Privacy

Privacy Policy

We take your privacy seriously. This policy explains exactly what data ROVmap collects, why we collect it, and how you stay in control of it.

Effective: April 25, 2026 GDPR Compliant ~12 min read
01

Overview

ROVmap B.V. ("ROVmap," "we," "us," or "our") operates rovmap.com and related mobile applications and APIs. This Privacy Policy describes how we collect, use, store, and share information about you when you use our Services.

As a mapping and location-based service operating in the European Union, ROVmap is subject to the General Data Protection Regulation (GDPR). We act as the data controller for personal data collected through our Services.

ROVmap is committed to data minimization. We only collect data that is necessary to provide you with a high-quality mapping experience. You are always in control.

02

Data We Collect

We collect information you provide directly, information collected automatically when you use our Services, and information from third-party sources.

Account Information

  • Name, email address, password (hashed)
  • Profile picture (optional)
  • Account preferences and settings

Location Data

  • GPS coordinates (when granted)
  • Search history and saved places
  • Route history and waypoints

Device & Usage

  • Device type, OS, browser version
  • IP address and approximate location
  • App interactions and feature usage

Analytics Data

  • Session duration and frequency
  • Pages visited and click patterns
  • Error logs and performance metrics

Information You Provide

When you create an account, use our Services, or contact us for support, you may provide us with personal information such as your name, email address, and payment details (if applicable). This information is collected with your active consent.

Automatically Collected Information

When you use our Services, we automatically collect certain technical data including your device identifiers, operating system version, browser type, and interaction logs. This data helps us maintain and improve the performance and reliability of our platform.

03

Location Data

Location data is the core of what makes ROVmap useful. We handle it with particular care and transparency.

We DO
  • Collect location only when you actively use navigation features
  • Allow you to use the app with approximate location only
  • Delete precise route history upon your request
  • Allow offline use without sharing location with our servers
We DON'T
  • Track your location in the background without your knowledge
  • Sell your precise location data to advertisers or brokers
  • Share your location history with law enforcement without legal process
  • Retain precise GPS coordinates longer than necessary

You can control location permissions at any time through your device settings. Revoking location permissions will limit certain features but will not prevent you from using basic map browsing functionality.

Our legal basis for processing location data is your explicit consent under GDPR Article 6(1)(a). You may withdraw this consent at any time.

04

How We Use Your Data

We use the information we collect for specific, legitimate purposes. We never use your data in ways that are incompatible with these purposes without seeking fresh consent.

Providing the Services Contract

Delivering maps, routing, navigation, and location search features that form the core of our platform.

Improving the Platform Legitimate Interest

Analyzing aggregated, anonymized usage patterns to identify bugs, optimize performance, and develop new features.

Personalization Consent

Remembering your saved places, preferences, and recent routes to give you a more relevant experience.

Security & Fraud Prevention Legitimate Interest

Detecting and preventing unauthorized access, abuse, and other security incidents.

Legal Compliance Legal Obligation

Retaining records as required by applicable law and responding to lawful requests from public authorities.

Communications Consent

Sending you service updates, feature announcements, and newsletters (only when you opt in).

05

Data Sharing

We do not sell your personal data. We share information only in the limited circumstances described below.

Service Providers

We share data with trusted third-party vendors who help us operate our Services — such as cloud hosting providers, map data licensors, analytics services, and customer support tools. These providers are contractually obligated to process data only on our behalf and in accordance with our instructions.

Aggregated & Anonymized Data

We may share aggregated, de-identified data (e.g., heatmaps of popular routes or traffic patterns) with partners and the public for research and planning purposes. This data cannot be used to identify you individually.

Legal Requirements

We may disclose your information if required by law, court order, or other governmental authority. We will notify you of such requests where legally permitted to do so.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

06

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.

Data Type Retention Period
Account information Duration of account + 30 days after deletion
Precise GPS location logs 90 days (rolling window)
Saved places & routes Until you delete them or close your account
Usage analytics (aggregated) 24 months
Support communications 3 years
Financial records 7 years (legal obligation)
07

Security

We implement industry-standard technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction.

  • End-to-end encryption for data in transit (TLS 1.3)
  • AES-256 encryption for data at rest
  • Regular penetration testing and security audits
  • Role-based access controls — staff access data only on a need-to-know basis
  • Multi-factor authentication for all internal systems
  • ISO 27001-aligned information security management

No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you discover a vulnerability, please contact security@rovmap.com.

08

Your Rights

Under the GDPR and other applicable privacy laws, you have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@rovmap.com.

👁

Access

Request a copy of all personal data we hold about you.

✏️

Rectification

Correct inaccurate or incomplete personal data.

🗑

Erasure

Request deletion of your personal data ("right to be forgotten").

⏸

Restriction

Ask us to pause processing your data in certain circumstances.

📦

Portability

Receive your data in a structured, machine-readable format.

🚫

Objection

Object to processing based on legitimate interests.

↩️

Withdraw Consent

Withdraw consent at any time where processing is consent-based.

⚖️

Lodge a Complaint

File a complaint with the Dutch DPA (Autoriteit Persoonsgegevens).

We will respond to rights requests within 30 days. In complex cases, we may extend this by a further two months, but we will inform you of any extension within the first 30 days.

09

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and analyze how our Services are used. You can control cookie preferences through our cookie banner or your browser settings.

10

Children's Privacy

Our Services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at privacy@rovmap.com.

If we become aware that we have collected personal data from a child under the age of 16 without verifiable parental consent, we will take steps to delete that information from our servers as quickly as possible.

11

International Data Transfers

ROVmap is headquartered in the Netherlands. Your data is primarily processed and stored within the European Economic Area (EEA). When we transfer data outside the EEA — for example, to service providers in the United States — we do so only under appropriate safeguards:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Transfers to countries with an EU adequacy decision
  • Binding Corporate Rules where applicable

You can request a copy of the specific safeguards we apply to any international transfer by contacting our Data Protection Officer.

12

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by email or by displaying a prominent notice on our website at least 30 days before the change takes effect.

We encourage you to review this page periodically. Your continued use of our Services after any changes constitutes your acceptance of the updated policy. The date at the top of this page indicates when the policy was last revised.

13

Contact & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below. We have appointed a Data Protection Officer (DPO) as required under the GDPR.

Privacy Requests

privacy@rovmap.com

Data Protection Officer

dpo@rovmap.com

Supervisory Authority

Autoriteit Persoonsgegevens (AP), The Hague

We aim to respond to all privacy-related inquiries within 5 business days and to formally resolve rights requests within 30 days.