CrashAtlas Map

Privacy Policy

Last updated: August 14, 2026

CrashAtlas ("we", "us", "our") operates the crashatlas.com website. This page describes how we collect, use, and protect your information when you use our service.

1. Information We Collect

Account Information

When you create an account, we collect your email address. We use magic link authentication and do not store passwords.

Payment Information

Web payments are processed by Stripe. Mobile payments are processed by Apple or Google, with subscription status managed through RevenueCat. We do not store your card number or bank details.

Usage Data

We use privacy-focused analytics (Plausible) to collect anonymous usage statistics without tracking cookies or personal data. If you accept analytics cookies in the cookie banner, we also use Google Analytics to understand how the service is used. For signed-in accounts, a visible browser periodically records whether the website was used on a given UTC day, including the first and last activity time for that day, to measure subscriber engagement. While a non-trial paid subscription is current, we also record use of bounded Premium feature categories, such as incident details, filters, and map display tools, with daily first/last use times and an aggregate use count. We do not store the page path or search terms in these account activity records.

Email Captures

If you submit your email through a newsletter or notice, we store the address and capture source to send product updates.

2. How We Use Your Information

  • Provide and maintain the service
  • Process payments and manage subscriptions
  • Send account-related billing and security communications
  • Send product updates when you opt in
  • Monitor and improve the service

3. Data Sharing

We do not sell personal data. We share only what is necessary with Stripe, Apple, Google, and RevenueCat for payment and subscription management, our email provider for requested account messages, optional Sentry error monitoring, and analytics or advertising providers disclosed by the service. The application and database are self-hosted in Germany.

4. Data Retention

We retain account data while your account is active and as needed for legal or billing obligations. If you delete your account, we remove your profile and comments and retain only records we are legally required to keep. Anonymous aggregate analytics may be retained indefinitely.

5. Your Rights

  • Access your account information
  • Update your username and profile
  • Delete your account and associated data, subject to legal retention duties
  • Unsubscribe from marketing emails

For GDPR requests, contact [email protected].

6. Cookies

We use essential cookies for authentication sessions. We do not use cookies to store passwords. Third-party content or advertising may be governed by the provider's own policy.

7. Security

We use HTTPS, restricted database access, hashed authentication tokens, secure session cookies, and least-privilege application roles. No Internet transmission or storage method is completely secure.

8. Children

The service is not directed to children under 13, and we do not knowingly collect their personal information.

9. Changes

We may update this policy and will post significant changes on the website.

10. Contact

Questions about this policy? Email [email protected].