Privacy Policy
Effective 22 July 2026
1. Scope and controller
This policy explains how Georivo processes personal data for account holders, prospective customers, support contacts, and visitors to published widgets. Contact the controller through the privacy form.
Controller:
YAS S.p.z.o.o.
SZLAK 77/222, 31-153 Kraków, Poland
2. Data we process
We process the following categories.
- Account and authentication data.
- Stripe customer, subscription, plan, and billing-period data; not full card details.
- Property, coordinates, places, labels, settings, embed domains, status, and aggregate play counts.
- Support messages and opted-in coverage notifications.
- Hashed session tokens, request metadata, anti-abuse and webhook-verification records.
3. Purposes and legal bases
We use data to provide accounts and subscriptions, publish and protect widgets, measure usage, respond, send requested messages, prevent abuse, comply with law, and improve reliability. Legal bases may include contract, requested pre-contract steps, consent, legal obligation, or legitimate interests.
4. Service providers
We use Google for sign-in, addresses, places, and live Maps 3D; Stripe for payments; our own mail server for transactional email; and cloud providers for hosting and storage. Starting live 3D sends technical and location-related request data to Google under its privacy policy.
5. Cookies and local access
Georivo uses a secure HTTP-only session cookie for authentication, not advertising. Google Maps and payment pages may use their own storage. Live Google 3D is requested only after a visitor clicks to start.
6. Retention
Account, subscription, and widget records are retained as needed for operation and legal, accounting, security, or dispute obligations. Sessions expire after 30 days and magic links after 15 minutes. Other records are kept only as reasonably necessary.
7. Sharing and transfers
We share data with service providers, when you direct widget publication, where required by law, or in a safeguarded business transfer. International transfers use recognised safeguards where required.
8. Your rights
You can manage billing and links, revoke widgets, and sign out. Depending on location, you may request access, correction, deletion, restriction, portability, objection, consent withdrawal, or complain to an authority. Identity verification may be required.
9. Security and changes
We use access controls, hashes, signed webhooks, restricted embed domains, and encrypted transport. No system is perfectly secure. Material changes are posted here with a new date.
