Privacy Policy — NoMap and Swiss Logistics Consulting GmbH

Effective date: 29. September 2026
Version: 1.0

1. Controller and contact

NoMap is owned and operated by Swiss Logistics Consulting GmbH (“SLC”, “we”, “us” or “our”).

Swiss Logistics Consulting GmbH
Hauptstrasse 41
6315 Oberägeri, Switzerland
UID: CHE-401.850.285

Primary privacy contact: info@swisslogisticsconsulting.com

NoMap support messages are forwarded to this address. To exercise your rights, use “Privacy request” as the subject and identify the relevant account, service or interaction. Do not send your password or API keys.

2. Scope and service types

This policy covers swisslogisticsconsulting.com, nomap.app, ocean.nomap.app, NoMap Router, NoMap’s MCP integration, and related NoMap interfaces that link to it. Only the sections relevant to the service you use apply.

ServiceAccess and processing
SLC corporate websiteStatic informational site, hosted separately. No cookies, analytics, CDN or contact form. Enquiries are sent by email.
Free NoMap simple routesAvailable through the website or MCP without a NoMap password. Route information and necessary technical request data are processed to answer the request.
NoMap subscriptionsEmail-and-password login, account and subscription administration, and Stripe payment processing.
Saved NoMap contentWorkspaces, projects, analyses and follows are stored. Access is limited to their owner and authorised administrators.
NoMap through an AI clientChatGPT, Claude or another compatible client sends tool arguments to NoMap and receives the result. The client applies its own account, conversation and privacy controls.

The NoMap Router connector is free and anonymous. It requires no NoMap account, sells nothing, and neither displays nor initiates any subscription, upgrade or payment.

For consulting work performed solely on a customer’s instructions, the customer’s privacy notice and applicable data-processing agreement govern that processing. SLC remains responsible for its own business correspondence and administration where it acts as controller.

3. Categories of personal data we collect

This section sets out the categories of personal data and other information we collect, in each case why. Some of it is personal data only in combination — a route request is not about a person, but an email address or an IP address is.

Route requests and results

We receive the wording of route requests and the structured arguments submitted through the website or MCP. Depending on the supported operation, these include places, ports, origins, destinations, coordinates, transport modes, waypoints, preferences and other route parameters.

Results may include identified places, coordinates, transport legs, distances, durations, route figures, map images, route links and supporting information. Relevant input information may be repeated in results, links or identifiers.

Route wording, uploaded text and location data can contain personal or commercially confidential information. Please provide only what is necessary and what you are authorised to disclose.

Uploaded documents and saved content

We process uploaded document text for the analysis and verification described in Section 5. We store the workspaces, projects, analyses and follows you choose to maintain.

Accounts and subscriptions

We process email addresses, password credentials and the account information needed for login and account management. We also process subscription status and access entitlements. Passwords are not part of routing prompts.

Stripe handles payment-card data. NoMap does not receive card details. NoMap retains the Stripe customer and subscription references, subscription status and renewal date needed to administer the subscription.

Technical records

Access logs contain the requesting IP address, requested address/URL and browser type. Requested URLs can contain the original route text. Error logs are also retained for troubleshooting.

Memory-based caches hold rendered maps, abuse-prevention counters and country-lookup results for the periods in Section 8.

First-party analytics

NoMap’s own analytics records actions, page information, a random identifier and country. IP addresses are not stored in the analytics records; they remain present in access logs as described above.

A random identifier can distinguish visits or activities even without a name or stored IP. We therefore do not describe these records as automatically anonymous.

Alerts, support and corporate enquiries

We process email addresses, followed items and subscription information for alerts, and messages or attachments sent for support and corporate enquiries. Google Workspace is used for email. NoMap support forwards to the primary privacy contact.

4. MCP tools and AI clients

When you ask ChatGPT, Claude or another compatible AI client to use NoMap, the client selects a tool and sends structured arguments to NoMap through the Model Context Protocol (MCP). These arguments may contain information drawn from your conversation. They are not necessarily a verbatim copy of your message.

NoMap resolves the locations, calculates the supported route, obtains necessary external data, produces the requested result and returns it to the client. The client presents the result.

ToolInputResult
plan_routeRoute wording in queryIdentified places and coordinates, transport legs, distances, durations and route/map links
route_mapquery, selected stats panels and inlineImage optionMap card/widget, title, image URL and route link
searchRoute wording in queryRoute results with titles, links and identifiers for detailed retrieval
fetchRoute identifier in idDetailed route breakdown; the current documented design recalculates from the request-bearing identifier

The free simple-route service does not require a NoMap password. The AI client may separately require its own account. NoMap does not need your entire chat history; it processes the arguments the client actually sends.

OpenAI, Anthropic and other client providers independently process conversations and returned results under their policies and settings:

Disconnecting NoMap prevents future calls through that connection. It does not erase prior NoMap records or client conversations. A deletion request to SLC does not automatically delete records held by the client provider.

5. Language-model processing

A third-party language-model provider is used in production to interpret requests and prepare route analysis. Every route request’s wording, route figures and uploaded document text are sent to that provider. This processing takes place in the United States.

The provider returns information used to interpret the request or prepare the response. This is a separate transfer from the tool request sent by ChatGPT or Claude: NoMap itself sends information to the provider, including when a request originates on the NoMap website.

No zero-retention setting is enabled for SLC’s account with that provider. SLC has not yet confirmed the account’s applicable API retention, training or service-improvement terms. We do not promise that the provider immediately deletes submitted information or excludes it from training.

Do not upload unrelated sensitive personal information or documents you are not authorised to disclose to that provider and SLC. Avoid unnecessary personal information in route requests.

6. Purposes and legal bases

We process information for the purposes below. Where EU or UK GDPR applies, the relevant bases are:

ActivityPurposeApplicable basis
Free route requests and MCP callsCalculate routes and return requested resultsLegitimate interests in answering user-requested anonymous routing queries; contract where processing is necessary for a contract with the individual
Language-model interpretation and analysisInterpret the request and prepare the requested analysisLegitimate interests in interpreting the request accurately and returning the result the user asked for
Account login and subscriptionsAuthenticate users, administer access and deliver subscriptionsPerformance of the service contract; legitimate interests for necessary business-contact administration where the customer is an organisation
Stripe billing and subscription referencesProcess payment, manage subscriptions and meet recordkeeping dutiesContract and applicable legal obligations
Saved workspaces, projects and analysesMaintain the content selected by the userContract or legitimate interests in delivering the organisation’s requested service, as applicable
Logs and abuse countersDeliver and secure the service, diagnose faults and resist misuseLegitimate interests in availability and security; legal obligations where applicable
First-party analytics and country lookupUnderstand service usageLegitimate interests in understanding service usage, with an opt-out offered in Section 9
Requested alertsSend the notifications the user followsConsent where relied upon; withdrawal through unsubscribe or a request to SLC
Support, enquiries and consultingRespond, provide agreed services and maintain necessary correspondenceRequested pre-contract steps or contract where applicable; otherwise legitimate interests in business correspondence
Required legal records and claimsMeet legal obligations and establish, exercise or defend claimsLegal obligations and legitimate interests, as applicable

Where Swiss data-protection law applies, processing must be transparent, proportionate and consistent with the disclosed purposes. A basis for ordinary processing does not by itself establish a lawful international-transfer mechanism.

SLC does not sell interaction data or use it for advertising, model training or unrelated secondary purposes. The operational analytics described above is a separate disclosed activity. The language-model provider’s independent uses remain subject to confirmation.

7. Categories of recipients and processing countries

The third parties below receive personal data or other information from us, each for the purpose stated. NoMap’s application and database are on one OVH server in Germany. The corporate website is on a separate server. NoMap currently has no backups.

Recipient or infrastructureInformation and purposeProcessing location
OVHNoMap hosting, database, request delivery and technical recordsGermany
Third-party language-model providerEvery route request’s wording, route figures and uploaded document text; interpretation and analysisUnited States
StripePayment information and subscription processing; NoMap stores references/status/renewal dateUnited States is among the operator-reported destinations
Google WorkspaceAlert, support and corporate email, including messages and attachmentsUnited States is among the operator-reported destinations
Public open-source road-routing service(s)Necessary route coordinates/argumentsGermany
Esri imagery, CARTO and public elevation-data service(s)Tile/asset requests and relevant coordinates; browser IP and request metadata for direct browser requestsUnited States
NoMap river serviceRequired route coordinates/argumentsGermany, on the same server as the NoMap application
Weather and vessel-tracking providersInformation required for the requested weather or vessel operationEuropean Union
Country-lookup providerThe requesting IP address, used only to derive a country and not stored by NoMap in analytics recordsExternal provider; location not yet confirmed
OpenAI, Anthropic or another client selected by the userTool arguments and results in the client conversationUnder the selected client’s applicable arrangements and policy
Corporate website hostWebsite delivery and any host-level technical recordsEuropean Union

No Google routing service is used. Google Workspace email processing is distinct from route calculation.

External map assets requested by the browser expose the browser’s requesting IP and request metadata. Server-to-server requests expose NoMap’s requesting server IP and the payload sent to that service. Advisers or authorities may receive information where a lawful professional or legal disclosure is necessary.

International-transfer arrangements

The current processing includes Germany and the United States. SLC has not yet documented the relevant provider agreements or transfer safeguards. This notice does not claim that standard contractual clauses, certifications or another mechanism are already in place.

8. Retention — how long we keep personal data

NoMap does not maintain a general database history of unsaved route interactions, but parts of an interaction remain in logs and temporary caches, and deliberately saved content remains stored. The language-model provider and AI clients can hold their own copies.

CategoryCurrent retention and deletion practice
Unsaved route computation and LLM response in NoMapProcessed for the interaction; no general persistent query-history database. Exceptions include the records below and information deliberately saved.
Access logs, including IP, requested URL/route text and browser type14 days
Error logs14 days
Rendered map cacheFive minutes, memory only
Abuse-prevention countersOne minute, memory only
Country-lookup cacheSix hours, memory only
Workspaces, projects, analyses and followsNo automatic expiry; retained until manually deleted
Account dataManual deletion on request
Stripe references, subscription status and renewal dateRemain after an account-deletion request under the present process
Alert subscriptionsRemain after account deletion under the present process; must be removed separately through the available unsubscribe/removal process
First-party analytics events24 months, then deleted automatically. Events recorded before this window was introduced have no expiry set and are removed on request.
Email alerts, support and corporate correspondenceKept until deleted
BackupsNo NoMap backups currently exist
Information held by the language-model providerRetention not yet confirmed; no zero-retention setting enabled
ChatGPT, Claude and other client recordsGoverned independently by the provider’s policy and account controls

Account deletion is currently handled manually on request. It does not automatically remove Stripe records or alert subscriptions. If you want these addressed as well, identify them in your privacy request. We will assess the request under applicable law and explain any necessary lawful retention exception.

“No automatic expiry” describes the current configuration; it is not a statement that indefinite retention is necessary or lawful.

9. Cookies, browser storage and analytics controls

NoMap website

ItemPurposeCurrent duration
Login/session cookieMaintain signed-in accessOne hour
Refresh/login cookieContinue authenticated access30 days
Admin cookieAdministrative accessSeven days
Browser preferencesMaintain selected preferencesUntil you clear site data
Random analytics identifierAssociate first-party action/page eventsUntil you clear site data, or immediately on opting out below

No advertising or third-party tracking cookies are used. First-party analytics with a random identifier is nevertheless active. Analytics runs on the website only; connector and MCP traffic is never measured this way. Events are deleted after 24 months. Clearing browser storage can remove a local identifier or preferences; it does not remove previously stored server events.

You can decline analytics here. Browsers that send a Do Not Track signal are treated as having declined already.

NoMap does not request access to your device location. Locations you type or include in a document are still processed as submitted content.

Corporate website

The corporate website is static and separate. It sets no cookies, uses no analytics or CDN, and has no contact form. Corporate enquiries go by email to info@swisslogisticsconsulting.com.

Map and route links are accessible to anyone who has the address. The address contains the original route request. Sharing such a link therefore shares the request wording as well as access to the route or map.

These links do not provide the owner/admin access restriction applied to saved workspaces, projects and analyses. Do not put sensitive or confidential information in request wording that may appear in a public link.

A request-bearing URL may also be retained by recipients, AI clients, browsers, access logs or services that load it.

11. Your rights and controls

Depending on applicable law and the circumstances, you may request access, correction, deletion, restriction of processing or portability, or object to processing. Where consent is the basis, you may withdraw it without affecting prior lawful processing.

Contact info@swisslogisticsconsulting.com. Identify the relevant account and approximate interaction time where necessary to locate a log entry. We may use proportionate identity checks.

Swiss access requests are generally answered within 30 days. Other requests are handled within their applicable legal deadlines. Necessary lawful exceptions, other people’s rights or recordkeeping duties may limit some requests; we explain the applicable reason.

You can stop future MCP calls by removing or disabling NoMap in your AI client. Manage client conversations separately through that provider. You can clear local cookies/preferences through browser controls. Account deletion and removal of linked saved content, alerts and billing references must be requested under the current manual process.

Where we act solely on a customer’s instructions, we may direct the request to that customer and assist it under the applicable agreement.

You may complain to the Swiss Federal Data Protection and Information Commissioner, or to the relevant EU/UK or other competent authority where applicable.

12. Security and permitted inputs

We restrict saved-content access to the owner and authorised administrators. Subscription login uses email and password. No internet service guarantees absolute security.

Do not submit passwords, API keys, payment-card details, identity documents, health records or unrelated sensitive personal information in route prompts or document uploads. Uploading a document transmits its text to the language-model provider as described in Section 5.

13. Age

NoMap is intended for users aged 16 and over. It is a professional freight-planning tool: it is not designed for, marketed to or directed at children, and the age threshold reflects the nature of the service rather than any restricted content. Do not submit children’s personal information through route requests or uploads.

14. Changes

The effective date is the date this unified policy goes live. We update the notice when tools, providers, storage, purposes, recipients or retention practices change. Where required, we provide additional notice or obtain consent before materially different processing begins.

Terms of use · Home