tracemaps Limited Privacy Policy
The Privacy Policy below describes what personal information tracemaps collect when you visit and interact with our website, and explains how we use your data.
1. About us
tracemaps Limited is the registered name of the company. You can contact us by sending an email to hello@tracemaps.com if you would like any more information.
2. What is personal data?
Personal data means a piece of information that can be used to identify a person whether used on its own or in conjunction with a second source. This could be a name, an address, or an IP address for example.
3. What is our legal basis for processing your personal data?
Under the UK and EU GDPR, we are required to identify the legal basis on which we process your personal data. We rely on the following:
- Consent – for email marketing, custom map requests, and use of location data post-sale.
- Contractual necessity – for fulfilling orders and providing customer support.
- Legitimate interests – for pre-sale processing of location data, analytics, product improvement, and communication/feedback (where your rights and freedoms are not overridden).
- Legal obligation – for compliance with accounting or legal recordkeeping requirements.
Where we rely on legitimate interest, we ensure it is balanced against your rights and freedoms, and you have the right to object to this processing (see "Your Rights" section 8 below).
4. What personal information do we collect and how is it used?
Depending on your level of interaction with our website tracemaps collect different pieces of information about you. The following information is only used to help us and our partners deliver our service to you and to improve it going forward, it is never sold to other parties.
4.1. Location information upload
tracemaps prints are created using location information, such as .gpx files, that have been provided by the customer. In most cases this data contains information on the location of the person who recorded it, at a particular time, on a particular date. This information is used to plot the map that will potentially be purchased by the customer.
Location information uploaded to tracemaps is handled in two stages, first to show visitors a preview of their print pre-sale, and second to produce the print for the customer post-sale.
Once uploaded, pre-sale location information is stored by Amazon Web Services and processed by Heroku. Please see section 5 Third party services for more information.
The lawful basis for collecting location information pre-sale is tracemaps legitimate interest. We cannot provide our services without this information and believe potential customers would reasonably expect us to process their information in this way for this purpose.
Post-sale location information is shared with a third party company called Mapbox who help us to produce some of the graphic elements of our products. Please see section 5 Third party services for more information.
Post-sale this data is retained in case the customer has any issues with their order that was produced or if they would like to make a new order using the same data.
This information is also retained by tracemaps to help us develop our products and services internally. If a new product or service is created using a customer’s data it will not be published without anonymizing the data or by obtaining consent from the owner.
The lawful basis for processing location information post-sale is consent.
4.2. Use of Strava data
If you choose to connect your Strava account to our website, we will collect specific activity data from your Strava account using Strava’s official API, based on your explicit permission. This may include location data (GPS), timestamps, and route information.
We use this data for the sole purpose of generating a preview and printed version of your custom map. We do not share Strava data with third parties except as necessary for rendering and printing the map, and we never display your activity data to others or use it for analytics or marketing.
You can revoke access at any time via your Strava account settings https://www.strava.com/settings/apps or by contacting us.
4.3. Custom map
Alongside our map creator we offer a bespoke service we call “custom maps” to handle more complicated customer requests. Customers can upload their location information and type a message to explain what they would like us to make.
Section 4.2 above, location information upload, describes how this information is used but in addition, for custom map requests tracemaps ask for a customer’s name, and an email and/or phone number. This information is required so we are able to contact you to discuss your request and provide our service.
The lawful basis for processing location and contact information for custom maps is consent.
4.4. Customers
When you place an order with us we ask you for your name, address, email address and telephone number so we can arrange delivery of your order and contact you in relation to it if the need arises.
To deliver your order to you we will share your name and address with our delivery partner who is currently Royal Mail. Please see section 5 Third party services for more information.
We do not receive or store any credit or debit card details; these are sent directly to our payment partner via Shopify through their payment interface integrated into our website. To take a payment Shopify will request your email address to send you a receipt, they will ask for your card number, its expiry date and its CVC (Card Verification Code) which is used to process the payment to tracemaps. You also have the option to ask Shopify to remember your payment details to make payment with them faster in the future. Please see section 5 Third party services for more information.
The lawful basis for processing customer information is contract.
4.5. Email marketing
To keep in touch and let customers and visitors know about new products, services or company updates that may be of interest tracemaps send out emails from time to time to mailing list subscribers.
If you would like to receive this information visitors can subscribe by entering their email address at the bottom of the home page or by putting a tick in the subscribe box at the checkout stage.
tracemaps only send marketing material to visitors and customers that directly consent and if you decide to opt-in you can opt-out at any time by clicking the ‘unsubscribe’ link in one of our marketing emails, or by sending an email to hello@tracemaps.com.
Klaviyo are our email marketing partner and they store and process the email addresses of our subscribers. We do not share our mailing list with anyone else other than Klaviyo. Please see section 4 Third party services for more information.
The lawful basis for collecting and storing email addresses for email marketing is consent.
4.6. Social media
tracemaps have active social media accounts on Facebook and Instagram to be able to communicate more easily with customers.
All content posted and shared by visitors on these web based applications is covered by the privacy policy of the host service and is separate from this privacy policy. More privacy policy information for each of these social media companies can be found from the relevant link below.
- Facebook - https://www.facebook.com/policy.php
- Instagram - https://help.instagram.com/155833707900388
Content posted and shared by visitors on these sites is never removed from the site it was posted on by tracemaps without acquiring detailed consent from the user first.
Users of these web applications have the right to request their data be deleted by using the delete features within the web application or by contacting the social media provider directly.
4.7. Communication and feedback
From time to time visitors and customers may communicate with tracemaps regarding our services in the form of email with questions or suggestions for how we can improve what we do.
We use this information for the development of our services and for training purposes.
tracemaps emails are hosted by Google’s Gmail service and are protected by their privacy policy. Please see section 5 Third party services for more information.
The lawful basis for collecting and processing communication and feedback is tracemaps legitimate interest.
5. Third party services
At tracemaps we work with a number of third parties and share some of your personal information with them to help us deliver our services to you.
These service providers are only given the information necessary to perform their limited functions on our behalf and are required to protect and secure your information. The third parties we work with are listed below along with what information they receive from us and with a link to their privacy policy;
Our key service providers include:
- Amazon Web Services (AWS) – hosts and stores personal data securely: https://aws.amazon.com/privacy/
- Heroku – handles computational processing of location and order data: https://www.salesforce.com/company/privacy/
-
Payment processor (e.g. Shopify Payments or other integrated solution) – processes payment information securely. Payment details are not stored or seen by us
https://www.shopify.com/uk/legal/privacy -
Royal Mail – delivers your printed products
https://www.royalmail.com/privacy-notice/ - Google (Gmail) – stores and processes our email communications: https://policies.google.com/privacy
- Klaviyo – manages our email marketing communications: https://www.klaviyo.com/legal/privacy
We may update this list from time to time and will always ensure new providers follow data protection best practices.
By accepting our privacy policy you grant tracemaps the right to share your personal information with these third parties for the purposes described above.
Your location information is shared with another third party company called Mapbox who help us to produce some of the graphic elements of our products.
Mapbox only receive your location information so it is not directly identifiable.
For the purpose of helping tracemaps to provide our service to you Mapbox request the right to store your location information on their distributed platform. Please read the following excerpt from their terms of service.
“You retain ownership of all content that you contribute to the Services via Mapbox Studio, Mapbox Studio Classic, the Dataset API and the Uploads API, excluding any content that you receive from Mapbox ("Your Content").
Limited to the purpose of hosting your content so that we can provide the Services to you, you hereby grant Mapbox a non-exclusive, worldwide, royalty-free, fully paid-up, transferable and sub licensable right and license to use, copy, cache, publish, display, distribute, modify, create derivative works, and store Your Content and to allow others to do so. This right and license enables Mapbox to host and mirror your content on its distributed platform. You warrant, represent, and agree that you have the right to grant Mapbox these rights.”
By accepting our privacy policy you grant tracemaps the right to share your location information with Mapbox for this purpose.
You retain ownership of your personal information which upon your request to tracemaps can be arranged to be deleted. However please note that due to the distributed nature of cloud hosting this may not take effect immediately.
6. International data transfers
Some of our service providers (such as Klaviyo, Google, and Amazon Web Services) are based outside the UK and European Economic Area (EEA). Where we transfer your data internationally, we ensure appropriate safeguards are in place to protect your data, such as:
- Standard Contractual Clauses (SCCs) approved by the UK ICO and the European Commission.
- Binding corporate rules or adequacy decisions, where applicable.
You can request more information about these safeguards by contacting us at hello@tracemaps.com.
7. How long does tracemaps keep your data
tracemaps only keep your personal information only as long as we need to in order to fulfill three main purposes; To provide our services to you, to respond to potential customer service issues, to keep adequate records of the services we have provided for accounting and legal reasons and to help us improve our services going forward. The length of time specific information is retained for is described below.
7.1. Location information
Location information is retained in case the customer has any issues with their order that was produced or if they would like to make a new order using the same data. This information is also retained by tracemaps to help us develop our products and services internally.
Location information may be held until a website user requests for it to be deleted.
7.2. Customer information
Customer information is retained to keep a record of an order for accounting purposes.
7.3. Email marketing
Email addresses are held for as long as the customer is subscribed to our email marketing.
If a customer opts-out of our email marketing their details are deleted from our contact list as soon as possible. This can be done automatically if the user clicks on the unsubscribe link in a marketing email or it can usually be done within 48 hours if they send an email to hello@tracemaps.com.
7.4. Social media
All contributions to our social media pages are retained unless deleted by the contributor.
7.5. Communication and feedback
All communication and feedback received by email is retained by tracemaps for training and the improvement of our products and services.
All visitors and customers of tracemaps have the right for their data to be deleted upon their request. If you would like to make this request please email hello@tracemaps.com and we will make the necessary arrangements.
8. What are your personal information rights?
You have statutory rights relating to any of your personal information that tracemaps hold, these rights have been listed below;
- Your right to be informed if your personal data is being used
- Your right to get copies of your data
- Your right to get your data corrected
- Your right to get your data deleted
- Your right to limit how organizations use your data
- Your right to data portability
- The right to object to the use of your data
- Your rights relating to decisions being made about you without human involvement
- Your right to access information from a public body
- Your right to raise a concern
Find out more about each of these at the ICO website here https://ico.org.uk/your-data-matters/.
tracemaps have read these rights and created and implemented this policy to address them. If you wish to follow up on any of these aspects or have a concern about how they are implemented do not hesitate to get in touch by emailing hello@tracemaps.com.
9. How do tracemaps acquire your Consent?
tracemaps acquire consent to collect and process personal data for the following uses.
- Creating a custom map
- For customers who purchase a map or gift card
- For email marketing subscribers
For creating a custom map consent is obtained by a positive opt-in tick box located at the Submit stage of a visitors custom map request.
For customers who purchase a map or gift card consent is obtained by a positive opt-in tick box located at the checkout stage of the map or gift card creator.
For email marketing subscribers consent is obtained by a positive opt-in action to enter their email address into a specific text entry box on the home page and click of a subscribe button.
10. How do I withdraw my consent?
If after you opt-in you change your mind you may withdraw your consent for us to store and process your information at any time by contacting hello@tracemaps.com. Consent for email marketing can also be removed by clicking on the unsubscribe link within a marketing email.
11. Disclosure
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
12. Links
When you click on links on our website, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
13. Security
tracemaps take the security of personal data seriously and have implemented organizational and technical measures to prevent your data being inappropriately lost, misused, accessed, disclosed, altered or destroyed.
Following an analysis or the risks presented by our processing the following information describes how tracemaps keep your data secure.
13.1. Personal data sent to tracemaps is stored and backed up by Amazon Web Services who employ industry leading practices to prevent security breaches. These measures include network firewalls, data encryption, and penetration testing. More information on Amazon Web Services’ security measures can be found here https://aws.amazon.com/security/.
13.2. Payment information is not received by tracemaps and is processed securely and directly by Shopify and their Payment Providers. Shopify has a multi-layered security policy designed to protect both merchants and their customers. It includes measures for physical access control, data encryption (SSL certificates), compliance with industry standards like PCI DSS, and features like two-factor authentication for account security. More information on Shopify’s security measures can be found here https://www.shopify.com/uk/legal/privacy.
13.3. Emails are protected by googles’ advanced security infrastructure making use of encryption and threat detection measures amongst other policies. More information can be found here https://privacy.google.com/intl/en-GB/your-security.html?categories_activeEl=sign-in.
13.4. Mapbox host location information of our customers on their network. Their website is served exclusively by HTTPS protocols and their infrastructure runs inside state of the art data centers designed and operated by Amazon Web Services. More information can be found here https://www.mapbox.com/platform/security/.
13.5. Heroku run their processes on behalf of tracemaps. Heroku has put in place appropriate physical, electronic and administrative procedures to safeguard and secure the information from loss, misuse, unauthorized access or disclosure, alteration or destruction. More information can be found here https://www.salesforce.com/company/legal/privacy/
13.6. Royal Mail only process address information for the purpose of delivering good to customers. More information can be found here https://www.royalmail.com/personal/identity-verification/your-security.
13.7. Klaviyo store and process tracemaps email marketing at multiple world class data centers located in the United States. Appropriate security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your personal data. More information can be found here https://www.klaviyo.com/legal/privacy.
13.8. Data stored and processed locally provides us with a third data backup should there be a problem with our cloud storage service. This data is kept behind password protected accounts that are regularly updated with strong passwords on secure physical premises.
tracemaps regularly review our data security practices improving and updating them where necessary.
14. Changes to this privacy policy
We may need to modify and update this privacy policy from time to time, so please review it frequently. Changes and clarifications to the policy will take effect immediately after being posted on the website. If we make material changes to this policy, we will notify you below in the change log that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If our company is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
15. Questions and contact information
If you would like to access, correct, amend or delete any personal information we have about you, register a complaint, or to simply request more information please send an email to hello@tracemaps.com and we will get back to you as soon as possible.
16. Change log
16.1. Initial issue 17.07.18
16.2. Policy update 07.07.25