Privacy Policy — MapA

Last updated: 2026-09-13

You can read this text in Italian or English.

1. Who we are

MapA (Android app and website, package com.drao.mapa) is a map of events and points of interest organised in groups. This policy explains what data we process, why, and who we share it with.

The app is not directed at children under 16. We do not knowingly collect data from children.

2. Data we process

Account: username, email address, password (stored in protected form by the authentication provider), user ID. If you sign in with Google, we receive the identifiers Google needs for login (email and Google account ID).

Profile and groups: active group, roles, memberships, join requests.

Content you post: title, address, notes, link, category, expiry, and coordinates of the event or point of interest.

Device location: precise and approximate location only while you use the app and only if you grant permission, to centre the map and to geocode addresses. We do not track location in the background. We do not keep a history of your location as a profile; if you create an event, the pin coordinates (which may match where you are) stay on that event.

Notifications: if you enable them, a device token (FCM on the native app or a Web Push subscription in the browser) so we can send reminders 48 and 24 hours before events expire.

Technical data: UI language, usage and performance diagnostics via hosting services (pages viewed, load metrics). IP address is processed by hosting, database and map providers as part of HTTPS traffic.

3. Why we use it

To provide your account, groups and the map (performance of the service).

To show the map and addresses (location, with your system permission).

To send the reminders you enabled (notification permission).

Security, abuse prevention and legal obligations.

To see whether the app works (hosting / diagnostics).

4. Sharing

We do not sell your data and we do not show ads.

Supabase: accounts, profiles, groups, events, notification tokens.

Google: Google sign-in (if you use it) and Firebase Cloud Messaging for Android push.

Mapbox: map tiles; may receive coordinates to render the view.

Geoapify: address search and geocoding.

Vercel: website hosting, and analytics / performance measurement if enabled on the web.

These providers process data on our behalf or as independent controllers under their own policies, including on servers outside the EEA where their contracts provide appropriate safeguards.

5. Retention

Account data and content are kept while the account is active, unless a longer legal retention applies (for example security or disputes).

If you delete your account, we delete the auth user and cascaded data (profile, memberships, push subscriptions). Groups you owned remain without an owner; events already posted in a group may stay visible to other members.

6. Security

Traffic between the app, the site and providers uses HTTPS. Application data access is filtered by database policies (RLS) based on the signed-in user and their groups.

7. Your rights

You may request access, correction, restriction, objection, portability and deletion, within applicable law (GDPR if you are in the EEA/UK).

For questions about privacy or terms, use the contact email on the MapA Google Play listing.

You can delete your account and associated data from Settings → Delete account in the app, or from this site’s Delete account page (/delete-account). This is permanent.

8. Android permissions

Internet: required for the app to work.

Location (precise and approximate): foreground only, to centre the map. We do not use background location.

Notifications: only if you enable them, for event reminders.

9. Changes

If we change this policy in a material way, we will update the date at the top of this page. Continued use after a change means you have seen the update, unless law requires otherwise.

Privacy Policy · Terms of Use · Delete account