privacy

PRIVACY POLICY

Last updated: 4 August 2026

The short version: PubPulse exists to help you find great pubs. To do that we need a small amount of information about you — an email, a display name, and (only when you actively use certain features) your approximate location. We don't sell your data, we don't share it with advertisers, and we don't build a profile on you to target you with anything. Everything below explains this in more detail.

1. Who we are

PubPulse is operated by DashedLTD ("we", "us"), a company registered in England and Wales. Registered address: [to be added].

For questions about your data or this policy: privacy@pubpulse.app

For general support: support@pubpulse.app

2. What this policy covers

This policy explains how we collect, use, share and protect your personal information when you use pubpulse.app.

PubPulse is a UK-based service. If you're in the UK or EU, this policy is written to comply with UK GDPR and EU GDPR.

3. Who can use PubPulse

PubPulse is for people aged 18 or over. When you sign up we ask for your date of birth and won't create an account for anyone younger. We do not knowingly collect data from under-18s. If you believe someone under 18 has an account, email us at privacy@pubpulse.app and we'll delete it.

4. What we collect and why

4.1 Account information

When you sign up we collect:

  • Email address — to identify your account and send you essential emails (password resets, security notifications)
  • Display name — your public identity on PubPulse (shown on leaderboards, vibe submissions, and other community features)
  • Date of birth — to confirm you're 18+. We store the fact that you're over 18 but not your date of birth beyond initial verification
  • Password — encrypted and never visible to us (managed by our authentication provider, Supabase)

If you sign in with Google, we receive your email address and name from Google. We do not access anything else in your Google account.

4.2 Location data

PubPulse uses your device location to show you nearby pubs. Here's exactly how it works:

  • When you open the app — we ask your browser for your current location and use it once to centre the map and find nearby pubs. We do not store this location.
  • When you search a new area — we log an anonymous record of the search coordinates (rounded to 2 decimal places, roughly 1 km precision) with no user identifier attached. This helps us understand which areas are popular so we can improve pub coverage. This data cannot be linked back to you.
  • When you check in or confirm a facility — we ask for your precise location to verify you're actually at the venue (within 200 metres). We store this location alongside your action, linked to your account. This is essential to prevent people submitting false data from home.

You can decline location access at any point in your browser settings. Some features (check-ins, facility confirmations) require it; browsing pubs does not.

4.3 Activity you record on PubPulse

We store the actions you take in the app so we can show them back to you and, in some cases, to other users:

  • Saved pubs — venues you tap the heart on. Private to your account.
  • Check-ins — pubs you mark yourself as visiting. Displayed on your profile and, in aggregate, on per-venue leaderboards.
  • Facility confirmations — when you confirm a pub has a beer garden, real ale, etc. Your identity is not shown publicly but is stored so we can prevent gaming (one confirmation per user per facility).
  • Vibe tags — atmosphere descriptions (cosy, lively, etc.) you submit. Displayed on venues without attribution to individual users.
  • Ratings and notes — 5-axis pub ratings and optional short notes. Whether these are public is your choice per rating.
  • Passport stamps — visit milestones. Displayed on your profile.
  • Preferences — settings you configure (notification opt-ins, etc.).

4.4 Technical information

Our servers automatically log:

  • IP addresses (used to prevent abuse and enforce rate limits — not linked to your account)
  • Browser type and device information
  • Timestamps of requests
  • Error logs

These logs are retained for up to 30 days.

4.5 What we do NOT collect

  • We do not track you across other websites
  • We do not use advertising cookies or fingerprinting
  • We do not sell or rent your data to anyone
  • We do not read your camera roll, contacts, or calendar
  • We do not run behavioural analytics (e.g. Google Analytics, Mixpanel)

5. Why we're allowed to process your data (lawful basis)

Under UK/EU GDPR, we rely on the following lawful bases:

  • Contract — providing you an account, storing your saves, and running features you actively use
  • Legitimate interests — preventing abuse, verifying proximity for check-ins, keeping our service secure, and understanding usage patterns (via anonymous aggregate data) to improve the app
  • Consent — for anything else where consent is required (e.g. marketing communications, if we ever introduce them)
  • Legal obligation — where we're required to retain or disclose data by law

6. Who we share your data with

We share your data only with the providers who help us run the service. These are called "sub-processors" under GDPR:

  • Supabase — database and authentication (EU region, Ireland)
  • Vercel — hosting the web app
  • Railway — hosting the API server (EU region)
  • Cloudflare — DNS and email routing
  • Google Places — pub discovery data (we send them coordinates, not your identity)
  • BestTime — historical pub busyness data (we send them venue IDs, not your identity)
  • Stadia Maps — the map tiles you see
  • Nominatim / OpenStreetMap — reverse geocoding (we send coordinates via our server, so they never see your IP)

We do not sell your data. We do not share data with advertisers or data brokers. If we are ever legally required to disclose your data (court order, regulatory request), we will notify you where legally permitted to do so.

7. Where your data is stored

All personal data is stored in the European Union (Ireland) via Supabase. Server logs are hosted in the EU via Railway. Some third-party services (Google Places, BestTime) may process requests via infrastructure outside the EU, but we send them only anonymised or venue-level data, never your personal information directly.

8. How long we keep your data

  • Account data — kept while your account is active. Deleted within 30 days of you deleting your account.
  • Check-ins, ratings, saves, confirmations — kept while your account is active. Deleted when you delete your account.
  • Anonymous search density records — kept indefinitely as they cannot be linked to you.
  • Vibe submissions — validity window of 1 hour for display purposes; kept in the database for up to 30 days for anti-abuse checks.
  • Server logs — 30 days.

9. Your rights

Under UK and EU GDPR you have the right to:

  • Access — get a copy of everything we hold about you. Available anytime via the "Export my data" button in Account Settings.
  • Rectification — correct anything wrong. Edit in Account Settings or email us.
  • Erasure ("right to be forgotten") — delete your account and all associated data via Account Settings. This is immediate and irreversible.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a machine-readable format (JSON export handles this).
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where we rely on consent, you can withdraw it anytime.
  • Complain — you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or your local EU data protection authority.

To exercise any of these rights, email privacy@pubpulse.app. We'll respond within 30 days.

10. Security

We take security seriously:

  • All data is transmitted over HTTPS
  • Passwords are hashed and never stored in plain text
  • Database access is restricted and monitored
  • API keys and secrets are stored securely and rotated regularly
  • We use row-level security in our database so users can only access their own data

No system is completely secure. If we ever experience a data breach that affects you, we will notify you as required by law.

11. Cookies

PubPulse uses only essential cookies required to keep you signed in (a session token from Supabase). We do not use tracking, advertising, or analytics cookies.

12. Changes to this policy

We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top. If the changes are significant we'll email you.

13. Contact us

Data or privacy questions: privacy@pubpulse.app

General support: support@pubpulse.app

© 2026 DashedLTD · Terms of Service · Privacy Policy