Privacy Policy

Last updated: 26 August 2026 · Mapica · mapica.app

This Privacy Policy explains how Mapica collects, uses, stores, and shares personal data when you use the Mapica app, mapica.app, public Local Creator and route pages, and related Mapica services.

Mapica helps travelers receive personalized travel plans and routes from Local Creators. Tickets, accommodation, car rentals, and certain other travel services may be provided by independent partners. Once you leave Mapica and continue to a partner website or checkout, that partner’s own privacy policy also applies.

Who we are

The controller responsible for your personal data operates under the Mapica brand.

For requests relating to your personal data or privacy rights, contact privacy@mapica.app.

Information we collect

The information we process depends on how you use Mapica.

Account and authentication

We may process:

Passwords are handled through Supabase Auth and are not stored as plain-text passwords in the Mapica profile database.

Profile information

You may choose to provide:

Where a full date of birth is not necessary for a feature, Mapica aims not to use it more broadly than necessary.

Trip information

When you create a trip, we may process:

Please do not include sensitive personal information in free-text fields unless it is genuinely necessary for your trip.

Messages and uploaded content

We may process:

Local applications

If you apply to become a Local Creator, we may also process:

Local applications are reviewed by authorized Mapica staff. Approval or rejection of a Local application is not based solely on automated decision-making.

Public Local profiles

Once a Local is approved, certain information may become publicly available, including:

Your email address and date of birth are not displayed in the public Local profile.

Location

If you give permission, Mapica may process precise or approximate device location in order to:

Mapica requests location access through the operating system permission controls. You can refuse or withdraw location permission through your device settings. Some map-related features may work less effectively without location access.

Device and technical information

We may process:

Payments

When you purchase a Mapica route or another service sold directly by Mapica, we may process:

Payments are processed by Stripe. Mapica does not store full payment card numbers.

Stripe may act as our processor for certain payment activities and as an independent controller for certain processing it performs for its own legal, regulatory, fraud-prevention, or service purposes.

Where the information comes from

Most information is provided directly by you.

We may also receive limited information:

Why we use your information and our legal bases

Under the GDPR, we process personal data only where we have an appropriate legal basis.

Performance of a contract or steps before entering into a contract

We process information where necessary to:

Legal basis: Article 6(1)(b) GDPR.

Consent

We may rely on consent for:

Legal basis: Article 6(1)(a) GDPR.

You can withdraw consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

Mapica’s legitimate interests

We may process limited information where necessary for legitimate interests such as:

Legal basis: Article 6(1)(f) GDPR. We do not rely on this basis where your rights and interests override our interests.

Legal obligations

Certain payment, accounting, tax, or dispute-related information may be processed or retained where necessary to comply with applicable law. Legal basis: Article 6(1)(c) GDPR.

Who we share information with

We do not sell your personal data. We share personal data only with recipients that need it for the relevant purpose. Third parties with whom we share data are expected to provide the same or equal protection of user data as stated in this Privacy Policy.

Local Creators

When you request a personalized trip, the assigned Local Creator receives the information reasonably necessary to prepare your trip, which may include destination, dates, travel party, interests, pace, budget, travel preferences, and your message to the Local. We aim not to disclose information that is unnecessary for fulfilling the request.

Supabase

We use Supabase for Authentication, PostgreSQL database, Storage, Realtime, Edge Functions, and backend infrastructure. Supabase processes information to provide these services to Mapica.

Stripe

Stripe provides payment processing and related fraud-prevention and security functionality. Depending on the activity, Stripe may act as a processor or as an independent controller.

Google Maps Platform and Google Places

Mapica uses Google Maps and Google Places for maps, place search, and related features. When these services are used, Google may receive technical information, search terms, IP addresses, and location coordinates in accordance with the Google Maps Platform terms and Google’s Privacy Policy. For certain processing, Mapica and Google act as independent controllers of the relevant personal data.

Firebase

Firebase may be used for push notification delivery and technical app functionality. For push notifications, a device or registration token and other technical information necessary to deliver the notification may be processed.

PostHog, Inc.

Mapica uses PostHog as a product analytics service to understand how users interact with the Mapica app, measure feature usage, diagnose technical issues, and improve the product. PostHog processes this information on behalf of Mapica as a service provider / data processor.

Mapica has configured PostHog’s EU Cloud hosting (ingestion host eu.i.posthog.com). Depending on the features enabled in Mapica, PostHog may process information such as:

Mapica does not use PostHog Session Replay in the current app configuration. Mapica does not send chat message bodies, payment card details, authentication tokens, or passwords to PostHog. Mapica does not use PostHog for cross-app advertising tracking or to build advertising profiles for third parties.

Analytics event data is retained according to Mapica’s PostHog project configuration and for no longer than needed for product improvement and diagnostics. You may request deletion of analytics data linked to your account via privacy@mapica.app or by deleting your Mapica account.

Vercel and Cloudflare

Mapica may use Vercel and, where applicable, Cloudflare for website, serverless, networking, and security infrastructure. These providers may process technical requests, IP addresses, and server logs in connection with providing their services.

Apple and Google sign-in

If you choose Sign in with Apple or Google Sign-In, the relevant provider processes information under its own privacy terms. Mapica receives only the information necessary to create or authenticate your Mapica account in accordance with the sign-in method you select.

Travel and affiliate partners

Mapica may provide links to independent providers of tickets, trains and buses, attractions, accommodation, car rentals, and other travel services. These may include providers such as Omio, Tiqets, Viator, Expedia, and DiscoverCars.

When you follow an affiliate or deep link, the partner may receive information such as a referral or affiliate identifier, the selected product, destination, travel dates or other contextual link parameters, and technical information associated with the referral.

After you leave Mapica, the partner independently collects any information you provide during search or checkout and processes that information under its own privacy policy. Mapica does not process your payment card details for these independent partner purchases.

Authorities and legal disclosures

We may disclose information where required by applicable law, a valid request from a competent authority, or where reasonably necessary to protect Mapica, its users, or legal rights.

International transfers

Some of our service providers operate internationally, so personal data may be processed outside the European Economic Area.

Where the GDPR requires additional safeguards for such transfers, we use one or more lawful mechanisms, which may include:

You can request further information about safeguards used for international transfers by contacting privacy@mapica.app.

Cookies, SDKs, and similar technologies

Our website and app may use technical storage or access mechanisms necessary for purposes such as authentication, security, remembering user settings, deep links, and providing core functionality.

The Mapica mobile app uses the PostHog SDK for in-app product analytics as described above. This is not a website cookie banner use-case; Mapica’s marketing website does not currently load PostHog.

Where Mapica uses optional analytics, advertising, or tracking technologies that require consent under applicable law, those technologies should not be activated before the required consent has been obtained. Where consent is required, you must be able to refuse or withdraw it as easily as you gave it.

Once you visit an independent travel partner, that partner’s own cookie and tracking choices apply.

Push notifications

If you allow notifications, Mapica may send:

You can disable push notifications through your iOS settings. Marketing notifications, if introduced, will be handled separately in accordance with applicable consent requirements.

How long we keep information

We do not keep personal data for longer than necessary for the purpose for which it was collected.

Unless a longer period is required by law or necessary for a dispute, we apply the following general retention periods:

After the relevant period expires, information is deleted, anonymized, or moved to restricted archival storage where continued retention is legally required.

Account deletion

If you create a Mapica account, you can initiate deletion of your account directly in the app:

Profile → Account → Delete Account

You can also contact privacy@mapica.app for questions concerning deletion.

Account deletion includes deleting or anonymizing associated personal information, except information that we are required or permitted to retain for purposes such as:

Public user-generated content associated with a deleted account will be deleted or anonymized unless there is a lawful reason to retain it.

Your privacy rights

Where the GDPR or similar law applies, you may have the right to:

To exercise your rights, contact privacy@mapica.app. We may request reasonable information to verify your identity.

We will respond without undue delay and normally within one month of receiving your request. Where permitted by law, that period may be extended.

You also have the right to lodge a complaint with the competent data protection supervisory authority, particularly in the EEA country of your habitual residence, place of work, or the alleged infringement.

Automated systems

Mapica may use automated systems to assist with travel recommendations, itinerary organization, content selection, service improvement, and technical moderation.

Mapica does not use solely automated decision-making that produces legal or similarly significant effects on users without an appropriate lawful basis and required safeguards. Local applications are subject to human review.

If Mapica begins sending messages or other personal data to a separate third-party AI provider, this Privacy Policy and relevant in-app disclosures must be updated before that processing begins.

Children

Mapica is not intended for independent use by children under 16. A person under 16 should not create their own Mapica account.

An adult account holder may provide limited information about children traveling with them, such as the number of children or age group, where necessary to prepare an appropriate trip. Please do not provide unnecessary sensitive information about a child.

If we become aware that a child has created an account in violation of our age requirements, we will take reasonable steps to delete the account and related information.

Security

We use technical and organizational measures designed to protect personal information against unauthorized access, unlawful use, alteration, accidental loss, disclosure, and destruction. However, no internet service can guarantee absolute security.

Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will show when the Policy was most recently changed.

If a change materially affects how personal data is used, we will provide additional notice where required by law or appropriate in light of the change.

Contact us