Privacy

How Food Passport handles your data

Plain English, no legal fog. Last updated 22 August 2026.

What we collect

  • Your email address, used only to send you a sign-in link.
  • The profile details you type in: username, display name, and optionally your citizenship and a dietary preference.
  • Stamps and check-ins. The public record keeps only a coarse location (roughly 100 m). The exact GPS fix is stored privately and used only to detect cheating.
  • Photos you upload as proof. They stay private until a moderator reviews them.
  • Community posts, field reports, and votes.
  • If you accept analytics: which pages and features you use, tied to your profile id, never your email.
  • Crash reports when something breaks, with cookies, tokens, and private fields removed before they leave your device.

What we never do

  • No ads. We do not sell or share your personal data.
  • Your dietary notes and exact locations never go to analytics.
  • Your citizenship is private unless you choose to show it.
  • We do not record your screen or your typing.

Your choices

  • Turning analytics off also forgets the profile id that analytics had been using.
  • Sign out from your passport page on any shared device.
  • Change who can see your citizenship in profile settings.
  • Ask us to delete your account and data by email (below).

Who processes it

  • Supabase — database and sign-in.
  • Vercel — hosting.
  • PostHog — analytics, only after you accept.
  • Sentry — crash reports, scrubbed of personal data.
  • Cloudflare R2 — photo storage.
  • Geoapify — restaurant coordinates. It never receives your location.

Contact

Questions or a deletion request: [email protected]