This notice describes how Mapbox, Inc., along with its affiliates, (collectively, “Mapbox”, “we” or “us”) collect, use, store, transfer and protect personal data we gather concerning prospective, current and former employees for management, human resources and benefits purposes. If you are an applicant, independent contractor or an employee, this policy applies to you.
Mapbox, Inc. and, if different, the Mapbox entity listed in Schedule 1 with whom you enter into an employment contract or for which you otherwise agree to or seek to provide services, are data controllers of your personal data. To the extent that Mapbox, Inc. and the Mapbox affiliates in the EEA jointly determine the purposes and means of processing your personal data, Mapbox, Inc. and the Mapbox affiliates in the EEA have an arrangement in place, which determines their respective roles and responsibilities in the processing of your personal data. The joint control arrangement particularly pertains to the processing of personal data in jointly used databases, platforms and IT systems. Mapbox, Inc. and each Mapbox affiliate in the EEA have determined that they will process the jointly controlled personal data in accordance with applicable data protection law and this Privacy Notice. The Mapbox affiliate with whom you enter into an employment contract, or for which you otherwise agree to or seek to provide services, is your primary contact point and is responsible for responding to requests regarding your rights. Mapbox, Inc. and the Mapbox affiliate will coordinate as is necessary to respond to such requests. You may contact the Mapbox HR team for more information on the joint control arrangement. If you have any other questions or concerns regarding the processing of your personal data by us, you may refer to the details provided below under “Contact us”.
“Personal data” is information that relates to you and which identifies you or is capable of identifying you as an individual and may be provided to us by you or generated as a result of being recruited by, applying to, or working at Mapbox.
We process a variety of different types of personal data, including:
There may be instances in which the personal data that you voluntarily provide to us is considered “sensitive personal data” under applicable data protection laws. “Sensitive personal data” includes personal data from which we can determine or infer an individual's racial or ethnic origin, political opinions, religious beliefs or other beliefs of a similar nature, membership of a trade union, physical or mental health or condition, genetic or biometric information, sexual life or sexual orientation, or information relating to the commission of a criminal offence. Mapbox complies with privacy and data protection legislation in the jurisdictions where employees are located in connection with its processing of sensitive personal data.
When collecting personal data is mandatory (either under applicable law or in accordance with a contractual requirement), this will be stated at the time of collection. The consequences of your failure to provide the required personal data may include rejection of your application, termination of your employment or your inability to avail of certain Mapbox benefits.
We use personal data for the purposes described below, except where restricted by law. In doing so, we rely on a number of separate and overlapping legal bases to lawfully process such data.
Mapbox uses personal data for the following purposes to comply with its contractual obligations to you, such as to:
Mapbox uses personal data for the following purposes to comply with its legal obligations, such as to:
Mapbox also uses personal data for the following purposes to protect the vital interests of its employees, such as to:
Mapbox also uses personal data in pursuit of its legitimate interests and those of its employees in line with all the purposes described above, including using data as necessary to:
Note that Mapbox may monitor its IT systems in a reasonable manner and for reasonable purposes related to managing our business and the workplace. Therefore, you should have no expectation of privacy when using our IT systems. The types of personal data that may be collected during such monitoring include your internet access, your personal access to Mapbox or its customer’s confidential data, IP address, log in information, emails, including communication partner and data and time of communication, instant messages, access information from access key, such as access door, date and time of access). Review of such personal data is conducted or facilitated by our IT security personnel using certain computer programs or software. Such monitoring may take place in circumstances where the need arises to fulfill any of the following business purposes: ensuring compliance with our policies, investigating claims and allegations or reasonable suspicions of misconduct, ensuring the security of our confidential information, intellectual property, systems, devices and networks, managing IT resources and auditing for compliance. Additionally, at times, meetings conducted via Google Meet are recorded for knowledge sharing purposes with the advance consent of all meeting participants.
In order to carry out the processing outlined above, your personal data may be disclosed to managers, senior executives, and members of our People, Payroll, IT, Finance, Operations, Sales Operations, Security, and Legal teams on a need to know basis. This may involve the disclosure of your personal data to other entities in the Mapbox family of companies.
In addition, we may disclose your personal data to the following third parties:
We also reserve the right to disclose your personal data if we are compelled to do so by a court of law or requested to do so by a governmental entity or if we determine it is necessary or desirable to comply with applicable law or to protect or defend our employees’ rights or our rights or property in the course of an investigation or proceeding or to detect or prevent fraud or to prevent death or injury.
Mapbox is a global business and we may disclose and transfer your personal data to persons or companies located outside the EEA for any of the purposes set out in this Notice. Some of these countries may not have the same levels of data protection or similar rules regulating government agency access to personal data as are present in the EEA. In these cases, we take steps to protect your personal data in accordance with applicable laws. We rely on the Standard Contractual Clauses to lawfully transfer your personal data to the United States and other countries. You can request a copy of the Standard Contractual Clauses by emailing privacy@mapbox.com.
(b) Employees located outside the EEA
Mapbox is a global business and we may disclose and transfer your personal data under applicable law to persons or companies located outside the country in which you work. More particularly, your information will be kept on our and our vendors' third party-hosted infrastructure (i.e., in the cloud) and may be accessed at any Mapbox office location by Mapbox managers, members of the Mapbox People Team, Payroll, IT, Finance, Operations, Sales Operations, Security, and Legal on a need to know basis. In the case of international transfers, we take reasonable precautions to protect your personal data in accordance with applicable laws. However, you should be aware that information that is transferred or stored outside your home country may be accessible to law enforcement or national authorities in the jurisdictions where it is stored.
Your personal data shall be retained for as long as it is necessary to meet the purposes for which it has been collected or lawfully further processed. This includes information necessary to pay you, to pay federal and state/provincial income tax withholdings on your behalf, to contribute to your retirement account, to book travel, and overall help support you in your work at Mapbox. If you stop working at Mapbox, we will delete or anonymize your personal data within ten years, and if you apply to Mapbox and are not hired, we will delete any personal data you have submitted to us or which we generated as part of your recruitment process within one year. Notwithstanding the foregoing, we may retain your personal data for longer periods of time if required by law or if it is necessary to retain documents for purposes of litigation.
Please make sure that your personal data is accurate and up to date, and please inform us of changes in a timely manner.
If you live in the EEA, with some limited exceptions, you may inquire about the personal data we maintain about you and exercise your rights to access, correct, export ("right of data portability"), and delete your personal data, including information contained in your employee file. In addition, when we process your personal data based on our legitimate interests (as set out above), you have a right to object to our processing of your personal data.
If you live in a non-EEA country, or work for Mapbox Asia Limited, with some exceptions, you may also access, correct, request deletion, and update your personal data, including information contained in your employee file. If you live in the People's Republic of China (PRC), you may also have your personal data deleted upon request if Mapbox’s use of such personal data violates your labor agreement or PRC law, or if such personal data as collected and used is incorrect.
If you would like to exercise any of the statutory rights set forth above, please contact the Mapbox People team at hr@mapbox.com. We will take steps to verify your identity before fulfilling your request.
You may also have a right to lodge a complaint with your local data protection authority, or privacy commissioner, as applicable.
We may update this notice from time-to-time. We will take reasonable steps to notify you of any changes.
If you have questions, complaints or suggestions about our personal data processing practices or if you would like to exercise your statutory rights, you can contact the Mapbox People team at hr@mapbox.com.