01
Who we are and what this covers
Maps We Made is an independent travel-mapping product operated under the Maps We Made name ("Maps We Made", "we", "us" or "our"). This Privacy Policy applies to mapswemade.com, our web app, our WhatsApp-assisted account and capture flows, and related support and waitlist communications (together, the "Service").
We determine why and how personal data is processed for the Service. If you have a privacy, account, safety or content concern, contact support@mapswemade.com. General enquiries can be sent to hello@mapswemade.com.
02
The short version
- We collect only the data needed to run your account, maps, trips and stories.
- Precise locations and travel media can be highly sensitive. You control whether content is private, available by link or public.
- We do not sell or rent personal data and do not use it for third-party behavioural advertising.
- We use service providers such as Meta/WhatsApp, Cloudflare and map-data providers to operate the Service.
- You can request access, correction, export or deletion by emailing support.
03
Data we collect
| Category | Examples | Why we need it |
|---|---|---|
| Account and identity | WhatsApp number and platform identifier, display name when available, inviter, account and browser-session identifiers | To create, secure and recover your account and attribute contributions |
| Waitlist and contact | Email address, consent time, source and waitlist status | To administer access and send the updates you requested |
| Places and location | Precise coordinates, place names, addresses, categories, notes, capture time and whether a location came from media or manual input | To place memories on maps and organize trips |
| Media and content | Photos, videos, titles, captions, story covers, file properties and embedded metadata needed for import | To process, display and share the content you choose |
| Trips and collaboration | Membership, roles, invitations, contributors, publication choices, changes and removal records | To let groups build and publish maps together |
| Messages and support | WhatsApp commands and message status, support emails, delivery records and abuse reports | To complete requested actions, reply and investigate problems |
| Technical and activity | IP address, browser/device details, request and security logs, pseudonymous product events, coarse country, aggregate story views/shares and upload status | To deliver, secure, diagnose and improve the Service |
We do not ask for payment-card data today. Please do not upload government identifiers, financial records, health information or other sensitive data that is not needed for a travel map.
04
Where data comes from
We receive data directly from you when you send a WhatsApp message, use the web app, upload media, create a place or trip, publish a story, join the waitlist or contact support. We also receive data from people who invite you or add you to a trip, and from Meta when WhatsApp delivers a message or identity event to us.
When you choose media, the app may read location and capture-time metadata from the file to propose map positions. We do not continuously track your device location in the background.
05
How and why we use data
We use personal data to:
- create and authenticate accounts through invited WhatsApp flows;
- save, organize, process and display places, photos, videos and stories;
- enable invitations, collaboration, sharing and publication;
- send requested service, security, support and waitlist communications;
- prevent spam, fraud, unauthorized access, misuse and security incidents;
- operate uploads, video encoding, backups and content delivery;
- measure aggregate product reliability and story engagement; and
- comply with law, enforce our Terms and protect people and the Service.
Depending on the law that applies to you, we rely on your request or consent, performance of our agreement with you, our legitimate interests in operating and securing the Service, and compliance with legal obligations. You may withdraw consent for future processing where consent is the basis, but that does not undo processing already lawfully completed.
06
Visibility, collaboration and public stories
Maps We Made has different sharing states:
- Private: available only to you and people authorized for the relevant trip or content.
- Link access: available to anyone who receives the link. We do not intend link-only content for search indexing, but recipients can forward, copy or capture it.
- Public: available openly and may be included in our public discovery feed, indexed by search engines, embedded, copied or reshared.
Trip members can see shared-trip content and may add, edit or remove material according to their role. A contributor's media is eligible for a public trip story only after that contributor allows public-story use through the product controls. Review visibility carefully before publishing. If content is already public, changing or deleting it may not remove copies made by other people or search engines.
07
Location and media metadata
Exact coordinates can reveal a home, routine or a person's movements. Before sharing, check every automatically detected location, especially content involving children, accommodation or private property.
We process uploaded files to create web-ready images, thumbnails, video renditions and posters. Shared image renditions are re-encoded without EXIF, XMP or IPTC camera metadata; the location you approve remains stored separately as map data so it can be corrected or removed independently. Source files may be held temporarily while processing and cleanup completes.
10
Retention and deletion
We keep account and map content while your account is active or as needed to provide the Service. Short-lived login, edit, invite and upload credentials expire automatically. Raw WhatsApp message and webhook content is redacted after 30 days once processing is complete; delivery and status-correlation records are removed or redacted after 90 days. A removed waitlist entry is deleted after 30 days.
Cloudflare product-event analytics is retained for up to three months. Persistent Cloudflare Worker request logs are disabled because private request URLs can contain login or invitation capabilities. Aggregate service metrics and sanitized product-operation failures remain available without storing those URLs in the product-event dataset.
Deleting a place immediately withdraws it from maps and published stories, irreversibly removes its text and coordinates, and queues every associated media object for storage cleanup. The Account screen can end one or all browser sessions and permanently delete the account. Account deletion withdraws owned places, trips and contributed media, removes identity aliases, redacts retained message payloads and revokes active sessions and invitations.
Residual encrypted copies may remain for a limited period in backups, delivery caches, security records or legal holds. We may retain non-identifying referential records where necessary to preserve database integrity, prevent fraud, handle disputes, maintain an audit trail or comply with law. Public copies made by others are outside our control.
11
Security and incident response
We use measures designed for the sensitivity of the Service, including encrypted transport, secure and HTTP-only session cookies, hashed or encrypted access tokens, private object storage, authorization checks, rate limits, media isolation and restricted administrative access.
No online service is risk-free. Protect invitation and private-share links, keep control of your WhatsApp account and tell us promptly at support@mapswemade.com if you suspect unauthorized access. If a breach creates a risk requiring notice, we will notify affected people and authorities as required by applicable law.
12
Your choices and rights
Depending on where you live, you may have rights to know what data we hold, access it, correct it, obtain a copy, erase it, restrict or object to processing, withdraw consent, nominate another person to exercise rights, or complain to a data-protection authority.
Use Account in the app to sign out or delete the account, or email support@mapswemade.com from an address you control. Because accounts are tied to WhatsApp identity, we may ask you to verify control of that account before acting. Tell us the request and the relevant WhatsApp number, email, trip or public link. We will respond within the period required by applicable law.
To leave the waitlist or stop waitlist updates, email support. Service and security messages may still be sent when necessary to run an active account.
13
Children
The Service is intended for adults and is not designed for children to hold their own accounts. Do not create an account if you are under 18 or the age required to enter a binding agreement where you live.
A parent or guardian who uploads media featuring a child must have the right to do so and must consider whether publishing the child's face, routine or exact location is safe. If you believe a child's data was provided improperly, contact support so we can investigate and remove it where appropriate.
14
International processing
Maps We Made and its providers may process data in India and other countries where they operate. Those countries may have different data-protection laws. Where required, we use contractual, technical or organizational safeguards and follow applicable restrictions on cross-border transfers.
15
Changes and contact
We may update this Policy when the product, providers or law changes. We will post the revised date here and give additional notice through the Service, email or WhatsApp when a change is material and notice is required.
Privacy, grievance, account, safety and takedown requests: support@mapswemade.com
General enquiries: hello@mapswemade.com