Back to Home
GDPR & CCPA Compliant

Privacy Policy

We are committed to protecting your personal data, agency telemetry, and maintaining transparency about how we collect and process information.

1. Overview & Data Controller

This Privacy Policy describes how MAPSCRAPX ("we", "us", or "our") collects, uses, stores, and protects personal data and corporate information when you use our web platform (mapscrapx.com), dashboard, mobile apps, and associated services.

For the purposes of the General Data Protection Regulation (GDPR) and global privacy laws, MAPSCRAPX acts as the Data Controller for your account and billing information, and as a Data Processor for B2B data queried through your authorized search tasks.

2. Information We Collect

We collect information to provide, secure, and improve our services:

  • Account Information: Full name, professional email address, phone number, company name, time zone, and account password hashes.
  • Billing & Payment Information: Payment transactions are handled securely via Merchant of Record partners (PaddleHQ). We do not store raw credit card numbers on our servers.
  • Usage & Telemetry Data: IP addresses, browser types, API execution logs, tool execution timestamps, and credit consumption records for security and quota auditing.
  • Third-Party OAuth Data: When connecting Google Business Profile (GBP) OAuth, we receive access tokens and location management permissions necessary to execute audits on your behalf.

3. How We Use Your Information

We use collected data exclusively for authorized business operations:

  • To initialize and operate your MAPSCRAPX workspace and tools.
  • To process subscription payments, calculate credit quotas, and issue tax invoices.
  • To deliver technical support, security alerts, and system status updates.
  • To prevent fraud, API abuse, or unauthorized automated rate-limit violations.

4. Third-Party Data Processors

We partner with trusted third-party infrastructure providers who adhere to strict data security standards:

PaddleHQ (Merchant of Record)Processes subscription billing, merchant compliance, and tax calculation.
Google Cloud & FirebaseEncrypted user database storage, authentication, and hosting infrastructure.
OpenAI / Anthropic LLM APIProcesses AI content generation prompts without storing training data.
SendGrid / ResendDelivers account verification emails, password resets, and alert notifications.

5. Data Retention & Erasure (Your GDPR Rights)

We retain personal data only for as long as your account remains active or as required by financial auditing laws (up to 7 years for tax invoices).

Under GDPR and CCPA, you have the following rights:

  • Right to Access: Request a copy of all personal data held about you.
  • Right to Erasure ("Right to be Forgotten"): Request full deletion of your account and stored workspaces.
  • Right to Rectification: Edit or update inaccurate account information via Settings.
  • Data Portability: Export your lead lists, report audits, and logs in CSV/JSON format.

6. Security Safeguards

We employ industry-standard security measures including HTTPS 256-bit SSL encryption in transit, AES-256 encryption at rest, two-factor authentication (2FA), IP whitelist filtering, and strict database access controls.

7. Contact Data Protection Officer (DPO)

To exercise your privacy rights or request data erasure, please contact our Data Protection Officer:

Data Officer: Privacy & Compliance Desk

Privacy Email: privacy@mapscrapx.com

Data Requests: support@mapscrapx.com