Privacy Policy — MapCompanion
DRAFT — FOR OWNER REVIEW. Not legal advice. Prepared for issue #106 (C4 prep), built from
docs/privacy/data-inventory.md(every claim there is cited tofile:line) and the architecture decision indocs/portal-architecture-design.md§A3.0. Before publishing: fill in the[OWNER-IMPRESSUM]block and remove this notice. The German version (privacy-policy.de.md) is the controlling text for German users; this is a courtesy translation and should be kept in sync with it.
Last updated: [DATE — set when the owner approves]
1. Controller
[OWNER-IMPRESSUM]
(Name, address, and email of the operator — a legal requirement, matching the app's Impressum.)
For any privacy question, contact us at the email address above.
2. What MapCompanion does, briefly
MapCompanion shows publicly visible micro-job offers from several portals (bemyeye, Roamler, AppJobber, Streetspotr) on one map and computes a route across several jobs. MapCompanion never accepts a job itself — there is no function for it. Tapping a job deep-links into that portal's own app, where acceptance, execution and payment happen.
For two portals (bemyeye, AppJobber), publicly visible offers are fetched directly from your device — no account needed. For the other two (Roamler, Streetspotr), your own, separately connected account fetches the offers — with your own credentials, from your own device.
3. What data we process
3.1 Location data
- GPS position: with your permission, the app reads your device location to show your own position on the map. This position does not automatically leave your device.
- Map viewport: when you move the map, the app sends the centre and corners of the visible viewport (not necessarily your real position — you can pan the map) encrypted to our server, so it can return jobs in that area. This viewport is used to answer your request and is not stored as a persistent record tied to you.
- Job locations: the positions of displayed jobs come from the portals themselves — this is data about the listings, not about you.
- Aggregate demand statistic (currently disabled): we operate a feature that, from map viewports, records only how often coarse map cells (roughly 20–40 km across) are queried — no precise coordinate, no user or session identifier, just a rolling count per cell that expires automatically after 14 days. This feature is disabled by default and will only be enabled after this policy has been reviewed separately. When active, its sole purpose is to decide where our own operator-side fetching (3.2) is applied first.
3.2 Portal credentials
Your own Roamler or Streetspotr credentials never leave your device toward our servers. They are stored exclusively, encrypted, in your device's secure storage area (Android Keystore) and used only to query the respective portal directly from your device. We never collect, store, or see these credentials at any point.
For portals or regions where no one has connected their own account (yet), we ourselves — using our own accounts, never yours — fetch a selected set of listings so the map is not left empty there. These operator credentials are stored encrypted and accessible to no one but the operator.
3.3 Optional MapCompanion account
You may optionally create an account (username + password) to carry app settings, such as a saved route, across devices. An email address is not required. Your password is hashed on your device before it is ever transmitted — we never see or store your plaintext password.
3.4 Session tokens
When the app starts, your device receives a randomly generated session token. Every request is encrypted with a key derived from that token. Without a connected account (3.3), this token is not linked to any known identity.
3.5 Job descriptions and translation (AI processing)
To make job descriptions easier to read, we send the job's description text (not your data) to Google's AI services (Gemini for rephrasing, Google Translate for translation). No user, session, or location data is included in these requests. The result is cached per job and shown identically to every user — it is not personalised.
3.6 Push notifications
Push notifications are marked "coming soon" in the app and are not currently implemented. No push service is used and no device token is collected.
3.7 Analytics / tracking
We currently use no analytics, tracking, or advertising SDKs. There is no advertising identifier, no behavioural profile, and no cross-app tracking.
4. Legal bases for processing
- Art. 6(1)(b) GDPR (contract performance): the core function — showing jobs on a map, computing routes, connecting your own portal accounts — rests on the usage agreement with you.
- Art. 6(1)(f) GDPR (legitimate interest): operator-side cold-start fetching in
under-covered regions (3.2), and — if enabled — the aggregate demand statistic (3.1), rest on
our legitimate interest in keeping the map usable even where no one has connected their own
account yet. The full balancing assessment is documented in
docs/privacy/lia.md.
5. Recipients and processors
- Google (Gemini API, Google Translate): processes job description text for rephrasing/ translation (3.5). Transfer may occur to the US; based on the EU Commission's Standard Contractual Clauses where applicable.
- Cloudflare (tunnel/access): technical intermediary for the connection to our server; processes connection metadata (e.g. IP address) as part of delivery.
- Hosting: [OWNER-IMPRESSUM — add hosting location/provider if different from the operator].
We do not transmit your portal credentials (3.2) anywhere — if you connect your own account, they remain exclusively on your device and are sent directly to the respective portal.
6. Retention
- Map viewports (3.1): used only to answer the corresponding request, not stored as a lasting personal record.
- Cached job listings: short-lived (minutes to a few hours), not an archive.
- Aggregate demand statistic (3.1, if enabled): expires automatically after 14 days per cell.
- Optional account (3.3): until you delete it.
- Session tokens (3.4): until the session expires.
7. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interest. You can disconnect a linked portal account at any time in the app. To exercise these rights, contact the address in Section 1.
You also have the right to lodge a complaint with a data protection supervisory authority.
8. Data security
All requests between the app and server are encrypted end-to-end with a key derived from your session token. Operator-side portal credentials are stored encrypted with AES-256-GCM. As described in 3.2, your own portal credentials never leave your device.
9. Minors
MapCompanion is not specifically directed at children. [OWNER-IMPRESSUM — add a minimum-age note if relevant, e.g. legal capacity to contract with the job portals themselves.]
10. Changes to this policy
We will update this policy whenever processing changes — in particular before a feature that is disabled today (e.g. 3.1's aggregate demand statistic, or any future analytics feature) is enabled. The current version is always available at this address.
German version (controlling): privacy-policy.de.md / /privacy/.
Last updated: