Mappsite — Conecta · Descubre · Crece

Privacy policy

Last updated: August 2026 · Version 3.5 · Multi-region scope (Chile, EU, USA, Brazil and others).

1. Data controller

This policy applies to Mappsite (hereafter "the site" or "we"), a discovery platform for small and medium businesses. The site has changed its name and is moving to a new domain: while the move lasts it answers on both mappsite.com and buscapymes.cl, which are the same service and the same controller, and old links keep working.

Data controller — Cristóbal Ignacio Martínez Urtubia, a natural person. He decides what the personal data this policy covers is used for.

To exercise your rights over your data, or for any question about it, write to us through the contact page: it is the channel in force and we handle it ourselves.

2. What data we handle

  • Account data (if you register): email, encrypted password, display name and, optionally, phone and delivery address.
  • Public data about your business (if you own it and publish it): name, address, phone, email, social profiles, opening hours, photos and delivery area.
  • Requests to businesses (bookings, messages, orders): name, contact details, notes and, where applicable, delivery address.
  • Approximate location: only if you allow it in your browser, to show nearby businesses. The coordinates are not stored. What is recorded is the district and region you search from, together with the search term and never with your name. Where you left your car inside a venue is a different thing and has its own bullet further down.
  • Technical data: activity logs, session identifiers and strictly necessary cookies (see the Cookie policy).
  • What you write to a business's virtual assistant is not stored: it travels to Cloudflare to generate the reply and is not written to any table of ours. The last few messages are kept in your own browser so the assistant can follow the thread, and they disappear when you close the tab. All we record about the chat is how many questions there were and whether it ended in a booking, an order or a message to the business: that carries no text, no contact details and nothing pointing at you.
  • Vehicle and parking: the plate, model and colour you save in your profile, and the mark of where you left the car inside a venue, with the time.
  • Queue and table: the name you use to take a turn or to occupy a table. It is optional and each business decides whether to ask for it.
  • Site usage: which pages and products are opened and what is searched for, to build each business's statistics. It is a count and it carries no identifier of yours: not your name, not your account, and not a visitor identifier, which no longer exists (see the Cookie policy). Two visits of yours are indistinguishable from visits by two people.

2.1 Sensitive data

We do not ask you for sensitive data (health, ethnic origin, beliefs, political or trade union membership, socio-economic situation, sexual life or orientation, gender identity, biometric or genetic data) and no form on the site requests any.

They can still reach us, because there are free-text fields: the note on a booking or a message to the virtual assistant. You do not need to write any of that to book, order or ask, and we recommend that you do not. What you write to the assistant is not stored; the note on a booking is, and it is deleted after 180 days. If you need to give a health detail, give it to the business in person or through its direct channel.

3. Purposes and legal basis

We handle your data in order to:

  • Run the platform and let you search for and contact businesses (performance of the service).
  • Deliver your request to the business owner and allow their reply (performance).
  • Security, fraud prevention and service improvement (legitimate interest).
  • Communications and non-essential trackers, if there were any (only with your consent).
  • Comply with applicable legal obligations.

We do not sell your personal data and we do not share it with third parties for advertising. Under CCPA/CPRA (California), this amounts to not "selling or sharing" your personal information.

4. Who it is shared with (processors)

When you book or message a business, that data is delivered directly to the owner of that business so they can reply to you. Mappsite is not a commercial intermediary: it makes the contact possible.

We use providers that handle data on our behalf:

  • Supabase — database and authentication.
  • Cloudflare — hosting and site delivery.
  • Cloudflare R2 — storage and delivery of the photos and videos each business publishes, served from cdn.mappsite.com.
  • Cloudflare Workers AI — the engine behind the virtual assistant and the content translation. It receives the text you write to the assistant and the content being translated, solely to generate the reply or the translation. It does not receive audio or voice recordings.
  • Resend — transactional email delivery (confirmations, notifications and password recovery). It receives your email address and the content of the message. While the domain move lasts there are two sending regions at once: mail on the new domain is handled in Ireland (European Union) and mail on the legacy domain in São Paulo (Brazil).
  • Google — optional sign-in (OAuth).
  • Geoapify — address search. When an address is typed into a form, it receives that text and, if a point is already marked on the map, its approximate coordinates, solely to suggest matching addresses. It processes that data in the European Union. OpenStreetMap / CARTO / Nominatim / Photon — maps and area names from a coordinate.
  • Flow — payment gateway for business subscriptions. Card payment is switched off and, while it stays that way, we send it no data.

We choose providers that offer public, verifiable data protection terms and security guarantees. A Data Processing Agreement (DPA) is in force with Supabase, Cloudflare and Resend: Supabase (Data Processing Addendum v1, dated 1 August 2026), Cloudflare (Customer DPA v6.4, dated 3 April 2026) and Resend (Data Processing Addendum, updated 31 December 2025). All three form part of each provider's terms of service and take effect when those terms are accepted, so there is no separately signed copy: do not go looking for one, a signature is not what makes them valid. The remaining providers on the list handle the data under their own terms of service and data protection terms.

5. International transfers

Some providers process data outside your country (for example, in the USA, the EU or Brazil). Those transfers rely on the European Union Standard Contractual Clauses, incorporated within each provider's Data Processing Agreement as listed in section 4; Cloudflare also publishes its standard clauses annex separately. Like the agreement they belong to, those clauses are deemed executed when the provider's terms of service are accepted, with no separate signature. This is also the safeguard Chilean law 19.628 accepts for transferring data to another country: contractual clauses with adequate guarantees.

6. Your rights

Depending on your country, you can exercise the following rights:

  • Access: obtain a copy of your data.
  • Rectification: correct inaccurate data.
  • Erasure or cancellation ("right to be forgotten"): delete your account and your data.
  • Portability: receive your data in a machine-readable format.
  • Objection and restriction of processing on justified grounds.
  • Withdraw consent at any time (without retroactive effect).
  • No sale or sharing (CCPA/CPRA): we do not sell or share your data.

You can exercise them from your account (export data and delete account) or by writing to us from the contact page. We will reply within the applicable legal deadlines.

7. Retention

We keep your account data for as long as the account is active: it is the live state of your profile, your favourites and your preferences, and it does not pile up. When you delete your account we erase or anonymise your personal data, except for what we must retain by legal obligation.

Whatever does not depend on your account is deleted on its own, on these terms:

  • 30 days: the mark of where you left your car, and whatever a business sends to its bin. The conversation with the virtual assistant is no longer listed here because it is not stored: there is no term to count.
  • 90 days: a queue turn, a table occupancy and an entry on a waiting list.
  • 180 days: the free-text note you write when booking or ordering, the notices already delivered to you and the messages you exchange with a business. The conversation is deleted as a whole 180 days after the last message, not message by message: half a conversation says less than none. These are the six months in which you can bring a complaint about a purchase.
  • 400 days: page and product view statistics and search terms. They are a count and carry neither your name nor any identifier of yours.

In a booking or an order, the note is deleted, not the transaction. The record of what you ordered is kept as a record of the transaction and for as long as the law requires; the comment you wrote by hand is deleted after 180 days. That is why you can still see your order and no longer the text you left with it.

There is data we cannot delete even if you ask us to, because another law requires us to keep it: payment records and the detail of a transaction, under tax and accounting rules, and the record that you gave your consent, because the law requires us to be able to prove it.

1460 days (four years): everything you write to us as the administrators of the app — the messages from a business, support tickets and whatever arrives through the contact page. What is at stake there is not a purchase but the use of personal data, and that is the term in which the law allows a claim about it and requires us to be able to prove what we answered. A ticket is deleted as a whole, replies included, four years after the last message on that same subject. And there is one kind of data for which no term has been set yet: the internal trail of actions, where one rule pushes towards deletion and another towards keeping. It is held for as long as it is needed to handle a complaint and the term is under review. We are not giving you a number that does not exist yet.

Three different things happen when you delete your account. Everything that is only yours is erased: your profile, your favourites, your preferences, your notices, your messages with a business and the mark of where you left your car. The transactions the law requires us to keep are unlinked from you — orders, bookings and payments stop pointing at your account, and your delivery address and the notes you wrote go with them. And the record that you gave your consent is kept, with your identifier, because it is the only proof that we asked you for it.

8. Security

We apply reasonable technical and organisational measures (encryption in transit, row-level access control in the database, encrypted passwords). No system is one hundred per cent secure; in the event of an incident affecting you, we will act in accordance with the applicable law.

9. Minors

Mappsite is intended for people over 18 years old. We do not knowingly collect data from minors. If you believe a minor has given us data, contact us so we can delete it.

10. Automated decisions and artificial intelligence

We do not make automated decisions with significant legal effects on you.

Each business's virtual assistant replies automatically, using an artificial intelligence system, based on what that business published on its page. It decides nothing for you and closes nothing in your name: it leaves the booking or the order ready for you to confirm.

11. Supervisory authority

You can complain to the data protection authority of your country (in Chile, the Personal Data Protection Agency; in the EU, your national authority).

12. Changes

We may update this policy. The date of the last update appears at the top. In the event of material changes, we will give notice on the site.

See also: Terms of use · Cookie policy.