Compliance
Privacy Policy
This Privacy Policy explains how Mapperoni, operated by Canvis Software LLC ("we," "us," or "our"), collects, uses, and protects personal information when you use our platform and services.
1. Who We Are
Mapperoni is a feedback collection platform operated by Canvis Software LLC. For data protection purposes, we act as:
- Data Controller for account holders and website visitors
- Data Processor for Customer Personal Data, including response data collected through customers' projects
Contact: privacy@mapperoni.com
2. Information We Collect
Information You Provide
- Account information: Name, email address, password
- Team information: Organization name, team member details
- Project content: Forms, questions, and configurations you create
- Response data: Information submitted through projects (processed on behalf of project owners)
- Communications: Support requests and correspondence
Information Collected Automatically
- Usage data: Pages visited, features used, timestamps
- Device information: Browser type, operating system, IP address
- Cookies: Session management and preferences (see Section 8)
3. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain services | Contract performance |
| Process transactions | Contract performance |
| Send service communications | Contract performance |
| Respond to support requests | Contract performance |
| Improve our platform | Legitimate interests |
| Ensure security and prevent fraud | Legitimate interests |
| Comply with legal obligations | Legal obligation |
| Send marketing (with consent) | Consent |
4. How We Share Your Information
We do not sell personal information. We share information with service providers that help us operate the Service, including Hetzner (hosting and encrypted backups), Mailgun (transactional email), Stripe (billing), and Mapbox (mapping). A user's browser connects directly to Mapbox when it loads a map. See our Subprocessor List for the current list and processing purposes.
5. Data Retention
- Account data: Retained while your account is active. Account deletion removes the account and authentication tokens. Contributions associated with a deleted account are anonymized rather than deleted where needed to preserve the relevant project's dataset.
- Project and response data: Customer team owners can delete projects or teams, and authorized users can delete individual submissions. Deletion removes applicable active application data; individual submission deletion removes its response and map-feature content and retains a tombstone record.
- Database backups: Encrypted backups may retain deleted data until their normal expiry. The remote backup lifecycle retains up to twelve monthly snapshots, in addition to shorter daily and weekly snapshots.
- Legal and operational retention: We may retain the minimum data needed to comply with law, resolve disputes, enforce agreements, or maintain security.
6. Your Privacy Rights
All Users
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data
European Economic Area (GDPR)
You have the right to:
- Access, rectify, or erase your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your supervisory authority
We process personal information for the legal bases described in Section 3. Where we transfer personal information outside the EEA, we use an appropriate transfer mechanism, such as the Standard Contractual Clauses where applicable.
California Residents (CCPA/CPRA)
Your Rights:
- Right to Know: Request the categories and specific pieces of personal information we collected
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: We do not sell or share personal information for cross-context behavioral advertising
- Non-Discrimination: We will not discriminate against you for exercising these rights
Categories of Personal Information Collected:
- Identifiers (name, email, IP address)
- Commercial information (transaction history)
- Internet activity (usage data)
- Professional information (organization name)
Sources: Directly from you, automatically through the platform
Business Purposes: As described in Section 3
To exercise your rights, contact privacy@mapperoni.com or use account settings.
7. International Data Transfers
We host the production database and encrypted database backups in Germany. Canvis Software LLC is established in California, and its authorized administrator may access Service data from the United States to operate, support, and secure the Service. For Customer Personal Data, the DPA incorporates the EU SCCs where they are required for that transfer. Our providers may process data in other locations as described in the Subprocessor List.
8. Cookies
We use essential cookies for platform functionality. We use Plausible Analytics for lightweight, cookie-free route-visit analytics. It does not host or store Customer project content, form answers, or map data.
Manage preferences in your browser settings.
9. Security
We use HTTPS/TLS for the production Service, application authentication and authorization controls, secure production cookies, and encrypted database backups. Details of the measures relevant to Customer Personal Data are in the DPA.
10. Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us immediately.
11. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or platform notice. Continued use after changes constitutes acceptance.
12. Contact Us
Privacy inquiries: privacy@mapperoni.com
For Project Owners
When you collect responses through Mapperoni, you are the Data Controller for that response data. You are responsible for:
- Providing appropriate privacy notices to respondents
- Ensuring lawful basis for collection
- Responding to data subject requests
- Configuring appropriate data retention
We act as your Data Processor and process Customer Personal Data according to our Data Processing Addendum. If a respondent contacts us directly about data controlled by you, we will direct or forward the request to you unless law requires us to respond.
