Privacy Policy

Last updated: July 2026

WaveOrigin OÜ (“we”, “our”, or “us”) operates the Unmapped platform — including the website www.unmappedgroup.com and the Unmapped mobile application available on iOS and Android (“the app” or “the platform”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have under the General Data Protection Regulation (GDPR).

1. Controller

The data controller responsible for your personal data is:

WaveOrigin OÜ

Tööstuse tn 75-71

10416 Tallinn

Estonia

Email: unmapped.network@gmail.com

Phone: +49 155 11338357

We have not appointed a Data Protection Officer because, based on our current processing activities, we are not legally required to do so under Article 37 GDPR.

2. Data We Collect

Account and profile data

  • Name, email address, username
  • Profile photo (avatar)
  • Bio, city, country
  • Skills, interests, hobbies, and countries traveled (self-reported)
  • Social media links (Instagram, LinkedIn, X/Twitter, GitHub, website)
  • Account role (Member, Ambassador, Founder)
  • Travel plans, including intended destinations, travel dates, and a visibility setting (public, connections-only, or private)

User-generated content (UGC)

  • Posts, comments, and project updates you create
  • Images you attach to posts, events, or projects
  • Events and projects you submit
  • Messages sent via direct or group chats
  • Event discussion messages
  • Join request messages

Interaction data

  • Events and projects you join or save
  • Likes, comments, and reposts on posts
  • Connections with other users

Technical and device data

  • IP address (processed by our infrastructure providers)
  • Browser type and device information
  • Push notification tokens and subscription data (if you enable notifications)

Internal analytics data

  • Platform actions you take (e.g. signing up, viewing events, joining projects, completing your profile)
  • This data is stored in our internal analytics system, is not shared with third parties, and is not used for advertising

Special categories of personal data

Unmapped does not require users to provide special categories of personal data (as defined in Article 9 GDPR). However, users may voluntarily include information in user-generated content — such as posts, messages, images, or free-text profile fields — that could incidentally reveal sensitive characteristics (for example, health information, political views, or religious beliefs). Where such information appears in content you choose to share, it is processed as part of that content. We do not separately categorise or use it for additional purposes. If you have questions about this, please contact us before sharing sensitive information on the platform.

3. How We Use Your Data

  • Operating and maintaining the Unmapped platform
  • Creating and managing your account
  • Enabling community features: chats, events, projects, connections
  • Sending in-app and push notifications about relevant activity
  • Improving the platform through internal usage analytics
  • Processing and reviewing content submissions (events, projects)
  • Responding to support requests
  • Ensuring platform safety, detecting fraud, and enforcing community standards

Legal bases (Art. 6(1) GDPR):

  • Contract performance (Art. 6(1)(b)): creating and managing your account, operating core platform features (chats, events, projects, connections), and delivering the community services you registered for
  • Legitimate interests (Art. 6(1)(f)): platform security and abuse prevention (our interest: maintaining a safe environment for all users); fraud prevention and content moderation (our interest: protecting the platform and its users from harm); internal analytics to monitor and improve platform reliability and functionality (our interest: understanding how the platform is used in order to improve it). Where we rely on legitimate interests, we have assessed that these interests are not overridden by your rights and freedoms.
  • Consent (Art. 6(1)(a)): push notifications (consent given when you grant notification permission on your device or browser); optional marketing communications

4. Push Notifications

If you grant notification permission, we store a push notification token linked to your account. This token is used to send you alerts about messages, join requests, connections, and platform activity.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time by:

  • Adjusting notification settings in your device (iOS: Settings → Notifications → Unmapped; Android: Settings → Apps → Unmapped → Notifications)
  • Revoking notification permission in your browser settings

Withdrawing consent does not affect past processing and does not impact your use of any other platform features.

5. Cookies and Analytics

We currently do not use analytics cookies or advertising cookies. Our platform uses session-management cookies strictly necessary to keep you logged in. These are required for the platform to function and are not subject to consent requirements under ePrivacy rules.

We collect internal usage analytics (page views, feature interactions) through our own infrastructure. This data is not shared with third parties and is not used for advertising.

If we add third-party analytics or advertising cookies in the future, we will update this policy and implement appropriate consent mechanisms.

6. Data Processors and Third-Party Services

We use the following service providers who process personal data on our behalf as data processors under Art. 28 GDPR. Data processing agreements or equivalent contractual protections are in place or incorporated into the relevant service terms where required. [VERIFY DPA STATUS BEFORE PUBLICATION]

Supabase, Inc.

Purpose: Database, authentication, file storage, real-time features

Location: United States; primary database region — [VERIFY SUPABASE PRODUCTION REGION BEFORE PUBLICATION]. Supabase and its subprocessors may process limited operational data outside the primary database region.

Transfer mechanism: Standard Contractual Clauses (SCCs) where applicable

Vercel, Inc.

Purpose: Application hosting, CDN, serverless functions

Location: United States (infrastructure and CDN nodes located globally, including outside the EU/EEA)

Transfer mechanism: Standard Contractual Clauses (SCCs)

Push Notification Services

Purpose: Delivery of push notifications to your device

Includes: Apple Push Notification Service (APNs) for iOS, Google Firebase Cloud Messaging (FCM) for Android, and browser-native push services for web

These services process device or push tokens and notification data (including notification title, content, and associated URLs) as necessary to deliver notifications to your device

Sentry, Inc.

Purpose: Error monitoring and application reliability

Location: United States

Transfer mechanism: Standard Contractual Clauses (SCCs)

Data processed: Our Sentry configuration strips request bodies, authentication headers, names, email addresses, and usernames before transmission. Only a pseudonymous internal user identifier is retained alongside error and stack trace information for debugging purposes.

We do not sell your personal data to any third party.

7. Data Retention

We retain personal data only as long as necessary for the purpose for which it was collected. When we refer to data being de-identified, this means that visible personal identifiers — such as name, email address, username, bio, location, avatar, and social links — are deleted or replaced with placeholder values (for example, “[Deleted User]”). Platform records may retain internal identifiers for referential integrity; where the original personal data has been removed or replaced, these records cannot practically be linked back to you without additional information that is no longer retained.

Upon account deletion, personal identifiers and publicly visible profile information are removed or de-identified. Certain records may be retained where necessary for platform integrity, security, legal obligations, dispute handling, or other legitimate purposes.

We may retain anonymous or aggregated statistical information — such as platform usage totals and cohort-level metrics — where that information can no longer reasonably be linked to you. Where retained records can still be linked to an individual using additional information, we treat those records as personal data and continue to protect them under the GDPR.

Individual data categories and their handling on account deletion are described below.

Account and profile data

Retained while your account is active. On account deletion, all personal identifiers are cleared: name, email, username, bio, avatar, location, social links, skills, interests, hobbies, countries traveled, goals, languages, travel preferences, and other profile fields are replaced with placeholder values or cleared entirely. A minimal profile record marked as deleted is retained for internal referential integrity (to preserve the structural integrity of community content you contributed). This tombstone record is treated as pseudonymous personal data, not as anonymous data. Backup copies are purged within 30 days.

Authentication credentials

Access is revoked and the authentication account is deleted upon account deletion processing.

Posts, comments, and discussions

Content (text and any attached images or links) is replaced with a placeholder on account deletion. Records are retained in de-identified form as part of community history, attributed to a deleted account. An internal reference to the deleted account’s profile tombstone is retained for referential integrity; that tombstone contains no personal identifiers.

Chat and event messages

Message content and any attached images are replaced with a placeholder on account deletion. The sender or author reference is set to null when your authentication account is deleted. De-identified message records are retained to preserve conversation history for other participants, and for platform integrity, safety, and dispute handling.

Events and projects you created

Retained as platform history. Creator identity is de-identified on account deletion — the event or project record is retained but the creator reference points to a deleted account profile with no personal identifiers.

Travel plans

Deleted when your account is deleted.

Saves and connections

Deleted on account deletion. Saves (bookmarks) and connection records linked to your account are removed.

Likes and reposts

Like and repost records linked to your account are deleted on account deletion. Aggregate engagement counts (e.g. total likes on a post) may decrease to reflect only current active users.

Join requests and applications

Structural join request records are retained for safety, abuse prevention, and operational records. Any personal message included in a join request is cleared on account deletion. The requesting user reference points to the deleted account’s profile tombstone after account deletion.

Reports and moderation records

Retained for up to 24 months after resolution for abuse prevention, dispute handling, and legal compliance. Retained longer if required by applicable law or for active legal claims. Where associated profile data has been de-identified, the report record retains internal references only.

Suspended and deleted account records

De-identified profile records (with personal identifiers removed) are retained for up to 24 months for platform safety, abuse prevention, and fraud prevention. Retained longer if required for active legal claims or by applicable law.

In-app notifications

Notifications addressed to your account are deleted on account deletion. For active accounts, read notifications older than 90 days are periodically cleared. Notifications sent to other users about activity you performed (for example, a like or connection request) may remain in those users’ notification histories, attributed to a deleted account.

Push notification tokens

Deleted immediately when you disable push notifications or when your account is deleted.

Internal analytics data

Behavioral event data linked to your account is deleted upon account deletion. Daily aggregated platform-level counts (e.g. total signups per month) are retained indefinitely and cannot be linked to any individual user.

Anonymous deletion analytics

At the point of account deletion, we extract a small number of aggregate statistics — such as account lifetime, platform role, country-level geographic data, and usage counts (posts created, events joined, connections made, etc.) — and store them in an anonymous analytics record. This record contains no name, email, username, user ID, social links, or any persistent identifier, and cannot be linked back to you. It is retained indefinitely for product analytics and platform improvement.

Support communications

Retained for up to 24 months from our last contact, or longer if legally required.

Technical and security logs

Retained for up to 12 months by our infrastructure providers. Retained longer if required for active security investigations.

Financial and tax records

If payment processing is introduced, statutory retention periods apply — currently 7 years under Estonian commercial law.

Backup copies

Automated backup snapshots may contain data for a technical window of up to 30 days, after which they are permanently purged.

8. Account Deletion

You can request permanent account deletion at any time from within the app:

Dashboard → Profile → Delete Account

Your deletion request will be reviewed and processed. Upon processing, your personal data is de-identified as described in Section 7 and your authentication account is deleted. This action cannot be undone.

  • Events, projects, messages, reports, and shared community records may be retained in de-identified form where required for platform integrity, legal obligations, safety, abuse prevention, or dispute handling.
  • Backup copies may persist for up to 30 days in automated backup snapshots, after which they are permanently purged.
  • Deletion does not guarantee refunds for prior paid activities.

Alternatively, contact us at unmapped.network@gmail.com to request account deletion by email.

9. Your Rights

Under GDPR, you have the following rights:

  • Right of access (Art. 15): request a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate or incomplete data (via your profile settings)
  • Right to erasure (Art. 17): request deletion of your personal data where the legal requirements are met. You may also delete your account directly through the in-app account deletion functionality (see Section 8).
  • Right to restriction (Art. 18): request that we restrict processing of your data
  • Right to data portability (Art. 20): receive your data in a machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interests
  • Right to withdraw consent (Art. 7): withdraw consent for notifications at any time without affecting prior processing

To exercise any of these rights, contact:

unmapped.network@gmail.com

We will respond without undue delay and normally within one month of receiving your request. Where permitted by the GDPR, this period may be extended by up to two additional months depending on the complexity and number of requests. We will inform you if an extension is required.

Supervisory authority: You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI): www.aki.ee, Tatari 39, 10134 Tallinn, Estonia.

10. Children

Unmapped is intended for users aged 18 and over. We do not knowingly collect personal data from minors. If we become aware that a user is under 18, we will delete their account. If you believe a minor has created an account, please contact us at unmapped.network@gmail.com.

11. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on users (Art. 22 GDPR).

12. Data Security

We implement appropriate technical and organisational security measures to protect personal data, including HTTPS encryption in transit, authentication via Supabase Auth, access controls, and row-level security policies in the database. Security measures provided by our infrastructure providers (Supabase and Vercel) also apply. No system is completely secure; in the event of a data breach, we will notify affected users and the relevant supervisory authority as required by Art. 33–34 GDPR.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be published at this URL. For material changes, we will notify registered users via email or in-app notification.

14. Contact

For any questions about this Privacy Policy or your data:

WaveOrigin OÜ

Tööstuse tn 75-71

10416 Tallinn

Estonia

Email: unmapped.network@gmail.com

Phone: +49 155 11338357

Unmapped World