Privacy
How Food Passport handles your data
Plain English, no legal fog. Last updated 22 August 2026.
What we collect
- Your email address, used only to send you a sign-in link.
- The profile details you type in: username, display name, and optionally your citizenship and a dietary preference.
- Stamps and check-ins. The public record keeps only a coarse location (roughly 100 m). The exact GPS fix is stored privately and used only to detect cheating.
- Photos you upload as proof. They stay private until a moderator reviews them.
- Community posts, field reports, and votes.
- If you accept analytics: which pages and features you use, tied to your profile id, never your email.
- Crash reports when something breaks, with cookies, tokens, and private fields removed before they leave your device.
What we never do
- No ads. We do not sell or share your personal data.
- Your dietary notes and exact locations never go to analytics.
- Your citizenship is private unless you choose to show it.
- We do not record your screen or your typing.
Your choices
- Turning analytics off also forgets the profile id that analytics had been using.
- Sign out from your passport page on any shared device.
- Change who can see your citizenship in profile settings.
- Ask us to delete your account and data by email (below).
Who processes it
- Supabase — database and sign-in.
- Vercel — hosting.
- PostHog — analytics, only after you accept.
- Sentry — crash reports, scrubbed of personal data.
- Cloudflare R2 — photo storage.
- Geoapify — restaurant coordinates. It never receives your location.
Contact
Questions or a deletion request: [email protected]