Our hosting provider may set a short-lived cookie to route traffic and to protect the site from automated abuse. Session-length. |
| paddle_* | Cookie · Paddle (our Merchant of Record) | Set when the checkout opens. Carries your order through the payment flow, keeps the checkout session together across steps, and supports Paddle's fraud checks. Session-length. |
| __cf_bm | Cookie · Cloudflare, on Paddle's behalf | Bot protection for Paddle's checkout: tells a real buyer from automated card-testing traffic. 30 minutes. |
The last two belong to the payment step. They are set by Paddle, our Merchant of Record, when you open the checkout to buy GetMap PRO. They are strictly necessary and cannot be switched off: they exist to deliver the payment you asked for and to keep it safe, so they are not part of the consent banner and refusing them would simply mean no checkout. They are not used to track you around the web, and they only appear if you actually start a purchase.
4.What the app keeps on your device
These are not trackers. They are the app's own memory, stored locally so that GetMap still knows your settings and trips before — or without — you signing in. They stay strictly necessary to the features you asked for, and they never leave your device on their own.
| Item | Type | What it holds |
|---|---|---|
| gm.settings.v1 | Local storage | Language, units, notification toggles, plan flag, sidebar state, home airport. |
| gm.location.v1 | Local storage | Whether you allowed browser location, or the city you picked instead. |
| gm.routes.v1 | Local storage | Your saved trips while you are signed out. |
| gm.countries.v1 | Local storage | Your visited countries and wishlist while you are signed out. |
| theme | Local storage | Dark or light appearance. |
Clearing site data in your browser removes all of it — including guest-mode trips and progress that have not been synced to an account.
5.Analytics — off until you allow it
Off until you switch it on
GetMap loads the three tools below only after you enable the analytics category, and stops sending to them the moment you switch it off again — in the same session, without a reload. Decline, and none of them is ever fetched.
We do not record your screen: session replay is switched off, and so is the kind of automatic capture that logs the text of everything you click. Only the specific events listed in our tracking plan are sent, never your email, your name or your precise location.
| Tool | Typical storage | Purpose |
|---|---|---|
| Google Analytics 4 | _ga, _ga_<container> cookies | Aggregate traffic and feature usage. Up to 2 years. Advertising signals stay off — they belong to the marketing category. |
| PostHog (United States) | ph_<key>_posthog in local storage, not a cookie | Product funnels: which limit people reach and where they stop. Your IP is not stored on the event. Up to 1 year. |
| Vercel Speed Insights | None — no identifier is created | How fast pages actually load for real visitors. Aggregate only. |
Switching the category off removes our permission to load them; use your browser controls to clear anything already stored.
6.Marketing — off until you allow it
GetMap runs no advertising and currently sets no marketing cookies at all. If that changes, this category would cover campaign attribution — knowing which link brought you here — and personalised offers. It stays off unless you switch it on, and it stays off regardless if your browser sends a Global Privacy Control signal.
Flight and hotel results link to partner booking sites through Travelpayouts. Those links carry an affiliate identifier so a booking can be attributed to us; the partner's own cookies are set on the partner's site, after you leave GetMap, under their policies. See the Terms of Use for the affiliate disclosure.
7.Third-party storage we do not control
Google Maps
The map is rendered by Google Maps Platform. Loading it contacts Google's servers and may create storage under Google's own policies, which we cannot switch off without removing the map. The map is a core feature of GetMap, so it is treated as strictly necessary. See the Google Privacy Policy.
Paddle checkout
When you buy GetMap PRO, the checkout is operated by Paddle.com, our Merchant of Record. It opens as an overlay on our /checkout page: Paddle's script is loaded there from Paddle's servers — on that page only, and only once you have started a purchase — and the payment form inside the overlay is served and processed by Paddle. Nothing you type into it reaches us.
The cookies that step sets — paddle_* and Cloudflare's __cf_bm, listed above — are set by Paddle under its own policies, and we can neither read nor disable them. They are governed by the Paddle Privacy Policy and by the Paddle Checkout Buyer Terms you accept when you pay.
Partner booking sites
Following a flight or hotel link takes you to another company's website. What it stores is up to that company and its cookie notice, not ours.
8.Changing your mind
You can change or withdraw your consent at any time, and doing so is exactly as easy as giving it:
- Use the button below — it reopens the same preferences dialog you saw on your first visit.
- Or use your browser: every major browser can block or delete cookies and site data per site. Note that blocking strictly necessary storage will sign you out and lose guest-mode trips.
- Or turn on Global Privacy Control in a browser or extension that supports it; we honour it automatically.
9.Questions and changes
We update this page whenever we add or remove a storage technology, and the effective date at the top always shows the current version. A new category or a new tracker resets your choice, so you get asked again rather than silently opted in.
Questions about anything on this page: [email protected].