Legal
Privacy
This notice explains which personal data Mapelina processes, why we process it, and the rights available to you.
Updated: August 9, 2026
Controller
- Andy Shek
- c/o Impressumservice Dein-Impressum
- Stettiner Str. 41, 35410 Hungen, Deutschland
- Email: support@mapelina.com
Data categories
- poster and project information, including selected location, coordinates, and design settings
- order, billing, shipping, and contact information
- payment status and technical transaction identifiers; full payment details are processed by Stripe
- technical connection, security, rate-limit, and error information required to operate and protect the service
- information you provide when contacting support
Purposes and legal bases
- contract performance and pre-contractual steps, including design, checkout, payment, printing, and shipping: Article 6(1)(b) GDPR
- compliance with statutory retention, tax, and record-keeping obligations: Article 6(1)(c) GDPR
- service security, abuse prevention, reliability, and troubleshooting: Article 6(1)(f) GDPR; our legitimate interest is operating a secure and reliable service
Recipients and services
We use technical and contractual service providers and disclose personal data only where necessary for the relevant purpose.
- Stripe for payment and checkout
- Prodigi for printing, production, and shipping
- Resend for transactional order and shipping emails
- PostgreSQL database and S3/R2-compatible object storage for project, order, and temporary print data
- Upstash Redis for distributed rate limiting and abuse prevention
- OpenFreeMap/OpenStreetMap-based map data, MapLibre, and a configured Nominatim-compatible geocoding provider for maps and location search
- hosting and infrastructure providers used to deliver and operate the application
International transfers
Some service providers may process data outside the European Economic Area. Where no adequacy decision applies, transfers are made only on a lawful GDPR basis and, where required, with appropriate safeguards such as standard contractual clauses.
Retention
- unpaid drafts and related checkout data are automatically cleaned up after the configured draft-retention period
- print assets are automatically removed from object storage after the configured storage-retention period
- order, payment, and accounting information is retained as necessary for contract performance, complaints, and statutory retention duties
- security and error information is kept only as long as needed for operations, security, and troubleshooting
Your rights
You can contact us at support@mapelina.com. Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability, and objection where applicable. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
Optional product analytics with PostHog
If you explicitly consent, we use PostHog for product analytics and session recordings. PostHog is not loaded and does not receive analytics data from Mapelina before consent.
We only collect data that helps us understand usability issues and drop-off in the purchase flow. Our analytics layer removes order and project identifiers, email addresses, address and location data, URLs, and free-form error messages. Page paths are sanitized before transmission.
For session recordings, we mask form inputs and visible text. Order-status and internal Ops pages are excluded from session recording, and query parameters are removed from recorded network URLs.
Your choice is stored locally in your browser. You can change or withdraw it at any time through “Analytics settings” in the footer.