1. Data controller and scope
Iceland Atlas is the data controller for personal data collected through the website and its digital features. For questions, requests or to exercise your rights, email support@geticelandatlas.com.
This notice describes processing carried out when you visit Iceland Atlas, create or use an account, generate or save an itinerary, use maps and tools, purchase a plan or contact support. Third-party websites reached through external links operate under their own privacy notices.
2. Data we process
Depending on the features you use, we may process:
- technical and browsing data: IP address, date and time, URL and referrer, browsing and search events, browser, operating system, device type, user agent, technical identifiers, cookies and data needed for security, abuse prevention and diagnostics;
- account data: Firebase identifier, verified telephone number, optional email, display name and profile photo, language, account creation and last sign-in dates, roles, plan and access status;
- profile and preferences: interests, trip dates, communication choices and saved settings;
- itinerary and travel-tool data: travel period and duration, times and airports, group composition and children's ages, mobility, vehicle and driving preferences, interests, selected activities and places, accommodation and food preferences, budget, dietary restrictions, allergies, free-text notes, wizard answers, generated itineraries and later changes;
- location: precise device location only when you voluntarily activate a nearby feature or the map geolocation control and grant browser permission; search queries and map area when you use geographic search or interactive maps;
- purchase data: selected plan, amount, currency, payment status and date, Stripe session, customer and transaction identifiers, contact and billing details provided at checkout. Full card details are entered directly with Stripe and are not stored by Iceland Atlas;
- analytics and advertising data: page views, selected content, searches, filters, tool use, paywall and checkout interactions, plan and role, user or browser identifier, attribution parameters and Meta identifiers (
_fbp,_fbcand external ID). For some Meta events we may also transmit IP address and user agent and, where available, telephone number, email, city and country in normalised or hashed form; - communications: messages sent to support or the privacy contact and the related contact details.
The country used to suggest a telephone prefix may be estimated from your IP address through country.is; Iceland Atlas does not store this estimate. Precise location requested by the browser is used on the device to display or sort nearby results and is not saved to your Iceland Atlas profile. Loading maps and tiles may nevertheless disclose technical data and the viewed map area to MapTiler.
3. Special-category data and children
The allergies and dietary restrictions field is optional and may reveal health data. It is processed only to personalise the itinerary at your request and on the basis of your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. You may withdraw consent and delete the itinerary or account at any time. Do not enter diagnoses, medical documents or unnecessary information.
Iceland Atlas is not intended for children using the service independently. An adult may provide the number and ages of children travelling with them only to adapt the itinerary to the group; we do not request children's names or contact details.
4. Purposes and legal bases
We process data to:
- create and manage the account, authenticate users, synchronise profiles, plans, preferences and content, generate and store itineraries and provide export, import, offline and requested features: performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR);
- manage checkout, payments, receipts, plan assignment, purchase recovery, refunds, disputes and accounting records: performance of a contract and legal obligations (Article 6(1)(b) and (c));
- protect accounts, APIs and infrastructure, limit abusive requests, diagnose faults and defend rights: legitimate interests in service security and continuity (Article 6(1)(f));
- answer support or privacy requests: performance of the service, legal obligations or legitimate interests, depending on the request;
- measure usage, improve product and content and measure campaigns with Google Analytics for Firebase, Meta Pixel and Meta Conversions API: consent, where required by applicable law (Article 6(1)(a));
- send optional offers or communications requested by the user: consent (Article 6(1)(a));
- use precise location for requested local features: your voluntary action and device permission, as part of the performance of the requested feature;
- comply with laws, authority orders and lawful requests: legal obligation (Article 6(1)(c)).
Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. Browser and device settings also allow you to block or erase cookies, local storage and location permissions. See the Cookie Policy for more information about local technologies.
5. Whether data is required
Data marked as necessary for authentication, purchase or itinerary generation is required to provide the relevant feature; without it we cannot complete that feature. Name, photo, marketing preferences, location, allergies, dietary restrictions and additional notes are optional. Do not put another person's personal data or unnecessary sensitive information in free-text notes.
6. Artificial intelligence and personalisation
To create or modify itineraries, we send OpenAI through its API the wizard answers, preferences, notes and necessary travel context, together with editorial catalogue data. We do not intentionally send OpenAI your name, telephone number, email or account identifier unless you put them in free-text notes.
OpenAI acts as an API service provider. According to the OpenAI API data controls, API data is not used to train models by default unless the customer opts in, and abuse-monitoring logs may be retained for up to 30 days, subject to legal requirements or different configurations. See also the OpenAI Data Processing Addendum.
Automated generation provides travel suggestions and personalisation but does not make decisions producing legal or similarly significant effects. Always verify operational information, accessibility, allergens, weather and safety with official sources and the relevant operators.
7. Providers and recipients
Data may be processed, only as necessary, by authorised personnel and by the following providers or categories of recipient:
- Google/Firebase and Google Cloud: hosting, telephone authentication, Firestore database, App Check/reCAPTCHA protection, analytics, backend execution and processing queues; Firebase privacy and security;
- Stripe: checkout, payments, fraud prevention, receipts and transaction management; Stripe Privacy Center;
- OpenAI: itinerary generation and modification through its API;
- Meta Platforms: Meta Pixel and Conversions API for attribution, measurement and advertising; Meta Privacy Policy and Meta Cookies Policy;
- MapTiler: maps, map tiles and search geocoding; MapTiler Privacy Policy;
- Sentry, if configured: backend error and performance monitoring, with default PII transmission disabled; Sentry Privacy Policy;
- country.is: temporary IP-country estimate used to preselect the telephone prefix;
- Google Places and Viator: operational information about places, activities and availability relevant to an itinerary; they may receive place or product identifiers, queries, language and dates needed for the request;
- advisers, professional service providers and public authorities where necessary for legal obligations, accounting, protection of rights or binding requests.
Providers may also process technical data collected directly when your browser connects to their services. If you follow a link to Google Maps, Viator, accommodation providers, operators or other external sources, you leave Iceland Atlas and the visited site's privacy notice applies.
8. International transfers
Some providers operate or use infrastructure outside the European Economic Area. In particular, Firebase Authentication is provided from data centres in the United States, while other Google/Firebase services may use global infrastructure. Where required, transfers rely on adequacy decisions, the Data Privacy Framework, Standard Contractual Clauses or other mechanisms recognised by applicable law, according to the arrangements and safeguards made available by the providers.
You may request information about the applicable safeguards by contacting us at the privacy address.
9. Retention and deletion
We apply the following criteria:
- account, profile, preferences and saved content are kept while the account remains active or until you delete them;
- drafts, wizard answers, generation queues and itineraries remain linked to the account for as long as required by the feature or until you delete the itinerary, reset the wizard or delete the account;
- when you delete the account from the relevant area, we delete the Firebase user and associated account, itinerary and generation-job documents from systems under our control, except for data that must be kept by law or to establish, exercise or defend legal claims;
- checkout, reconciliation, transaction and billing data are kept for periods required by tax, accounting, anti-fraud and dispute rules; Stripe may retain them independently under its own obligations;
- local storage, cache and offline copies remain on the device until the feature removes them or you clear the site/app data;
- technical logs and diagnostic data are kept for a period proportionate to security and troubleshooting needs;
- analytics, advertising data and related cookies follow Google and Meta retention settings and policies;
- residual backup copies are deleted or overwritten on normal technical cycles and are not used for other purposes in the meantime.
Data may be kept longer where necessary for legal obligations, investigations, fraud, disputes or legal claims.
10. Security
We use technical and organisational measures proportionate to risk, including encrypted connections, authentication and verified tokens, per-user and role-based access controls, Firestore rules, App Check/reCAPTCHA protection, request rate limiting and error monitoring. No transmission or system can, however, be guaranteed absolutely secure.
11. Your rights
Where provided by law, you may request access, correction, erasure, restriction, portability and object to processing; you may also withdraw consent at any time and not be subject to solely automated decisions producing legal or similarly significant effects.
You can edit some data and delete itineraries or your account directly from the account area. For any request, email support@geticelandatlas.com. We may ask for information needed to verify your identity and will respond within the time required by applicable law.
You also have the right to complain to the competent data protection authority. If you are in Italy, you may contact the Italian Data Protection Authority.
12. Changes to this notice
We may update this notice when the service, providers or applicable law changes. The date shown above is the latest revision; material changes will be communicated through appropriate means.
Atlas