Privacy Policy
Last updated: 14 September 2026
Contents
- Who is responsible
- Short version
- What we collect and why
- What stays on your device
- The extension’s permissions
- Legal bases
- Cookies and analytics
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights
- Data you collect about others
- Children
- Changes to this policy
- Contact and complaints
1. Who is responsible
MapContacts is operated by Anton Prokopets, a sole proprietor at Grafska 4A, Nizhyn 16600, Ukraine. For the personal data described in this policy, we are the controller.
Privacy enquiries: privacy@mapcontacts.net. We answer within 30 days, usually sooner.
2. Short version
- We collect the minimum needed to run accounts and subscriptions: your email address, your plan, and technical logs.
- The business listings you collect with the extension never reach us. They are processed in your browser and stored on your device.
- We never sell personal data, and we run no advertising or tracking network.
- Card details are handled by Paddle, our payment processor and merchant of record. We never see them.
3. What we collect and why
Account data
Your email address, a hashed authentication identifier or the identifier from the sign-in provider you choose, your display name if you give one, your plan and subscription status, and your licence key. We use this to create your account, to tell the extension whether your subscription is active, and to contact you about the Service.
Billing data
When you buy a plan, Paddle collects and processes your payment details as merchant of record. We receive from Paddle only what we need to run the subscription: the transaction and subscription identifiers, the plan bought, the amount and currency, the billing country, the last four digits and brand of the card, and the invoice status. We never receive your full card number, CVC or bank credentials.
Usage and licence data
When the extension checks your licence, our server records the licence key, the time of the check, the extension version, and the IP address the request came from. We also count how many rows you have exported in the current billing period. This is how we enforce plan limits and detect licence sharing and abuse. We do not log your search queries or the contents of what you collect.
Support correspondence
If you write to us, we keep the message, your address and our reply so we can handle the issue and any follow-up.
Website server logs
Our web server records requests to mapcontacts.net: IP address, timestamp, URL, referrer, user agent and response status. These logs exist for security and for diagnosing faults.
4. What stays on your device
Everything the extension collects — business names, addresses, phone numbers, websites, opening hours and the rest of the listing fields — is written to local extension storage in your own browser. It is not transmitted to us, to any analytics service, or to any third party.
You can clear that local database from the extension at any time, and uninstalling the extension removes it. Because we never hold a copy, we cannot restore it for you if you delete it.
Exported CSV and XLSX files are written by your browser to your own filesystem. We have no access to them.
5. The extension’s permissions
The extension asks only for the browser permissions it needs to do its job: access to the map search pages you use it on, so it can read the listings the page displays; local storage, so collected rows survive a page reload; downloads, so it can hand you the exported file; and network access to our own licence endpoint. It does not read pages you have not activated it on, and it injects no advertising and no third-party scripts.
6. Legal bases
Where the EU or UK GDPR applies, we rely on:
- Performance of a contract — creating and running your account, validating your licence, taking payment, providing support.
- Legitimate interests — keeping the Service secure, preventing abuse and licence sharing, diagnosing faults, and maintaining server logs. We limit these to what is necessary and balance them against your interests.
- Legal obligation — keeping tax and accounting records of transactions.
- Consent — only if you opt in to product-update emails. You can withdraw it at any time with the unsubscribe link; it does not affect service emails such as receipts or security notices.
7. Cookies and analytics
The marketing pages of this website set no cookies and load no third-party scripts, fonts or pixels. There is no Google Analytics, no advertising tag and no cross-site tracking anywhere on this site.
Once accounts are live, the signed-in area will set a strictly necessary session cookie to keep you logged in. That cookie is required for the Service to function and is not used for advertising or profiling.
8. Who we share data with
We do not sell or rent personal data, and we do not share it for advertising. We use a small number of service providers, each bound by a data processing agreement and each given only the data it needs:
| Provider | Role | Data involved |
|---|---|---|
| Paddle.com Market Limited (Ireland / UK) | Payments, merchant of record, invoicing, tax | Name, email, billing address, payment details, transaction history |
| OVH (EU) | Server hosting for the website and licence API | Everything stored server-side, plus server logs |
| Cloudflare, Inc. (US/EU) | DNS, reverse proxy, and inbound email routing | IP address and request metadata; inbound email to our addresses |
| Supabase (EU region) | Authentication and account database | Account data, plan and licence records |
| Brevo (EU) | Transactional email delivery | Email address and message content of service emails |
We may also disclose data where we are legally required to, or to establish or defend a legal claim. If the business is ever transferred, account data would transfer with it and we would notify you first.
9. International transfers
We keep server-side data in the EU. Some providers, notably Cloudflare and Paddle, may process limited data outside the EEA or the UK. Where that happens, the transfer relies on the European Commission’s Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with the provider’s own supplementary safeguards. Ask us at privacy@mapcontacts.net for a copy of the relevant documents.
10. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account exists, then deleted within 30 days of deletion request or closure |
| Licence validation logs | 90 days |
| Web server logs | 30 days |
| Support correspondence | 24 months after the conversation ends |
| Invoices and transaction records | As long as tax law requires, typically 7 years |
11. Security
The site and the licence API are served over HTTPS only, with HSTS. Our server accepts administrative access by SSH key only, runs a firewall with automatic security updates, and exposes no database to the internet. Access to production data is limited to the operator. Passwords, where used, are stored hashed by our authentication provider.
No system is perfectly secure. If a breach ever affects your personal data and poses a risk to you, we will notify you and the competent supervisory authority as the law requires, without undue delay.
12. Your rights
Subject to the conditions in applicable law, you can ask us to give you access to your personal data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. You can also withdraw consent to marketing email at any time.
Write to privacy@mapcontacts.net. We may ask you to confirm the email address on the account before we act, to be sure we are not disclosing data to the wrong person. Exercising these rights is free, and we will not treat you differently for doing so.
If you are in California, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.
13. Data you collect about others
When you use the extension, you decide what to collect and what to do with it. For that data you are the controller and we are not a processor, because the data never reaches our systems. You need your own lawful basis for it, and you handle any request you receive from a person whose details are on your list.
Business listing details can still be personal data — a sole trader’s mobile number is a clear example. Our Acceptable Use Policy sets the limits we require: business listing information only, no personal profiles, no special category data, and no unsolicited bulk messaging.
14. Children
MapContacts is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, tell us and we will delete it.
15. Changes to this policy
When we change this policy we update the date above and publish the new version here. For changes that materially affect how we handle your personal data, we will email account holders in advance.
16. Contact and complaints
Privacy: privacy@mapcontacts.net
Postal:
Anton Prokopets, Grafska 4A, Nizhyn 16600, Ukraine
If you are unhappy with our response, you can complain to your local data protection authority. In the EU that is the authority of your country of residence; in the UK it is the Information Commissioner’s Office. We would rather you came to us first.