Legal · Effective April 21, 2026
Privacy Policy
Also see Terms of Service.
This Privacy Policy explains how Mapbase, Lda. (“Mapbase”, “we”, “our” or “us”) collects, uses and shares personal data when you visit mapbase.dev, create an account, or use our products and services (the “Service”). We are the controller of personal data processed in connection with the Service, for purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
01Who we are
Controller: Mapbase, Lda.
Address: Lisboa, Portugal
Contact: [email protected]
02Information we collect
We collect personal data in three ways:
a. Information you provide. When you create an account, contact us or subscribe, you may provide your name, email address, company name, role, and any other details you choose to share.
b. Information collected automatically. When you use the Service, we and our providers automatically collect log data (IP address, user agent, timestamps), device and browser information, approximate location (from IP) and interaction data (pages viewed, links clicked, API calls made).
c. Information from third parties. We receive information from our payment processor, analytics providers and identity providers when you interact with those services through Mapbase.
03Payment data (Stripe)
Subscriptions are billed through Stripe, Inc. (and its affiliates). When you enter payment details, they are submitted directly to Stripe; we receive a tokenized reference, the last four digits of the card, the card brand, the billing country and transaction metadata. We never receive or store full card numbers.
Stripe acts as an independent controller for fraud prevention and regulatory compliance, and as our processor for executing payments. Stripe’s privacy notice is available at stripe.com/privacy.
04Analytics and cookies (Google Analytics)
We use Google Analytics 4 (provided by Google Ireland Ltd.) to measure traffic to mapbase.dev and understand how visitors engage with our marketing pages. Google Analytics sets cookies and similar identifiers that may collect information about your device, browser, pages viewed, referrer and approximate location (from IP).
We configure Google Analytics with IP anonymization enabled and have disabled advertising features (Google Signals, remarketing lists and advertising reporting). We do not use Analytics data to build user profiles across sites.
Where required by law (including for visitors in the EU, EEA, UK and Switzerland), we only set non-essential cookies — including Google Analytics — after you provide explicit consent via our cookie banner. You can withdraw your consent at any time from the Cookie settings link in our footer, or by clearing cookies in your browser.
Types of cookies we use:
- Strictly necessary. Session, authentication and security cookies required for the Service to function.
- Analytics. Google Analytics (_ga, _ga_*) — measure traffic and improve the product. Consent-based in the EU/EEA/UK.
- Preferences. Remember UI settings such as theme or language.
05How we use personal data
We process personal data for the following purposes:
- Providing, operating and securing the Service;
- Authenticating users and managing accounts;
- Processing subscriptions, invoices and payments;
- Communicating with you about your account, updates and security notices;
- Understanding how the Service is used and improving it;
- Preventing fraud, abuse and violations of our Terms;
- Complying with legal obligations (including tax and accounting);
- With your consent, sending product news and marketing emails (you can unsubscribe at any time).
06Legal bases (GDPR)
Under the GDPR, we rely on the following legal bases:
- Contract — to provide the Service you request and process your subscription.
- Legitimate interest — to secure the Service, prevent abuse, analyze aggregate usage, and defend legal claims.
- Consent — for non-essential cookies and marketing emails. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — to comply with tax, accounting and other applicable laws.
07Sharing and sub-processors
We share personal data only with vetted service providers that act on our instructions, under data processing agreements, and with appropriate safeguards. Our current sub-processors include:
- Stripe, Inc. — payment processing and subscription billing.
- Google Ireland Ltd. — website analytics (Google Analytics 4).
- Vercel, Inc. — application hosting and edge delivery.
- Supabase / PostgreSQL providers — database hosting for application data.
- Transactional email providers — for account and system emails.
We also disclose personal data where required by law, in response to valid legal process, or to protect our rights, property or safety and that of our users.
08International data transfers
Some of our providers (including Stripe and Google) may process personal data outside the European Economic Area. Where that is the case, we rely on appropriate safeguards — including the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework — to ensure an adequate level of protection.
09Data retention
We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this Policy. Specific retention periods include:
- Account data: for the life of your account, and up to 12 months after closure.
- Billing and invoice data: retained for up to 10 years, as required by accounting and tax laws.
- Request logs and API metrics: typically 90 days, then deleted.
- Analytics data: up to 14 months, following Google Analytics 4 default retention.
10Your rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your personal data, subject to legal retention obligations;
- Restrict or object to certain processing;
- Portability — receive your data in a structured, machine-readable format;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your local data protection authority (for EU residents, the authority in your country of residence).
California residents have additional rights under the CCPA/CPRA, including the right to know, delete and correct personal information, and the right to opt out of the “sale” or “sharing” of personal information. We do not sell personal information as defined under the CCPA.
11How to exercise your rights
Send an email to [email protected] with a short description of your request. We will respond within 30 days. We may need to verify your identity before acting on a request.
12Security
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure or destruction — including encryption in transit (TLS), encryption at rest, principle-of-least-privilege access controls and audit logging. No system is 100% secure; in the event of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.
13Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email. The “Effective” date at the top indicates when the latest version was published.
15Contact
Questions about this Policy or our privacy practices? Contact us at [email protected].