Privacy Policy
This Privacy Policy explains how Mapica collects, uses, stores, and shares personal data when you use the Mapica app, mapica.app, public Local Creator and route pages, and related Mapica services.
Mapica helps travelers receive personalized travel plans and routes from Local Creators. Tickets, accommodation, car rentals, and certain other travel services may be provided by independent partners. Once you leave Mapica and continue to a partner website or checkout, that partner’s own privacy policy also applies.
Who we are
The controller responsible for your personal data operates under the Mapica brand.
- Website. https://mapica.app
- Privacy. privacy@mapica.app
- Support. support@mapica.app
For requests relating to your personal data or privacy rights, contact privacy@mapica.app.
Information we collect
The information we process depends on how you use Mapica.
Account and authentication
We may process:
- your email address;
- your Mapica account identifier;
- identifiers received when you sign in with Apple or Google;
- your name or display name;
- interface language;
- authentication and session information.
Passwords are handled through Supabase Auth and are not stored as plain-text passwords in the Mapica profile database.
Profile information
You may choose to provide:
- your name;
- profile photo or avatar;
- city and country;
- date of birth where needed for age eligibility or a relevant feature;
- language;
- notification preferences;
- other optional profile information.
Where a full date of birth is not necessary for a feature, Mapica aims not to use it more broadly than necessary.
Trip information
When you create a trip, we may process:
- destinations;
- travel dates;
- number and type of travelers;
- whether children are traveling and their age group;
- interests;
- preferred pace;
- budget;
- accommodation preferences;
- car availability;
- ticket and transport preferences;
- messages or special requests you choose to provide;
- itinerary and route information;
- places associated with your trip;
- interaction with your trip.
Please do not include sensitive personal information in free-text fields unless it is genuinely necessary for your trip.
Messages and uploaded content
We may process:
- messages with a Local Creator;
- messages sent through Mapica chat;
- photos and images you choose to upload;
- route cover images;
- routes, places, and descriptions you create;
- reviews and other user-generated content.
Local applications
If you apply to become a Local Creator, we may also process:
- your name;
- country and city;
- languages;
- your “about” information;
- areas or regions you know;
- expertise categories;
- a sample mini-route;
- application status;
- communications concerning your application.
Local applications are reviewed by authorized Mapica staff. Approval or rejection of a Local application is not based solely on automated decision-making.
Public Local profiles
Once a Local is approved, certain information may become publicly available, including:
- public name;
- profile photo;
- city or region;
- languages;
- about information;
- expertise;
- published routes;
- public ratings or metrics where those features are enabled.
Your email address and date of birth are not displayed in the public Local profile.
Location
If you give permission, Mapica may process precise or approximate device location in order to:
- show your position on the map;
- calculate routes;
- provide walking navigation;
- show nearby places;
- provide features that directly depend on your location.
Mapica requests location access through the operating system permission controls. You can refuse or withdraw location permission through your device settings. Some map-related features may work less effectively without location access.
Device and technical information
We may process:
- IP address;
- device type;
- operating system;
- app version;
- device language;
- technical identifiers;
- Firebase Cloud Messaging registration token for push notifications;
- error and crash information;
- server logs;
- security and abuse-prevention information.
Payments
When you purchase a Mapica route or another service sold directly by Mapica, we may process:
- transaction identifier;
- amount;
- currency;
- payment status;
- the product purchased;
- information necessary for accounting or dispute handling.
Payments are processed by Stripe. Mapica does not store full payment card numbers.
Stripe may act as our processor for certain payment activities and as an independent controller for certain processing it performs for its own legal, regulatory, fraud-prevention, or service purposes.
Where the information comes from
Most information is provided directly by you.
We may also receive limited information:
- from Apple or Google when you use social sign-in;
- from Stripe regarding payment status;
- from your device when you grant permissions;
- from the Local Creator involved in your trip;
- from our infrastructure and security providers;
- from publicly available sources where necessary for a feature about which you have been informed.
Why we use your information and our legal bases
Under the GDPR, we process personal data only where we have an appropriate legal basis.
Performance of a contract or steps before entering into a contract
We process information where necessary to:
- create and manage your account;
- create a trip;
- send a trip request to a Local Creator;
- prepare and deliver an itinerary;
- operate the Mapica marketplace;
- process a Mapica purchase;
- provide a paid service;
- provide customer support.
Legal basis: Article 6(1)(b) GDPR.
Consent
We may rely on consent for:
- access to precise location where consent is required;
- optional analytics or tracking technologies;
- marketing communications where consent is required by law;
- optional device permissions or features.
Legal basis: Article 6(1)(a) GDPR.
You can withdraw consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
Mapica’s legitimate interests
We may process limited information where necessary for legitimate interests such as:
- protecting accounts;
- preventing fraud and abuse;
- maintaining service security;
- technical diagnostics;
- improving product reliability;
- product analytics to understand feature usage and UX;
- marketplace moderation;
- reviewing Local applications;
- establishing, exercising, or defending legal claims.
Legal basis: Article 6(1)(f) GDPR. We do not rely on this basis where your rights and interests override our interests.
Legal obligations
Certain payment, accounting, tax, or dispute-related information may be processed or retained where necessary to comply with applicable law. Legal basis: Article 6(1)(c) GDPR.
Who we share information with
We do not sell your personal data. We share personal data only with recipients that need it for the relevant purpose. Third parties with whom we share data are expected to provide the same or equal protection of user data as stated in this Privacy Policy.
Local Creators
When you request a personalized trip, the assigned Local Creator receives the information reasonably necessary to prepare your trip, which may include destination, dates, travel party, interests, pace, budget, travel preferences, and your message to the Local. We aim not to disclose information that is unnecessary for fulfilling the request.
Supabase
We use Supabase for Authentication, PostgreSQL database, Storage, Realtime, Edge Functions, and backend infrastructure. Supabase processes information to provide these services to Mapica.
Stripe
Stripe provides payment processing and related fraud-prevention and security functionality. Depending on the activity, Stripe may act as a processor or as an independent controller.
Google Maps Platform and Google Places
Mapica uses Google Maps and Google Places for maps, place search, and related features. When these services are used, Google may receive technical information, search terms, IP addresses, and location coordinates in accordance with the Google Maps Platform terms and Google’s Privacy Policy. For certain processing, Mapica and Google act as independent controllers of the relevant personal data.
Firebase
Firebase may be used for push notification delivery and technical app functionality. For push notifications, a device or registration token and other technical information necessary to deliver the notification may be processed.
PostHog, Inc.
Mapica uses PostHog as a product analytics service to understand how users interact with the Mapica app, measure feature usage, diagnose technical issues, and improve the product. PostHog processes this information on behalf of Mapica as a service provider / data processor.
Mapica has configured PostHog’s EU Cloud hosting (ingestion host eu.i.posthog.com). Depending on the features enabled in Mapica, PostHog may process information such as:
- app interactions and screen views;
- session and technical identifiers generated by the analytics SDK;
- device and application information (for example device type, OS, and app version);
- diagnostic and product-usage events (for example checkout funnel steps without payment credentials);
- a pseudonymous Mapica account identifier after sign-in, where needed to understand product usage across sessions.
Mapica does not use PostHog Session Replay in the current app configuration. Mapica does not send chat message bodies, payment card details, authentication tokens, or passwords to PostHog. Mapica does not use PostHog for cross-app advertising tracking or to build advertising profiles for third parties.
Analytics event data is retained according to Mapica’s PostHog project configuration and for no longer than needed for product improvement and diagnostics. You may request deletion of analytics data linked to your account via privacy@mapica.app or by deleting your Mapica account.
Vercel and Cloudflare
Mapica may use Vercel and, where applicable, Cloudflare for website, serverless, networking, and security infrastructure. These providers may process technical requests, IP addresses, and server logs in connection with providing their services.
Apple and Google sign-in
If you choose Sign in with Apple or Google Sign-In, the relevant provider processes information under its own privacy terms. Mapica receives only the information necessary to create or authenticate your Mapica account in accordance with the sign-in method you select.
Travel and affiliate partners
Mapica may provide links to independent providers of tickets, trains and buses, attractions, accommodation, car rentals, and other travel services. These may include providers such as Omio, Tiqets, Viator, Expedia, and DiscoverCars.
When you follow an affiliate or deep link, the partner may receive information such as a referral or affiliate identifier, the selected product, destination, travel dates or other contextual link parameters, and technical information associated with the referral.
After you leave Mapica, the partner independently collects any information you provide during search or checkout and processes that information under its own privacy policy. Mapica does not process your payment card details for these independent partner purchases.
Authorities and legal disclosures
We may disclose information where required by applicable law, a valid request from a competent authority, or where reasonably necessary to protect Mapica, its users, or legal rights.
International transfers
Some of our service providers operate internationally, so personal data may be processed outside the European Economic Area.
Where the GDPR requires additional safeguards for such transfers, we use one or more lawful mechanisms, which may include:
- European Commission adequacy decisions;
- the EU–US Data Privacy Framework for certified organizations where applicable;
- European Commission Standard Contractual Clauses;
- other transfer mechanisms permitted by applicable data protection law.
You can request further information about safeguards used for international transfers by contacting privacy@mapica.app.
Cookies, SDKs, and similar technologies
Our website and app may use technical storage or access mechanisms necessary for purposes such as authentication, security, remembering user settings, deep links, and providing core functionality.
The Mapica mobile app uses the PostHog SDK for in-app product analytics as described above. This is not a website cookie banner use-case; Mapica’s marketing website does not currently load PostHog.
Where Mapica uses optional analytics, advertising, or tracking technologies that require consent under applicable law, those technologies should not be activated before the required consent has been obtained. Where consent is required, you must be able to refuse or withdraw it as easily as you gave it.
Once you visit an independent travel partner, that partner’s own cookie and tracking choices apply.
Push notifications
If you allow notifications, Mapica may send:
- trip updates;
- messages relating to a Local;
- order or route status updates;
- security notifications;
- other service-related Mapica notifications.
You can disable push notifications through your iOS settings. Marketing notifications, if introduced, will be handled separately in accordance with applicable consent requirements.
How long we keep information
We do not keep personal data for longer than necessary for the purpose for which it was collected.
Unless a longer period is required by law or necessary for a dispute, we apply the following general retention periods:
- Account and profile. While your account remains active and until account deletion is completed.
- Trips, private messages, and preferences. While needed for the account or service; after account deletion, these are generally deleted or anonymized from active systems within 30 days.
- Backups. Deleted information may remain in backup systems for up to 90 days before backup rotation or deletion.
- Local applications. Rejected or withdrawn applications are generally retained for no more than 12 months unless longer retention is necessary for a dispute or abuse prevention.
- Push tokens. Until the device is no longer registered, notifications are disabled, the account is deleted, or the token becomes invalid.
- Diagnostic and security logs. Generally no longer than 12 months unless longer retention is necessary to investigate a security incident.
- Privacy and support requests. Relevant records may be retained for up to three years after the request is closed where necessary to demonstrate compliance or protect legal rights.
- Payment and accounting records. For the period required by applicable accounting and tax law. Where French accounting retention requirements apply, certain accounting records may be retained for up to 10 years.
After the relevant period expires, information is deleted, anonymized, or moved to restricted archival storage where continued retention is legally required.
Account deletion
If you create a Mapica account, you can initiate deletion of your account directly in the app:
Profile → Account → Delete Account
You can also contact privacy@mapica.app for questions concerning deletion.
Account deletion includes deleting or anonymizing associated personal information, except information that we are required or permitted to retain for purposes such as:
- accounting and tax obligations;
- fraud prevention;
- compliance with law;
- dispute resolution;
- establishing, exercising, or defending legal claims.
Public user-generated content associated with a deleted account will be deleted or anonymized unless there is a lawful reason to retain it.
Your privacy rights
Where the GDPR or similar law applies, you may have the right to:
- know whether we process your personal data;
- access and obtain a copy of it;
- correct inaccurate information;
- request deletion;
- restrict processing;
- obtain certain information in a portable format;
- object to processing based on legitimate interests;
- withdraw consent;
- object to direct marketing;
- not be subject to certain decisions based solely on automated processing.
To exercise your rights, contact privacy@mapica.app. We may request reasonable information to verify your identity.
We will respond without undue delay and normally within one month of receiving your request. Where permitted by law, that period may be extended.
You also have the right to lodge a complaint with the competent data protection supervisory authority, particularly in the EEA country of your habitual residence, place of work, or the alleged infringement.
Automated systems
Mapica may use automated systems to assist with travel recommendations, itinerary organization, content selection, service improvement, and technical moderation.
Mapica does not use solely automated decision-making that produces legal or similarly significant effects on users without an appropriate lawful basis and required safeguards. Local applications are subject to human review.
If Mapica begins sending messages or other personal data to a separate third-party AI provider, this Privacy Policy and relevant in-app disclosures must be updated before that processing begins.
Children
Mapica is not intended for independent use by children under 16. A person under 16 should not create their own Mapica account.
An adult account holder may provide limited information about children traveling with them, such as the number of children or age group, where necessary to prepare an appropriate trip. Please do not provide unnecessary sensitive information about a child.
If we become aware that a child has created an account in violation of our age requirements, we will take reasonable steps to delete the account and related information.
Security
We use technical and organizational measures designed to protect personal information against unauthorized access, unlawful use, alteration, accidental loss, disclosure, and destruction. However, no internet service can guarantee absolute security.
Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will show when the Policy was most recently changed.
If a change materially affects how personal data is used, we will provide additional notice where required by law or appropriate in light of the change.
Contact us
- Privacy and GDPR. privacy@mapica.app
- Support. support@mapica.app
- General. hello@mapica.app
- Website. https://mapica.app
- Contact. https://mapica.app/contact