Privacy Policy — NoMap and Swiss Logistics Consulting GmbH
Effective date: 29. September 2026
Version: 1.0
1. Controller and contact
NoMap is owned and operated by Swiss Logistics Consulting GmbH (“SLC”, “we”, “us” or “our”).
Swiss Logistics Consulting GmbH
Hauptstrasse 41
6315 Oberägeri, Switzerland
UID: CHE-401.850.285
Primary privacy contact: info@swisslogisticsconsulting.com
NoMap support messages are forwarded to this address. To exercise your rights, use “Privacy request” as the subject and identify the relevant account, service or interaction. Do not send your password or API keys.
2. Scope and service types
This policy covers swisslogisticsconsulting.com, nomap.app, ocean.nomap.app, NoMap Router, NoMap’s MCP integration, and related NoMap interfaces that link to it. Only the sections relevant to the service you use apply.
| Service | Access and processing |
|---|---|
| SLC corporate website | Static informational site, hosted separately. No cookies, analytics, CDN or contact form. Enquiries are sent by email. |
| Free NoMap simple routes | Available through the website or MCP without a NoMap password. Route information and necessary technical request data are processed to answer the request. |
| NoMap subscriptions | Email-and-password login, account and subscription administration, and Stripe payment processing. |
| Saved NoMap content | Workspaces, projects, analyses and follows are stored. Access is limited to their owner and authorised administrators. |
| NoMap through an AI client | ChatGPT, Claude or another compatible client sends tool arguments to NoMap and receives the result. The client applies its own account, conversation and privacy controls. |
The NoMap Router connector is free and anonymous. It requires no NoMap account, sells nothing, and neither displays nor initiates any subscription, upgrade or payment.
For consulting work performed solely on a customer’s instructions, the customer’s privacy notice and applicable data-processing agreement govern that processing. SLC remains responsible for its own business correspondence and administration where it acts as controller.
3. Categories of personal data we collect
This section sets out the categories of personal data and other information we collect, in each case why. Some of it is personal data only in combination — a route request is not about a person, but an email address or an IP address is.
Route requests and results
We receive the wording of route requests and the structured arguments submitted through the website or MCP. Depending on the supported operation, these include places, ports, origins, destinations, coordinates, transport modes, waypoints, preferences and other route parameters.
Results may include identified places, coordinates, transport legs, distances, durations, route figures, map images, route links and supporting information. Relevant input information may be repeated in results, links or identifiers.
Route wording, uploaded text and location data can contain personal or commercially confidential information. Please provide only what is necessary and what you are authorised to disclose.
Uploaded documents and saved content
We process uploaded document text for the analysis and verification described in Section 5. We store the workspaces, projects, analyses and follows you choose to maintain.
Accounts and subscriptions
We process email addresses, password credentials and the account information needed for login and account management. We also process subscription status and access entitlements. Passwords are not part of routing prompts.
Stripe handles payment-card data. NoMap does not receive card details. NoMap retains the Stripe customer and subscription references, subscription status and renewal date needed to administer the subscription.
Technical records
Access logs contain the requesting IP address, requested address/URL and browser type. Requested URLs can contain the original route text. Error logs are also retained for troubleshooting.
Memory-based caches hold rendered maps, abuse-prevention counters and country-lookup results for the periods in Section 8.
First-party analytics
NoMap’s own analytics records actions, page information, a random identifier and country. IP addresses are not stored in the analytics records; they remain present in access logs as described above.
A random identifier can distinguish visits or activities even without a name or stored IP. We therefore do not describe these records as automatically anonymous.
Alerts, support and corporate enquiries
We process email addresses, followed items and subscription information for alerts, and messages or attachments sent for support and corporate enquiries. Google Workspace is used for email. NoMap support forwards to the primary privacy contact.
4. MCP tools and AI clients
When you ask ChatGPT, Claude or another compatible AI client to use NoMap, the client selects a tool and sends structured arguments to NoMap through the Model Context Protocol (MCP). These arguments may contain information drawn from your conversation. They are not necessarily a verbatim copy of your message.
NoMap resolves the locations, calculates the supported route, obtains necessary external data, produces the requested result and returns it to the client. The client presents the result.
| Tool | Input | Result |
|---|---|---|
plan_route | Route wording in query | Identified places and coordinates, transport legs, distances, durations and route/map links |
route_map | query, selected stats panels and inlineImage option | Map card/widget, title, image URL and route link |
search | Route wording in query | Route results with titles, links and identifiers for detailed retrieval |
fetch | Route identifier in id | Detailed route breakdown; the current documented design recalculates from the request-bearing identifier |
The free simple-route service does not require a NoMap password. The AI client may separately require its own account. NoMap does not need your entire chat history; it processes the arguments the client actually sends.
OpenAI, Anthropic and other client providers independently process conversations and returned results under their policies and settings:
Disconnecting NoMap prevents future calls through that connection. It does not erase prior NoMap records or client conversations. A deletion request to SLC does not automatically delete records held by the client provider.
5. Language-model processing
A third-party language-model provider is used in production to interpret requests and prepare route analysis. Every route request’s wording, route figures and uploaded document text are sent to that provider. This processing takes place in the United States.
The provider returns information used to interpret the request or prepare the response. This is a separate transfer from the tool request sent by ChatGPT or Claude: NoMap itself sends information to the provider, including when a request originates on the NoMap website.
No zero-retention setting is enabled for SLC’s account with that provider. SLC has not yet confirmed the account’s applicable API retention, training or service-improvement terms. We do not promise that the provider immediately deletes submitted information or excludes it from training.
Do not upload unrelated sensitive personal information or documents you are not authorised to disclose to that provider and SLC. Avoid unnecessary personal information in route requests.
6. Purposes and legal bases
We process information for the purposes below. Where EU or UK GDPR applies, the relevant bases are:
| Activity | Purpose | Applicable basis |
|---|---|---|
| Free route requests and MCP calls | Calculate routes and return requested results | Legitimate interests in answering user-requested anonymous routing queries; contract where processing is necessary for a contract with the individual |
| Language-model interpretation and analysis | Interpret the request and prepare the requested analysis | Legitimate interests in interpreting the request accurately and returning the result the user asked for |
| Account login and subscriptions | Authenticate users, administer access and deliver subscriptions | Performance of the service contract; legitimate interests for necessary business-contact administration where the customer is an organisation |
| Stripe billing and subscription references | Process payment, manage subscriptions and meet recordkeeping duties | Contract and applicable legal obligations |
| Saved workspaces, projects and analyses | Maintain the content selected by the user | Contract or legitimate interests in delivering the organisation’s requested service, as applicable |
| Logs and abuse counters | Deliver and secure the service, diagnose faults and resist misuse | Legitimate interests in availability and security; legal obligations where applicable |
| First-party analytics and country lookup | Understand service usage | Legitimate interests in understanding service usage, with an opt-out offered in Section 9 |
| Requested alerts | Send the notifications the user follows | Consent where relied upon; withdrawal through unsubscribe or a request to SLC |
| Support, enquiries and consulting | Respond, provide agreed services and maintain necessary correspondence | Requested pre-contract steps or contract where applicable; otherwise legitimate interests in business correspondence |
| Required legal records and claims | Meet legal obligations and establish, exercise or defend claims | Legal obligations and legitimate interests, as applicable |
Where Swiss data-protection law applies, processing must be transparent, proportionate and consistent with the disclosed purposes. A basis for ordinary processing does not by itself establish a lawful international-transfer mechanism.
SLC does not sell interaction data or use it for advertising, model training or unrelated secondary purposes. The operational analytics described above is a separate disclosed activity. The language-model provider’s independent uses remain subject to confirmation.
7. Categories of recipients and processing countries
The third parties below receive personal data or other information from us, each for the purpose stated. NoMap’s application and database are on one OVH server in Germany. The corporate website is on a separate server. NoMap currently has no backups.
| Recipient or infrastructure | Information and purpose | Processing location |
|---|---|---|
| OVH | NoMap hosting, database, request delivery and technical records | Germany |
| Third-party language-model provider | Every route request’s wording, route figures and uploaded document text; interpretation and analysis | United States |
| Stripe | Payment information and subscription processing; NoMap stores references/status/renewal date | United States is among the operator-reported destinations |
| Google Workspace | Alert, support and corporate email, including messages and attachments | United States is among the operator-reported destinations |
| Public open-source road-routing service(s) | Necessary route coordinates/arguments | Germany |
| Esri imagery, CARTO and public elevation-data service(s) | Tile/asset requests and relevant coordinates; browser IP and request metadata for direct browser requests | United States |
| NoMap river service | Required route coordinates/arguments | Germany, on the same server as the NoMap application |
| Weather and vessel-tracking providers | Information required for the requested weather or vessel operation | European Union |
| Country-lookup provider | The requesting IP address, used only to derive a country and not stored by NoMap in analytics records | External provider; location not yet confirmed |
| OpenAI, Anthropic or another client selected by the user | Tool arguments and results in the client conversation | Under the selected client’s applicable arrangements and policy |
| Corporate website host | Website delivery and any host-level technical records | European Union |
No Google routing service is used. Google Workspace email processing is distinct from route calculation.
External map assets requested by the browser expose the browser’s requesting IP and request metadata. Server-to-server requests expose NoMap’s requesting server IP and the payload sent to that service. Advisers or authorities may receive information where a lawful professional or legal disclosure is necessary.
International-transfer arrangements
The current processing includes Germany and the United States. SLC has not yet documented the relevant provider agreements or transfer safeguards. This notice does not claim that standard contractual clauses, certifications or another mechanism are already in place.
8. Retention — how long we keep personal data
NoMap does not maintain a general database history of unsaved route interactions, but parts of an interaction remain in logs and temporary caches, and deliberately saved content remains stored. The language-model provider and AI clients can hold their own copies.
| Category | Current retention and deletion practice |
|---|---|
| Unsaved route computation and LLM response in NoMap | Processed for the interaction; no general persistent query-history database. Exceptions include the records below and information deliberately saved. |
| Access logs, including IP, requested URL/route text and browser type | 14 days |
| Error logs | 14 days |
| Rendered map cache | Five minutes, memory only |
| Abuse-prevention counters | One minute, memory only |
| Country-lookup cache | Six hours, memory only |
| Workspaces, projects, analyses and follows | No automatic expiry; retained until manually deleted |
| Account data | Manual deletion on request |
| Stripe references, subscription status and renewal date | Remain after an account-deletion request under the present process |
| Alert subscriptions | Remain after account deletion under the present process; must be removed separately through the available unsubscribe/removal process |
| First-party analytics events | 24 months, then deleted automatically. Events recorded before this window was introduced have no expiry set and are removed on request. |
| Email alerts, support and corporate correspondence | Kept until deleted |
| Backups | No NoMap backups currently exist |
| Information held by the language-model provider | Retention not yet confirmed; no zero-retention setting enabled |
| ChatGPT, Claude and other client records | Governed independently by the provider’s policy and account controls |
Account deletion is currently handled manually on request. It does not automatically remove Stripe records or alert subscriptions. If you want these addressed as well, identify them in your privacy request. We will assess the request under applicable law and explain any necessary lawful retention exception.
“No automatic expiry” describes the current configuration; it is not a statement that indefinite retention is necessary or lawful.
9. Cookies, browser storage and analytics controls
NoMap website
| Item | Purpose | Current duration |
|---|---|---|
| Login/session cookie | Maintain signed-in access | One hour |
| Refresh/login cookie | Continue authenticated access | 30 days |
| Admin cookie | Administrative access | Seven days |
| Browser preferences | Maintain selected preferences | Until you clear site data |
| Random analytics identifier | Associate first-party action/page events | Until you clear site data, or immediately on opting out below |
No advertising or third-party tracking cookies are used. First-party analytics with a random identifier is nevertheless active. Analytics runs on the website only; connector and MCP traffic is never measured this way. Events are deleted after 24 months. Clearing browser storage can remove a local identifier or preferences; it does not remove previously stored server events.
You can decline analytics here. Browsers that send a Do Not Track signal are treated as having declined already.
NoMap does not request access to your device location. Locations you type or include in a document are still processed as submitted content.
Corporate website
The corporate website is static and separate. It sets no cookies, uses no analytics or CDN, and has no contact form. Corporate enquiries go by email to info@swisslogisticsconsulting.com.
10. Public route and map links
Map and route links are accessible to anyone who has the address. The address contains the original route request. Sharing such a link therefore shares the request wording as well as access to the route or map.
These links do not provide the owner/admin access restriction applied to saved workspaces, projects and analyses. Do not put sensitive or confidential information in request wording that may appear in a public link.
A request-bearing URL may also be retained by recipients, AI clients, browsers, access logs or services that load it.
11. Your rights and controls
Depending on applicable law and the circumstances, you may request access, correction, deletion, restriction of processing or portability, or object to processing. Where consent is the basis, you may withdraw it without affecting prior lawful processing.
Contact info@swisslogisticsconsulting.com. Identify the relevant account and approximate interaction time where necessary to locate a log entry. We may use proportionate identity checks.
Swiss access requests are generally answered within 30 days. Other requests are handled within their applicable legal deadlines. Necessary lawful exceptions, other people’s rights or recordkeeping duties may limit some requests; we explain the applicable reason.
You can stop future MCP calls by removing or disabling NoMap in your AI client. Manage client conversations separately through that provider. You can clear local cookies/preferences through browser controls. Account deletion and removal of linked saved content, alerts and billing references must be requested under the current manual process.
Where we act solely on a customer’s instructions, we may direct the request to that customer and assist it under the applicable agreement.
You may complain to the Swiss Federal Data Protection and Information Commissioner, or to the relevant EU/UK or other competent authority where applicable.
12. Security and permitted inputs
We restrict saved-content access to the owner and authorised administrators. Subscription login uses email and password. No internet service guarantees absolute security.
Do not submit passwords, API keys, payment-card details, identity documents, health records or unrelated sensitive personal information in route prompts or document uploads. Uploading a document transmits its text to the language-model provider as described in Section 5.
13. Age
NoMap is intended for users aged 16 and over. It is a professional freight-planning tool: it is not designed for, marketed to or directed at children, and the age threshold reflects the nature of the service rather than any restricted content. Do not submit children’s personal information through route requests or uploads.
14. Changes
The effective date is the date this unified policy goes live. We update the notice when tools, providers, storage, purposes, recipients or retention practices change. Where required, we provide additional notice or obtain consent before materially different processing begins.