Legal

Privacy Policy – App

How the MapMe iPad app handles your data, including purchases, analytics, and advertising measurement after you consent.

Last updated September 15, 2026

This privacy policy applies specifically to the MapMe iPad application. For our website, see the Privacy Policy.

Controller

The controller for this app is:
Ferdinand Werner
NandMe
Frühlingstraße 10
63897 Miltenberg
Germany

Personal Data Collection

MapMe processes personal data in a few limited cases: subscription handling, product analytics, and, if you consent, advertising measurement.

We do not collect your name, email address, or location for our own records. Purchases are authenticated by Apple through your iCloud account.

Data Usage

We use Apple's StoreKit API to verify purchases and to give you access to the features you have paid for.

RevenueCat manages MapMe Plus entitlements, purchase validation, and subscription status. It receives transaction and entitlement data from Apple. We do not receive your Apple ID credentials. On iPad, RevenueCat also collects Apple's AdServices attribution token. That token is sent to Apple to measure Apple Search Ads installs. It is not sent to Meta.

TelemetryDeck receives named product-analytics events. That includes feature use, app lifecycle, and in-app purchase events (product identifier, subscription type, offer type). If you submit optional in-app review feedback or an unsubscribe survey, the selected category and any text you type are sent to TelemetryDeck. Production builds do not set a custom user identifier and do not send your name, email address, or phone number as account data.

If you give consent on the in-app consent screen, advertising-measurement data is sent to Meta as described below.

Advertising Measurement

The iPad app bundles the Meta SDK (FBSDKCoreKit 18.1.1). The SDK stays completely inactive (not initialised, no network requests) until you give explicit consent on an in-app consent screen.

The Mac version (Mac Catalyst / "iPad app on Mac") never initialises the SDK at all.

The legal basis for this processing is consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG.

Apple's App Tracking Transparency prompt is Apple's permission for the advertising identifier. It is shown only after our own consent screen. It is not the legal basis for this processing.

Recipient

The recipient is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

For this advertising-measurement processing we and Meta are joint controllers under Art. 26 GDPR.

What is transmitted after consent

After you consent, the following is transmitted:

  • A Meta-generated anonymous app identifier
  • Device and app information
  • One event: app activation
  • The advertising identifier (IDFA) only if you also allow tracking in Apple's ATT prompt

What is not transmitted

  • No purchase, trial or subscription events are sent to Meta from the app.
  • Meta's automatic in-app event logging and automatic advanced matching (email, phone number, name, city, gender) are switched off.
  • No data at all reaches Meta if you decline the consent screen.

Third-country transfer

Onward transfers to Meta Platforms, Inc. in the USA are covered by the EU-US Data Privacy Framework adequacy decision, supplemented by Meta's standard contractual clauses.

Apple SKAdNetwork

Apple's SKAdNetwork reports app installs to advertising networks in aggregated form. It is operated by Apple at the operating-system level, transmits no identifier of the individual user, and works independently of the consent above.

Data Storage

Purchase receipt information is stored on the device through the StoreKit 2 API, in encrypted form. Apple uses it to confirm that purchases are valid.

The consent decision, its timestamp and the version of the consent text are stored only on the device, never on a server and not in iCloud.

Data Sharing

We share data with the following parties, and only as described on this page:

  • Apple, for StoreKit purchases and, where applicable, iCloud, SKAdNetwork, App Tracking Transparency, and AdServices attribution
  • RevenueCat, for subscription management
  • TelemetryDeck, for product analytics
  • Meta Platforms Ireland Limited, for advertising measurement, and only after you consent

User Rights

Under the GDPR you can request information about personal data, and you can ask us to correct or delete data we hold.

You can withdraw advertising-measurement consent in the app under Settings → Privacy. Withdrawal takes effect immediately in the running session. No further data is transmitted afterwards.

The ATT permission can be withdrawn separately under iOS Settings → Privacy & Security → Tracking.

To exercise other rights, contact us at the address below.

Cookies and Tracking

The app does not use cookies. After you consent, the Meta SDK is used for advertising measurement as described above. If you decline the consent screen, no data is sent to Meta. The Mac version never initialises the SDK.

SKAdNetwork is a separate Apple mechanism and is described above. Please note that our website may use cookies.

Data Retention

The consent decision is stored on the device. It stays there until you change it or delete the app.

Purchase records are held by Apple and by RevenueCat as needed to keep your subscription working.

Children's Privacy

We do not knowingly target this app at children.

Changes to the Privacy Policy

Any changes to this privacy policy will be communicated to users within the app. Users will be notified via a pop-up message if there are any updates to the privacy policy.

Contact Information

For any questions or concerns regarding this privacy policy, please contact us at ferdinand@nandme.app.