What this policy covers

This policy describes how MapInCheck ("we", "us") collects, uses, and protects information when you use the MapInCheck website and application.

Information we collect

  • Account information. Name, email address, company name, and password when you register.
  • Workspace data. Products, MAP prices, reseller accounts, contacts, and notes you add to your workspace.
  • Scan data. Listing URLs, advertised prices, seller names, and screenshots collected when you run monitoring scans.
  • Billing information. Subscription and payment records. Card details are processed by our payment provider and are not stored on our servers.
  • Usage data. Log data such as IP address, browser type, and pages visited, used for security and to improve the service.
  • Sample scan requests. Contact and company details, product identifiers or URLs, MAP context, and notes you submit when asking us to evaluate a free sample scan.

How we use information

  • To provide and operate the MapInCheck service, including scans, evidence storage, and notifications you send.
  • To manage your subscription, billing, and support requests.
  • To review, scope, deliver, and follow up on a sample scan you request.
  • To secure the service and prevent abuse.
  • To communicate service updates. We do not sell your data or share it with third parties for their marketing.

Third-party services

We use a small number of service providers to operate MapInCheck, such as hosting infrastructure, search APIs used for monitoring scans, email delivery, and payment processing. These providers process data only as needed to provide their service to us.

Website analytics

On our public marketing pages, Google Analytics is disabled unless you choose to allow analytics. If allowed, it measures page use and privacy-safe actions such as starting a sample-scan request or registration. Advertising storage remains disabled, and we do not send your name, email address, organization name, catalog, reseller, or scan data to analytics. You can change your choice by clearing this site's stored data in your browser.

Google account and Gmail data

If you connect a Google Workspace or Gmail account, MapInCheck requests permission to send email from that connected account. We use this access only to send reseller notices, scan reports, and related messages that you initiate or configure inside MapInCheck.

MapInCheck does not read, search, store, or import your Gmail inbox, sent mail, contacts, calendar, or unrelated Google account content. If you connect a Google Drive catalog, MapInCheck reads only the Sheet, CSV, or XML file you explicitly select for synchronization. We store the connected sender or catalog authorization details and encrypted OAuth tokens needed to maintain the connection.

MapInCheck's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Data protection

We protect account, workspace, scan, evidence, billing, and Google OAuth data using administrative, technical, and organizational safeguards. All browser and Google API traffic is encrypted in transit using HTTPS/TLS. Gmail and Google Drive access and refresh tokens are encrypted at rest before they are stored. Production deployments require the encryption key at startup, and runtime data files are restricted to the dedicated service account.

Access to connected-Google data is limited by authenticated workspace membership and role. OAuth credentials are decrypted only by the application when needed to refresh authorization, send a user-approved message, or synchronize a file the user selected. Administrative access is restricted, security and service health are monitored, and encrypted credentials are excluded from public pages, logs, reports, and application backups that are not authorized to retain secrets.

Google user data is not sold, used for advertising, or shared with third parties except as required to provide the MapInCheck service, comply with law, or protect the security of the service. We do not use Google user data to train generalized AI or machine learning models.

Data retention

Google OAuth tokens and connected-account identifiers are retained only while the connection is active. Disconnecting Gmail or Google Drive removes the stored connection credentials; you can also revoke MapInCheck from your Google Account. Workspace data is retained while your account is active, and screenshot evidence is retained according to your plan's retention window. You can request deletion of your account and associated data at any time.

Your rights

You may request access to, correction of, or deletion of your personal data by contacting us at support@mapincheck.com.

Contact

Questions about this policy can be sent to support@mapincheck.com.