This policy explains what information YDNAmaps collects, why, how it is stored and shared, and the rights you have over it. It is written to reflect what the site actually does. If anything here is unclear, contact us using the details below.
The data controller for YDNAmaps is {{YOUR FULL NAME OR COMPANY NAME}}, {{YOUR POSTAL ADDRESS}}. For any question about this policy or your data, contact {{YOUR CONTACT EMAIL, e.g. privacy@ydnamaps.com}}.
We collect only what is needed to run the map and your account. When you create an account we store your email address. When you submit a Y-DNA record we store the haplogroup, the DNA testing service, the kit number, an ethnicity label if you provide one, the town and country of your earliest known paternal ancestor and its map coordinates, and optionally an ancestral surname and your name. We also store which account submitted each record and timestamps. We do not ask for or store payment details, government identifiers, or precise personal addresses.
This distinction is central to how the site is built. Your email address is never shown publicly — it is stored separately from the map data and is visible only to you and site administrators. Your name is shown on the map only if you explicitly tick the box asking for it when you submit; otherwise it stays private. An ancestral surname is optional and, if you provide it, is shown publicly and is searchable, because linking surnames to lineages is the purpose of the site. The haplogroup, kit number, town, country and coordinates of an approved record are public. Please do not submit information you are not willing to have shown, other than your name and email which are protected as described.
YDNAmaps does not receive, store or process your raw DNA data, your DNA sample, or your full genetic sequence. What you submit is a haplogroup — a broad classification of a paternal lineage shared by very large numbers of people — together with a testing kit number and a place. We believe this means the site does not process genetic data in the strict sense that GDPR treats as a special category. This is, however, a legal judgement about sensitive data, and you should treat it as our current good-faith position rather than settled fact. {{CONFIRM THIS POSITION WITH A DATA-PROTECTION LAWYER BEFORE LAUNCH.}}
We rely on two legal bases under the GDPR. For your account and for publishing a record you have submitted, we rely on your consent, which you give by creating an account and by choosing to submit and, where relevant, to make your name public. You can withdraw that consent at any time by deleting your record or your account. For keeping the service secure and functioning, we rely on our legitimate interest in operating the map reliably and preventing abuse.
We keep your account and your submitted records for as long as your account exists. If you delete a record, its public map data and its associated private contact information are removed. If you ask us to delete your account, we remove your records and contact information. Backups and logs held by our infrastructure providers may persist for a limited period afterwards before being overwritten.
We do not sell your data and we do not share it for advertising. Approved public map data is, by design, visible to anyone who uses the site. To run the service we rely on a small number of processors: Google Firebase provides our database and authentication; our site is hosted on Netlify; map tiles are served by MapTiler; place search uses the OpenStreetMap Nominatim service; and web fonts are served by Google Fonts. When you use the map or search, technical requests such as your IP address may be visible to these providers as a normal part of delivering the service.
Some of the providers above operate outside the European Union, including in the United States. Where your data is processed outside the EU, those transfers are intended to be covered by the safeguards those providers offer, such as standard contractual clauses. {{IF YOU HAVE A GERMAN/EU AUDIENCE, HAVE COUNSEL CONFIRM THE TRANSFER SAFEGUARDS FOR EACH PROVIDER.}}
YDNAmaps does not use advertising cookies or third-party analytics trackers. Authentication uses local browser storage that is strictly necessary to keep you signed in. If we ever add analytics or advertising, this policy and a consent mechanism will be updated before doing so.
Under the GDPR you have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, and to receive it in a portable form. You can exercise most of these directly: your submissions and account are visible and removable from your profile. For anything else, contact {{YOUR CONTACT EMAIL, e.g. privacy@ydnamaps.com}} and we will respond within the timeframe the law requires. You also have the right to lodge a complaint with a supervisory authority; in Germany this is your regional data protection authority.
YDNAmaps is not intended for children. You must be old enough under the law of your country to consent to the processing of your data before creating an account or submitting a record.
We may update this policy as the site develops. When we make a material change we will update the date at the top of this page. Continuing to use the site after a change means you accept the updated policy.