Privacy Policy

Last updated: 1 August 2026

This page explains what personal data we collect, why, and what we do with it. The short version: we only collect what we need to make and ship your map, we never sell your data, and we run no advertising trackers.

Who is responsible for your data

The data controller is Grá Maps, a general partnership registered in Ireland, of 12 Springlawn Heights, Dublin 15, Ireland. You can reach us at hello@gramaps.com about anything on this page. We are small enough that we are not required to appoint a Data Protection Officer, so your email comes straight to us.

What we collect, why, and on what legal basis

Orders. Your name, email and shipping address, plus what you ordered. We need this to make your map, post it to you and keep the accounting records the law requires. Legal basis: performance of our contract with you, and our legal obligation to keep tax records.

Payment details. Handled entirely by Stripe. We see the last four digits of your card and whether the payment succeeded, nothing more. We never receive or store your full card number. Legal basis: performance of our contract.

Custom order and preview requests. The details you enter in the form: the location you chose, your name, email and any notes. We need these to design your map and reply to you. Legal basis: performance of our contract, or steps taken at your request before entering one.

Drop list. If you sign up, your email address, so we can tell you when a new map is released. Legal basis: your consent, which you can withdraw at any time.

Emails you send us. Whatever you write to us, kept so we can deal with your question and refer back to it if you get in touch again. Legal basis: our legitimate interest in answering customers properly.

Who else sees it

We use a small number of service providers who process data on our behalf. They may only use it to provide their service to us.

Some of these providers are based in, or store data in, the United States. Where that happens, transfers are covered by the safeguards those companies have in place, such as the European Commission's standard contractual clauses.

We do not sell or share your data with anyone for marketing. We run no advertising trackers, no analytics pixels and no third party profiling.

Cookies

We do not use advertising or analytics cookies, which is why you are not being asked to click a consent banner. The only storage this site uses is what is technically necessary to make it work, such as remembering what is in your cart while you browse. Netlify may set a cookie when you submit a form, for spam protection.

How long we keep it

Keeping it safe

Access to order data is limited to the two of us. Payment data never reaches our systems at all. We do not keep customer lists on paper or on unencrypted devices. If a breach ever occurred that put your rights at risk, we would tell you and the Data Protection Commission, as we are required to.

Your rights

Under the GDPR you have the right to ask us for a copy of the data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time, and that does not affect anything done before you withdrew it.

To exercise any of these, email hello@gramaps.com. We will respond within one month. There is no charge.

Note that we cannot delete records we are legally required to keep for tax purposes until that period has run out.

Complaining

If you think we have handled your data badly, please tell us first and we will try to put it right. You also have the right to complain directly to the Irish supervisory authority:

Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 · dataprotection.ie

Changes

If we change this policy we will update the date at the top of the page. If the change is significant and affects existing customers, we will email you.

Contact

Grá Maps, Dublin, Ireland · hello@gramaps.com