Skip to content
Swisscape

Privacy policy

We collect as little as possible: enough to sell you the Secret Map, keep you signed in and understand which pages help travellers.

Last updated 7 October 2026

Who is responsible

[Operator name not configured — set it before launch], [Postal address not configured — set it before launch]. Contact for data protection: [Contact email not configured — set it before launch]. This policy follows the Swiss Federal Act on Data Protection (FADP) and, for visitors in the EU/EEA, the General Data Protection Regulation (GDPR).

What we collect and why

Browsing the site

We count visits with our own statistics: the page, the page you arrived on, the referring website's domain, campaign tags in the link, device type, an approximate country derived from the request, and a random identifier that lives only in your browser tab (sessionStorage) and disappears when you close it. We do not store IP addresses for these statistics and do not use cookies for them. Purpose: understanding which pages help travellers and which sources send visitors. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)).

Our hosting provider processes technical logs (including IP addresses) for security and operations and deletes them after a short period. Map tiles are loaded from swisstopo's servers, which receive your IP address as part of the request.

Optional product analytics

Only if you agree, we use PostHog (hosted in the EU) to understand how people use the map, for example which filters are useful. PostHog sets cookies. Legal basis: consent (GDPR Art. 6(1)(a)); you can withdraw it at any time here:

Optional product analytics are not enabled on this site.

Buying the Secret Map

Payments are processed by Stripe, which receives your payment details, email address and country. We receive the email address, payment status, amount and a Stripe reference — never your full card number. We also store which page you bought from, to understand what works. Legal basis: performance of the contract (GDPR Art. 6(1)(b)) and legal accounting obligations (Art. 6(1)(c)).

Your account

Your email address, sign-in records, purchases, access rights, and places you save, shortlist or mark as visited. Sign-in uses one-time email links; we set essential cookies to keep you signed in. Legal basis: performance of the contract.

Reports and messages

If you report a problem on a place or write to us, we keep your message and, if you give it, your email address to reply and to fix the information.

Service providers

  • Supabase — database, authentication and file storage.
  • Stripe — payment processing.
  • Our hosting provider — serving the website.
  • An email delivery provider — sending sign-in links.
  • PostHog — optional product analytics, only with consent.
  • swisstopo — map tiles.

Some providers process data outside Switzerland and the EU/EEA, including in the United States. Where that happens, transfers rely on an adequacy decision (such as the Swiss–US and EU–US Data Privacy Frameworks) or on standard contractual clauses.

How long we keep data

  • Statistics: aggregated indefinitely; raw events for up to 25 months.
  • Account data: as long as your account exists; deleted within 30 days of a deletion request, except purchase records.
  • Purchase records: 10 years, as required by Swiss accounting law.
  • Reports and messages: as long as needed to handle them, at most 3 years.

Your rights

You can ask for access to your data, correction, deletion, restriction, a copy in a portable format, and object to processing based on legitimate interest. You can withdraw consent at any time. Write to us at the address above. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, to your local data protection authority.

Children

The service is not directed at children under 16, and we do not knowingly collect their data.

Changes

We will update this page when our processing changes; the date at the top shows the current version.