Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how ITMAP.ai ("ITMAP", "we", "us") collects, uses, shares and protects information when you visit itmap.ai, create an account, sign in with Google, or otherwise use our services (together, the "Service"). It applies to every visitor, including people who browse without an account. By using the Service you agree to this Policy and to our Terms of Service.
1. Who we are
ITMAP.ai is an independent, AI-powered enterprise IT market-intelligence platform for technology buyers and vendors. ITMAP is the data controller for the personal data described in this Policy. You can reach us at privacy@itmap.ai.
2. Information we collect
2.1 Information you give us
- Account data: your sign-in email address, first and last name and, if you provide it, your company name, job designation and company email address.
- Company profile verification: if you register with a personal email provider (for example Gmail, Yahoo or Outlook) and choose to unlock research reports, news and the intelligence feed, we ask for a work email address and send a one-time verification link to it. We store whether that address has been verified.
- Content you create: RFP projects and answers, saved comparisons, questions typed into AI chat, contact-form messages and feedback.
- Vendor data: if you act on behalf of a technology vendor, the business contact details and product information you submit for review.
2.2 Information we receive when you sign in with Google
You may create an account or sign in using your Google Account ("Sign in with Google"). When you do, Google asks for your consent and then shares the following with us through Google's OAuth 2.0 service using theopenid,email andprofile scopes:
- your Google Account email address and whether Google has verified it;
- your name (given name and family name) as set in your Google Account;
- your Google profile picture URL;
- a unique Google Account identifier that lets us recognise the same account on later sign-ins.
We use this information only to create your ITMAP account, sign you in, pre-fill your profile and, where an ITMAP account with the same verified email already exists, link the two so that you keep one account. We treat an email address verified by Google as a verified ITMAP sign-in email.
We do not request access to your Gmail messages, Google Contacts, Calendar, Drive or any other Google data, and we never post to or modify anything in your Google Account. We do not receive or store your Google password. The short-lived tokens Google issues during sign-in are used once to read the profile fields above and are not retained.
ITMAP's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow humans to read it except with your consent, for security purposes, to comply with law, or as part of aggregated, anonymised internal operations.
You can review and withdraw ITMAP's access to your Google Account at any time at myaccount.google.com/permissions. Withdrawing access does not delete your ITMAP account; you can still sign in with the email link, or ask us to delete the account (see Section 8).
2.3 Information collected automatically
- Activity data: pages, markets, vendors and reports you view, filters and searches you use, AI chat prompts, RFPs you build, time spent and interactions.
- Traffic and device data: random first-party visitor and session identifiers, page path, referring page, campaign (UTM) parameters, browser user agent, IP address and the approximate country, region and city derived from it.
- Sign-in history: when you signed in, which method you used (email link or Google) and the number of sessions used before your email was verified.
We do not use browser fingerprinting, request GPS location, or trust a browser-supplied IP address or location.
3. Cookies and similar technologies
- Session cookie (HTTP-only, secure): keeps you signed in. Deleted when you sign out or the session expires.
- Visitor cookie (HTTP-only): a random identifier that recognises the same browser over time so that traffic statistics are not double-counted, and so that a browser's earlier visits can be associated with your account once you sign in.
- Traffic-session cookie (HTTP-only): expires after 30 minutes of inactivity; groups page views into one visit.
- Browser storage: we use local and session storage for preferences such as dismissed notices, the free-preview timer for anonymous visitors, and your acceptance of the Terms. These values never leave your browser except as described in Section 5.
- Advertising measurement: pages include the Reddit conversion pixel, which sets Reddit's own cookies and reports page visits and sign-ups to Reddit so that we can measure the effectiveness of our advertising. See Section 5.
You can block or delete cookies in your browser settings. Blocking the session cookie will prevent you from staying signed in.
4. How we use information
- Create and administer your account, authenticate you (by email link or Google) and keep your account secure.
- Send transactional emails: sign-in and email-verification links, company-email verification links and service notices. We do not send marketing newsletters without a separate opt-in.
- Provide the Service: market landscapes, vendor scores, comparisons, reports, news, intelligence feeds, security intelligence, RFP tools and AI chat.
- Apply access rules, for example unlocking research reports, news and the intelligence feed once a company email has been verified.
- Measure traffic, geographic demand and market interest; troubleshoot, secure and improve the Service.
- Provide vendors with the market-interest and lead information described in Section 5 and in the Terms.
- Comply with legal obligations and enforce our Terms.
Where the GDPR or similar laws apply, we rely on: performance of a contract (providing the Service you signed up for), our legitimate interests (security, analytics, product improvement, business-to-business marketing), your consent (Google sign-in, sharing with vendors, advertising measurement) and compliance with law.
5. How we share information
- Technology vendors. As set out in the Terms, when you engage with a vendor's market or products on ITMAP we may share your name, company name, job designation and business email address with that vendor, who may contact you. You can withdraw this consent at any time by emailing us.
- Google LLC. When you choose Sign in with Google, Google processes the sign-in under the Google Privacy Policy. We do not send your ITMAP activity to Google.
- Service providers acting on our instructions: cloud hosting and database (Replit), transactional email delivery (Resend), IP-to-location lookup (ipwho.is receives the IP address only), AI model providers that process the text of your AI chat prompts and our content pipelines, and error and performance monitoring.
- Reddit, Inc. for advertising measurement: page visits and account sign-ups are reported through the Reddit pixel and, for sign-ups, a server-side conversion event containing a hashed email address, IP address, user agent and a random event identifier. We do not share your name, company or on-site activity with Reddit.
- Legal and safety: where required by law, regulation, legal process or to protect the rights, property or safety of ITMAP, our users or others.
- Business transfers: in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.
We do not sell personal data and we do not share Google user data with third parties except as necessary to provide the sign-in feature itself.
6. Data retention
- Account and profile data are kept for as long as your account exists, then deleted or anonymised within 90 days of a deletion request, except where we must retain records by law.
- Verification tokens for sign-in and company-email links are single-use and are cleared as soon as they are used or replaced.
- Traffic records, including IP addresses, are retained indefinitely for trend analysis unless deletion is required by applicable law or you request it.
- Content you create (RFPs, comparisons, chat history) is kept until you delete it or your account is deleted.
7. Security
All traffic to ITMAP is encrypted with TLS. Sign-in is passwordless: we rely on single-use emailed links and on Google's authentication rather than storing user passwords. Verification tokens are random, single-use and stored so that they cannot be read from any user-facing interface. Detailed traffic intelligence and account administration are restricted to authorised ITMAP administrators. No method of transmission or storage is completely secure; please contact us immediately if you believe your account has been compromised.
8. Your rights and choices
- Access, correction and portability: you can view and edit your name and company profile on your Profile page and request a copy of your data by email.
- Deletion: email privacy@itmap.ai from your account address to delete your account and associated personal data.
- Google sign-in: revoke ITMAP's access at myaccount.google.com/permissions. You can also ask us to unlink Google from your account so that only email-link sign-in remains.
- Vendor sharing: withdraw consent to sharing with vendors at any time by email; withdrawal does not affect data already shared.
- Objection and restriction: where local law provides, you may object to or restrict certain processing, and you may lodge a complaint with your data-protection authority.
We respond to verified requests within 30 days. Available rights vary by jurisdiction.
9. International transfers
ITMAP is operated from the United Arab Emirates and our service providers process data in the United States and other countries. Where required, we rely on contractual safeguards such as standard contractual clauses for those transfers.
10. Children
The Service is intended for business users and is not directed to anyone under 18. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top shows the current version. Material changes will be announced by email or an in-app notice before they take effect.
12. Contact us
Privacy questions and requests: privacy@itmap.ai. General enquiries: itmap.ai/contact.