Legal
Privacy policy
gmaps.dev collects businesses listed on Google Maps and serves them to its customers. This says what that means for our customers, and for the people and businesses in our results.
Last updated September 25, 2026
gmaps.dev is run by OpenWings Automação Comercial Ltda., CNPJ 63.852.648/0001-06, Rua Padre João Wislinski, 441, Santa Cândida, Curitiba – PR, CEP 82630-494 ("gmaps.dev", "we").
Our data protection contact (encarregado under the LGPD, data protection officer under the GDPR) is Gustavo Salomé Silva, at privacy@gmaps.dev.
1. What gmaps.dev does
We collect business listings that anyone can see on Google Maps: the name, category, address, phone numbers, website, opening hours, coordinates, rating and number of reviews, and the link to the listing. We keep them in one set of places that every customer searches, and serve them through our API, our console and exports. On paid plans, when a customer asks, we also look for email addresses on the business's own website. We never collect review text, reviewers' names or photos, and we never sign in to Google. gmaps.dev is not affiliated with Google or Alphabet.
2. Who this covers
Customers open an account and use the API or the console. People in our results are the people a business listing can identify, like a sole trader whose business carries their name, or a personal phone number listed as the business's number. This policy covers both, and anyone who sends us a removal request.
3. What we collect about customers
- Account: your email address, your name, the language you pick, and whether and when you accepted the acceptable use policy.
- Usage: the credits each request charged or refunded, the collections you start and the places they returned, the exports you create, your API keys (stored as hashes), and your webhook endpoints with their delivery log.
- Billing: your plan, your credit balance, and your Stripe customer and payment references. Card numbers never reach us. Stripe holds them.
- Technical: the IP address, time, URL and headers of each request, such as which browser or program sent it, in our web server's logs.
We use this to run the service, meter it, bill it, keep it secure and help you. We don't sell it, and we don't train models on it.
4. What we collect about people in our results
What the business listing showed when we collected it (section 1). A place can carry the name or the phone number of the person behind the business, and being public doesn't take away that person's privacy rights. Email addresses come only from the business's own website, and we show them only to paying customers who accepted the acceptable use policy.
Legal basis. For people in our results, the legitimate interest in business information that was published so people could find it (LGPD art. 7, IX; GDPR art. 6(1)(f)), balanced by the safeguards in this policy: public listings only, no reviews or photos, email addresses only for paid accounts that accepted the policy, and a removal form that keeps data out before and after we collect it. For customers, the contract you accept when you sign up (LGPD art. 7, V; GDPR art. 6(1)(b)).
5. Removal requests
When you ask us to remove something, we keep the email address you give us, what you asked us to remove, your reason, the language you used and the dates. We use them to confirm the request, to send you our decision and to keep the removed data out of gmaps.dev. To stop abuse, the form also counts requests from each IP address for one hour. It keeps nothing else about your connection.
6. How long we keep things
- Places have no end date: they stay in our set until we accept a request to remove them. When a customer searches an area and our copy is more than 180 days old, we collect it again and update it. A place we agree to remove leaves every search and export at once, and we delete our copy within an hour.
- Collection results, the list of places a collection returned and its progress log, are deleted after 30 days. The collection's counts and charges stay. An export file is built when you open its link and is never stored. The link stops working after 24 hours.
- Logs: webhook delivery logs 7 days, error records 30 days, web server logs 30 days.
- Accounts: deleting yours locks it and stops your API keys at once. We keep it 14 days so you can change your mind, then delete it and everything it owns. Payment records the law requires us to keep stay, without your account.
- Backups run every night. They stay 7 days on our server and 30 days in encrypted storage, and then they expire.
- Removal requests stay as long as the removal does, so that we never collect the removed data again.
7. Your rights (LGPD and GDPR)
Customer or not, you can ask us to confirm whether we hold data about you, to show it to you, to correct it, to delete or anonymize it, to hand it over in a portable format, and to stop processing it where our basis is legitimate interest. You can also complain to the data protection authority where you live. In Brazil, that's the ANPD.
Customers can delete their account in the console, under Account. For anything else, write to privacy@gmaps.dev. Anyone can ask us to remove a place, a phone number, an email address or a website with the removal form, without an account and at no cost. We answer within 15 days.
8. Who else handles the data
- Oracle Cloud: the server that runs our API and holds our database.
- Stripe: payments. Card data never reaches us.
- ZeptoMail (Zoho): sends our emails. It receives the address, the name and the message.
- Cloudflare: DNS, the hosting of this site and the console, and the encrypted storage for our backups.
- Amazon Web Services: the machine that collects places from Google Maps. It receives what to search and where, never who asked.
- OpenStreetMap: the console's map. Your browser loads the map images from OpenStreetMap's servers, which see your IP address.
Our server and the collecting machine are in São Paulo, Brazil. Transfers outside Brazil rely on these providers' standard contractual clauses.
9. Security
API keys are stored as hashes. Everything that travels over the internet is encrypted: the API, this site and the console use TLS, the database accepts outside connections only over TLS, and the collecting machine talks to our server through an encrypted tunnel in which it can only answer, never open a connection into the server. Backups are encrypted in storage. No system is perfect: if a breach affects you, we'll tell you and the authority as the law requires.
10. Children
gmaps.dev is not for people under 18, and we don't knowingly keep accounts for them.
11. Emails we send
- About your account: sign-up confirmation, password resets and the notice when you delete your account. They're part of the service and keep coming while the account exists.
- About a removal request: the confirmation link and our decision, to the address you gave us.
- News and tips: we send none. If that changes, we'll ask first, with the choice off by default, and you can take it back.
12. Changes
We announce a material change by email to customers and with a dated note at the top of this page.