Privacy Policy
Effective 22 July 2026
1. Scope and controller contact
This policy explains how the Georivo Location Story Widget processes personal data for account holders, prospective customers, support contacts, and visitors to published widgets. Contact the controller through the privacy contact form.
Controller:
YAS S.p.z.o.o.
SZLAK 77/222, 31-153 Kraków, Poland
2. Data we process
- Account data: email address, display name, Google account identifier, and authentication records.
- Billing data: Stripe customer and subscription identifiers, plan status, and billing period. Georivo does not receive full payment-card details.
- Product data: property address and coordinates, selected places, labels, widget settings, permitted embed domains, publication status, and aggregate play counts.
- Messages and consent records: support requests and opted-in coverage notifications.
- Security and technical data: session tokens stored as hashes, request metadata processed by hosting providers, and records needed to prevent abuse and verify webhooks.
3. Why we process data
We process data to provide accounts and subscriptions, publish and protect widgets, measure plan usage, respond to requests, send requested sign-in or coverage messages, prevent fraud and abuse, comply with law, and improve service reliability. Depending on the context, the legal basis is performance of a contract, steps requested before a contract, consent, legal obligation, or legitimate interests in operating and securing the service.
4. Service providers
We use Google for sign-in, address resolution, places, and live Maps 3D; Stripe for payments and subscription management; our own mail server for transactional email; and cloud infrastructure providers for hosting and database storage. These providers process data under their own terms and applicable data-processing commitments. When a visitor launches a live map, Google receives technical and location-related request data under the Google Privacy Policy.
5. Cookies and local access
Georivo uses a secure, HTTP-only session cookie to keep signed-in users authenticated. It is not used for advertising. Embedded Google Maps and payment pages may use their own storage or cookies under their policies. Live Google 3D is requested only after a visitor clicks to start the experience.
6. Retention
Account, subscription, and widget records are retained while needed to operate the account and satisfy legal, accounting, security, and dispute-resolution obligations. Sessions expire after 30 days. Magic sign-in links become unusable after 15 minutes. Support, consent, and anti-abuse records are retained only as long as reasonably necessary for those purposes.
7. Sharing and international transfers
We share data only with service providers, when you direct us to publish a widget, where required by law, or in a business transfer with appropriate safeguards. Providers may process data in countries outside yours. Where required, transfers rely on recognised safeguards such as adequacy decisions or standard contractual clauses.
8. Your choices and rights
You can manage billing and published links in your dashboard, revoke widgets, and sign out. Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, withdraw consent, and complain to a supervisory authority. Submit a request through the privacy contact form; we may need to verify your identity.
9. Security and changes
We use access controls, hashed credentials, signed provider webhooks, restricted embed domains, and encrypted transport. No system is perfectly secure. Material policy changes will be posted here with an updated effective date.
