Mappinest iconMappinest wordmark
Loading account...

Privacy Policy

Last updated: August 3, 2026

1. Who controls your personal data

Mappinest, vl. Boris Vitlic, Ekonomija 7, 21325 Tucepi, Split-Dalmatia County, Croatia, is the data controller for personal data processed through the Mappinest website, customer accounts, billing, support, and direct use of the Services and Products.

You can contact us about this Privacy Policy or the use of your personal data at info@mappinest.com.

When a customer decides why and how personal data in Customer Content is used, the customer is the controller and Mappinest processes that data on the customer's instructions. The parties must put any legally required data processing agreement in place before that processing begins.

2. Personal data we process

Depending on how you use Mappinest, we may process the following information.

  • Account and identity data, including your email address, username, full name, organization, password hash, and two-factor authentication settings.
  • Profile and billing data, including your billing address, country, tax details, purchase order or invoice notes, plan, invoices, and Stripe customer or subscription identifiers.
  • Service configuration, including API key names, types, scopes, permitted domains and resources, and uploaded file metadata and processing status.
  • Customer Content, including uploaded tilesets, map styles, files, metadata, and other material that you choose to store or process through Mappinest.
  • Service usage and technical data, including requested endpoints and resources, request counts, dates and times, account or API key associations, IP addresses, country derived from an IP address, referring domain, user agent, browser and device category, response status, and security or operational logs.
  • Communications, including contact form fields, support requests, and other messages you send to us.
  • Browser data needed to operate the website, including authentication and security cookies, cookie preferences, and similar local browser storage.

Passwords are stored as cryptographic hashes. Mappinest does not store the full payment card details that you enter through Stripe.

Do not upload sensitive personal data unless it is necessary, lawful, and protected by appropriate contractual and security measures.

3. Why we process personal data

Providing the service

We process account, service configuration, Customer Content, usage, communication, and billing data to create and secure accounts, authenticate requests, host and deliver map content, show usage information, provide support, administer subscriptions, and process payments. This processing is necessary to enter into or perform a contract with you or the organization you represent.

Operating and protecting Mappinest

We process technical and usage data to operate the platform, prevent abuse, investigate incidents, debug failures, improve reliability, understand service capacity, enforce our Terms, and protect legal claims. We rely on our legitimate interests in providing a secure and reliable service. Where required, we balance those interests against the rights of affected individuals.

Meeting legal obligations

We process information required for accounting, taxation, payment records, lawful requests, and other obligations imposed by applicable law.

4. Cookies and browser storage

Mappinest uses essential cookies and similar browser storage to keep you signed in, refresh sessions, protect requests against cross-site request forgery, remember privacy choices, and support account convenience features. These technologies are required to provide the website and secure customer accounts.

Mappinest currently uses only essential cookies and browser storage for these purposes. We do not use advertising trackers or analytics tools that follow people across websites. If optional analytics or advertising technologies are introduced, we will update this Privacy Policy and request consent where required.

You can clear cookies and local storage through your browser. Removing essential data may sign you out or prevent parts of the service from working correctly.

5. Customer Content and map request data

We process Customer Content only as needed to receive, validate, convert, store, cache, back up, transmit, display, and delete it while providing and securing Mappinest. The service providers listed below may support that processing. We do not sell Customer Content or use it for targeted advertising.

Requests made by a customer's map users may generate technical records such as IP address, request time, requested resource, referring domain, user agent, response status, and related security information. Mappinest uses these records for delivery, security, troubleshooting, usage analytics, rate limits, and billing where applicable.

Customers are responsible for providing any privacy notice and legal basis required for personal data they upload or cause Mappinest to receive through their applications. Customers should configure API keys, domain restrictions, and access permissions appropriately for their use case.

6. Service providers and international transfers

We share personal data only when needed to provide or secure Mappinest, comply with the law, or protect legal rights. Recipients may include the following providers and categories.

  • Vercel for website hosting and delivery.
  • Amazon Web Services for cloud infrastructure, databases, object storage, content delivery, queues, and operational logging.
  • Zoho for transactional and support email services.
  • Stripe for subscription and payment processing when paid billing is used. Stripe receives payment details directly and processes them under its own privacy terms where it acts as an independent controller.
  • Professional advisers and contractors who need the information for their work and are subject to confidentiality and data-protection obligations.
  • Courts, regulators, tax authorities, law-enforcement bodies, or other public authorities when disclosure is legally required.

Some providers may process personal data outside Croatia or the European Economic Area. A transfer to a country without an adequacy decision must be covered by another lawful safeguard, such as the European Commission's Standard Contractual Clauses where applicable.

You can contact us for information about the providers and transfer safeguards relevant to your personal data.

7. How long we keep personal data

We keep personal data only as long as needed to provide and secure Mappinest, meet legal obligations, resolve disputes, and enforce agreements. The main retention rules are set out below.

  • Account and service data is retained while the account is active. Relevant records may remain after closure where needed for security, billing, legal compliance, or claims.
  • Customer Content is retained while the customer stores it through Mappinest. After deletion or account closure, copies may remain temporarily in caches, backups, or recovery systems until they are overwritten or expire under normal retention cycles.
  • Operational, security, and usage records are retained as needed for security, customer analytics, billing reconciliation, abuse prevention, and legal claims. Aggregated records may be kept longer than raw logs.
  • Billing, invoice, payment, and tax records are retained for the period required by applicable accounting and tax law.
  • Support and contact communications are retained while needed to answer the request, maintain the customer relationship, or establish, exercise, or defend legal claims.

We delete or anonymize personal data when it is no longer needed, unless the law requires continued retention.

8. Security and personal data breaches

We use technical and organizational measures appropriate to the risks of the processing. These include encrypted network connections, cryptographic password hashing, access controls, authentication safeguards, logging, monitoring, and backup or recovery measures where applicable. No online service can guarantee absolute security.

If a personal data breach occurs, we will investigate it and notify the competent supervisory authority within the legally required period where notification is required. We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms or where the law otherwise requires notice.

9. Your data protection rights

Subject to the conditions and exceptions in applicable law, you may ask us to do the following.

  • Provide access to your personal data and information about its processing.
  • Correct inaccurate or incomplete personal data.
  • Delete personal data that we no longer have a lawful reason to retain.
  • Restrict processing in the circumstances provided by law.
  • Object to processing based on legitimate interests or to direct marketing.
  • Provide eligible data in a structured, commonly used, machine-readable format or transfer it to another controller where technically feasible.
  • Withdraw consent where processing is based on consent.

Mappinest does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.

To exercise a right, email info@mappinest.com. We may need to verify your identity before acting on the request. We will respond within the period required by applicable law.

You may also complain to the Croatian Personal Data Protection Agency (AZOP) or the supervisory authority in the EU or EEA country where you live, work, or believe an infringement occurred.

10. Children

Mappinest is not directed to anyone under 18. If you believe that a person under 18 has provided personal data to us, contact us so that we can review and delete it where appropriate.

11. Changes to this Privacy Policy

We may update this Privacy Policy when our services, providers, or legal obligations change. We will publish the revised version with a new date. If a change materially affects registered users or how we process their personal data, we will provide additional notice through the service or by email where appropriate.

Mappinest, vl. Boris Vitlic
Ekonomija 7
21325 Tucepi, Split-Dalmatia County
Croatia
OIB: 95035095107
VAT ID: HR95035095107
Established: May 30, 2022
Email: info@mappinest.com