VoxMap
FR EN

Privacy Policy

Last updated: May 2, 2026 — Version 1.0

1. Data controller

The controller of your personal data is VoxMap, reachable at voxmap.fr@gmail.com. For any question relating to data protection: dpo@voxmap.fr.

2. Data collected and purposes

VoxMap collects: (a) your email address for authentication and to send the OTP code, (b) the BCrypt hash of your password — never stored in clear text, (c) your city of residence (optional) to personalize the initial map view, (d) server logs (IP address, user-agent, timestamp) for debugging and security purposes, retained for a maximum of 30 days.

3. Legal basis

Processing is based on (a) performance of the contract (account creation and maintenance, Article 6.1.b GDPR) for technical data that is strictly necessary, and (b) explicit consent (Article 6.1.a GDPR) for optional data such as city of residence and future personalization processing.

4. Recipients

Your data is not communicated to any commercial third party. No data is shared with advertisers without your prior explicit consent. Technical sub-processors (OVH for hosting) are bound by a contract compliant with Article 28 GDPR.

5. Transfers outside the EU

No data is transferred outside the European Union. The entire infrastructure is hosted in Strasbourg (OVH), within French territory, not subject to the US CLOUD Act or other extraterritorial legislation.

6. Retention period

Active account: as long as the account is in use. Inactive account for more than 3 years: automatic deletion with prior notice by email 30 days beforehand. Server logs: 30 days. Anonymized voting data (petitions, consultations): retained indefinitely in irreversibly anonymized form (SHA-256 hash + salt) to ensure the historical integrity of consultations.

7. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights: access to your data, rectification, erasure (right to be forgotten), portability, objection to processing, restriction of processing, and the right to withdraw your consent at any time. To exercise these rights, contact dpo@voxmap.fr while providing proof of identity, or use the dedicated form at voxmap.app/delete-account. Response within one month maximum.

8. Cookies and trackers

The mobile application does not use cookies within the meaning of the ePrivacy regulation. No advertising tracker is integrated in the current version. Should advertising (AdMob, Google) be introduced in the future, prior consent will be requested via Google's UMP SDK, in compliance with Directive 2002/58/EC and CNIL recommendations.

9. Security

Security measures in place: HTTPS connections with Let's Encrypt certificates, BCrypt password hashing (workFactor 12), JWT authentication with refresh token rotation, ISO 27001 certified OVH hosting, daily backups and regular code audits.

10. DPO contact

Data Protection Officer: dpo@voxmap.fr. Postal address (to be completed in the final version): VoxMap, [postal address], France. Response guaranteed within one month maximum for any legitimate request.

11. Complaint to the CNIL

If you believe your rights are not respected or that your data is being processed in a non-compliant manner, you may file a complaint with the French Data Protection Authority: cnil.fr/plaintes or by post to CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

12. Modification of the policy

This policy may evolve over time. Any substantial modification (new purpose, new recipient, etc.) will be notified to the user by email and at their next sign-in. The current version is available at voxmap.app/privacy with the date of the last update.

13. Push notifications

The VoxMap application may send push notifications to your phone in four categories: (1) General announcements (app updates, important communications) — legal basis: legitimate interest; (2) Results from your commune (publication of election results for the commune you selected as residence) — legal basis: contract performance; (3) Account management (subscription expiration, failed payment) — legal basis: contract performance; (4) News and updates (re-engagement, suggestions) — legal basis: explicit consent (you must enable this type of notifications manually in the app settings; disabled by default). You can disable each category at any time from the application (notification settings) or block all notifications from your phone's system settings. To send you these notifications, we store a technical identifier (FCM token) assigned by Google and/or Apple to your device. This identifier is retained as long as your account is active and deleted upon account deletion or when an uninstallation is detected. No notification content is shared with any third party for advertising purposes.


VoxMap · voxmap.fr · voxmap.app · Hosted by OVH (Strasbourg, France) · DPO contact: dpo@voxmap.fr

← Back to home

© 2026 VoxMap · Privacy Policy · Terms & Conditions