Privacy

Privacy Policy

This Privacy Policy explains how Mappy collects, uses, stores and protects information when you use the route planning application, create an account, sign in with Google, validate addresses, contact us, or save routes.

Last updated: September 11, 2026

Information we collect

Account data: email address, display name, profile image/avatar if provided by Google, preferred language, selected theme and account status.

Authentication data: secure session identifiers stored in HttpOnly cookies, hashed session tokens, basic security metadata such as hashed IP address and hashed user agent, readable session device labels, approximate country code when available, and login timestamps.

Route data: addresses you import or enter, validation status, coordinates and formatted addresses returned during geocoding, route zones, route history, and the number and last time a saved address list is loaded into the planner. Saved routes stored in your account retain the address text needed for later revalidation, not provider coordinates or completed route geometry.

Local alias data: if you explicitly save a confirmed address alias, Mappy stores the label you entered and the address you confirmed in this browser local storage so future validation can try the confirmed address first. In v1 this alias data is not uploaded to Mappy servers.

Public business alias data: Mappy may maintain a server-side registry of public business or place aliases, sourced from official public pages or manual review, so common company/location names can resolve to factual business addresses before external geocoding. This registry is not built from private address books or Google user data.

Contact data: your name, email address and message when you send us a message through the contact form.

Technical data: browser/device information normally sent with web requests, rate-limit counters and basic operational logs. Mappy does not load Google Analytics. When Google AdSense is enabled on eligible public content pages, advertising-related technical data is sent to Google as described below. Operational logs do not intentionally include OCR images.

Google sign-in data

If you choose “Continue with Google”, Mappy requests only the minimum data needed to sign you in: your Google account identifier, email address, name and profile picture when provided by Google. We use this data only to create or access your Mappy account, link your Google identity to your account, display your profile and secure your sessions.

Mappy does not request access to Gmail, Google Drive, Google Calendar or Google Contacts. We do not sell Google sign-in data, use it for advertising, or share it with third parties except as necessary to operate the user-facing account feature or comply with legal obligations.

Address validation and geocoding providers

When you validate addresses, Mappy may send the address text and relevant location hints to third-party geocoding providers so the application can verify addresses, return coordinates, show pins and create route zones. Providers may include HERE, Geoapify, TomTom, OpenStreetMap/Nominatim, Photon, MapTiler and, only if enabled in the production configuration, Google Maps Platform.

Mappy uses geocoding results only for the route planning features visible in the application. We do not resell geocoding results as a dataset.

Mappy may send the address you entered to Geoapify for a background check and obtain a new location independently of an earlier provider result. We do not send delivery notes or use earlier HERE/Google coordinates as the reference for that check. An uncertain result may require you to correct or complete the address.

Geoapify processes API requests under its Privacy Policy: https://www.geoapify.com/privacy-policy/.

Camera OCR and AI transparency

The camera scanner uses automated Tesseract.js optical character recognition (OCR) in your browser to read printed address text. The captured frame and recognized text are not sent to Mappy servers for OCR; Tesseract language/model files may be downloaded when the scanner is first used. You can review and edit the result and must confirm it before the address is added. A confirmed address may then be sent to the geocoding providers described above for validation.

The current Mappy release does not use a chatbot or generative AI to create route advice or automatically publish public text. Long-text address extraction uses deterministic rules. Public, help and legal content is human-reviewed and published under Mappy editorial responsibility. If future in-scope generative output is displayed or published, Mappy will provide a clear disclosure at first exposure and preserve applicable machine-readable provenance or marking.

How we use information

We use information to provide account login, saved routes, route history, address validation, delivery workflow, profile settings, support replies, abuse prevention, troubleshooting, security and service improvement.

Legal bases and your rights

Where applicable, account and saved-route processing is necessary to provide the features you request; security and abuse-prevention records rely on Mappy’s legitimate interest in operating a safe and reliable service; support data is used to answer your request; consent or a legal obligation is used where the law requires it.

Depending on the law that applies to you, you may request access, correction, deletion, restriction, objection or portability, and withdraw consent without affecting earlier lawful processing. You may also complain to the Personal Data Protection Agency in Bosnia and Herzegovina or another competent supervisory authority. Use the contact page so we can verify and respond to the request.

International availability and regional rights

Mappy can be accessed from many countries, but technical availability alone does not make every privacy law apply in the same way. Scope depends on factors such as the controller’s establishment, whether a service is actively offered to or monitors people in a region, the processing involved and statutory thresholds.

Our compliance review covers Bosnia and Herzegovina, the EU/EEA and EU AI rules, the United Kingdom, applicable United States federal and state rules, Canada, Brazil, Australia, Japan, India and South Africa, plus other local rules when the product actively enters or targets a market. This list does not limit any rights granted by applicable law.

Where an applicable U.S. state law provides them, you may have rights to know or access, correct and delete personal information, obtain a portable copy, opt out of sale, sharing or targeted advertising, limit certain uses of sensitive information, and appeal a denied request. Mappy does not sell account, route, contact or Google Sign-In data. AdSense processing on eligible public content pages may be treated as sharing, sale or targeted advertising under some laws. For users in applicable U.S. states, Google receives Global Privacy Control signals directly and applies restricted data processing to those ad requests.

Advertising, analytics and cookies

Mappy does not load Google Analytics. Google AdSense may be enabled only on eligible public content pages in English, German and Spanish. It is not loaded on the route planner, account/profile, saved-route, admin, legal, contact, about or Bosnian-language pages. Strictly necessary account-session cookies and local browser settings remain separate and may still be used to provide features you request.

When AdSense is enabled, the browser may send Google the page URL and IP address, and Google may use cookies, web beacons or other identifiers to deliver and measure ads, prevent fraud and, where permitted by the user’s choices, personalize ads. Mappy does not add imported addresses, route contents or IDs, coordinates, account/profile fields, contact messages or Google Sign-In data to AdSense requests. Learn how Google uses data from partner sites at https://policies.google.com/technologies/partner-sites and review Google’s Privacy Policy at https://policies.google.com/privacy.

Mappy uses privacy-minimised first-party product analytics to count site-wide daily active registered accounts, estimate daily unique guest devices, count page views by a fixed page category and count a limited allowlist of planner actions. The page category is resolved before the request, so raw paths, query strings and route IDs are not sent. The server creates a date-specific HMAC from the account ID or request metadata and stores only the daily hash, audience category and aggregate event counts, without an analytics cookie or browser identifier. Product analytics does not store raw IP addresses, full user-agent strings, imported addresses, route contents, coordinates or GPS data.

For users in the EEA, United Kingdom and Switzerland, Mappy uses Google’s certified consent management platform with the IAB Transparency and Consent Framework before personalized advertising or advertising storage that requires consent. Users can refuse or manage choices and later reopen Google’s privacy and cookie settings without losing access to the core planner. For users in applicable U.S. states, Google’s regional controls and Global Privacy Control handling apply. Google Analytics and Google Ads conversion measurement remain disabled unless this Policy and the consent configuration are updated again.

Google controls retention of its advertising cookies and logs under Google’s policies and the user’s settings. Mappy may receive aggregated AdSense reporting, but does not copy Google advertising identifiers into Mappy accounts or saved routes.

Storage and retention

Account data is kept while your account is active. If you delete your account, we deactivate the account, revoke active sessions and remove or anonymize personal account fields where possible.

Saved address lists and their usage count/last-used timestamp remain available to your account until you delete the route or delete your account. Mappy stores the original entered addresses for later use, but does not persist geocoding-provider coordinates, formatted provider responses, zones or coordinate-bearing navigation links in saved routes. Addresses are revalidated when you load a saved list. Operational logs and rate-limit records are kept only as needed for security and reliability.

Daily product-analytics hashes and aggregate event counts are retained for up to 90 days. Because guest hashes rotate each day, they are not used to build a cross-day guest profile.

Aliases you enter and confirm yourself remain in this browser until you clear site data. Google geocoding results are not saved as reusable aliases; older Google aliases are removed when the alias store is read.

Public business aliases are time-limited and periodically revalidated or disabled because companies may move, close or update their locations.

New HERE/Google coordinates can be used for the active validation session, subject to the provider’s display rules. They are not retained as reusable results in Mappy’s shared address cache or local drafts. Original address inputs awaiting an independent check are kept for up to 90 days from entry into that queue. Accepted Geoapify results may be cached for later route planning under the applicable source licences, until corrected or removed.

Google controls retention and deletion of AdSense advertising data under its own policies and user controls. Clearing site cookies or changing Google privacy settings can remove or limit browser-side advertising identifiers; Mappy account deletion does not delete data controlled independently by Google.

Data deletion

Password-based accounts can delete saved routes and use Delete account from the profile page. Google-only accounts, or users who cannot access the self-service control, can request deletion through the contact page. Once verified, account deletion also removes the Google identity link stored by Mappy.

Include the email address connected to the account so we can verify and process the request. Local browser data must be removed separately by clearing Mappy site data in the browser.

The shared address cache and background validation queue are separate from account records. To request removal of an address from them, use the contact page and identify the address concerned. Deleting an account alone does not identify every shared cache entry.

Security

Mappy uses HTTPS, HttpOnly secure cookies for account sessions, hashed session tokens in the database, rate limiting, CORS restrictions and security headers. No method of transmission or storage is perfect, but we take reasonable steps to protect user data.

Your choices

You can use the core route planner without creating an account. You can update profile preferences, change your password, sign out from sessions and delete saved routes from the profile page. Password-based accounts can also use the self-service account deletion control; Google-only accounts can submit a verified request through the contact page.

You can choose not to save address aliases. If you saved aliases locally, you can remove them by clearing browser or app data for Mappy.

Where advertising is enabled, you can refuse or change optional advertising choices through Google’s consent message or privacy and cookie settings without losing access to the core planner.

Contact

For privacy questions or data deletion requests, contact us through the contact page or by using the email address shown there.