The public website can be explored without an account. Location is requested only for a specific feature and with permission.
LEGAL INFORMATION
Privacy policy
What data Play The Map uses, why it is needed, how long it is kept and the controls available to each person.
PLAY THE MAP · 2026-09-05-privacy-v2
At a glance
Councils receive ordinary aggregated or pseudonymised statistics, not a traveller's identity or individual history by default.
Identified safety and location access is limited, purpose-specific and auditable. Permissions can be withdrawn and accounts can be deleted.
1. Data controller
The controller for Play The Map's own processing is VIRTUAL ART VFX & 3D, S.L., Spanish tax ID B98930902, registered address at Av. Pianista Martínez Carrasco, 4, door 20, 46026 Valencia (Spain). Contact admin@playthemap.com or the postal address above for privacy enquiries.
This policy covers playthemap.com, the official Android app and traveller, municipal, administrative and safety workspaces. Where a public authority independently determines a processing purpose, its identity and role will be explained in context; Play The Map may act as processor under the applicable agreement.
2. Data we may process
| Category | Examples in Play The Map |
|---|---|
| Account and identity | Name or alias, email, password hash, language, avatar, email verification and Google sign-in identifier if chosen. |
| Device and security | Android installation ID, app version, platform, device-grouped sessions, access times, user agent, IP or IP hash, tokens and audit logs. |
| Travel and preferences | Favourites, visited or pending places, enrolments, routes, challenges, passport, badges, points, coins, progress, notification preferences and prepared trips. |
| Location and field activity | Coordinates, accuracy, heading, speed, altitude, time, travel mode, tracks, stops, check-ins and proximity events when enabled. |
| Safety and community | Private groups, trusted contacts, location-sharing consents, Safe Route, Accompany Me, SOS, Scheduled SOS and alert delivery state. |
| Optional emergency data | Blood group, allergies, medical notes and contact notes only when entered and enabled by the person. |
| Content | Check-in photos, memories, user-created routes, text, files, invitations and share links. |
| Usage and diagnostics | Searches, filters, map opens, video interaction, app conversion, technical errors, performance, fraud and abuse signals. |
| Municipalities and communications | Professional municipality application data, body, role, phone, project, messages, reviews and invitations; support requests. |
3. Data sources
- The person using the service.
- The device, subject to operating-system permissions.
- Councils and authorised contributors.
- Identity providers chosen by the person.
- Technical security, network and usage signals generated while providing the service.
4. Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Account, authentication, web/Android sync, favourites and requested features. | Contract or pre-contractual steps (GDPR 6(1)(b)). |
| Email verification, account and device security, abuse prevention, incident response and audit. | Service performance and legitimate interest in security, integrity and fraud prevention (6(1)(b) and (f)). |
| Location for nearby results, navigation, routes, check-ins, groups or persistent assistance. | Specific, withdrawable consent plus device permission (6(1)(a)). |
| Optional health or emergency data. | Explicit consent and, where applicable in a real emergency, vital interests (9(2)(a) and (c)). |
| Sharing alerts or location with selected group members, trusted contacts or authorised safety staff. | Requested feature, specific consent and, in an emergency, vital interests. |
| Service, catalogue and conversion measurement without behavioural advertising. | Legitimate interest with minimisation; consent where optional terminal storage is used. |
| Municipality applications and professional relationships. | Pre-contractual steps, contract, professional legitimate interest and legal duties. |
| Rights, complaints, legal requests and evidence. | Legal obligation and legitimate interest in legal claims. |
| Non-essential marketing. | Consent, withdrawable at any time. |
We do not sell personal data or use it for third-party behavioural advertising.
5. Location, routes and municipal analytics
Location is not enabled by opening the website. Nearby results require an action and browser permission; continuous and background functions are Android-only and can be paused or revoked.
GPS samples used to rebuild a track are limited and converted into a simplified path and metrics. Default retention is 90 days for trip samples and 30 days for raw analytics; municipal aggregates may be held for up to 24 months.
Ordinary municipal dashboards contain aggregated or pseudonymised heatmaps, flows and metrics. Identified safety access is separate, limited to authorised named roles and audited.
6. Safety features and sensitive data
Safe Route, SOS, Scheduled SOS, Accompany Me, private groups and trusted contacts are optional and require the relevant confirmation. Group members see name, avatar, location and signal age only during an active session when sharing is enabled.
The emergency medical profile is disabled by default. Play The Map does not diagnose or make automated medical decisions.
An SOS may be sent to prepared contacts, group members, the relevant municipality and authorised safety staff. Failed delivery is not shown as received and the feature does not replace calling 112.
7. Recipients and providers
- Infrastructure, database, file storage, email, backup and technical support providers under limited contractual access.
- Google or another identity provider only when chosen.
- Selected group members, trusted contacts and feature recipients.
- Councils receive ordinary aggregated or pseudonymised content and statistics; identified data only with a specific function, authorisation and legal basis.
- Emergency services, police, courts and authorities when legally required or necessary to protect vital interests.
- A corporate successor, subject to applicable notice and safeguards.
We do not provide hotels, restaurants, sponsors or shops with tourist lists, individual locations or behavioural profiles for their advertising.
8. International transfers
We prioritise processing in the EEA. Where a provider processes data elsewhere, we rely on an adequacy decision, Standard Contractual Clauses or another valid safeguard and supplementary measures when needed. Ask admin@playthemap.com for details.
9. Retention
| Data | Retention criterion |
|---|---|
| Account and progress | While active; deleted or anonymised on account deletion, subject to temporary active-feature blocks and legal retention. |
| Sessions and devices | Web sessions normally expire after 30 days; revoked or expired session logs are normally purged after 90 days. |
| Live location | Only for the active purpose and briefly afterwards; stale ordinary presence is deleted and analytics live presence is normally cleared within 24 hours. |
| Route samples | Normally 90 days for processing; the simplified path and metrics remain until the trip or account is deleted. |
| Mobility analytics | Raw samples normally 30 days; statistical aggregates normally up to 24 months. |
| Groups and invitations | Until closure or expiry and for the minimum security and dispute period. |
| Alerts and audit | As needed to handle the incident and legal liabilities, with restricted access when kept as evidence. |
| Municipality applications | During review and the relationship; unsuccessful applications only as needed for duplicates, enquiries and claims, then deleted or anonymised. |
| Communications | For the request and applicable limitation periods under restricted access. |
10. Your rights
You may request access, correction, deletion, objection, restriction and portability and may withdraw consent prospectively. Device permissions, location, sessions and account deletion can also be managed through the available controls.
Email admin@playthemap.com with the right requested and enough information to locate the account. Extra identification is requested only where reasonably necessary. You may complain to the Spanish Data Protection Agency at aepd.es.
11. Children
Accounts for children under 14 are not enabled. If such an account is detected without verifiable guardian consent, it will be disabled and unnecessary data deleted. Users aged 14 to 17 should avoid publishing information that enables location outside private features and use sensitive features with suitable supervision.
12. Recommendations and automated decisions
The catalogue may be ordered or recommended from filters, context, favourites or progress. This has no legal or similarly significant effect. Play The Map does not currently use active AI to decide user rights, grant rewards, validate emergencies or make decisions about people.
13. Security and privacy by design
Measures include role and municipality access control, encryption in transit, password hashing, hashed tokens where appropriate, session expiry and revocation, minimisation, backups, rate limits, separation of sensitive duties and audit trails.
No system is invulnerable. A qualifying breach will be managed and notified to authorities and affected people where legally required.
14. Changes and contact
Material updates will be communicated reasonably and renewed consent requested when necessary. The current date and version always appear above.
For rights, privacy, providers or safeguards: admin@playthemap.com.

