Back to GetMap

Legal

Privacy Policy

Effective · Last updated

This policy explains what personal data GetMap collects, why we need it, who else touches it, how long it stays, and what you can demand from us. It is written to be read, not to be survived.

1.Who is responsible for your data

Juicyapps LLC, [REGISTERED ADDRESS — TBD], is the data controller for the personal data described here. This policy covers https://getmap.travel and the GetMap apps.

Data protection contact: [email protected]. We have not appointed a statutory Data Protection Officer, because we do not carry out the kind of large-scale monitoring that would require one; that address reaches the people who actually handle these requests.

We have not designated a representative in the EU or the UK under Article 27 GDPR / UK GDPR. That does not narrow your rights or where you can enforce them: write to the address above, and you may complain to your own national authority — see Your rights.

The short version

We collect what the app needs to work: an account, your saved trips and game progress, the photos you upload to complete quests, and — only if you allow it — your location. We never see your card details. We do not sell your data. Analytics and marketing technologies stay switched off until you turn them on in Cookie settings.

2.What we collect

Account data

Sign-in runs on Firebase Authentication (Google). If you sign in with Google or Apple we receive a user identifier, your email address, your display name and your profile picture URL, plus the authentication tokens that keep you signed in. If you continue as a guest, the account is anonymous: a random identifier and nothing else.

Your profile and progress

Stored in our Supabase database, in one record per account: name and email copied from your account, level, points, skill scores, credit balance, streak, your saved trips (city, country, dates, budget, departure airport and the generated plan), your wishlist and visited countries with their trip dates, and your completed quests with the date, the measured distance from the quest point and a link to the photo you uploaded.

Quest photos and their metadata

When you complete a photo quest, the photo is uploaded to our Supabase storage bucket and a link to it is saved on your profile.

We read the location metadata of your photo

Before uploading, the app reads the photo's embedded EXIF data in your browser and takes the GPS coordinates out of it, to check whether the picture was taken within 200 metres of the quest point. Only the resulting distance is stored on your profile — the coordinates themselves are not.

The photo file itself is uploaded as you selected it, so any metadata your camera wrote into it — location, timestamp, device model — is stored with the file. If you would rather not share that, strip the metadata before uploading, or use a photo that does not carry it (in which case the quest check cannot pass and you will need another one).

Location

If you allow it, the browser gives us your approximate position so the map and the audio guides can show what is around you. You can instead pick a city by hand, and you can revoke the browser permission at any time in your browser or system settings. Coordinates sent to our own backend are rounded to two decimal places — roughly one kilometre — before they leave your device. Requests for maps, place details and walking routes are served by Google and carry the coordinates those requests are about.

Trip inputs

The cities, countries, travel dates, number of guests, currency and departure airport you type in, so we can search flights, hotels, weather and exchange rates for you.

Payment data

Handled by Paddle, our Merchant of Record — see Payments and Paddle. Card and other payment details are entered on Paddle's checkout and go straight to Paddle; they never pass through our servers, and we never receive or store your card number.

Technical data

Our hosting provider records the usual server-side request data: IP address, user agent, the page or endpoint requested, timestamps and error traces. We use it to run and secure the Service.

Your cookie choice

The choice you make in the cookie banner is written to your browser's local storage only. It is not sent to us, and it is not a cookie.

3.Why we use it, and on what legal basis

Purposes of processing and their legal bases under the GDPR
PurposeDataLegal basis
Give you an account and sync it across devicesAccount data, profile and progressPerformance of a contract — Art. 6(1)(b)
Generate routes, guides, weather, currency and travel search resultsTrip inputs, location, credit balancePerformance of a contract — Art. 6(1)(b)
Verify and reward photo questsPhoto, its GPS metadata, distance, progressPerformance of a contract — Art. 6(1)(b)
Show what is around youPrecise location from your browserConsent — Art. 6(1)(a), given through the browser permission prompt
Take payment and manage your subscriptionOrder and subscription records from PaddlePerformance of a contract — Art. 6(1)(b)
Keep tax, accounting and dispute recordsOrder recordsLegal obligation — Art. 6(1)(c)
Keep the Service secure, prevent fraud and quest manipulation, fix faultsTechnical data, progress dataLegitimate interests — Art. 6(1)(f): running a service that works and is not abused
Measure how the product is used, and marketing attributionAnalytics and marketing identifiersConsent — Art. 6(1)(a), withdrawable at any time

Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override your interests; you can object at any time (see Your rights).

4.What we do not do

  • We do not sell your personal data, and we never have.
  • We do not run advertising inside GetMap, and we do not share your data with ad networks. Marketing technologies are described here so that the policy stays accurate if we ever switch them on — and they stay off until you consent.
  • We do not build behavioural profiles of you, and we do not make decisions about you with legal or similarly significant effects (see Automated processing).
  • We do not upload your address book, contacts, calendar or photo library.

5.Payments and Paddle

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. Paddle takes the payment, calculates and remits tax, issues the invoice, and handles refunds and chargebacks.

  • What goes to Paddle: your email address, the name and billing address you enter at checkout, your payment method, your country and IP address for tax calculation and fraud checks, and an identifier that ties the order to your GetMap account.
  • What never reaches us: your card number, expiry date and security code. They are entered in Paddle's own checkout — served by Paddle, on Paddle's infrastructure, inside the page — and are processed under Paddle's PCI DSS certification. We never receive your full card number, and we never store card data.
  • What comes back to us: an order and subscription record — identifier, plan, status, renewal date, currency and amount, the email used at checkout, the country used for tax, and, where Paddle provides it, the card brand and the last four digits.

We use that record to switch your account to GetMap PRO, to keep it in step with renewals and cancellations, and to answer billing questions.

Opening the checkout loads Paddle's script from Paddle's servers onto our checkout page, so from that moment Paddle sees the request itself, including your IP address. Nothing of Paddle's loads before you start a purchase.

Paddle's own role in your data

For the payment itself, Paddle is not our processor: as the seller of record it is an independent controller of the payment, tax, invoicing and anti-fraud data it collects, and it decides how that data is used to meet its own legal duties — tax reporting, accounting, sanctions and fraud screening, and card scheme rules. What it does with that data is set out in the Paddle Privacy Policy.

Where Paddle instead processes personal data on our behalf — for example the account identifier we attach to an order so we can switch on PRO — it does so as our processor under the Paddle Data Processing Addendum, which implements Article 28 GDPR and incorporates the Standard Contractual Clauses for transfers outside the EEA and the UK.

For anything that lives on Paddle's side — a copy of an invoice, a change of billing address, the payment data behind a transaction — you can go straight to the Paddle buyer portal at paddle.net with the email address you used for the purchase, or ask us at [email protected] and we will raise it with them.

6.Cookies, local storage and analytics

The Cookie Policy lists every cookie and storage item by name and category. In summary:

  • Strictly necessary storage keeps you signed in, remembers your settings, saved trips and visited countries, and lets our hosting provider protect the site. It runs without consent because the Service cannot work without it.
  • Analytics and marketing technologies do not run until you allow them in the cookie banner. Today none are active. We are preparing to add Google Analytics 4, Amplitude and PostHog; each will load only inside the consent gate, and each will be listed in the Cookie Policy before it goes live.
  • You can change or withdraw your choice at any time from Cookie settings. Withdrawal is as easy as consent and does not affect processing that already happened.

We honour the Global Privacy Control signal: if your browser sends it, we keep the marketing category switched off and treat it as an opt-out of any sharing for cross-context behavioural advertising.

7.Who processes your data

We use a small number of providers. Each receives only what it needs, acts on our instructions as a processor (except where marked), and is bound by a data processing agreement.

Third-party providers that process personal data for GetMap
ProviderWhat it doesTheir policy
Google (Firebase Authentication)Sign-in with Google or Apple, guest accounts, session tokensfirebase.google.com
Google Maps PlatformMap rendering, place details and photos, walking routes. Receives the coordinates of the map area and route you are looking atpolicies.google.com
SupabaseThe database holding your profile and progress, and the storage bucket holding your quest photossupabase.com
VercelHosting and content delivery for the website; server logs and IP addresses. With your consent, also Speed Insights — aggregate page-load timings, no identifiervercel.com
Google Analytics 4 — only with your consentAggregate traffic and feature usage. Not loaded at all unless you enable the analytics categorypolicies.google.com
PostHog — only with your consentProduct funnels: which limits people reach and where they stop. Processed in the United States, so this is a transfer outside the EEA and the UK; not loaded at all unless you enable the analytics categoryposthog.com
Paddle — independent controllerThe checkout, payments, tax, invoices, refunds and chargebacks, as Merchant of Record. Its processing on our behalf is covered by the Paddle Data Processing Addendumpaddle.com
TravelpayoutsAirport and airline lookups, and the partner links behind flight and hotel resultstravelpayouts.com
Photon / OpenStreetMapCity name suggestions in the planner. Queries are proxied through our server, so your IP address is not exposed to themopenstreetmap.org
Our own GetMap backendAudio guides, narration, place photos, weather, currency rates, flight and hotel searchThis policy

We may also disclose data:

  • to professional advisers, or to a buyer or successor if the Service is transferred — in which case we will tell you before your data moves;
  • where the law requires it, or where it is necessary to establish, exercise or defend a legal claim, or to protect someone's safety.

8.International transfers

Most of our providers are established in the United States or operate global infrastructure, so your data may be processed outside the EEA and the UK.

Where that happens, the transfer is covered by an appropriate safeguard under Chapter V of the GDPR — normally the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and, for providers certified under it, the EU–US Data Privacy Framework. You can ask us for a copy of the safeguard that applies to a specific provider.

9.How long we keep it

Retention periods
DataKept for
Account, profile, trips, quests, creditsAs long as the account exists. After a deletion request, removed from our live systems within 30 days; encrypted backups age out on their own rotation, within 90 days.
Quest photosUntil you delete the quest entry or the account, then removed with it.
Order and subscription recordsAs long as tax and accounting law requires us to keep them — normally several years. Paddle keeps its own records, as the Merchant of Record that invoiced and remitted the tax, under its own policy and retention rules.
Walking routes from GoogleCached at most 30 days — the maximum Google Maps Platform terms allow for coordinates from the Routes API — and deliberately never written into your saved trip.
Server and request logsA short period, set by our hosting provider's default retention, then discarded.
Your cookie choice12 months in your browser, then we ask again. It never reaches our servers.

To delete your account, write to [email protected] from the email address on the account. Cancel any active subscription first, or ask us to do both.

10.How we protect it

  • All traffic between your device and our servers is encrypted with HTTPS.
  • Our API credentials live only in server-side environment variables. They are never included in the browser bundle; the browser talks to our own endpoints, which add the credentials server-side.
  • Database access is restricted per account by row-level security tied to your signed-in identity, so one account cannot read another's record. The elevated key used by our internal admin tools is server-only and separately protected.
  • Access to production systems is limited to the people who need it.

No service can promise perfect security, and we make no such promise. If a breach affects your rights, we will notify the supervisory authority and, where required, you — within the deadlines the GDPR sets.

11.Your rights

If you are in the EEA, the UK or a country with comparable rules, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted where we have no overriding reason to keep it.
  • Restriction — have processing paused while a dispute is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
  • Objection — object to processing based on our legitimate interests, including profiling, at any time.
  • Withdraw consent — at any time, without affecting processing already carried out. Use Cookie settings for analytics and marketing, and your browser or system settings for location.
  • Complain — to the data protection authority of the country where you live or work. We are established outside the EEA and the UK, so there is no single “lead” authority for us under the one-stop-shop mechanism: your own national regulator is the right one, and you do not have to go through us first.

To use any of these, write to [email protected] from the address on your account. We answer within one month, and will tell you if we need the two-month extension the GDPR allows for complex requests. We may ask a question or two to confirm it is really you — never a copy of an identity document unless there is no other way.

12.California privacy rights (CCPA / CPRA)

If you are a California resident, this section applies to you in addition to the rest of this policy.

Categories we collect

  • Identifiers — account identifier, name, email address, IP address.
  • Commercial information — your subscription and order records.
  • Internet or network activity — requests to our servers, and, only with your consent, product analytics.
  • Geolocation data — your position, if you allow it, and the location metadata of quest photos.
  • Visual information — the photos you upload to complete quests.

The sources, purposes and recipients are the ones described in What we collect, Why we use it and Who processes your data. We keep each category for the periods in How long we keep it.

Sale and sharing

We do not sell personal information, and we have not sold or shared it in the preceding twelve months. If we ever enable marketing technologies, some disclosures could count as “sharing” for cross-context behavioural advertising under the CPRA — which is exactly why those technologies stay off until you switch them on. You can opt out at any time through Cookie settings, and we treat a Global Privacy Control signal from your browser as a valid opt-out request.

Sensitive personal information

Precise geolocation is sensitive personal information under the CPRA. We use it only to deliver the feature you asked for — showing what is near you and verifying a quest — which is a use the CPRA exempts from the right to limit. We do not use it to infer characteristics about you.

Your rights

  • to know what we collect, use, disclose and share;
  • to delete personal information we hold about you;
  • to correct inaccurate personal information;
  • to opt out of any sale or sharing;
  • to limit the use of sensitive personal information, where that right applies;
  • not to be discriminated against for exercising any of them — we will not degrade the Service or change your price because you did.

Send requests to [email protected]. An authorised agent may act for you with written permission that we can verify. We respond within 45 days and may extend once by another 45 days if we tell you why.

13.Children

GetMap is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, write to [email protected] and we will delete the account and its contents. Age requirements for older minors are in the Terms of Use.

14.Automated processing

Two parts of the Service are automated, and you should know how they work:

  1. Quest verification. The distance between your photo's GPS metadata and the quest point is compared automatically, entirely on your device. A failed check simply means no reward; you can retry with another photo or write to us.
  2. Content generation. Guides, routes and trip plans are produced automatically, in part by language models, from your trip inputs.

Neither produces a decision with legal or similarly significant effects for you within the meaning of Article 22 GDPR, and neither is used to profile you.

15.Changes to this policy

We update this policy when the Service or the law changes. The effective date at the top always shows the current version. For changes that materially affect your rights — a new category of data, a new purpose, a new kind of recipient — we will give notice in the app or by email before they take effect, and ask for fresh consent where consent is the basis.

16.Contact

Privacy questions and data-subject requests: [email protected].

Postal address: Juicyapps LLC, [REGISTERED ADDRESS — TBD].

No Article 27 representative is designated in the EU or the UK, and no single lead supervisory authority applies to us. Complaints go to the regulator where you live or work.