Loading...

Terms and Service

Review the guidelines for using MapiBot. These Terms explain your rights, our responsibilities, and how we keep the platform safe and reliable for all riders.

Review our Terms of Service to understand your rights and obligations when using MapiBot.

Learn how we handle your data responsibly by reviewing our Privacy Policy.

Terms of Service

These Terms of Service (“Terms”) govern your use of MapiBot sites, apps, APIs, and services (collectively, the “Service”). By using the Service, you agree to these Terms and our Privacy Policy. If you do not agree, do not use the Service.

  • Use the Service only for lawful purposes and in a manner that does not infringe, misappropriate, or violate anyone’s rights.
  • No probing, scanning, or circumventing security or rate limits; no reverse engineering except where permitted by law.
  • No scraping or bulk export beyond what our UI/API expressly allows; no resale, sublicensing, or white-labeling without our written permission.
  • Overlays and APIs are provided for planning, research, and navigation support only—you remain responsible for your decisions and safety.

  • Scopes & actions. With your explicit OAuth consent, we request read and activity:read_all to import your activities and compute surface analytics. If you optionally grant activity:write, we may post a surface summary comment and/or prepend a short “Surface report (Mapibot.com)” block to your activity description. These writes are idempotent and affect only your activities.
  • Token handling. OAuth tokens are stored server-side with access controls; we do not store your Strava password.
  • Disconnect anytime. You can disconnect in Account → Strava. We delete tokens immediately and cease all Strava API calls. You may also request deletion of imported activity copies.
  • Compliance. We use Strava data solely to provide requested features and comply with Strava’s API Terms. We do not sell Strava data or use it for targeted advertising.

  • Premium features and add-ons (e.g., Strava Sync) are offered via monthly or annual subscriptions billed by Stripe. Prices and plan details are shown at checkout.
  • Plans may include a free trial. If you don’t cancel before the trial ends, your subscription begins automatically and renews until canceled.
  • You can manage or cancel any time via the Billing Portal (Account → Manage billing). Cancellation takes effect at the end of the current billing period unless otherwise stated.
  • Refunds. We offer a 30-day money-back guarantee as stated on the checkout page. To request a refund, contact support@mapibot.com.

  • If issued an API key, you must keep it confidential and use it only as documented. You are responsible for all activity under your key.
  • We may enforce rate limits, quotas, or geographic restrictions and may revoke keys that violate these Terms or harm the Service.
  • No sharing, resale, or redistribution of raw tiles/overlays beyond your app or site without written permission.

Surface detection, saturation, storm traces, and similar layers are model-based estimates and may be incomplete or inaccurate. You must use your own judgment and local knowledge. Outdoor activity carries inherent risk—MapiBot is not a substitute for safety precautions or professional advice.

We rely on providers such as Stripe (billing), Google Firebase (auth, storage, hosting, functions), map/tile and surface-matching services, and Strava APIs. Their terms and privacy policies apply alongside ours. We are not responsible for outages or changes by these providers.

  • You retain ownership of your content. You grant us a limited license to process it solely to provide the Service.
  • MapiBot and its logos, software, models, overlays, and documentation are our intellectual property and may not be copied, modified, or derivative-worked except as permitted in these Terms.

You are responsible for safeguarding your credentials and for activity on your account. If you sign in with Google or another identity provider, password updates are managed through that provider. Notify us immediately of any suspected unauthorized use.

We may suspend or terminate access for violations of these Terms, abuse of premium features, security concerns, or to comply with law. You may cancel your account at any time; data will be handled per the Privacy Policy.

The Service is provided “as is” and “as available.” To the maximum extent permitted by law, we disclaim warranties of merchantability, fitness for a particular purpose, and non-infringement. We are not liable for indirect, incidental, special, consequential, or exemplary damages, or for loss of data, revenue, or profits.

You agree to defend, indemnify, and hold harmless MapiBot and its affiliates from claims, damages, liabilities, and expenses arising from your use of the Service or violation of these Terms.

  • You must be at least 13 (or the minimum age in your jurisdiction) to use the Service.
  • These Terms are governed by the laws of the state and country where Sherpa-map LLC is organized, without regard to conflict-of-laws rules. Venue for disputes will be in those courts.
  • We may update these Terms by posting a revised version with an updated “last modified” date. Material changes will be notified reasonably in advance when required.

Questions about these Terms or your account? Email support@mapibot.com.

Privacy Policy

When you create an account, we collect your email address, display name, and basic profile information from your chosen sign-in method (Google or email). If you upgrade to Premium, Stripe securely processes your payment information—MapiBot does not store card details.

Strava data (when you connect): with your explicit OAuth consent, we may receive your Strava athlete profile (ID and basic profile fields), activity metadata (name, distance, time, elevation, sport type, start time), and optional activity streams (e.g., latlng, altitude, elapsed time) needed for surface analysis. If you grant activity:write, we can create comments and/or prepend a short “Surface report (Mapibot.com)” block to your activity description.

Technical data: device/browser information, IP address, and limited cookie identifiers for authentication and security.

  • Authenticate you and maintain your session.
  • Provide surface-intelligent maps and analytics (e.g., paved / unpaved / off-road percentages) from Strava activity streams you authorize.
  • If permitted (activity:write): post a summary comment and/or update your activity description with a surface block, idempotently and only for your activities.
  • Operate and improve the service, including aggregated, de-identified analytics. We never sell personal data or Strava data.

We use essential cookies for sign-in and security, including a session cookie (__session) and a short-lived Strava OAuth state cookie (strava_state). We use Firebase App Check and reCAPTCHA Enterprise to protect forms and APIs. With your consent, we may use analytics to understand usage and improve performance.

We share data only with providers that enable core functionality and process data under strict agreements:

  • Stripe for payments and subscription management.
  • Google Firebase (Auth, Firestore, Functions, Storage) for authentication, hosting, data storage, and serverless processing.
  • Strava APIs to import your activities and, if you allow, post comments / description updates back to Strava.
  • Mapping and analysis infrastructure (e.g., tile and surface-matching services) strictly to compute your requested map layers and surface reports.

We do not sell or rent your personal information or Strava data. We do not use Strava data for targeted advertising.

  • Account & app data: retained while your account is active. You can delete your account at any time from the Account page.
  • Strava connection: when you disconnect Strava, we immediately delete your OAuth tokens and stop all Strava API access for your account. You can also request deletion of imported activity copies we store for your view/analysis.
  • Legal obligations: certain records (e.g., billing) may be retained as required by law.

You may request access, correction, or deletion of your personal data. If you are in a region with specific privacy laws (e.g., GDPR or CCPA), you can exercise those rights through our support team. Contact: support@mapibot.com.

  • Scopes requested: read and activity:read_all to import your activities; optional activity:write to post a surface summary comment and/or prepend a short surface report block to your activity description.
  • Tokens & security: OAuth access/refresh tokens are stored server-side (Firebase) with access controls and encryption at rest. We do not store your Strava password.
  • Limited use: Strava data is used only to provide features you request (importing activities, computing surface stats, writing back comments/blocks if enabled). We do not sell or transfer Strava data to third parties except the processors listed above.
  • Disconnect any time: use Account → Connect to Strava → Disconnect to revoke access. We delete tokens immediately and cease API calls. You may also request deletion of any imported copies we hold.
  • User control: you can re-connect to grant missing permissions (e.g., activity:write) or keep read-only mode.

See also the Strava Terms of Service and Strava Privacy Policy.

Compliance & Notices

Last updated: 2025-09-07

  • This product uses the Strava API but is not endorsed or certified by Strava.
  • Scopes requested: read and activity:read_all to import your activities; optional activity:write to post a surface summary comment and/or prepend a short surface report block to your activity description.
  • Tokens & security: OAuth tokens are stored server-side (Firebase) with access controls and encryption at rest. We never store your Strava password.
  • Disconnect anytime: tokens are deleted immediately and Strava API access stops.
Top