MapicitoCreate your map

Privacy

Privacy Policy

Mapicito is local-first: your map projects stay in this browser unless you choose cloud sync or start an order that requires server processing.

Effective and last updated: 23 August 2026

1. Controller

The data controller is MSP Trading OÜ, registry code 14623503, Olevi tn 12, 65604 Võru, Võru maakond, Estonia. Privacy questions and requests: svenpedras@gmail.com.

2. Data we process

  • Local projects: map composition, text, markers, routes and settings stored in your browser.
  • Optional account: email address, password hash, sessions and cloud-synced project data.
  • Purchases: opaque buyer identifier, Stripe references, product, amount, currency, billing name and address, optional business tax ID, payment and refund status.
  • Printed orders: name, email, phone, delivery address, selected artwork, print specifications, provider order and tracking status.
  • Security and operations: limited request and error information used for rate limiting, abuse prevention and service reliability.

3. Purposes and legal bases

  • Contract and steps you request before a contract: provide optional account and cloud features, create quotes, take payment, deliver a digital file, produce and ship a poster, and provide order support.
  • Legal obligations: keep accounting and tax records, handle consumer claims, and meet product-safety and other duties that apply to an order.
  • Legitimate interests: prevent fraud and abuse, apply rate limits, keep the service reliable, secure accounts and purchases, and establish or defend legal claims. We balance these interests against your rights, and you may object where this basis applies.
  • Consent: used only where we specifically ask for it. You may withdraw consent at any time without affecting processing that was lawful before withdrawal. Mapicito does not currently use consent for advertising or optional analytics cookies.

An account is optional. If you place an order, the checkout and delivery fields marked as required are necessary to enter into and perform the contract; without them we cannot take payment, supply the file or deliver the poster.

4. Service providers

We use Hostinger for application hosting, Supabase/PostgreSQL for server-side records, Stripe for checkout and payments, and Printify and its selected print provider for production and delivery. Map and place-search requests may be served through OpenStreetMap/OpenFreeMap, Photon/Komoot and Mapterhorn infrastructure. Providers receive only the data necessary for their role and process it under their own applicable privacy terms.

5. Browser storage and cookies

Mapicito uses browser storage for local projects, recovery state and checkout continuity. Essential HttpOnly cookies keep an optional account session or anonymous purchase connected to the correct browser. We do not currently use advertising cookies. Disabling essential storage can prevent saving, payment verification or downloading a purchased file. See the Cookies & Local Storage notice for the current storage categories.

6. Retention

  • Local projects remain until you delete them or clear the browser's Mapicito storage.
  • An account session lasts up to 30 days and an anonymous buyer cookie lasts up to 365 days. Account and cloud projects remain until deletion is requested; residual backup copies are removed as routine backup cycles overwrite them, unless retention is legally required.
  • Rate-limit records are normally removed within two days after the last relevant request.
  • Order, payment and accounting records are retained for the statutory period that applies to the record. Delivery, production and support data is retained for as long as needed to fulfil the order, handle the two-year conformity-claim period, resolve disputes, prevent fraud and meet legal obligations.

When no fixed period applies, we decide retention by the purpose for which the data was collected, the status of the order or account, the likelihood and duration of a legal claim, and mandatory accounting, tax, consumer and product-safety requirements. Our providers may retain their own records under their notices and legal duties.

7. International processing

Some providers may process data outside Estonia or the EEA. Where required, transfers are protected by an adequacy decision, the European Commission's standard contractual clauses or another lawful transfer mechanism. You may ask for information about the applicable safeguard, or a copy where available, by emailing svenpedras@gmail.com; legally protected commercial details may be redacted.

8. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, or withdraw consent where consent is the basis. You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority. Contact svenpedras@gmail.com. We may need to verify the request and may retain records where the law requires it.

9. Automated decisions

Mapicito does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. Payment and production providers may perform automated security or fraud checks under their own privacy notices.

10. Security

Connections use HTTPS. Payment card data is collected by Stripe rather than Mapicito. Server credentials are not sent to the browser, and purchase access is tied to opaque browser or account credentials. No internet service can promise absolute security; please report suspected misuse promptly.

MapicitoPersonal map art, made in Estonia
TermsPrivacyCookiesReturnsShippingContact

© 2026 MSP Trading OÜ · Registry code 14623503 · VAT EE102646430