Legal
Privacy Policy
Last updated 22 August 2026
mapv.io is currently a free beta travel-planning service operated from Cyprus by Alexandros Magos, an individual rather than a company or organisation. For GDPR purposes, the individual operator is the data controller for the personal data described in this policy.
Service and controller address: Armonias 11, Larnaca 6046
Privacy questions and requests can be sent to [email protected].
No advertising or analytics tracking
mapv.io does not use Google Analytics, advertising networks, marketing pixels or behavioural advertising, and does not sell personal data. Third-party services are used only where needed to provide features such as maps, weather, email and AI.
Information mapv.io handles
- Account and security: your email address, username and display name, sign-in information, account-security information, and basic technical information needed to keep your account working and protect the service.
- Trips: the trips, places, routes, dates, times, notes, ideas, packing lists and planning preferences you save.
- Bookings and imports: booking and traveller details, costs, deadlines, notes and document links you save. If you forward or upload a booking confirmation, mapv.io keeps the original email or file only while it is being processed or retried, then removes that original evidence after processing reaches a final state. Extracted booking details and review information may remain with the trip.
- AI features: the question or instruction you send and the relevant trip information needed to answer it or prepare a proposed change. Limited usage and reliability records are also kept so AI features can be operated safely and fairly.
- Support and service records: messages you send to support and limited security, email-delivery and service records needed for troubleshooting, abuse prevention and legal obligations.
Purposes and legal bases
mapv.io uses personal data to create and secure your account, save and calculate trips, manage bookings, process booking confirmations you submit, provide maps and weather, run AI features you request, answer support messages, prevent abuse and keep the service reliable.
Where the GDPR applies, the main legal bases are providing the service you asked for, legitimate interests in security and reliable operation, your consent or deliberate instruction for optional features such as publishing a trip or using device location, and legal obligations where applicable.
mapv.io does not use AI to make legal or similarly significant decisions about you, such as decisions about credit, employment, insurance or eligibility.
AI features
mapv.io uses the OpenAI API for AI features and may use the Anthropic API as a fallback. Depending on the feature, the provider receives what you submit plus only the trip context needed for the request, such as itinerary or booking details, notes, locations, timings, routes and saved Ideas. For follow-up questions, the Trip Assistant can include up to six recent chat messages.
AI output can be incomplete or wrong. Booking-import results can be held for your review, and proposed itinerary changes do not alter a trip until you choose to apply them. AI providers are not authorised by mapv.io to buy or cancel travel or contact a travel provider for you. Do not upload passwords, full payment-card numbers, passport scans, health information or other unnecessary sensitive information.
OpenAI and Anthropic state that standard API inputs and outputs are not used to train their models by default. Under their standard API policies, some request data can be retained for up to 30 days for safety or abuse monitoring, subject to legal requirements and the provider terms linked below.
OpenAI API data controls · OpenAI DPA · Anthropic API retention · Anthropic DPA
Public trips
Trips are private unless you choose to publish them. A public trip can show your display name and username together with the trip information you chose to put in the itinerary, including places, dates, times, routes, notes and ideas.
The public view is designed not to show your account email, booking references or booking document links. Review a trip before publishing it and avoid putting confidential or unnecessary personal information in public trip fields.
Cookies and device location
mapv.io uses only the cookies and browser storage needed to keep you signed in, protect requests, remember drafts and preferences, and keep short Trip Assistant context during your browser session. These are not used for advertising or analytics.
Trip Mode asks for your current location only after you choose “Use my location”. That location is used on your device to show how far you are from the current stop and is not intentionally sent by Trip Mode to mapv.io or Google.
When you use pages with Google Maps, your browser communicates with Google to load maps and request places or routes. Google handles that data under its own privacy terms.
Service providers and other recipients
- OpenAI and Anthropic — AI processing for features you choose to use.
- Google — optional Google sign-in and Google Maps Platform for maps, places, geocoding and routes. mapv.io does not request access to Gmail, Drive or Calendar when you sign in with Google. Google Privacy Policy
- Open-Meteo — weather data requested using the trip coordinates and dates needed for a forecast. Open-Meteo Terms & Privacy
- Namecheap Private Email — account and support email, and forwarded Booking Inbox messages when you use that feature. Namecheap Privacy Policy
- Hosting — the core mapv.io application and database are hosted on operator-controlled hardware in Cyprus.
International data transfers
Some service providers can process data outside Cyprus or the European Economic Area. Where required, mapv.io relies on the provider’s applicable data-processing terms and recognised safeguards such as Standard Contractual Clauses or an adequacy decision. Providers can change their processing locations, so their linked privacy information contains the current details.
Retention and deletion
Account, trip and booking information is generally kept while it remains part of your account. Original booking emails and uploaded booking files are temporary and are removed from mapv.io application storage after processing reaches a final state. AI itinerary proposals are automatically removed after 30 days.
You can permanently delete your account from Account settings. This removes your account and the trips and account-owned data associated with it from primary application storage. Account deletion cannot be undone.
Limited security, support or administrative records may be kept where reasonably necessary for legal obligations, security, fraud or abuse prevention, or dispute handling. Copies handled by third-party providers are subject to their own retention policies.
Security
mapv.io uses access controls, secure password storage, encryption where appropriate, backups and other reasonable safeguards designed to protect personal data.
No online service can guarantee absolute security. Keep your account credentials private and revoke sessions you do not recognise.
Your GDPR rights and complaints
If the GDPR applies, you can have rights including access, rectification, erasure, restriction of processing, data portability and objection, subject to the conditions and exceptions in applicable law. Where processing relies on consent, consent can be withdrawn without affecting earlier lawful processing.
To exercise a privacy right, email [email protected]. mapv.io may need to verify that the request relates to you before acting on it.
If the GDPR applies, you also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. In Cyprus, the supervisory authority is the Office of the Commissioner for Personal Data Protection.
Changes to this policy
This policy may be updated as mapv.io or the services it relies on change. The date at the top will be revised for material changes, and additional notice may be provided where appropriate.