This Policy explains how Mapfolio (“Mapfolio”, “we”) handles personal data in connection with the Mapfolio service. Mapfolio is operated by Daniel Arnarsson, a sole proprietor in Japan, trading as “Mapfolio”. Because we are established in Japan, the Act on the Protection of Personal Information (“APPI”) applies to our handling of personal data. Where users are located in the EEA, UK, or other jurisdictions with data-protection laws, those laws may also apply.
1. Roles
- Customer Account Data (your account, your team members, your billing): Mapfolio is the controller.
- Customer Content, including data about your End-Clients (the home seekers receiving your shortlists): you, the Customer, are the controller and Mapfolio is the processor, acting on your documented instructions through the Service.
If you are an End-Client viewing a shortlist, the Customer (the agent or agency that shared it) is responsible for how your information was obtained and used. We process your data on their behalf.
2. Data we collect
You provide directly
- Account info: name, email, password (hashed), team name, role, profile photo.
- Billing info: handled by our payment processor, Stripe. We receive only billing metadata (last 4 digits, card brand, country, billing email). Mapfolio does not see or store full card numbers.
- Customer Content: listings, addresses, photos, notes, client preferences, files you upload, integration data you sync.
Collected automatically
- Authentication and session data: login timestamps, IP address, user-agent, device identifiers.
- Product telemetry: which features you use, errors, performance metrics.
- Engagement data on shared proposals: which listings an End-Client viewed, when, for how long, which they starred. We retain engagement timestamps for the lifetime of the proposal so the Customer’s CRM history remains intact.
- Cookies and local storage: see Section 11 below.
From third parties
- If you sign in with Google, we receive your name, email, and profile photo from Google.
- Geocoding, distance, and routing data from Google Maps and Navitime when you query addresses.
3. How we use data
- Provide, secure, and maintain the Service.
- Authenticate you, prevent abuse, and detect fraud.
- Process payments and send billing notices.
- Send service emails (security alerts, billing receipts, product changes). Marketing emails only with consent and always with an unsubscribe link.
- Improve the Service: debug, analyse aggregate usage, train internal heuristics on anonymised or aggregated data only.
- Comply with legal obligations.
4. Aggregate / demand-intelligence data
5. Sharing
We share personal data only with:
-
Subprocessors that help run the Service:
Subprocessor Purpose Region Supabase Database, authentication, storage Tokyo, Japan Cloudflare CDN, hosting, R2 image storage Global Stripe Payment processing Global Resend Transactional email US / EU Google OAuth sign-in, Maps, geocoding Global Navitime Public-transit routing in Japan Japan - Your team members with whom you share workspaces.
- End-Clients to whom you share proposals (for the data inside that proposal).
- Legal/compliance: where required by law, court order, or to protect rights, safety, or the integrity of the Service.
- Successors in a merger, acquisition, or sale of assets, subject to confidentiality.
We do not sell personal data and do not share it for cross-context behavioural advertising.
6. International transfers
Mapfolio data is hosted primarily in Tokyo, Japan (Supabase). If you or your End-Clients are in the EEA, UK, or other regions with cross-border restrictions, transfers are made under appropriate safeguards (e.g., Standard Contractual Clauses, the UK International Data Transfer Addendum, or the corresponding mechanism for your jurisdiction).
7. Retention
- Account data: retained while your account is active; deleted within 90 days after termination, subject to legal holds and to the signup record described below.
- Signup record: when an account is created we keep a minimal, permanent record of that signup: the email address used, the date the account was created, whether it was a personal or an agent account, any referral code it came through, and the date the account was deleted. We keep this record indefinitely, including after you delete your account, so that we can prevent fraud and repeated abuse of free trials and passes, and keep accurate business records. It holds no other profile data, no content, and no activity history. We do not use it to contact you, and we do not share or sell it.
- Customer Content: retained while your account is active. After cancellation, retained for 30 days for export, then deleted on a rolling schedule.
- Engagement data: retained for the lifetime of the parent proposal. When the proposal is deleted, engagement data is deleted with it.
- Logs: retained for up to 90 days for security and debugging.
- Aggregated/anonymised data: retained indefinitely as it is not personal data.
8. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent. To exercise these rights:
- If you are a Mapfolio Customer: use your account settings or email [email protected].
- If you are an End-Client: contact the agent or agency that shared the proposal with you (they are the controller). We will assist them in responding.
One exception applies to deletion. The signup record described in Section 7, meaning your email address and the dates around your account, is kept even after your account is erased, because we rely on it to prevent fraud and repeated abuse. Everything else tied to your account is deleted. If you object to us keeping that record in your particular case, write to [email protected] and we will review the request.
You may also lodge a complaint with your local data protection authority. In Japan, that is the Personal Information Protection Commission (個人情報保護委員会, “PPC”). EU/EEA users may contact their national supervisory authority; UK users may contact the Information Commissioner’s Office (ICO).
9. Security
We implement administrative, technical, and organisational measures appropriate to the risk: TLS in transit, encryption at rest, role-based access, audit logging, least-privilege internal access, and regular review. We are working toward ISO 27001 certification. No system is perfectly secure; report vulnerabilities to [email protected].
10. Children
The Service is for business use and not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have, contact [email protected].
11. Cookies and similar technologies
- Strictly necessary cookies/local storage for authentication and session management.
- Functional storage to remember preferences (last-used view, filters, sidebar state).
- Analytics in aggregated form to understand product usage. We do not use third-party advertising cookies.
You can clear cookies in your browser; doing so may sign you out.
12. Changes to this Policy
We will post updates here and, for material changes, notify you by email or in-product at least 14 days before they take effect.
13. Contact
Daniel Arnarsson, sole proprietor trading as Mapfolio (Japan)
Email: [email protected]
Security: [email protected]