Privacy policy
Last updated: 27 September 2026
PintHoppers is an iPhone app for visiting pubs and finishing lists of them. This page says which personal data we process and why, how long we keep it, and how to use your rights. It is the information required by Article 13 of the UK GDPR and by Article 10 of Türkiye's Personal Data Protection Law No. 6698 (KVKK).
Who is responsible
The controller is the individual who develops the app, Mehmet Oya. For any question or request about your personal data: privacy@pinthoppers.com.
What we keep, and for how long
The app has no password: you sign in with a six-digit code sent to your email address. Everything we keep, and for how long, is below. The 30-day limits are applied by an automatic job that runs every day.
| Data | Kept for |
|---|---|
| Your email address | As long as your account exists |
| Your display name, avatar and language | As long as your account exists |
| The moment your age (18 or over) was confirmed | As long as your account exists |
| Your date of birth | Not kept. It is sent once at sign-up for the 18+ check, compared on the server and never written down. |
| The record linking your address to your account | As long as your account exists |
| Your sessions | As long as the session stays signed in |
| Which address a sign-in code was sent to | While the code is valid (15 minutes) |
| An unfinished sign-up: an account and address that asked for a code but never made a profile | Deleted 30 days after it was last used, together with its sign-in log |
| Sign-in log: your address and when you signed in or asked for a code | 30 days |
| A copy of sign-in events in the service logs of our infrastructure provider, Supabase | Supabase's own retention period; we cannot delete this copy |
| Your phone's location (to find pubs and the area near you) | Not kept. Used only when you ask, for that one search. |
| Your location and its accuracy at the moment you check in | 30 days; then the location is deleted and the visit stays |
| Your visits: which pub, when, and how far from it you were | As long as your account exists |
| Your favourite pubs and lists | As long as your account exists |
| Your Mile attempts: which Mile, when it started, when it ended | As long as your account exists |
| The error report sent when the app crashes: the error, the app and iOS versions, the device model and a random identifier for this installation. Your IP address, location, name and email are not sent | 30 days |
| Check-ins waiting on your phone while there is no signal (location included) | Until sent to the server or refused; deleted as soon as you sign out or delete your account; on your phone only |
| The areas you chose most recently | At most 5 areas; deleted when you sign out or delete your account; on your phone only, never sent to the server |
Why we process it
- Your account and signing in (email address, identity record, sessions, sign-in code): to provide the app to you. The lawful basis is the performance of a contract (UK GDPR Article 6(1)(b); KVKK Article 5(2)(c)).
- Your profile, visits, favourites and Mile attempts: they are the app itself - how it shows you how far you have come. Same lawful basis.
- The 18+ check: PintHoppers is for people aged 18 and over. Same lawful basis; your date of birth is not kept.
- The sign-in log, 30 days: to be able to look into a security or sign-in problem reported late. The lawful basis is legitimate interests (UK GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
- Error reports, 30 days: to find out why the app crashed and fix it. The lawful basis is legitimate interests (UK GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
We do not use your data for advertising, profiling or sale, and we do not sell it to anyone.
Location
The app reads your location only while you use it, and only if you allow it in the iOS permission prompt. A location read to find pubs or the area near you is not saved anywhere. When you check in, your location goes to the server to confirm you are at the pub. It is deleted after 30 days; only which pub you visited and when remains.
Who processes your data
Service providers that process your data on our behalf:
- Supabase: database and sign-in infrastructure. Servers in the European Union, in Paris.
- Resend: sends the sign-in code email, and processes your email address to do so. The processing takes place in the United States.
- Sentry: receives the error report when the app crashes. Its servers are in the European Union, in Frankfurt.
- Cloudflare: serves this website. The site sets no cookies.
Apple (MapKit) provides the map in the app. To draw it, your phone asks Apple directly for the map images of the area on screen. Those requests are not processed on our behalf and fall under Apple's own privacy policy; we send Apple no data about your account. If an Android version ships, its map will be Google Maps, and this page will be updated before that version is released.
Beyond these, your data is not shared with any other person or organisation.
International transfers
PintHoppers has no server in Türkiye or in the United Kingdom. Your data is processed in these places:
- Supabase: European Union, Paris (France). Some of Supabase's sub-processors are in the United States and Singapore.
- Sentry: European Union, Frankfurt (Germany).
- Resend: United States.
- Cloudflare: serves this site from the data centre nearest to the reader.
- Apple: the map images come from Apple's servers.
For users in Türkiye, each of these is a transfer abroad under Article 9 of the Personal Data Protection Law No. 6698 (KVKK). For users in the United Kingdom, UK law treats the European Union as providing adequate protection (UK GDPR Article 45), and the transfers to Paris and Frankfurt rest on that. Transfers to the United States and Singapore are covered by the standard contractual clauses in the providers' data processing agreements. For users in Türkiye, we are putting in place the standard contracts of the Personal Data Protection Board that Article 9 of the KVKK provides for, with each of these providers; on the date this page was last updated, none of them was complete. As each one is completed, this section will say which contract was signed with which provider, and when. You can ask for a copy of the contracts at privacy@pinthoppers.com.
Deleting your account
From inside the app, without writing to anyone: Profile → Settings → Delete account. The deletion happens on the server. Your profile, visits, favourites, Mile attempts and sessions are deleted, and your email address is deleted from your account and from the sign-in log.
Two things are not, and we would rather say so. The copy in Supabase's service logs goes when Supabase's own period ends. Database backups carry deleted data for at most 7 more days; they are kept only to restore the database, and are not read for anything else.
Your rights
You have the right to know whether your data is processed, to get a copy of it, to have it corrected or deleted, and to object to its processing (UK GDPR Articles 15-21; KVKK Article 11). Write to the address above; we answer within 30 days at the latest.
If you are not satisfied with our answer you can complain: in the UK to the Information Commissioner's Office, in Türkiye to the Personal Data Protection Authority.
Age limit
PintHoppers is not for anyone under 18. If you declare at sign-up that you are under 18, no account is created, and you can delete your email address from your account and from the sign-in log. If you do not, it is deleted by itself after 30 days.
Changes
If this policy changes, the current version is published on this page and the date at the top changes.