Privacy Policy

Last updated: May 31, 2026

RatMap ("we", "us", or "our") operates the RatMap mobile application. This Privacy Policy explains how we collect, use, and protect your information when you use our app, and the rights you have over your data.

1. Information We Collect

Account Information: When you create an account, we collect your email address and username. If you sign in with Apple or Google, we receive basic profile information from those services.

Location Data: We collect your device's location when you submit a rat sighting or use the map. Location is used to place sightings on the map and to show nearby activity. We only access location while the app is in use and with your permission. EXIF GPS metadata is stripped from photos before upload.

Photos: Photos you attach to sightings are uploaded to our servers and displayed publicly within the app. We do not access your photo library beyond the images you choose to share.

Push Tokens and Delivery Logs: When you enable notifications, we store an anonymous device push token and a log of notifications we send (for delivery diagnostics and rate limiting).

Crash Reports: If you opt in, we collect anonymous crash data via Sentry to fix bugs. This is off by default and never includes account content.

Consent Records: When you grant or revoke consent for a feature, we record what you accepted and when, so we can prove your consent if asked.

2. Lawful Bases for Processing (EU / UK / Brazil)

For users in jurisdictions that require a lawful basis, the following table maps each data category to its purpose and the legal basis we rely on:

DataPurposeLawful basis
Email, username, auth credentialsAccount creation and loginContract (GDPR Art. 6(1)(b))
GPS at sighting time, photosPlot sightings on the mapContract
Friend graphSocial featuresContract
Push tokens, cached device locationDecide whether to send nearby/friend notificationsConsent (Art. 6(1)(a))
Push delivery logsDeliver notifications, rate limitingConsent
Crash diagnostics (Sentry)Improve the app, debug crashesConsent — off by default

You can withdraw consent at any time in Settings → Notifications / Privacy. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

3. How We Use Your Information

4. Subprocessors

We use the following service providers (subprocessors) to operate the app. We have data processing agreements in place with each:

5. International Data Transfers

Our primary database and storage are hosted by Supabase in the United States (AWS region us-west-2). If you are located in the EU, UK, Switzerland, or another jurisdiction with cross-border transfer rules, your data is transferred to the United States. We rely on Standard Contractual Clauses (and where applicable the EU–US Data Privacy Framework) as the legal mechanism for this transfer.

6. Data Sharing

Your username, sightings, and profile information are visible to other RatMap users — that is the point of the app. We do not sell your personal information to third parties. The only third parties who process your data are the subprocessors listed in Section 4.

7. Data Retention

8. Data Storage & Security

Your data is stored on Supabase, which provides encryption at rest and in transit. We use industry-standard security measures (Row-Level Security on every user-facing table, hashed credentials, scoped storage paths) to protect your information, but no method of transmission over the internet is 100% secure.

9. Your Rights

You have the right to:

You can exercise the access, portability, and deletion rights directly in the app: Settings → "Export My Data" (Art. 15 / Art. 20) and Settings → "Delete Account" (Art. 17). Account deletion is immediate and irreversible. For any other request, email ratmapsupport@gmail.com and we will respond within 30 days.

10. Children's Privacy

RatMap is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us so we can remove it.

11. Regional Rights

European Economic Area & United Kingdom

If you are in the EEA or UK, you may lodge a complaint with your national data protection authority. In the absence of an EU-based representative, the lead authority for cross-border issues defaults to the Irish Data Protection Commission (dataprotection.ie). UK residents may complain to the ICO (ico.org.uk).

Australia

If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988. You may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

New Zealand

If you are in New Zealand, your rights are governed by the Privacy Act 2020. You may complain to the Office of the Privacy Commissioner (privacy.org.nz).

Brazil (LGPD)

If you are in Brazil, you have rights under the LGPD including access, correction, anonymization, portability, deletion, information about subprocessors, and revocation of consent. To exercise these rights contact ratmapsupport@gmail.com, or complain to the ANPD (gov.br/anpd).

Singapore (PDPA)

If you are in Singapore, your rights are governed by the Personal Data Protection Act. Our designated Data Protection Officer is reachable at ratmapsupport@gmail.com. You may complain to the Personal Data Protection Commission (pdpc.gov.sg).

Canada (PIPEDA)

If you are in Canada, your rights are governed by PIPEDA (and provincial laws where applicable). You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).

12. Data Protection Contact

For privacy questions, access/deletion/portability requests, or to withdraw consent, contact ratmapsupport@gmail.com. We will respond within 30 days.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app. The "Last updated" date above reflects the current version. Continued use of RatMap after changes constitutes acceptance of the updated policy.