Legal

Privacy policy.

Last updated: 28 September 2026

Mapseen (“we”) takes privacy seriously. This policy explains what we collect, why, and what your choices are.

Data we collect

  • Account data: email, name, hashed password, OAuth identifiers.
  • Workspace data: business names, websites, target keywords, AOV and conversion rate inputs.
  • Search Console data: queries, pages, clicks, impressions, position, fetched on your behalf.
  • Analytics: anonymised usage data via Vercel Analytics; error reports via Sentry.
  • Billing: handled by Stripe. We do not store card details.

How we use it

To provide the Service, generate insights, send transactional and digest emails (if enabled), maintain security, and comply with the law.

Sharing

We do not sell personal data. We share data with sub-processors as required to operate the Service: Supabase (database and auth), Stripe (billing), Resend (email), Sentry (errors), Vercel (hosting and analytics), OpenAI (insights generation), Serper, DataForSEO and Google (third party SEO data).

International transfers

Data may be processed outside Australia by our sub-processors. We rely on standard contractual clauses where applicable.

Your rights

Access, correction, deletion, portability, and the right to lodge a complaint with the OAIC (Australia) or your local supervisory authority.

Retention

We keep account and workspace data for as long as your account is active, plus 30 days after deletion. Aggregated, anonymised analytics may be retained longer.

Security

TLS for all transport. At rest encryption via our hosting provider. RLS policies isolate tenant data. Production access limited to a small group, with audit logging for sensitive actions.

Children

The Service is not directed at children under 16 and we do not knowingly collect their data.

Changes

We will notify you of material changes 14 days in advance via email or in app.

Contact