TagMaps

TagMaps Privacy Policy

Last updated: October 5, 2026

1. About this policy

This policy explains how TagMaps collects, uses, stores and shares information when you use tagmaps.co and the TagMaps web, Android and iOS applications. TagMaps is a location-tag discovery and sharing service. For privacy questions or requests, contact privacy@tagmaps.co.

2. Information you provide

Account information: your email address, account identifier and authentication records. Email/password accounts use credentials processed by Supabase Authentication; passwords are not displayed in your profile. Optional profile information includes your display name, profile picture and phone number. The phone number and profile editor data are private to your account in the current app.

Tag information: tag title, required description, chosen latitude and longitude, optional photo, public/private setting, expiry, owner identifier and creation/update records. You choose the location you publish; it can identify your home, workplace or current whereabouts, so choose carefully.

Messaging information: message text, sender identifier, conversation participants, related tag and timestamps. If you contact us, we receive the information you include in your request.

3. Google account data and sign-in

If you choose Continue with Google, Google and Supabase process the sign-in and TagMaps receives your Google account identifier, email address and basic profile data, including available name and profile-picture information. Supabase stores the linked identity and account metadata; the app uses account/session identifiers for authentication and authorization, and may use your Google name as a profile display-name default. Supabase manages authentication tokens and the app stores session credentials locally to keep you signed in.

We use this Google data to create or recognize your TagMaps account, enable sign-in and protect account-owned features. We do not request Gmail, Google Drive, contacts or calendar access. We do not sell Google user data, use it for advertising or use it to train AI models. We share it with Supabase to provide authentication and account storage, and disclose it only where needed for service security or a lawful request. Google sign-in is optional; you can use email/password sign-in or browse public tags without signing in.

4. Location, photos and technical information

With your browser or device permission, TagMaps obtains your current location to center the map or help choose a tag location. You can deny permission and explore manually. This app does not implement continuous or background live-location sharing. Location becomes stored tag data when you publish chosen coordinates. Google Maps receives map requests and the map area being viewed, which may correspond to your current location if you center the map there.

When you choose an image from your device, TagMaps processes and uploads that selected image for the tag or profile feature. It does not upload your entire photo library.

Hosting, authentication, maps and email providers process technical information such as IP addresses, browser/device information, requests and service/security logs. The app stores authentication/session information on your device. The web app also caches application files for loading and updates. The current TagMaps app has no added advertising or behavioral analytics SDK.

5. How we use information

We use information to show and search location tags, display tag descriptions and photos, authenticate users, enforce ownership and private-link access, deliver conversations, maintain profiles and owner history, send account confirmation and password-recovery emails, respond to requests and secure and operate the service. We do not sell personal information or use Google account data for targeted advertising.

6. Who can see your content

Anyone, including visitors without an account, can see active public tag titles, descriptions, coordinates and photos. Public content can be copied or shared by other people. Private tags do not appear in public map/search/list results. Any signed-in user holding the exact private tag link can view its details and photo; recipients can forward the link or copy the content. Private sharing does not require an invitation list. Switching visibility invalidates the existing private link.

Conversation messages are available to their participants under server access controls. Messages are stored on the service; TagMaps does not provide end-to-end encrypted messaging. Your email address and private phone number are not included in public tag discovery. Avoid including sensitive information in tag descriptions, photos or messages that you do not want the relevant viewers to receive.

7. Service providers and other disclosures

TagMaps uses Supabase for authentication and database storage, including account metadata, tags, photos, profiles and messages; Cloudflare for web hosting and content delivery; Google for optional sign-in and Google Maps; and Brevo, through the configured authentication email service, for confirmation and password-recovery email delivery. These providers process the information needed to deliver their services under their own terms and privacy policies. Processing may occur outside your country.

When you choose Navigate, TagMaps sends the tag destination coordinates to the external maps service you open. That service handles your navigation and any location permission under its own policy. We may disclose information when required by law or needed to address fraud, abuse or service security. We do not make tag content private merely because it is accessed through a service provider.

8. Storage, retention and deletion

Account and content data are stored in the TagMaps Supabase project while needed to provide your account and service features. Expiry removes a tag from public discovery but retains it as inactive owner history until you explicitly delete it. Deleting a tag removes its stored photo and related conversations/messages from the active application database.

You can delete your account from the profile account-deletion control. The current database deletion removes your authentication account and sessions, optional profile data, owned tags/photos, and conversations and messages linked to the deleted account. Copies already received by other people cannot be recalled. Operational logs or provider backup copies may remain under provider retention processes or legal requirements; we do not promise immediate erasure from all provider systems or a fixed backup-retention period. If you cannot access your account, contact privacy@tagmaps.co for a deletion request. We may need to verify account ownership.

9. Your choices and requests

You can browse public tags without login, choose email/password instead of Google sign-in, deny or revoke location permission in browser/device settings, omit optional phone numbers and photos, edit your profile and tags, change tag visibility or expiry, remove photos, delete your tags and delete your account. You can revoke TagMaps access in your Google Account's third-party connections settings; this does not itself delete stored TagMaps account data, so use account deletion or contact us for that request.

Contact privacy@tagmaps.co to request access, correction or deletion, or to raise a privacy concern. Rights vary by where you live, and we may verify identity before acting. This policy does not claim a particular legal status or replace rights provided by applicable law.

10. Security and policy changes

TagMaps uses HTTPS and server authentication/authorization to restrict account writes, profiles, private tags and conversations. No online service can guarantee absolute security. Protect your credentials and private links, and sign out on shared devices.

We will update the date and content of this policy when our data practices change and provide additional notice where required. Privacy contact: privacy@tagmaps.co.

Provider policies: Supabase, Cloudflare, Google, Brevo.