MapSmartPrivacy Policy
Last updated: 27 July 2026
What we collect, why, who we share it with, and the choices you have.
1. Who we are
Angus Austin O’Neill trading as Map Smart (ABN 87 128 586 948) of Runaway Bay, Queensland, Australia (MapSmart, we, us) operates the MapSmart application at mapsmart.au.
Our commitment. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We commit to this whether or not the small business exemption applies to us.
We designed MapSmart around a simple rule: we do not invent data. If we do not know a price, a place or a saving, we say so rather than guess. We apply the same principle here. This policy describes what we actually do.
2. The short version
- We collect what we need to plan your day: who you are, where you are starting from, and what you want to get done.
- We do not sell your personal information. Ever.
- We never store your voice recordings, and we do not use your content to train AI models.
- Your account data is stored in Australia (Sydney). Some supporting services, such as maps, AI, voice and analytics, are overseas, mainly in the United States. See clause 7.
- We collect precise location only while you are using location features, and only with your permission.
- You can access, correct, export or delete your information. See clause 10.
3. What we collect
3.1 Information you give us
| What | Examples | Why |
|---|---|---|
| Account | Email address, display name, profile photo, password (held by our authentication provider, we never see it) | To create and secure your account |
| Home and saved places | Home address and its coordinates, saved places such as the office or work | To anchor routes to where you actually start and end |
| Your lists and plans | Items, quantities, notes, preferences, chosen products and retailers, recipes, trips, events | To resolve items, plan routes and show your day |
| Preferences | Language, theme, notification settings, return by time, how you value your time | To personalise the app |
| Questionnaire responses | Routines, interests, household details you choose to provide | To tailor suggestions |
| Voice input | Audio you record when using voice features, and the text transcribed from it | To let you speak your plan instead of typing it |
| Contacts you choose to share | Name and contact detail of a person you invite or delegate to | To send an invitation or a delegated task |
| Support communications | Messages you send us | To help you |
3.2 Information collected automatically
- Precise location, from your device, collected only when you use a feature that needs it (planning from your current position, navigation, nearby search) and only with your device permission. You can withdraw it at any time in your device settings.
- Usage and device data: pages viewed, features used, approximate location derived from IP, device and browser type, timestamps.
- Diagnostics: error reports, performance data and technical logs when something goes wrong.
- Cookies and similar: strictly necessary cookies for sign in and security, and analytics cookies. See clause 12.
3.3 Information from third parties
- Authentication providers: if you sign in with a third party account, we receive your email, name and profile image.
- Google Calendar: if you connect it, we receive event titles, times and locations to plan around your commitments. We store your access tokens encrypted (AES 256 GCM). You may disconnect at any time.
- Public and licensed data sources: retailer product and price data, place and business information, fuel prices, and weather. This is information about products and places, not about you.
3.4 Google user data and Limited Use
If you choose to connect Google Calendar, MapSmart requests the single read only scope https://www.googleapis.com/auth/calendar.readonly. We use it for one purpose: to read the events on your calendar so we can show your day and plan routes around your existing commitments. MapSmart cannot create, edit or delete anything in your calendar.
MapSmart's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as needed to provide the Service (or for security or to comply with the law), and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with the law, or where the data has been aggregated and de identified. Google Calendar tokens are stored encrypted (AES 256 GCM). You may disconnect at any time in Profile, which revokes our access, and you may instead connect a read only calendar feed link (.ics), which does not use Google APIs at all.
3.5 Sensitive information
We do not seek sensitive information (as defined in the Privacy Act), such as health, religious or political information. Please do not put it into free text fields. If you do, you consent to us handling it to provide the Service. Note: your home address and precise location are not sensitive information under the Act, but we treat them as high risk and protect them accordingly.
3.6 Children
The Service is not directed at children under 16. We do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
4. Why we collect it
We collect and use personal information to:
- create, secure and administer your account, and verify access;
- provide the core Service: interpret what you need, match items to real products and places, plan and optimise routes, and navigate;
- enable sharing, delegation, household connections, events and invitations you initiate;
- send notifications you have asked for, such as a delegated task being accepted;
- personalise suggestions and remember your choices so we stop asking the same question;
- keep the Service safe: prevent fraud, abuse and unauthorised access, and enforce our Terms;
- diagnose faults, monitor performance and improve the Service; and
- comply with our legal obligations.
We use your information only for the purpose we collected it, a directly related purpose you would reasonably expect, or a purpose you have consented to.
5. Voice, AI, and how your inputs are processed
5.1 Voice. When you use voice input, the audio is sent to our speech to text provider to be converted to text and is then discarded. We never store your voice recordings. We keep only technical metadata about the transcription (its duration, detected language and processing cost) so we can monitor performance and costs, not the audio, and not its content.
5.2 Transcript retention. The raw transcript of a voice capture and its parse records are automatically deleted after 90 days. The items you created from that voice input are kept, because they are your list.
5.3 AI processing. To interpret your requests, ask clarifying questions and match items, we send the relevant text (for example, an item name like butter, or a spoken plan) to third party AI providers. We do not send them your account credentials or your full profile.
5.4 No training on your data. Our AI providers are contractually prohibited from using your inputs to train their models.
5.5 AI can be wrong. See clause 10 of the Terms. AI output is assistance, not a guarantee.
6. Who we share it with
We do not sell your personal information, and we do not disclose it for anyone else’s marketing.
We share it only:
- With people you choose. When you share a list, delegate a stop, invite someone to an event or trip, or connect a household member, they can see what you shared with them. You control this.
- With service providers who host and run the Service on our behalf, under contracts that require them to protect it and use it only for us. See clause 7.
- Where required or permitted by law: to comply with a court order, subpoena, regulator or law enforcement request, or where necessary to prevent a serious threat to life, health or safety, or to protect our legal rights.
- On a business transfer: if our business is sold or restructured, to the acquirer, subject to this policy. We will tell you if this happens.
7. Overseas disclosure
Your account data is stored in Australia. Our primary database, holding your account, lists, saved places, trips and connections, is hosted in Sydney, Australia.
However, some of our service providers process personal information outside Australia, principally in the United States. By using the Service, you acknowledge this.
We take reasonable steps to ensure overseas recipients handle your information consistently with the APPs, including through contractual protections. However, once information is held overseas it may be subject to that country’s laws, and Australian law may not apply to it.
| Provider | What they do for us | Location |
|---|---|---|
| Clerk | Authentication and account security | United States |
| Supabase | Database and file storage | Australia (Sydney) |
| Vercel | Application hosting and delivery | United States |
| Mapbox | Maps, geocoding, directions, travel times | United States |
| Places and business information, Calendar if you connect it, product search | United States | |
| Anthropic | AI interpretation, clarifying questions, matching | United States |
| OpenAI | Voice transcription and text to speech | United States |
| Bright Data | Retail product and price data collection | United States and global |
| Sentry | Error monitoring and diagnostics | United States |
| PostHog | Product analytics | United States |
| Resend | Transactional email | United States |
| Open-Meteo | Weather | European Union |
| FuelPricesQLD | Queensland fuel prices (no personal information) | Australia |
We review this list as our providers change. The current list is always in this policy.
8. How we protect it
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including:
- encryption in transit (HTTPS and TLS) for all traffic;
- encryption at rest for stored data, and AES 256 GCM encryption for third party access tokens such as calendar credentials;
- row level access controls so users can only reach their own data;
- authentication and session security managed by a specialist provider. We never store your password;
- least privilege access, rate limiting, and audit logging; and
- error monitoring so failures surface and get fixed.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is active |
| Lists, trips, saved places, connections | While your account is active, or until you delete them |
| Voice transcripts and parse records | 90 days, then automatically deleted |
| Voice audio | Never stored, discarded immediately after transcription |
| Diagnostics and error logs | Up to 12 months |
| Analytics | Up to 24 months |
| Records we must keep by law | As long as the law requires |
When you delete your account, we delete or de identify your personal information within 30 days, except where we must keep it to comply with a legal obligation, resolve a dispute or enforce our agreements. Residual copies may persist in our encrypted database backups for a short period after that, until those backups are overwritten in the ordinary course.
10. Your rights and choices
10.1 Access. You may ask for a copy of the personal information we hold about you. We will respond within 30 days. We do not charge for a request, though we may charge a reasonable fee for a substantial one.
10.2 Correction. You may correct most information in the app. If you cannot, ask us and we will fix it.
10.3 Deletion. You may delete your account at any time in the app or by emailing us. See clause 9.
10.4 Location. You may grant or withdraw location permission at any time in your device settings. Some features will not work without it.
10.5 Notifications. You can turn push notifications off in the app or in your device settings.
10.6 Calendar. You may disconnect your calendar at any time, which revokes our access.
10.7 Anonymity. Where lawful and practicable you may deal with us anonymously, but we cannot provide a personalised, account based routing service without knowing where you are starting from.
10.8 Complaints. If you think we have breached the APPs, contact our Privacy Officer at support@ryte.com.au. We will acknowledge within 5 business days and respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5288 Sydney NSW 2001.
11. Marketing
We send service messages (delegation updates, security alerts, changes to these documents) as part of the Service. You cannot opt out of essential ones while you hold an account.
We will only send promotional messages if you have consented, and every one will have a working unsubscribe. We comply with the Spam Act 2003 (Cth).
12. Cookies and analytics
We use:
- Strictly necessary cookies: sign in, session security, and preferences. The Service will not work without them.
- Analytics: to understand which features are used and where people get stuck, so we can improve the app.
You can block or delete cookies in your browser, though sign in may stop working. Where required, we will seek your consent for non essential cookies before setting them.
We do not use advertising cookies, and we do not run third party advertising.
13. Changes to this policy
We may update this policy. If a change is material, we will give you reasonable notice by in app notice or email before it takes effect. The last updated date above always reflects the current version.
14. Contact us
Privacy Officer
Angus Austin O’Neill trading as Map Smart (ABN 87 128 586 948)
Runaway Bay, Queensland, Australia
Email: support@ryte.com.au
We will acknowledge privacy enquiries within 5 business days.
Angus Austin O’Neill trading as Map Smart, ABN 87 128 586 948. Runaway Bay, Queensland, Australia.