01 · Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Nicolas Dunke
Neuburgerstraße 25c
76287 Rheinstetten, Germany
Email: [email protected]
02 · What we process
MapsMover helps you move your own Google Maps saved places from one Google account to another. To provide the service we process:
- Account data — your email address and account identifier, provided when you sign in with Google.
- Transfer data — the list names and places contained in the Google Takeout export you upload, stored so the transfer can run and resume.
- Billing data — your purchase history and credit balance (payment card details are handled solely by our payment processor, never by us).
- Technical access data — server logs such as IP address, browser type, and request time, generated automatically by our hosting and CDN providers.
The legal basis for this processing is Art. 6 (1)(b) GDPR (performance of a contract) for the transfer service and account, and Art. 6 (1)(f) GDPR (legitimate interest in a secure, functioning service) for technical logs.
03 · SSL/TLS encryption
For security, this site uses SSL/TLS encryption for all data transmitted between your browser and our servers. You can recognize an encrypted connection by the https:// prefix and the lock icon in your browser’s address bar. While encryption is active, the data you submit cannot be read by third parties.
04 · Hosting & CDN
Vercel
Our application is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit MapsMover, Vercel automatically processes technical access data (such as IP address, requested URL, and timestamp) to deliver the site and protect it against abuse. Data transfers to the USA are covered by the EU Standard Contractual Clauses. More information: vercel.com/legal/privacy-policy.
Cloudflare
We use the content delivery network and security services of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare routes traffic to our servers, caches static content, and mitigates attacks. For this purpose it processes technical access data and may set strictly necessary cookies (e.g. __cf_bm) to distinguish humans from bots. Data transfers to the USA are covered by the EU Standard Contractual Clauses. More information: cloudflare.com/privacypolicy.
05 · Database & authentication
Supabase
Your account, credit balance, and transfer data are stored in a Postgres database and authenticated through Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992. Supabase acts as our processor under a data processing agreement. Sign-in is handled via Google OAuth; we receive only your email address and a stable account identifier from Google — we never receive or store your Google password. More information: supabase.com/privacy.
06 · Your uploaded places
To run a transfer, you upload a Google Takeout export of your own saved places. We parse it and store the list names, place titles, and Google Maps links so the transfer can be performed and resumed if interrupted. This data is processed strictly to carry out the transfer you requested (Art. 6 (1)(b) GDPR) and is associated with your account. You can request deletion of your transfer data at any time (see Your rights).
07 · Browser extension
MapsMover offers an optional Chrome extension that performs the actual saving in your browser, using your own signed-in Google Maps session. Installing it is not required to use the website. The extension processes the following data:
- Pairing token — a token you generate on the transfer page and paste into the extension. It is stored locally in
chrome.storage.localand sent to MapsMover as an authorization header so we can tell which account a transfer belongs to. It is the only credential the extension holds; your Google password is never involved. - Transfer queue — the places of your current transfer and their status (pending, saved, skipped, failed) plus any error text, kept locally so the transfer survives closing the popup or restarting the browser.
- Place outcomes — for each place, whether it was saved, skipped, or failed, sent back to MapsMover so the progress page and your credit balance stay correct.
The extension only interacts with Google Maps pages that it opens itself, in order to click Save and select the target list. It does not read your browsing history, does not act on any other website, does not transmit the content of the pages it opens, and contains no advertising, analytics, or tracking. The legal basis is Art. 6 (1)(b) GDPR (performance of the transfer you requested).
You can end the extension's access at any time: choose “End session” in the extension popup to clear the locally stored token and queue, revoke the token on the transfer page, or uninstall the extension — uninstalling deletes all of its locally stored data.
08 · Payments
Stripe
Payments for place credits and passes are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When you make a purchase, the payment and card data you enter are transmitted directly to Stripe; we never see or store your full card details. We receive only a payment confirmation and a customer reference to allocate your credits. The legal basis is Art. 6 (1)(b) GDPR. More information: stripe.com/privacy.
10 · Web analytics
To understand how MapsMover is used — which pages are visited and which buttons are clicked — we use Umami, a privacy-focused analytics tool. Umami is cookieless: it sets no cookies, writes nothing to your browser's local or session storage, and does not follow you across other websites.
Visitors from the EU, the EEA, and the United Kingdom are not analysed at all. The analytics script is not delivered to them — our server declines to serve it based on the region of the incoming request, before any script runs. Nothing is read from your device, no data is sent, and no consent is needed, because no analytics processing takes place. The rest of this section describes how the tool behaves for visitors elsewhere.
We do not collect personal data through analytics. No name, email address, account identifier, or uploaded place ever reaches the analytics data. What is recorded is the page you viewed, the page that referred you, your approximate country, and coarse technical details such as browser, operating system, and screen size — plus a small number of named product events, for example that a transfer was started or which button on the homepage was clicked. These events carry only counts and fixed labels, never your list names, place titles, or any text you entered.
Your IP address is not stored.It is used only in the moment of the request, together with your browser's user agent and a salt that rotates regularly, to compute an irreversible hash. That hash lets us count one person visiting three pages as one visitor rather than three, and nothing more. It cannot be turned back into an IP address, and once the salt rotates the same visitor is no longer recognizable. We build no profiles, sell no data, and share nothing for advertising. Analytics data cannot be linked to your MapsMover account.
Analytics data is processed using Umami, a self-hosted, open-source analytics tool running on our own infrastructure in Germany. No third-party analytics processor is involved. The legal basis is Art. 6 (1)(f) GDPR — our legitimate interest in understanding, in aggregate, how the service is used so we can improve it. Because no cookies are used and no information is stored on or read from your device, no consent banner is required. You may object to this processing at any time (see Your rights).
11 · Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate data (Art. 16);
- erase your data (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest (Art. 21).
To exercise any of these rights, contact us at [email protected]. You may also delete your account at any time, which removes your stored transfer data.
12 · Right to lodge a complaint
If you believe the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work, or the place of the alleged infringement.
13 · Changes to this policy
We may update this privacy policy to reflect changes to our service or legal requirements. The current version always applies and is dated at the top of this page.