Privacy Policy
This policy is not yet final: the bracketed values below are decisions that
have not been made. It is published in draft so the terms of the service are
visible before purchase.
Who we are
MapIT is a premium map service for Garmin watches, operated by Benjamin Hall ("Kloof Apps", "we", "us"), a sole trader (Einzelunternehmen) established in Germany, at [REGISTERED ADDRESS].
We are the data controller for the information described here.
For any privacy question, or to exercise any right below, contact [PRIVACY CONTACT EMAIL].
The short version
MapIT is run by one person, and collects about as little as a paid service can.
There is no account. Your name is never asked for, card details never reach me, and where you go is not tracked. What is held is a code identifying your watch, a record of what you paid for, and — only if you tick the box — your email address.
The rest of this page is the formal version. "We" below means the company named above, which is the legal entity responsible for your data; in practice that is still one person.
A device identifier
Your watch generates a short code (twelve characters, like ABCD EFGH JKMN) derived from its Garmin device identifier. This is how we know which watch a licence belongs to. We never receive the underlying Garmin identifier — it stays on the watch.
- Why: it is the only thing connecting your payment to your watch.
- Lawful basis: performance of our contract with you.
- Kept: for as long as the licence exists, then [RETENTION: EXPIRED LICENCE PERIOD] after it expires.
Which days you used the app
When your watch checks its licence, we record that it was active on that day — the date only, never a time. Over a week that becomes "active on four days", and nothing finer.
- Why: to know whether people who buy MapIT actually use it. Without it the first sign that something is wrong is a renewal that does not happen, twelve months too late.
- Lawful basis: our legitimate interest in understanding whether the service works.
- Kept: with the licence, and removed when you ask us to delete your data.
Which days you looked at the price
If you open your activation page and it shows you a price, we record that your watch saw it on that day. Looking twice in one day is recorded once.
- Why: so we can tell the difference between "people see the price and decide against it" and "people never find the page at all". Those need opposite fixes, and without this we would be guessing.
- Lawful basis: our legitimate interest in understanding why people do or do not buy.
- Kept: 90 days, then automatically erased. This is the only thing we record about browsing rather than about the service you hold, so it has a deliberately short life.
We do not track you across the site, and there is nothing here about which pages you read or how long you spent — only whether a price was shown to your watch's activation page on a given day.
Your email address — only if you ask us to
When you buy MapIT, Stripe collects an email address to send your receipt. We offer a tickbox to store that address against your licence. It is unticked by default, and we do not store the address unless you tick it.
- Why: a MapIT licence is tied to a watch, not to an account. If your watch breaks or you replace it, an email address is the only way we can find your licence and move it across. We also use it to remind you before your access expires.
- Lawful basis: consent. You can withdraw it at any time.
- Kept: until you remove it, or the licence is deleted.
- We never sell or share it, and we do not send marketing unless you separately opt in.
Payment records
Payments are processed by Stripe, which acts as the merchant of record. Your card details go directly to Stripe and never reach our systems.
We store a reference to the payment, the amount, the currency, the date, and which service year it covers.
- Why: to know what you are entitled to, to handle refunds and support, and to meet our accounting and tax obligations.
- Lawful basis: performance of our contract, and legal obligation for the accounting records.
- Kept: ten years from the end of the calendar year in which you paid, as required by German tax law. This applies even if you ask us to delete everything else — we will erase the rest and keep only the payment record until that period expires.
A device name, if you set one
Optional, and only for your own convenience in the management portal. Stored on consent, and removable at any time.
Technical logs
Our servers record IP addresses and request metadata to detect abuse and diagnose faults.
- Lawful basis: legitimate interests — keeping the service available and preventing fraud.
- Kept: [RETENTION: LOG PERIOD].
We deliberately strip device identifiers, email addresses, and payment credentials from our logs before they are written.
What we deliberately do not collect
- No GPS tracks, routes, or location history.
- No record of which map tiles you view. Your watch requests map tiles directly from our map provider, so those requests do not pass through our servers. We could not build a picture of where you have been even if we wanted to.
- No card details, ever.
- No advertising profiles, and no advertising trackers.
- No account, and no name, postal address, or phone number.
Cookies
MapIT's website uses no non-essential cookies and no analytics trackers.
The payment form is provided by Stripe and runs inside a secure frame on our page. Stripe sets cookies necessary for processing your payment and preventing fraud.
Who else processes your data
| Who | What they do | Where |
|---|---|---|
| Cloudflare | Hosting, database, DNS, and inbound email routing | Our database carries an EU jurisdiction constraint, so your licence, payment and contact details are stored in EU data centres |
| Scaleway | Sending verification and service email | French company, hosted in the EU |
| Stripe | Payment processing, as merchant of record | Contracts with EU customers through its Irish entity |
| [ERROR MONITORING] | Diagnostics | [MUST OFFER AN EU REGION] |
| [MAP PROVIDER] | Serving map tiles to your watch directly | Receives requests from your watch, not from us |
Each has a data processing agreement with us. Where data leaves the EEA, it is covered by Standard Contractual Clauses or an equivalent safeguard.
Your rights
You have the right to access, correct, export, and delete your data, to withdraw consent for your email address or device name at any time, to object to processing based on legitimate interests, and to complain to your national data protection authority.
Most of these you can do yourself in the management portal. For anything else, email [PRIVACY CONTACT EMAIL] and we will respond within one month.
One honest limitation: because MapIT has no accounts, we can only connect you to your data through your device code or a verified email address. If you have neither, we may not be able to identify your records — which is a consequence of collecting as little as we do.
Children
MapIT is not directed at children under 16, and we do not knowingly collect their data.
Changes
If we change this policy materially we will update the date above and, where we hold a verified address and the change is significant, tell you by email.
Contact
Benjamin Hall, [REGISTERED ADDRESS] — [PRIVACY CONTACT EMAIL]
Supervisory authority: [LANDESDATENSCHUTZBEHÖRDE FOR THE LAND OF THE REGISTERED ADDRESS]