Privacy Policy
Last updated: 2026-10-04
1. Who we are
Map2Point (“we”, “us”) provides a mobile and web application that lets groups traveling together — whether on a multi-stop road trip or gathering at a single meeting point — share a live map, send voice messages, coordinate stops, track shared expenses, and receive alerts about their group’s status. This policy explains what data we collect through the app and this website, why, and what control you have over it.
2. What we collect
- Account information: display name, email address (if you sign up with one), optional phone number and phone-sharing preference, profile photo (if you add one), and authentication data handled by our authentication provider. Guest accounts only require a display name. A profile phone number is not SMS verification.
- Trip data: trip or meeting point names, destinations, stops, vehicle information, and participant roles you or your group create.
- Location data: collected only while you actively choose to share your location on an active trip or meeting point. Native mobile sharing can continue in the background with your permission. You can stop sharing or leave the trip; ending the trip also ends live sharing. A public live link can expose vehicle positions to its holders as explained below. Our infrastructure providers process data to deliver the service; we do not sell location data or use it for advertising.
- Photos: profile avatars, trip covers, vehicle photos, stop photos and expense receipts stored with our storage provider. Trip media uses access-controlled storage and temporary signed links. Uploaded profile avatars use public URLs, so anyone who has that URL can view the image.
- Expense data: if your group tracks shared costs in a trip, we store the expense title, amount, currency, who paid, an optional note, and any attached receipt photo, visible only to that trip’s participants. This is self-reported record-keeping — see Terms of Service section 6 for what this does and doesn’t cover.
- Purchase and billing data: when you buy a paid plan, Stripe processes the payment through its hosted Checkout. Stripe receives the information you enter there, which may include contact, billing, and payment-method details. We receive and store the Stripe identifiers and transaction or subscription status needed to confirm your purchase, provide the plan or credits, manage renewals, and handle support, refunds, or disputes. For a Trip Pass, this can also include the trip it unlocks. We do not receive your full card number or security code through this integration.
- Voice messages: audio you record and send within a trip, visible only to that trip’s participants (or a specific vehicle, if you target one).
- Messages and SOS: text messages, voice-message metadata and playback receipts, and emergency alerts including vehicle/trip references, activation/resolution times and actor references. Alert payloads may include a note. SOS is a group-coordination feature, not an emergency-services record system.
- Usage data: if you accept analytics cookies on this website, we collect usage data via configured PostHog and/or Google Analytics integrations to understand how the product is used. This is entirely optional — see our cookie banner. Usage identifiers and technical data are not guaranteed to be anonymous.
3. How we use your data
We use your data solely to provide the product: showing your group’s live map, delivering voice messages and notifications, managing trip membership and invitations, processing paid purchases, granting purchased access or credits, managing subscriptions, and responding to billing questions or refund requests. Where you’ve opted in, we also use analytics to understand product usage and improve it. We do not sell personal data, and we do not use your location or trip content for advertising.
4. Who can see your data
Authenticated trip access is controlled through database row-level security and Storage policies. Authorized participants, including read-only participants, can view shared trip records. Organizers manage participant lists and vehicle/role assignments within their trips. Tripmate phone numbers are returned only when the profile owner enables phone sharing with the trip; you can still see your own number.
A public live link is an exception to participant-only access: anyone holding a valid link can see the live-view information, including vehicle labels, positions and open emergency alerts. Do not share that link with unintended viewers. Text and voice messages are not included in that public view. Profile avatar URLs are public; private-media signed links may remain usable until their expiry, and recipients may retain copies they have already downloaded.
Payments are handled by Stripe through Stripe Checkout. Stripe receives the information needed to process your payment and may process information under its own privacy responsibilities as well as to provide payment services to us. We receive billing identifiers and transaction status from Stripe; we do not receive your full card number or security code through this integration. See the Stripe Privacy Policy for more information about Stripe’s processing.
5. Data retention
Different records have different lifecycles. Ending a trip does not delete the trip, participant history, stops, expense ledger or emergency history. These can remain in trip history subject to access controls. Repository migrations define separate cleanup functions and schedules for raw positions, while allowing a coarse route summary to remain with the trip. The checked-in source does not by itself verify that those jobs are deployed or completing successfully in production, and the route summary is not a guarantee of anonymity.
The repository’s trip-end SQL is designed to delete text and voice-message database records and queue voice files for separate Storage cleanup; it also defines a cron backstop for ended trips. The local source does not prove that this SQL or its cron job is active and succeeding in production. A queued file is not proof of completed file deletion. We do not promise immediate removal of every file, cached copy or backup when a trip ends or a deletion request is sent. The checked-in schema retains emergency records with the trip; deletion-specific SOS minimization and scheduled removal are not implemented in the repository runtime.
Planned account-deletion treatment — not yet automated
The following is the approved design for account deletion, not a description of a working automated cleanup service:
- Necessary historical participant references would use a separate random identifier and the label “Deleted participant”, without a retained link to the old login identifier, email or phone. This is pseudonymization, not guaranteed anonymization: remaining trip context can still identify a person.
- An expense would remain only while needed for the group ledger, retaining its trip, amount, currency and timestamp. References to the deleted payer or creator would use that replacement identifier; the title would become generic and notes and receipt images would be removed.
- Avatars, personal voice recordings, receipt images, personal vehicle media and attributable unreferenced files would be deleted. Shared trip files would remain only while needed by other participants, with uploader-identifying metadata and EXIF removed. The image itself may still identify someone.
This design still requires implementation and legal/privacy review, particularly the lawful purpose, retained fields and retention period for SOS data. It does not establish that retention is lawful in every case. Billing records required for accounting or legal obligations need a separate, minimized retention policy; replacing a participant identifier does not erase records held by Stripe.
6. Your rights
You can request access to, correction of, or deletion of your account data by contacting us at privacy@map2point.com. Depending on your location, you may have additional rights under regulations like the GDPR or CCPA, including the right to data portability and the right to object to certain processing. We respond to these requests in accordance with applicable law.
Automated account deletion and its Storage/billing cleanup are not currently available. Email is the current request channel, not an instant deletion action or confirmation of completion. We may need to verify your identity and assess shared records and applicable retention obligations. These implementation limitations do not remove your rights to request erasure or complain to a competent data-protection authority. Do not send passwords, access tokens or payment-card details by email.
7. Cookies
This website uses strictly necessary cookies (for authentication and preferences) at all times, and optional analytics cookies (PostHog, Google Analytics) only if you accept them via the cookie banner and the integration is configured. To choose again, clear this site’s cookies and local storage in your browser settings, reload the page and make a new banner choice. This may sign you out and does not erase previously collected analytics data. Contact us about that data or if you need help.
8. Changes to this policy
We’ll update the date at the top of this page when this policy changes, and for material changes, we’ll make a reasonable effort to notify active users directly.
9. Contact
Questions about this policy? Email privacy@map2point.com.