Privacy Policy
freakmaps.com · Last updated: September 2026
1. Introduction
Welcome to FreakMaps. This privacy policy explains how information is collected and used when you visit freakmaps.com (the "Site").
The data controller for this Site is the operator of freakmaps.com, Bartłomiej Banasik. Where a purchase is involved, the selling legal entity is identified at Stripe checkout and on your invoice. You can reach the controller using the contact details in section 16.
2. Information Collected
2.1 Automatically Collected Information
Some technical information about your device and browsing is processed when you visit the Site. Most of the list below is collected only if you accept analytics cookies; your IP address is also processed for error monitoring and security as described in section 2.6:
- Browser type and version
- Operating system
- IP address
- Pages visited and time spent on pages
- Referring website
- Date and time of visit
2.2 Personal Information
Anonymous browsing is not used to build a profile of you and you are not asked for personal details. Two exceptions apply even when you are signed out: your IP address is processed if an error report is generated (section 2.6), and a bot check runs if you open a sign-in form. If you create an account, personal data is collected as described in section 2.3 below.
2.3 Account Data
You can create an account with Google Sign-In, Apple Sign-In, or with a one-time sign-in link or code sent to your email address. Depending on the method, the following is stored:
- Email address (all sign-in methods)
- Full name — only when returned by Google or Apple
- Profile picture — only when returned by Google or Apple
- Account creation date and last sign-in timestamp
- Short-lived sign-in tokens and one-time codes, which expire after use or after a few minutes
- For each signed-in session: the IP address the session was created from and your browser user agent, kept for the life of the session so sessions can be identified and revoked
This data is stored in a PostgreSQL database hosted by Hetzner Online GmbH, located in Nuremberg, Germany (European Union). Authentication sessions are maintained via secure, HTTP-only cookies. You can delete your account at any time from Settings → Account, which removes your account data, custom presets, checkout attempts and entitlements; the limited exceptions are set out in section 10. The legal basis for processing account data is the performance of the contract with you (GDPR Article 6(1)(b)).
2.4 Paid Pass, Billing, and Custom Preset Data
If you buy an Export & Customisation Pass, payment is processed by Stripe. FreakMaps does not store or receive full card numbers, CVC codes, or bank account details. Stripe may process payment method details, billing data, fraud-prevention data, and checkout cookies under its own privacy policy.
- Stripe checkout session ID, payment intent ID, customer ID, amount, currency, plan, app, and timestamps
- Active export entitlement status, plan duration, start/end time, and revocation status
- Custom map preset names and preset JSON needed to sync your saved map styling
- Anonymized billing audit records using an HMAC hash of your user ID instead of your raw user ID or email
Paid pass data may be shared across FreakMaps and RailsMaps because one pass unlocks both apps for the same shared account.
2.5 Support Chat (Crisp)
Live chat support is provided through Crisp (Crisp IM SAS), a customer messaging platform. On the web, Crisp is only loaded after you sign in and open support chat.
- Your internal account identifier (when you are signed in), so chat threads can be linked to the correct account — your name and email are not automatically sent to Crisp
- The messages you send, files you attach, and related chat metadata such as timestamps
- Technical data Crisp collects to operate chat (for example device or browser type, IP address, and session identifiers)
The legal basis for processing support chat data is the legitimate interest of the site operator in responding to your requests and, where applicable, performance of the contract with you (GDPR Article 6(1)(b) and (f)). Crisp acts as a processor for the site operator. Chat history is retained according to the Crisp workspace settings and support workflow; you can request deletion using the contact details below.
2.6 Error Monitoring, Email Delivery and Anti-Abuse
A few further services run in the background so the Site stays working and sign-in stays safe. None of them is used for advertising or profiling:
- Sentry: error and performance monitoring. Error reports contain the error, the page or screen you were on, browser or device type, and your IP address at the point of collection. A sample of performance and session data is also sent on ordinary page loads, not only when something breaks. Personal data is not deliberately attached: the SDK runs with sendDefaultPii disabled.
- Resend: delivery of account emails. When you request a sign-in link or one-time code, your email address and the message are passed to Resend so it can be delivered.
- Cloudflare Turnstile: a bot check shown on sign-in forms. It collects technical signals from your browser to tell people apart from automated abuse. It is not an advertising or tracking product.
The legal basis for error monitoring and anti-abuse is the legitimate interest of the site operator in keeping the Site secure, available and working correctly (GDPR Article 6(1)(f)); you can object to this processing using the contact details below. The legal basis for sending account emails is performance of the contract with you (GDPR Article 6(1)(b)).
3. Cookies and Tracking Technologies
3.1 What Are Cookies
Cookies are small text files stored on your device when you visit the Site. They help understand how you use the Site and improve your experience.
3.2 Types of Cookies Used
Essential Cookies (Required)
These cookies are necessary for the Site to function properly:
- Cookie Consent (cc_cookie): Stores your cookie preferences · Authentication Session (better-auth.session_token): Maintains your signed-in state; only set when you create an account and sign in. This cookie is strictly necessary to provide the account feature and cannot be disabled while signed in. · Cloudflare Turnstile: short-lived storage set only when a sign-in form loads its bot check, used to prevent automated abuse.
Support Chat Storage (only if you open chat)
Crisp is not loaded with the rest of the page and is not one of the cookie banner categories. It loads only when you are signed in and actively open support chat — a service you have asked for at that moment — and it then stores what it needs to keep your conversation going:
- Crisp (client.crisp.chat): Support chat session and preferences · only set when you open chat while signed in
Analytics Cookies (Optional)
These cookies help understand how visitors use the Site:
- Google Analytics: Tracks page views, session duration, and user behavior to help improve the Site
3.3 Managing Cookies
You can manage your cookie preferences using the cookie consent banner that appears when you first visit the Site. You can also control cookies through your browser settings. Most browsers allow you to refuse cookies or delete cookies that have already been set. Note that disabling cookies may affect the functionality of the Site.
4. Google Analytics
Google Analytics is used to analyze how visitors use the Site. Google Analytics uses cookies to collect information such as:
- Number of visitors
- Pages visited
- Time spent on the Site
- Geographic location (country/city level)
- Device and browser information
Google Analytics data is pseudonymous: it is not used to identify you by name, though it does involve identifiers such as a randomly generated client ID. For more information about how Google uses data, visit Google's Privacy Policy.
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
5. Cloudflare Web Analytics
The Site uses Cloudflare Web Analytics, which collects Real User Measurements (RUM) to monitor site performance. This includes metrics such as page load times, time to first byte, and other performance indicators.
Cloudflare Web Analytics is privacy-friendly: it does not use cookies, does not track individual users across sites, and does not collect personal data. All data is aggregated and anonymized. For more information, see Cloudflare's Privacy Policy.
6. Map Tiles and Third-Party Services
The interactive maps use base map tiles built from OpenStreetMap (OSM) data. By default, all map tiles — including the base map — are served from FreakMaps' own servers. No third-party tile servers are contacted during normal use.
When you view maps on the Site:
- Base map tiles and overlay data are loaded from FreakMaps' own tile server
- Map label fonts and icon sprites are loaded from GitHub Pages (protomaps.github.io), which means your IP address may be visible to GitHub
- If you manually switch to an OpenStreetMap raster base map in the settings, tiles will be loaded directly from OpenStreetMap servers and your IP address will be visible to them
For more information, see the OpenStreetMap Privacy Policy and GitHub Privacy Statement.
7. How Information Is Used
The collected information is used to:
- Provide and maintain user accounts and authentication services
- Process paid export/customisation passes and enforce entitlement status
- Store and sync custom map presets for signed-in users
- Respond to support requests via live chat
- Understand how visitors use the Site
- Improve Site functionality and user experience
- Analyze traffic patterns and trends
- Identify and fix technical issues, and monitor errors and performance
- Send account emails such as sign-in links and one-time codes
- Detect and prevent automated abuse of sign-in and checkout
- Optimize content and features
8. Data Sharing and Disclosure
Your information is not sold, traded, or rented to third parties. Data may be shared with the following processors and services:
- Hetzner Online GmbH: Database and server hosting for account data (Nuremberg, Germany, EU). Hetzner Privacy Policy
- Google (Sign-In): OAuth authentication provider. When you sign in with Google, your browser communicates with Google servers. FreakMaps only stores the profile data returned after successful authentication. Google Privacy Policy
- Apple (Sign-In): OAuth authentication provider. When you sign in with Apple, your browser communicates with Apple servers. FreakMaps only stores the profile data returned after successful authentication. Apple Privacy Policy
- Stripe: Payment processor for paid Export & Customisation Pass checkout, payment confirmation, refunds, disputes, fraud prevention, and tax/accounting records. FreakMaps does not store full card details. Stripe Privacy Policy
- Crisp (Crisp IM SAS): Live support chat when you open chat while signed in on the web. Crisp processes chat content and related session data for the site operator. Crisp Privacy Policy
- Sentry (Functional Software, Inc.): Error and performance monitoring. Sentry Privacy Policy
- Resend: Delivery of account emails such as sign-in links and one-time codes. Resend Privacy Policy
- Cloudflare Turnstile: Bot protection on sign-in forms. Cloudflare Privacy Policy
- Google Analytics: For website analytics purposes (anonymized data)
- Cloudflare: For performance monitoring via Real User Measurements (no personal data collected)
- GitHub Pages: When loading map label fonts and icon sprites (your IP address may be visible)
- OpenStreetMap: Only if you manually select an OSM raster base map in the map settings (your IP address may be visible)
Information may be disclosed if required by law or to protect rights and safety.
9. Affiliate Links
The Site contains affiliate links for third-party travel booking partners. When you click an affiliate link (for example, the "Plan your trip" partner links in the sidebar), you are redirected through a tracking URL that may set cookies on your device so the partner can attribute a booking to FreakMaps and pay a commission. FreakMaps does not receive your name, email, payment details, or any other personal information from these bookings — only aggregated, anonymous click and conversion counts.
The current affiliate partners and their tracking domains are:
- DiscoverCars (
discovercars.com) - 12Go Asia (
12go.asia) - Omio via Impact (
omio.sjv.io,omio.com)
Cookie windows vary by partner (typically 30 days; DiscoverCars uses up to 365 days) and usually use last-click attribution. You can block these cookies in your browser settings or use tracking-protection extensions; doing so will not affect your ability to use the Site or to book travel directly with the partner.
For details on how each partner processes data, see DiscoverCars' Privacy Policy, 12Go's Privacy Policy, Omio's Privacy Policy, Impact's Privacy Policy.
10. Data Retention
Analytics data is retained for up to 26 months. Cookie consent preferences are stored for 182 days. Account data (name, email, profile picture) is retained for as long as your account is active and deleted upon account deletion. Authentication session data is retained until you sign out or the session expires. Custom map presets, checkout attempts, and active export entitlements are deleted with your account. Support chat history is retained according to the Crisp workspace settings until deleted by the site operator or upon your request. Error monitoring reports are retained according to the Sentry project settings, typically 90 days. Email delivery logs held by Resend are retained according to its standard retention. Minimal anonymized Stripe audit records may be retained as long as needed for tax, accounting, dispute, refund, fraud-prevention, and legal compliance.
11. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
- Right to Access: Request information about the data held about you
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data — account holders can exercise this directly by deleting their account in Settings → Account. Some anonymized billing audit records may be retained where required for legal, tax, accounting, refund, dispute, or fraud-prevention reasons.
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request transfer of your data
- Right to Object: Object to data processing
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, please use the contact details below.
You also have the right to lodge a complaint with a data protection supervisory authority. You may complain to the authority in your country of residence or place of work. The authority for the site operator is the Polish Personal Data Protection Office (Urząd Ochrony Danych Osobowych, uodo.gov.pl).
12. International Data Transfers
Primary account records (name, email, profile picture, presets, and entitlements) are stored in the European Union — specifically on servers hosted by Hetzner Online GmbH in Nuremberg, Germany. Analytics and performance data processed by Google Analytics and Cloudflare may be subject to transfers outside the EEA; both services operate under Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR. When you use support chat, your messages, internal account identifier, and related session data are processed by Crisp (Crisp IM SAS, France), which may involve transfers outside the EEA under Crisp’s data protection terms and applicable safeguards. Error monitoring data is sent to a Sentry project hosted in the European Union (Frankfurt region), so it is not transferred outside the EEA. Account email delivery handled by Resend may involve transfers outside the EEA under Standard Contractual Clauses or equivalent safeguards.
13. Security
Reasonable security measures are implemented to protect information from unauthorized access, alteration, or destruction. However, no internet transmission is completely secure.
14. Children
The Site is not directed at children. You must be at least 13 years old to create an account, or older where your country sets a higher age for consent to online services — in Poland that age is 16. Personal data is not knowingly collected from children below the applicable age. If you believe a child has created an account, get in touch and it will be deleted.
15. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time. Changes will be posted on this page. Continued use of the Site after changes constitutes acceptance of the updated policy.
16. Contact
If you have questions about this Privacy Policy or wish to exercise your rights, get in touch at:
Email: [email protected]
Website: freakmaps.com
17. Attribution
Map data © OpenStreetMap contributors, available under the Open Database License (ODbL). Base map styling powered by Protomaps, an open-source map project. Paid export removes only the FreakMaps/RailsMaps brand watermark; required map/source attribution remains.