Privacy Policy
Last updated 3 September 2026
This policy explains what Still on the map collects, why, and what you can ask us to do about it. The data controller is FREEDOMWAY LTD, registered in England and Wales, company no. 15158648, 24-26 Arcadia Avenue, Fin009, London N3 2JU, United Kingdom. For anything on this page, write to support@stillonthemap.com.
1. What we collect
- What you type: the business name, country, city and search term you submit. We keep them because they are what a report is made of.
- Your email address, only if you give it, to send you a report, or when you ask to be told about a paid plan. One purpose each, no newsletter, never sold.
- The measurements: the scanned business’s public listing (name, address, coordinates, category, rating, review count, opening hours), its rank at each of the nine grid points, and the same public details for the competitors that appear alongside it.
- Public review content: rating, text, date, the owner’s public reply, and the display name the reviewer chose to publish. See section 4.
- A one-way fingerprint of your IP address, used only to count how many scans one visitor started in the last hour and day. We do not store the IP address itself.
- Billing details, for subscribers: name, email, country and the last four digits of the card, held by Stripe and visible to us in their dashboard. The card number never reaches our servers.
Audience measurement. We count visits and the steps people take (how many arrive, how many run a scan, how many subscribe) using PostHog. It is configured so that itsets no cookie and cannot recognise you from one visit to the next: we see how many people did something, never who. Session recording is switched off, so nothing you type is captured.
Advertising measurement. We advertise on Facebook and Instagram, and the Meta pixel is on this site so we can tell whether an ad brought someone who actually used the product. It does set cookies, and Meta can recognise a returning visitor across sites. That is what a pixel is, and we are not going to describe it as anything gentler. What we send it is deliberately narrow: that a scan was started, that someone joined a waiting list, that a checkout was opened, that a subscription was paid, and the amount. We never send the business name, the search term, the address, or your email.
In the EU and the UK, the pixel does not load until you accept it. On your first visit you are asked, with a decline button the same size as the accept button, and nothing from Meta runs on this site until you choose. Elsewhere (the United States, Canada, Morocco and so on) the pixel runs from the first page and the same banner lets you turn it off with one click. If you decline, the site behaves identically — you only make our advertising harder to measure, which is our problem, not yours. You can change your mind at any time with the Cookie choice link at the bottom of every page.
The other script that sets something in your browser is Cloudflare Turnstile, the check that stops bots from draining our scanning budget.
2. Why we are allowed to hold it (lawful basis)
- To perform our contract with you: running the scan you asked for, sending your report, running a subscription and billing it.
- Our legitimate interests: preventing abuse and controlling the cost of free scans, keeping a history of measurements so a returning visitor can see change over time, and improving the scoring model.
- Legal obligation: keeping records of payments for tax and accounting.
3. How long we keep it
- Scans and the measurements in them: kept, so that the history a report shows is real.
- Email addresses given for a report or for a plan: until you ask us to delete them.
- Visitor fingerprints: 30 days, which is all the abuse limits need.
- Billing records: as long as tax law requires, currently six years in the UK.
If you ask us to erase your data, we delete your email address and unlink it from the scans. The measurement itself is about a business listing, not about you, and we keep it.
4. Data about people who are not our customers
A Google Maps listing carries reviews, and each review carries the display name its author chose to publish. To score how a business handles its reviews (whether the owner replies, how fast, to which ratings) we store the rating, the text, the date, the owner’s reply and that display name. We never store a reviewer’s photo, profile URL or account identifier.
Our basis is legitimate interest: this information is already published by the person on a public listing, and we use it only to measure the business being scanned. If you are a reviewer and want your review removed from our records, write to support@stillonthemap.com and we will delete it.
5. Who else processes it
We use a small number of providers. Each one is a processor acting on our instructions.
- Supabase: the database holding scans and measurements.
- Vercel: hosting and delivery of the site.
- DataForSEO: runs the Google Maps searches we measure.
- Resend: sends reports and alerts by email.
- Cloudflare: the anti-bot check on the scan form.
- PostHog: counts visits and steps, as described above.
- Meta (Facebook, Instagram): measures which ads brought visitors who used the product.
- Stripe: takes and holds payment details for paid plans.
Some of these are based outside the UK and the EEA. Where data is transferred, it is covered by the Standard Contractual Clauses or the UK equivalent in our agreements with them. We do not sell personal data, and we do not share it for advertising.
6. Your rights
You can ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Write to support@stillonthemap.com and we will reply within one business day and act within one month.
If you are unhappy with our answer, you can complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data protection authority where you live.
7. Security
The site is served over HTTPS. Card data is handled entirely by Stripe, a PCI DSS Level 1 service provider. It never touches our servers, so there is no card number here to steal. Database access uses server-side keys that are never sent to your browser. Access to the production database is limited to the company’s director.
8. Children
This is a service for businesses. It is not intended for anyone under 18, and we do not knowingly collect data about children.
9. Changes
If we change this policy in a way that affects you, we will say so on this page and, for subscribers, by email. The date at the top always shows the current version.