Valid from: 26 September 2026
This translation is provided for information only; the German version is legally binding.
With the following privacy policy we would like to inform you which types of your personal data (hereinafter also referred to as "data") we process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering"). The terms used are not gender-specific.
The controller responsible for data processing on this website is: Simon Schillinger Tränkestraße 20 79114 Freiburg Germany Email: info@mapshot.io The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses or similar).
Below we set out the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Processing is necessary for compliance with a legal obligation to which the controller is subject.
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, securing the availability and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subjects' rights, the deletion of data and responses to threats to the data. We also take the protection of personal data into account when developing or selecting hardware, software and processes, in line with the principles of data protection by design and by default.
To protect the data you transmit via our online offering, we use SSL encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.
In the course of our processing of personal data, the data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, payment institutions in the context of payment transactions, service providers commissioned with IT tasks, or providers of services and content that are embedded in a website. In such cases we comply with the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this is done only in accordance with the legal requirements. Subject to express consent or a contractually or legally required transfer, we process data, or have it processed, only in third countries with a recognised level of data protection or on the basis of special safeguards, such as contractual obligations through so-called standard contractual clauses of the EU Commission, certifications or binding corporate rules (Art. 44 to 49 GDPR, information page of the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en ).
Cookies are small text files stored by a browser on the user's device that can contain information about the use of a website. On our website, we use only technically necessary first-party cookies. These include session and login cookies for the client portal (mapshot.io/clients) and the internal administration area. These cookies are strictly necessary for the provision of the function you have explicitly requested and are processed on the basis of § 25 (2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) and Art. 6 (1)(b) and (f) GDPR. We do not use third-party cookies, nor any statistics, marketing, or personalization cookies. Our website analytics are performed cookie-free via Pirsch Analytics (see Section 8), without storing or reading any information on your device. You can configure your browser to reject cookies. However, this may cause certain features of our website (e.g., logging in to the client portal) to become unavailable.
We process data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships and related measures, and in the context of communication with contractual partners (or pre-contractually), e.g. to answer enquiries. We process this data to fulfil our contractual obligations, to safeguard our rights and for the purposes of the administrative tasks associated with this information as well as for business organisation. Within the framework of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or to fulfil legal obligations, or with the consent of the contractual partners (e.g. to participating telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Contractual partners are informed about further forms of processing, e.g. for marketing purposes, within the scope of this privacy policy. We inform the contractual partners which data are required for the aforementioned purposes before or during data collection, e.g. in online forms, by special marking (e.g. colours) or symbols (e.g. asterisks or similar), or in person. We delete the data after the expiry of statutory warranty and comparable obligations, i.e. generally after 4 years, unless the data are stored in a customer account, e.g. for as long as they must be retained for legal archiving reasons (e.g. for tax purposes 8 years for invoices and accounting vouchers, 10 years for books and records). Data disclosed to us by the contractual partner in the context of an order are deleted in accordance with the specifications of the order, generally after the end of the order. Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between the users and the providers.
For business reasons and in order to recognise market trends and the wishes of contractual partners and users, we analyse the data available to us on business transactions, contracts, enquiries, etc., whereby the group of data subjects may include contractual partners, prospective customers, customers, visitors and users of our online offering. The analyses are carried out for the purposes of business evaluations, marketing and market research (e.g. to determine customer groups with different characteristics). In doing so, we may take into account, where available, the information provided by our contractual partners, e.g. on services used. The analyses serve us alone and are not disclosed externally unless they are anonymous analyses with aggregated, i.e. anonymised, values. Furthermore, we respect the privacy of users and process the data for analysis purposes as pseudonymously as possible and, where feasible, anonymously (e.g. as aggregated data).
On our website (mapshot.io) we use the cookieless web analytics service Pirsch Analytics, provided by Emvi Software GmbH, Auf dem Stützkamp 14, 31177 Harsum, Germany. Pirsch enables us to collect access statistics anonymously (e.g. page views, referring pages, approximate time spent) in order to design the content and functions of our online offering according to demand and to improve them continuously. In addition, we record anonymous events in the panorama viewer, such as which places or peaks are tapped and whether the guided tour is used. We share aggregated, anonymous evaluations of this (e.g. shares, no individual visits) with the respective location partners and sponsors. The processing is based on our legitimate interest in the statistical evaluation of website usage pursuant to Art. 6(1)(f) GDPR. Since Pirsch works entirely without cookies and without accessing the storage of your device, consent under Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is not required. Pirsch does not use cookies, LocalStorage or similar device-side identifiers and does not create personal profiles. The visitor's IP address is processed exclusively on the server side, hashed with a salt that changes daily and is not stored. This hash makes it possible to recognise repeat visits within the same day without identifying individual users or tracking them across several days. In particular, the following are processed: the URL accessed, the referring page (referrer), browser and operating system information, screen resolution and the country derived from the IP address. Personal data within the meaning of the GDPR are not stored permanently. Data processing takes place exclusively on servers in Germany; no data is transferred to third countries. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider. Further information: https://pirsch.io/privacy and https://docs.pirsch.io/general/data-privacy
When you contact us (e.g. via contact form, email, telephone or social media), the information provided by the enquiring persons is processed insofar as this is necessary to answer the contact enquiries and any requested measures. Contact enquiries within the framework of contractual or pre-contractual relationships are answered in order to fulfil our contractual obligations or to respond to (pre-)contractual enquiries, and otherwise on the basis of our legitimate interest in responding to the enquiries.
In order to provide our online offering securely and efficiently, we use the services of one or more web hosting providers from whose servers (or servers managed by them) the online offering can be accessed. For these purposes we may use infrastructure and platform services, computing capacity, storage space and database services as well as security and technical maintenance services. The data processed in the context of providing the hosting offering may include all information relating to the users of our online offering that arises in the course of use and communication. This regularly includes the IP address, which is necessary to deliver the content of online offerings to browsers, and all entries made within our online offering or on websites.
We ourselves (or our web hosting provider) collect data on every access to the server (so-called server log files). Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used on the one hand for security purposes, e.g. to prevent the servers from being overloaded (in particular in the event of abusive attacks, so-called DDoS attacks), and on the other hand to ensure the utilisation and stability of the servers.
Hetzner Website: https://www.hetzner.com/ Privacy policy: https://www.hetzner.com/legal/privacy-policy/
Our online offering is designed so that content is generally delivered from our own servers or our own infrastructure. This applies in particular to the map material of the panorama viewer (vector and satellite maps, provided via our own servers, e.g. vecviewer.mapshot.io and satellite.mapshot.io), the panorama images and the fonts used, which are embedded locally and not loaded from external providers (e.g. Google Fonts). When you visit our website, no third-party content (e.g. videos, social media plugins, external fonts or third-party map services) is therefore currently embedded that would establish a connection between your browser and third-party servers and thereby transmit your IP address to third parties. Should we embed third-party content in the future, this will only be done on an appropriate legal basis – where required on the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) – and we will update this privacy policy accordingly.
- no third-party content currently embedded -
Wir setzen Dienstleistungen, Plattformen und Software anderer Anbieter (nachfolgend bezeichnet als "Drittanbieter”) zu Zwecken der Organisation, Verwaltung, Planung sowie Erbringung unserer Leistungen ein. Bei der Auswahl der Drittanbieter und ihrer Leistungen beachten wir die gesetzlichen Vorgaben. In diesem Rahmen können personenbezogenen Daten verarbeitet und auf den Servern der Drittanbieter gespeichert werden. Hiervon können diverse Daten betroffen sein, die wir entsprechend dieser Datenschutzerklärung verarbeiten. Zu diesen Daten können insbesondere Stammdaten und Kontaktdaten der Nutzer, Daten zu Vorgängen, Verträgen, sonstigen Prozessen und deren Inhalte gehören. Sofern Nutzer im Rahmen der Kommunikation, von Geschäfts- oder anderen Beziehungen mit uns auf die Drittanbieter bzw. deren Software oder Plattformen verwiesen werden, können die Drittanbieter Nutzungsdaten und Metadaten zu Sicherheitszwecken, zur Serviceoptimierung oder zu Marketingzwecken verarbeiten. Wir bitten daher darum, die Datenschutzhinweise der jeweiligen Drittanbieter zu beachten.
The data processed by us are deleted in accordance with the legal requirements as soon as the consents permitting their processing are withdrawn or other permissions cease to apply (e.g. if the purpose of processing these data no longer applies or they are not required for the purpose). If the data are not deleted because they are required for other, legally permissible purposes, their processing is restricted to these purposes. This means that the data are blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person. Further information on the deletion of personal data may also be provided in the individual data protection notices of this privacy policy.
pursuant to Art. 7(3) GDPR, to withdraw your consent at any time. As a result, we may no longer continue the data processing based on this consent in the future;
pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information about the purposes of processing, the categories of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the source of your data if they were not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;
pursuant to Art. 16 GDPR, to request the rectification of inaccurate or the completion of your personal data stored by us without undue delay;
pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
pursuant to Art. 18 GDPR, to request the restriction of processing of your personal data if you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, we no longer need the data but you require them for the establishment, exercise or defence of legal claims, or you have objected to the processing pursuant to Art. 21 GDPR;
pursuant to Art. 20 GDPR, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;
pursuant to Art. 21 GDPR, the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Article 6(1)(e) GDPR (processing in the public interest) or Article 6(1)(f) GDPR (processing on the basis of a balancing of interests); this also applies to profiling based on these provisions within the meaning of Article 4(4) GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. If your objection is directed against the processing of data for direct marketing purposes, we will stop the processing immediately. In this case, it is not necessary to state a particular situation. This also applies to profiling insofar as it is related to such direct marketing. If you wish to exercise your right to object, an email to info@mapshot.io is sufficient.
pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or of our place of business.
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification. Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that addresses may change over time and please check the information before contacting them.
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to provide information about us. Please note that user data may be processed outside the European Union. This may result in risks for users because, for example, the enforcement of users' rights could be made more difficult. With regard to US providers certified under the EU-U.S. Data Privacy Framework or offering comparable guarantees of an adequate level of data protection (e.g. EU standard contractual clauses), we point out that they thereby undertake to comply with EU data protection standards. Furthermore, user data within social networks are generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of usage behaviour and the resulting interests of the users. These usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are generally stored on the users' computers in which the usage behaviour and interests of the users are stored. Furthermore, data can also be stored in the usage profiles independently of the devices used by the users (in particular if the users are members of the respective platforms and are logged in to them). For a detailed description of the respective forms of processing and the options to object (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks. In the case of requests for information and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you can contact us.
Instagram: social network; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy. Insofar as statistical data ("Insights") are processed in the context of our Instagram presence, we are jointly responsible for this together with Meta Platforms Ireland Limited (Art. 26 GDPR). The joint controller agreement is available at: https://www.facebook.com/legal/terms/page_controller_addendum.
The client portal at mapshot.io/clients is available to registered business customers. It allows management of MapShot subscriptions, maintenance of custom POIs (Points of Interest), access to view statistics, and review of contract information. Processing of personal data in the client portal is carried out on the following legal bases: – Art. 6(1)(b) GDPR (contract performance) for login, contact, billing and subscription data, – Art. 6(1)(c) GDPR (legal obligation) for statutory retention of invoice records, – Art. 6(1)(f) GDPR (legitimate interest) for managing third-party portal access.
Login to the client portal uses an email-based one-time password (OTP) system. After entering their email address, the user receives a time-limited 6-digit code which must be entered to confirm the session. The following data is processed and stored: – Email address (authentication and identification), – Session token (persistent login, stored in our PostgreSQL database), – OTP verification records (temporary, automatically deleted upon expiry). Session data is automatically invalidated upon logout or inactivity. OTP codes are sent via our own mail server (mail.mapshot.io).
Each login to the client portal is logged with the email address used, the associated organisation and the time of login. We also store, per user account, the time of the most recent portal access. This log serves security, detection of unauthorised access and traceability (Art. 6(1)(f) GDPR). IP address and browser information are not stored. Entries are deleted automatically after 90 days (or after 90 days of inactivity). In addition, a pseudonymous organisation identifier (numeric ID) is transmitted to our cookie-free web analytics tool Pirsch upon login (see the web hosting/analytics section); no association with individual persons takes place there.
In the account section of the portal, users can provide the following organisational data required for contract processing and invoicing: – Contact person: salutation, first name, last name, – Billing email address, – Full billing address: street, house number, postal code, city, country. The legal basis is Art. 6(1)(b) GDPR. The information is voluntary but required for proper invoicing.
Customers may grant portal access to additional email addresses for their account. The email address of the added person is stored in our system and that person automatically receives a notification email about the access granted. The legal basis is Art. 6(1)(f) GDPR (legitimate interest of the customer organisation in user management). Third parties affected are informed about the processing of their data in accordance with Art. 14 GDPR via the notification email. These individuals may object to processing and request deletion of their data at any time: info(at)mapshot.io. Upon revocation of access, the email address is deleted immediately.
Users can create custom geographic points (POIs) such as sights, places and mountains in the portal, which appear directly in their MapShot view. Processing is carried out for contract fulfilment (Art. 6(1)(b) GDPR). POI data is stored and processed on servers operated by the provider. POI data is retained until deleted by the user or until the subscription ends.
The client portal does not involve any automated decision-making or profiling within the meaning of Art. 22 GDPR.
Using the form ‘Send images to the MapShot team’, you can submit photos to us for the possible creation of MapShot panoramas. Data processed: salutation, name, company/organization, email address, the image files you upload (these may contain metadata such as EXIF/GPS information) and the geographic coordinates you provide for each image. Purpose: receiving, reviewing and processing your submission and, where applicable, creating and operating MapShot panoramas based on the submitted images. In the form you also confirm that you hold the necessary rights to the images and do not infringe any third-party rights. Legal basis: your consent (Art. 6(1)(a) GDPR), which you actively give before submitting and which we store together with the timestamp as proof. You can withdraw your consent at any time with effect for the future, e.g. by email to info@mapshot.io. Recipients and storage: the images are stored in our object storage at Wasabi Technologies (data centre within the EU; see also the list of services in section 12). Our team receives a notification with a link to an internal view of the submission by email via our own mail server (mail.mapshot.io). We send a confirmation email to the address you provided. Email verification: before processing your submission, we send a one-time verification code (OTP) to the email address you provided to confirm that you have access to that mailbox. The code is held exclusively in our server's working memory (not permanently stored) and is deleted after successful entry or after 10 minutes at the latest. The email address itself is processed as described above. Retention: the images and associated data are stored for as long as necessary to review and, where applicable, create the panoramas, and are deleted afterwards unless statutory retention obligations or a continuing basis for use (e.g. publication of a panorama created from them) apply.
You can subscribe to our newsletter via the sign-up form on our website (e.g. in the footer or on the "Newsletter" page). In addition, after logging in to our client portal we ask you once whether you would like to receive the newsletter. Data processed: your email address, as well as — for proof purposes — the time of sign-up and confirmation, your IP address, and the wording of the consent you gave. Purpose: sending the newsletter with information, news and tips about MapShot. Legal basis: your consent (Art. 6(1)(a) GDPR). Confirming your sign-up: when you sign up via the form on our website, you first receive an email with a confirmation link (double opt-in); your email address is only added to the mailing list once you click that link. This ensures the sign-up actually came from you. When you sign up through our client portal, your email address has already been verified by your prior portal login (sign-in via a one-time email code), so no separate confirmation email is sent in that case. Sending: the newsletter is sent using our own technical infrastructure (our own email server). We do not use an external newsletter service provider and we do not carry out any open or click tracking. Storage and processing: your data is stored on servers within the European Union. Where we use hosting and infrastructure providers for this, we do so on the basis of data processing agreements (Art. 28 GDPR). Withdrawal and storage period: you can withdraw your consent at any time with effect for the future, for example via the unsubscribe link at the end of every newsletter email. The lawfulness of the processing carried out up to the withdrawal remains unaffected. Your data is stored for as long as you are subscribed to the newsletter and is deleted from the mailing list after you unsubscribe.
Whenever a MapShot panorama is opened – for example by scanning a QR code plaque, opening a panorama link or using it in our apps – we record an anonymous usage statistic for it. Data processed: per view, the identifier of the location plaque that was opened (QR plaque), the type of access path (e.g. QR scan, link forwarded by a visitor, reference link, app, or re-opening the same page by reloading or using back/forward in the browser; for this the viewer asks the browser how the page was opened – nothing is stored on the device), a coarse device class (mobile, desktop or tablet), the platform (web, iOS or Android), the preferred language as a language code (e.g. "de", "en", "fr") and the time of the view. We also record how long the panorama was open on screen (in seconds), whether it was interacted with (yes/no) and how long after loading the first interaction happened. No personal data: We do not store your IP address, nor do we set cookies or access information on your device. Only coarsely aggregated values are stored (such as "mobile" or "de"), never full device or browser identifiers. The data is not linked to any user account or to any specific person; we are therefore unable to identify individuals. No tracking and no profiling take place. Purpose: producing anonymous usage statistics to improve our service and to evaluate and report view counts to the respective location partners and sponsors (e.g. how often a particular location plaque was opened). Legal basis: our legitimate interest in the statistical analysis of how our own service is used (Art. 6(1)(1)(f) GDPR). To the extent that the collected data is anonymous and not related to a person – as described above – it is not subject to the GDPR.
To collect payment for our invoices we use the payment service provider Stripe Payments Europe, Ltd., One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland ("Stripe"). Invoicing and bank transfer: When we issue an invoice, we transmit to Stripe the name of your organisation, the billing email address, the billing address as well as the invoice number and amount. Stripe provides a bank account assigned to your organisation (virtual IBAN) through which incoming transfers are matched to the invoice automatically. In doing so, Stripe receives the transfer details from the sending bank (including the payer's name and IBAN, amount and payment reference). Online payment: You can pay online via the personal payment link on the invoice (mapshot.io/bezahlen/…). You are redirected to Stripe's payment page and enter your payment details (e.g. card details or IBAN for a SEPA direct debit) directly with Stripe. We do not receive these details, only whether and when payment was made and the payment method. When paying with Apple Pay or Google Pay, Apple or Google are also involved; when paying with PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg – each under their own privacy policies. The payment page is not included in our website analytics. Legal bases: The processing is necessary for the performance of the contract (Art. 6(1)(b) GDPR); payment and invoice data are retained under statutory retention obligations (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code, AO) – invoices and accounting vouchers for eight years, books and records for ten years. Where Stripe processes data for fraud prevention and to meet its own regulatory obligations (e.g. anti-money-laundering), Stripe is itself the controller. Transfers to third countries: Stripe may transfer data to Stripe, Inc. in the USA. This is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, supplemented by the European Commission's standard contractual clauses. Stripe privacy policy: https://stripe.com/privacy PayPal privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full