Privacy Policy
We take your privacy seriously. This policy explains exactly what data ROVmap collects, why we collect it, and how you stay in control of it.
Overview
ROVmap B.V. ("ROVmap," "we," "us," or "our") operates rovmap.com and related mobile applications and APIs. This Privacy Policy describes how we collect, use, store, and share information about you when you use our Services.
As a mapping and location-based service operating in the European Union, ROVmap is subject to the General Data Protection Regulation (GDPR). We act as the data controller for personal data collected through our Services.
ROVmap is committed to data minimization. We only collect data that is necessary to provide you with a high-quality mapping experience. You are always in control.
Data We Collect
We collect information you provide directly, information collected automatically when you use our Services, and information from third-party sources.
Account Information
- Name, email address, password (hashed)
- Profile picture (optional)
- Account preferences and settings
Location Data
- GPS coordinates (when granted)
- Search history and saved places
- Route history and waypoints
Device & Usage
- Device type, OS, browser version
- IP address and approximate location
- App interactions and feature usage
Analytics Data
- Session duration and frequency
- Pages visited and click patterns
- Error logs and performance metrics
Information You Provide
When you create an account, use our Services, or contact us for support, you may provide us with personal information such as your name, email address, and payment details (if applicable). This information is collected with your active consent.
Automatically Collected Information
When you use our Services, we automatically collect certain technical data including your device identifiers, operating system version, browser type, and interaction logs. This data helps us maintain and improve the performance and reliability of our platform.
Location Data
Location data is the core of what makes ROVmap useful. We handle it with particular care and transparency.
- Collect location only when you actively use navigation features
- Allow you to use the app with approximate location only
- Delete precise route history upon your request
- Allow offline use without sharing location with our servers
- Track your location in the background without your knowledge
- Sell your precise location data to advertisers or brokers
- Share your location history with law enforcement without legal process
- Retain precise GPS coordinates longer than necessary
You can control location permissions at any time through your device settings. Revoking location permissions will limit certain features but will not prevent you from using basic map browsing functionality.
Our legal basis for processing location data is your explicit consent under GDPR Article 6(1)(a). You may withdraw this consent at any time.
How We Use Your Data
We use the information we collect for specific, legitimate purposes. We never use your data in ways that are incompatible with these purposes without seeking fresh consent.
Delivering maps, routing, navigation, and location search features that form the core of our platform.
Analyzing aggregated, anonymized usage patterns to identify bugs, optimize performance, and develop new features.
Remembering your saved places, preferences, and recent routes to give you a more relevant experience.
Detecting and preventing unauthorized access, abuse, and other security incidents.
Retaining records as required by applicable law and responding to lawful requests from public authorities.
Sending you service updates, feature announcements, and newsletters (only when you opt in).
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
Security
We implement industry-standard technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction.
- End-to-end encryption for data in transit (TLS 1.3)
- AES-256 encryption for data at rest
- Regular penetration testing and security audits
- Role-based access controls — staff access data only on a need-to-know basis
- Multi-factor authentication for all internal systems
- ISO 27001-aligned information security management
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you discover a vulnerability, please contact security@rovmap.com.
Your Rights
Under the GDPR and other applicable privacy laws, you have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@rovmap.com.
Access
Request a copy of all personal data we hold about you.
Rectification
Correct inaccurate or incomplete personal data.
Erasure
Request deletion of your personal data ("right to be forgotten").
Restriction
Ask us to pause processing your data in certain circumstances.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests.
Withdraw Consent
Withdraw consent at any time where processing is consent-based.
Lodge a Complaint
File a complaint with the Dutch DPA (Autoriteit Persoonsgegevens).
We will respond to rights requests within 30 days. In complex cases, we may extend this by a further two months, but we will inform you of any extension within the first 30 days.
Children's Privacy
Our Services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at privacy@rovmap.com.
If we become aware that we have collected personal data from a child under the age of 16 without verifiable parental consent, we will take steps to delete that information from our servers as quickly as possible.
International Data Transfers
ROVmap is headquartered in the Netherlands. Your data is primarily processed and stored within the European Economic Area (EEA). When we transfer data outside the EEA — for example, to service providers in the United States — we do so only under appropriate safeguards:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- Transfers to countries with an EU adequacy decision
- Binding Corporate Rules where applicable
You can request a copy of the specific safeguards we apply to any international transfer by contacting our Data Protection Officer.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by email or by displaying a prominent notice on our website at least 30 days before the change takes effect.
We encourage you to review this page periodically. Your continued use of our Services after any changes constitutes your acceptance of the updated policy. The date at the top of this page indicates when the policy was last revised.
Contact & Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below. We have appointed a Data Protection Officer (DPO) as required under the GDPR.
Privacy Requests
privacy@rovmap.com
Data Protection Officer
dpo@rovmap.com
Supervisory Authority
Autoriteit Persoonsgegevens (AP), The Hague
We aim to respond to all privacy-related inquiries within 5 business days and to formally resolve rights requests within 30 days.