Privacy Policy
Non-binding translation
This English version is provided for convenience only. The legally binding version of this privacy policy is the German original, which prevails in the event of any discrepancy between the two.
Last updated: 28 August 2026
Scope
This privacy policy applies to our website at www.placemapr.com and to our iOS app “Placemapr” (together, “our services”). Sections 1 to 3 and sections 6 and 8 apply to both. Sections 4 and 5 concern the website only; section 7 concerns the app only.
1. An overview of data protection
General information
The following information provides a simple overview of what happens to your personal data when you use our services. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to the privacy policy set out below this text.
Data recording in our services
Who is responsible for recording data in our services?
Data processing in our services is carried out by us as their provider. You will find our contact details in the section “Information on the controller” in this privacy policy.
How do we record your data?
Your data is collected in part by you providing it to us. This may, for example, be data you enter into a contact form.
Other data is recorded automatically, or with your consent, by our IT systems when you use our services. This is primarily technical data (e.g. internet browser or operating system, device type, or time of access). This data is recorded automatically as soon as you use our services.
What do we use your data for?
Part of the data is collected to ensure our services are provided without errors. Other data may be used to analyse your user behaviour. Where contracts can be concluded or initiated via our services, the transmitted data is also processed for contract offers, orders, or other enquiries.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or erasure of this data. If you have given consent to data processing, you may withdraw that consent at any time with future effect. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
Please contact us at any time regarding this and any other questions on data protection.
2. Hosting
We host the content of our services with the following provider:
External hosting
This website is hosted externally. The server-side services used by our app are likewise operated by external providers. The personal data recorded in the process is stored on those providers’ servers. This may primarily involve IP addresses, contact requests, meta and communication data, contract data, contact details, names, access data, and other data generated via our services.
External hosting is carried out for the purpose of fulfilling our contract with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of secure, fast, and efficient provision of our services by professional providers (Art. 6(1)(f) GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Digital Services Data Protection Act), insofar as the consent covers the storage of cookies or access to information on the user’s terminal equipment (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our providers will process your data only to the extent necessary to fulfil their performance obligations and will follow our instructions with regard to this data.
We use the following providers:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The website is provided via Firebase App Hosting as the origin server; the content displayed in our services is stored in Google Firestore and processed via Google Cloud Functions. The data centre locations used for this are located within the European Union.
Insofar as personal data is transferred to Google LLC in the USA, the company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
For more information on how Google handles user data, please see Google’s privacy policy: https://policies.google.com/privacy?hl=en.
Cloudflare
Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany, and its parent company Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”).
Cloudflare offers a globally distributed content delivery network (CDN) with DNS. Technically, the transfer of information between your device and our services is routed through Cloudflare’s network. This enables Cloudflare to analyse the data traffic between your device and our services and to act as a filter between our servers and potentially malicious traffic from the internet. In doing so, Cloudflare may also use cookies or other technologies for recognising internet users, which are, however, used solely for the purpose described here.
We also use Cloudflare’s object storage (Cloudflare R2) to store the images displayed in our services as well as the photos shared by users. The data centre locations used for this are located within the European Union.
The use of Cloudflare is based on our legitimate interest in providing our services as error-free and securely as possible (Art. 6(1)(f) GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal equipment (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data transfer to the USA is based on the European Commission’s standard contractual clauses. Further information on security and data protection at Cloudflare is available here: https://www.cloudflare.com/privacypolicy/.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.
Data processing agreement
We have concluded data processing agreements (DPAs) for the use of the services named above. These are contracts required under data protection law which ensure that the providers process the personal data of the users of our services only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory information
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.
When you use our services, various items of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller responsible for data processing in our services is:
ThinkLane Systems GmbH
Venner Strasse 362
41068 Mönchengladbach
Deutschland
Phone: +49 155 67682462
Email: info@thinklane-systems.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for processing it no longer applies. If you assert a justified request for erasure or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once these grounds cease to apply.
General information on the legal bases for data processing in our services
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is additionally based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your terminal equipment (e.g. via device fingerprinting), data processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where it is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the relevant legal bases in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data
In the course of our business activities, we work with various external parties. This sometimes requires the transfer of personal data to these external parties. We only pass on personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so (e.g. disclosure of data to tax authorities), where we have a legitimate interest pursuant to Art. 6(1)(f) GDPR in the disclosure, or where another legal basis permits the disclosure of data. Where processors are used, we pass on personal data of our customers only on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.
These are, in detail:
- Google Ireland Limited, Dublin, Ireland — hosting, database, server functions, anonymous sign-in and the AI function (sections “External hosting”, “Anonymous sign-in”, “AI-assisted trip planning”)
- Apple Distribution International Ltd., Cork, Ireland — map display, abuse prevention, App Store and in-app purchases (sections “Maps and images in the app”, “Abuse prevention”, “App Store and in-app purchases”)
- Cloudflare Germany GmbH, Munich, Germany, and Cloudflare, Inc., San Francisco, USA — delivery of content and images, and storage of shared photos (sections “Cloudflare” and “Photos you add”)
- Umami Software, Inc., San Francisco, USA — audience measurement on the website (section “Umami Analytics”)
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You may withdraw consent you have already given at any time. The lawfulness of the data processing carried out up until withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
The supervisory authority competent for us is:
Landesbeauftragte fĂĽr Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 DĂĽsseldorf, Germany
https://www.ldi.nrw.de
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.
Information, correction and erasure
Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to correction or erasure of this data. Please contact us at any time regarding this and any other questions on personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You may contact us at any time in this regard. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of the personal data we hold about you, we generally require time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request the restriction of data processing instead of erasure.
- If we no longer need your personal data but you require it to exercise, defend or establish legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, such as enquiries you send to us, our services use SSL or TLS encryption. On our website you can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
No automated decision-making
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. Our AI-assisted trip planning produces a suggestion for your trip; it does not make any decision that produces legal effects concerning you or similarly significantly affects you.
4. Data recording on this website
Cookies
Our web pages use so-called “cookies”. Cookies are small data packets and do not cause any damage to your terminal equipment. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are deleted automatically by your web browser.
Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies may be used to evaluate user behaviour or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g. for the shopping cart function), or to optimise the website (e.g. cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent may be withdrawn at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
Where other cookies and services are used on this website, you can find details in this privacy policy.
Server log files
The provider of these pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not merged with other data sources.
This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this purpose, server log files must be recorded.
Umami Analytics
This website uses the Umami web analytics service. The provider is Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, CA 94108, USA (“Umami”). Umami helps us understand how our website is used so that we can improve it.
Umami does not set cookies and does not store or read information on your terminal equipment. It records the page you visited, the page you came from (referrer), the type and version of your browser and operating system, your device type and screen resolution, your browser’s language setting, and the country derived from your IP address. Your IP address is processed only temporarily and is not stored.
Umami is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the statistical analysis of user behaviour in order to improve our offering. Because Umami neither sets cookies nor accesses information on your terminal equipment, consent under Section 25(1) TDDDG is not required.
Processing takes place on Umami servers in the European Union. We have concluded a data processing agreement with Umami pursuant to Art. 28 GDPR.
For more information, please see Umami’s privacy policy: https://umami.is/privacy.
Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your enquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR where your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where this has been requested; consent may be withdrawn at any time.
The data you send to us via contact enquiries remains with us until you request its deletion, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your request has been dealt with). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.
5. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you consent to receiving the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw your consent to the storage of the data, the email address, and their use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the withdrawal.
The data you provide to us for the purpose of receiving the newsletter is stored by us or by the newsletter service provider until you unsubscribe from the newsletter, and is deleted from the newsletter distribution list after you unsubscribe or after the purpose ceases to apply. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Data stored by us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or by the newsletter service provider in a blocklist, insofar as this is necessary to prevent future mailings. The data from the blocklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage in the blocklist is not limited in time. You may object to storage if your interests outweigh our legitimate interest.
6. Links to external offerings
Our services contain links to third-party websites, for example to Google Maps, to the websites of accommodations, to booking portals, and to online shops. This content is not embedded in our services: no data is transmitted to the respective provider unless you click the link.
If you click such a link, you leave our services. A connection to the respective provider is established, and in particular your IP address and the address requested are transmitted to them. From that point on, the respective provider alone is responsible for the processing of your data; we have no influence on that processing. For links to Google Maps, Google’s privacy policy applies: https://policies.google.com/privacy?hl=en.
Amazon associates programme
We participate in the Amazon associates programme (Amazon EU S.Ă r.l., 38 avenue John F. Kennedy, L-1855 Luxembourg). Our links to amazon.de carry a partner identifier; if you make a purchase there, we may receive a commission. This does not change the price for you.
The identifier is part of the link’s address: nothing is transmitted to Amazon before you click, and we set no cookies for it. After the click, Amazon stores a cookie on its own responsibility in order to attribute a purchase to our identifier; we have no access to it. For details, and how to object, see Amazon’s privacy notice. The legal basis is our legitimate interest in financing our services, Art. 6(1)(f) GDPR.
7. Data recording in our iOS app
General information
Using our app requires neither a user account nor registration. We do not collect your name or your email address unless you voluntarily provide it to us as part of a problem report. We do not analyse your usage behaviour using analytics or advertising software; the app contains no tracking or advertising libraries and does not request permission for cross-app tracking. For AI-assisted trip planning the app signs in automatically and anonymously; this too requires no input from you (see “Anonymous sign-in”).
Anonymous sign-in (Firebase Authentication)
The first time you open trip planning in our app, a unique identifier is created for you. It is stored in your device’s keychain and — if you have enabled iCloud Keychain — synchronised with your other Apple devices. We use Firebase Authentication to create this identifier, a service provided by Google (see section 2). Your IP address is transmitted to Google in the process. The identifier contains no personally identifiable information such as your name, email address or device identifiers. We use it solely to account for your allowance for AI-assisted trip planning and for the credits you have obtained through an in-app purchase — of a Placemap or of a credit pack.
The legal basis is our legitimate interest in providing the AI function in a way that is protected against abuse and controlled in cost (Art. 6(1)(f) GDPR). Firebase Authentication is not restricted to data centres within the European Union; a transfer to the USA is therefore possible. Such transfer is based on the European Commission’s standard contractual clauses; for Google’s certification under the “EU-US Data Privacy Framework”, see section 2.
We do not store any information against this identifier that identifies you as a person. Under Art. 11 GDPR we can therefore only match a request for access or erasure to a record if the identifier is available to us. Please contact us at the address given above in such a case — we will help you determine the identifier on your device. Please also note that deleting the app does not remove the data stored against this identifier.
Location data
Our app requests permission to access your location. Your location is used to show your position on the map and to calculate distances and routes to the places displayed. Location data is processed exclusively locally on your device. It is neither transmitted to us nor to third parties, and is not stored by us.
You can withdraw the permission at any time in your device’s system settings; the app remains usable with reduced functionality in that case. The legal basis for accessing your location is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG), which you give by confirming the system prompt and may withdraw at any time with future effect.
Data stored locally on your device
Your trips and daily itineraries, saved accommodations, places marked as favourite or as seen, places you have created yourself, and the references to the photos you have added are stored on your device. They are not synchronised between multiple devices, and the data is deleted as soon as you remove the app from your device.
This data is transmitted to us in three cases only: when you create a place of your own, to the extent described in the section “Statistics on places you create”, when you use AI-assisted trip planning, to the extent described in the section “AI-assisted trip planning (Vertex AI)”, and when you expressly release a photo for sharing, to the extent described in the section “Photos you add”. Beyond that it does not leave your device.
Abuse prevention (Firebase App Check and Apple App Attest)
To protect our servers against abusive and automated access, we use Firebase App Check in conjunction with Apple’s App Attest service. Your device confirms to Apple that it is running an unmodified installation of our app and receives a cryptographic authenticity token, which is attached to our server requests.
This does not allow us to identify you; no user or device identifiers are transmitted to us. The legal basis is our legitimate interest in preventing abusive access to our systems (Art. 6(1)(f) GDPR).
Problem reports and feedback
You can use the app to report problems with individual places and to send us general feedback. The following data is transmitted to us and stored in Google Firestore: the category you selected, your message, the identifier and name of the place concerned, the identifier of the associated destination, the version of our app, the version of your operating system, your device model (e.g. “iPhone15,3”), your device’s language setting, and the time of the report.
Providing an email address is voluntary and serves solely to allow us to reply to your report. Without it we can evaluate your report but cannot respond to you.
Please do not include personal data of other people in your message unless this is necessary for your request.
The legal basis is our legitimate interest in handling your report and improving our offering (Art. 6(1)(f) GDPR). Insofar as you voluntarily provide your email address, its processing is based on your consent (Art. 6(1)(a) GDPR); consent may be withdrawn at any time. We delete your report once it has been conclusively dealt with and no statutory retention obligations prevent deletion.
Statistics on places you create
When you create your own place in the app, we transmit its coordinates, the identifier of the destination you added it to, and — where available — the place identifier assigned by Apple. We evaluate this information to identify which places are frequently added to our destinations and to expand our content accordingly.
The transmission takes place without any user or device identifier. The name you assigned, the category, and any notes on the place are not transmitted. This data does not allow us to draw conclusions about your identity. The legal basis is our legitimate interest in the further development of our content (Art. 6(1)(f) GDPR).
Photos you add
You can add your own photos from your photo library to the places shown in our app. These photos initially remain entirely on your device: the app stores only a reference to the item in your photo library, and it stores that reference solely on your device. Neither the photo nor that reference is transmitted to us.
For each photo you can decide separately whether you would like to share it with other users (“Share with other travelers”). Only with this explicit choice is a copy of the photo transmitted to us. You may voluntarily provide a freely chosen name for the photo credit.
In this case, the following is transmitted and stored: the photo itself, the name you provided, your anonymous identifier (see “Anonymous sign-in”), the identifier of the place concerned and of the associated destination, the version of our app, the time of submission, and the time of our decision on publication. The photo’s metadata — in particular EXIF information such as the time of capture, camera model, and location — is removed on your device before the photo leaves it.
We store the image files with Cloudflare and the associated information in Google Firestore (for both providers, see section 2). The data centre locations used for this are located within the European Union.
Shared photos are reviewed by us before publication. Once approved, the photo is publicly visible, together with the name you provided, to all users of our app and, where applicable, on our website. Please do not share photos in which other people are recognisable without their consent.
By sharing a photo you grant ThinkLane Systems GmbH a non-exclusive, worldwide, royalty-free, sublicensable and transferable licence to host, store, reproduce, technically modify (in particular to change its size and format), publish, publicly display, and distribute the photo in connection with the Placemapr services and their promotion. You warrant that you hold the rights necessary for this and that no third-party rights preclude its publication.
The legal basis for processing shared photos is your consent (Art. 6(1)(a) GDPR), which you give by explicitly selecting “Share with other travelers”. You may delete a shared photo in the app at any time; we then withdraw it from publication and delete the copies stored by us. The photo may remain retrievable for a short time in the caches of the content delivery network. The lawfulness of the processing carried out up until withdrawal remains unaffected by the withdrawal.
AI-assisted trip planning (Vertex AI)
Our app offers you the option of automatically generating a daily itinerary from the places of a destination. Your request is first transmitted to a server function operated by us in a data centre in Frankfurt am Main, which forwards it to the Vertex AI service. The provider of both services is Google (see section 2).
When you invoke this function, the following data is transmitted and processed by an AI model: the names, identifiers, categories and coordinates of the places on your trip, the marking of places you have flagged as favourites, the number and weekdays of your travel days, and — where you have saved them — the names and coordinates of your accommodations. Your name, email address, device identifiers, and your current location are not transmitted; nor is your anonymous identifier transmitted to the AI model.
Processing is not restricted to data centres located within the European Union; a transfer to third countries, in particular to the USA, is therefore possible. Data transfer to the USA is based on the European Commission’s standard contractual clauses; for Google’s certification under the “EU-US Data Privacy Framework”, see section 2.
Use of this function is voluntary; the app is fully usable without it. The legal basis is Art. 6(1)(b) GDPR: the processing is necessary in order to provide the service you have requested — the generation of a daily itinerary. Further information on data processing by Firebase is available at https://firebase.google.com/support/privacy.
Allowance for AI-assisted trip planning
AI-assisted trip planning is available to you to a limited extent. In order to maintain this allowance, we store the following against your anonymous identifier in Google Firestore: the time and type of each planning operation, the number of segments generated, the number of additionally purchased credits, and a total counter of operations performed so far.
The contents of your trip planning — such as places, notes or accommodations — are not stored in this record. Entries for individual operations are deleted as soon as they are no longer needed to maintain the allowance or to answer queries about it; the total counter and the number of purchased credits remain for as long as the identifier exists. Storage takes place in data centres within the European Union.
In addition, we log technical metrics for each operation: time, duration, type of operation, destination identifier, number of segments, number of characters and tokens processed, the model used, and any error type. Your identifier is stored only as a checksum that cannot be traced back; the contents of your requests are not logged. These logs are deleted automatically after 30 days.
The legal basis for maintaining the allowance and for the logging is our legitimate interest in cost control, abuse prevention and troubleshooting (Art. 6(1)(f) GDPR).
Importing shared places
You can use your device’s share function to pass places from other apps — such as Apple Maps or Google Maps — to our app. The place passed over is initially processed exclusively locally on your device.
If it is a shortened link from Google (e.g. “maps.app.goo.gl”), the link must be resolved in order to determine the coordinates it contains. Your device calls up the link directly at Google for this purpose; your IP address is transmitted to Google in the process. If the shared content contains no coordinates, we determine them via Apple’s geocoding service; the place name is transmitted to Apple in the process.
The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to perform the function you have expressly requested.
App Store and in-app purchases
Our app is obtained via the App Store. The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (“Apple”). When you download the app, the data required for this is transmitted to Apple, in particular your Apple Account identifier, the time of the download, and payment information. We have no influence on this processing; Apple is independently responsible for it.
Within the app you can unlock individual destinations for a fee. Payment is handled exclusively by Apple. We receive neither payment data nor information about your identity, but only the information as to whether an unlock exists. For details on data processing by Apple, see https://www.apple.com/legal/privacy/en-ww/.
Maps and images in the app
The app uses the Apple MapKit map service to display maps; the provider is Apple. In order to use this service, it is necessary to transmit your IP address. When the map is loaded, your device downloads the required map data from Apple’s servers, and the map section requested is transmitted to Apple. This information may also be transferred to and stored on Apple servers in the USA. We have no influence on this data transfer.
Apple MapKit is used in the interest of an appealing presentation of our app and to make it easy to find the places displayed. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Data transfer to the USA is based on the European Commission’s standard contractual clauses. For more information on how Apple handles user data, please see Apple’s privacy policy: https://www.apple.com/legal/privacy/en-ww/.
The images shown in the app are delivered via Cloudflare’s content delivery network; the section “Cloudflare” applies accordingly. The content itself is obtained from Google Firestore; the section “External hosting” applies accordingly.
8. Changes to this privacy policy
We adapt this privacy policy when our services, the providers we use, or the legal requirements change. The version published on this page is the one that applies; the date of the last change can be found at the beginning of this policy.
Parts of this privacy policy were created using the privacy policy generator by eRecht24; they have been adapted by us and supplemented with sections of our own.