Privacy Policy
Version 2026-09-08. Effective 2026-09-08
This policy explains what personal data World Crochet Map processes, why, for how long, who can see it and what your rights are. It follows the EU General Data Protection Regulation (GDPR) and French law, and applies to everyone who visits the service wherever they live. The data controller is the operator identified in the Legal Notice; contact: mapelote.fr@gmail.com.
1. What we collect and why
- Map dot: display name, avatar (preset or photo you upload, with location metadata stripped in your browser), city / region / country and approximate coordinates, optional Instagram / TikTok links. Purpose: display your dot on the public map. Legal basis: performance of the contract (Terms). You choose to join.
- E-mail address (required to join): purpose: let you recover your dot from another device, contact you about your dot or about moderation, and comply with legal requests. Legal basis: contract and legitimate interest (account recovery, security). It is never displayed publicly and we do not send newsletters without a separate opt-in.
- Creations, notes and chat messages: the content you post plus its time. Purpose: the service itself. Legal basis: contract.
- Community identity: a pseudonymous member token, display name, country and language you choose. Purpose: chat rooms, blocks, likes and moderation.
- Technical and security data: a salted, one-way hash of your IP address (never the raw IP) stored with dots, messages, reports and rate-limit counters, for a limited time. Purpose: abuse prevention, rate limiting, moderation, legal compliance. Legal basis: legitimate interest and legal obligation.
- Measurement: World Crochet Map uses privacy-friendly, first-party analytics. Page views and feature usage are counted using a technical session value kept in your browser's sessionStorage, which is pseudonymised (hashed with a server-side secret) before storage, so that sessions can be told apart. No advertising identifier and no cross-site tracking are used, and the data is never shared for advertising. Legal basis: legitimate interest (understanding usage).
- Partnership and contact forms: name, organisation, e-mail, message and the details you type. Purpose: answer you. Legal basis: pre-contractual steps at your request / legitimate interest.
- Content reports: your explanation and, if you give it, a contact e-mail. Purpose: process the report and reply. Legal basis: legal obligation (Digital Services Act) and legitimate interest.
- Professional accounts (when available): e-mail and password (hashed by our authentication provider), profile details you publish, subscription status and payment references (never card numbers, which stay with the payment provider). Legal basis: contract.
- Proof of acceptance: the version and date of the Terms or Guidelines you accepted, linked to your dot or member reference, without IP address. Legal basis: legal obligation / legitimate interest (evidence).
2. What is public
Your display name, avatar and approximate location (city level) are public on the map and on country and city pages, as are the creations, notes and chat messages you post and the likes you give within rooms. Social links appear only if you switch them to public. Your e-mail address, IP hash, management token and internal identifiers are never public. The live arrivals feed mentions only a place, never a person.
3. Processors and international transfers
We use the following service providers, each bound by a data-processing agreement and the GDPR: - Lovable. Application platform, hosting and deployment (the host's exact legal entity and address are being confirmed and will be added here). - Lovable Cloud (managed database infrastructure operated with Supabase) (database, authentication for professional accounts and file storage (avatars, creation photos). - Stripe) payments for paid features when they are available; Stripe receives the data needed to process a payment and acts as an independent controller for that processing. - OpenFreeMap / OpenMapTiles. Map tiles loaded by your browser (your browser's IP is seen by the tile server); Nominatim (OpenStreetMap), with Photon (Komoot) as fallback (city search, proxied through our server so your IP is not sent to them. - Lovable AI Gateway / Google Gemini) only when you explicitly ask for a note (a “Petit mot”) to be translated, its text is processed to produce that translation. - Google Search Console. Aggregated search statistics about the site, no personal data of members.
Some providers process data outside the European Economic Area, notably in the United States. Transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses with supplementary measures. You can request a copy of the relevant safeguards at mapelote.fr@gmail.com.
4. Retention
- Dot, creations, notes, chat messages, professional profile: as long as they are online, then deleted or anonymised within 30 days of your deletion request; backups expire within 30 further days.
- Notes on the map: automatically expire after their display period.
- E-mail address: with your dot; deleted with it.
- IP hashes and rate-limit counters: 30 days maximum.
- First-party measurement events: 13 months.
- Content reports and moderation decisions: 3 years after the decision (evidence required by the Digital Services Act).
- Proof of acceptance of the Terms or Guidelines: 5 years after the end of the relationship.
- These periods are applied by us; automated purge jobs for IP hashes and measurement events are not yet in place, and older records are removed manually until they are.
- Payment and subscription records: 10 years (French accounting law), at the payment provider and in our billing tables.
- Contact and partnership requests: 3 years after the last exchange.
5. Your rights
You have the right to access, rectify, erase and receive (portability) your personal data, to restrict or object to processing based on legitimate interest, and to withdraw consent where processing relies on it. You can delete your dot and content yourself from the map at any time. For any other request write to mapelote.fr@gmail.com from the address linked to your dot so we can verify it; we answer within one month (extendable by two months for complex requests, in which case we tell you).
You may lodge a complaint with your local data-protection authority. In France: CNIL, www.cnil.fr. EU residents can also contact the authority of their country; UK residents the ICO; other residents their competent authority.
6. Children
The service is not intended for children under 16. We do not knowingly collect their data; if you believe a child under 16 has added content, tell us at mapelote.fr@gmail.com and we will remove it.
7. Security
Data is encrypted in transit (HTTPS) and at rest by our providers. Public reads go through controlled endpoints that never expose e-mails, tokens or IP data; sensitive operations on your profile (editing or deleting your dot) require your private management token, while other public interactions are validated and rate-limited with protections suited to how they work. Access to raw data is limited to the operator. Despite this, no system is perfectly secure; in case of a breach likely to create a high risk for you, we will notify you and the authority as required by the GDPR.
8. Cookies and local storage
No advertising or analytics cookie is used. Your browser stores strictly necessary values only: your private management token for your dot, your community member token, your language and theme choice, a technical session value used for internal measurement, and (when you arrive through a community partner link) the partner reference for 30 days so the partner can be credited. Professional accounts store an authentication session. You can clear these values from your browser at any time.
9. Changes
We will update this policy when the service changes. The version and effective date are shown at the top; significant changes are announced on the site.
