1. Scope and person responsible
This policy applies to website visitors, prospects, business customers, administrators, employees and contractors registered by a customer, and end customers whose information is processed in MapMyStaff.
Person responsible for the protection of personal information: until delegated in writing, this role belongs to the person with the highest authority within MapMyStaff. Requests are received through the Contact page by choosing “Security or privacy.” Official contact information must be published before this policy takes effect.
2. Information collected
- Demo requests: name, business email, company, team size, and main problem.
- Contact requests: name, business email, company, subject, article viewed, and message.
- Account data: identity, business contact information, role, permissions, and authentication information managed through Firebase Authentication.
- Operational data: employees, schedules, territories, absences, services, appointments, addresses, routes, customers, notes, surveys, referrals, promotions, credits, and financial data configured by the customer.
- Technical data: logs, request identifiers, date and time, source page, campaign parameters, browser, and limited anti-abuse information.
- Payment data: billing information and payment status; complete card data must be processed by the payment provider and not stored directly by MapMyStaff.
3. Data submitted through website forms
When a form is submitted, the browser sends the completed fields, language, request type, source page, context URLs without query parameters, and available UTM parameters to a Firebase HTTPS function. An invisible anti-bot field is checked. Firebase App Check, together with reCAPTCHA Enterprise, also produces a security token intended to confirm that the request comes from the authorized web application. The function validates the data, creates a request number, records the request in Firestore, and sends a transactional notification through Postmark. The IP address is not retained in clear text: a temporary fingerprint may be used to limit abuse.
4. Purposes
- respond to demo, sales, support, security, or billing requests;
- create and administer accounts;
- provide booking, scheduling, routing, customer-relationship, survey, referral, and analysis functions;
- secure the service, prevent fraud, and diagnose errors;
- manage billing and contractual obligations;
- improve the product using aggregated or de-identified data;
- comply with legal obligations.
5. Legal bases and consent
MapMyStaff limits collection to information necessary for the stated purposes. Consent is requested when required. Marketing communications require separate consent and can be withdrawn at any time. Business customers are responsible for having the necessary authority to provide MapMyStaff with information about their employees and their own customers.
6. Providers and disclosures
MapMyStaff may use providers to operate the service, including Google Firebase/Google Cloud for hosting, functions, authentication, App Check, reCAPTCHA Enterprise and databases; Postmark for transactional email; and HERE and/or OSRM for certain geocoding and routing functions. No active payment provider is identified in the current reference file; any future provider must be documented before activation. Only the data necessary for the relevant service is disclosed. Some providers may process data outside Quebec or Canada; a privacy impact assessment must be conducted when required by law.
7. Retention and destruction
The final retention schedule has not yet been approved. Until approval, information must not be retained longer than necessary for the documented purposes, contractual obligations or applicable legal requirements. Any specific period must be recorded in the retention register before this policy takes effect.
8. Security measures
MapMyStaff uses role-based access controls, server-side validation, encryption in transit, Google Cloud security capabilities, logging, anti-abuse rate limiting, and separate secret management. No system is entirely free of risk, however. If an incident presents a risk of serious harm, MapMyStaff applies the required measures and notifications.
9. Your rights
You may request access to or correction of your information, withdraw consent when permitted, or make a complaint. A request may be sent to the person identified above. Identity verification may be required before responding.
10. Cookies and analytics
The website uses cookies strictly necessary for its operation. No non-essential analytics, advertising or personalization tool is documented as active in the current reference file. Any future activation must be documented and subject to applicable choices before use.
11. Changes
The date of the latest update is shown below. Material changes will be communicated appropriately. Last updated: July 21, 2026.
12. Limit of this text
This version documents the technical implementation delivered with v1577. Bracketed elements must be confirmed before publication, and the text should undergo legal review before commercial launch.