Skip to content
BeBartender.
Privacy PolicyTerms of UseDelete accountPolski

In this document

  1. 1. Controller and contact
  2. 2. Data processed
  3. 3. Purposes and legal bases
  4. 4. Recipients and service providers
  5. 5. Processing locations and transfers
  6. 6. Retention
  7. 7. Your rights and account deletion
  8. 8. Updates
Back to top

About the app

Privacy Policy

Effective date: 15 September 2026.

1. Controller and contact

The controller of personal data is Marek Przybolewski, an individual operating BeBartender. For app and personal data enquiries, email contact@bebartender.com.

Address: Jasna 7/63, 82-200 Malbork, Poland.

This policy covers the BeBartender app, the bebartender.com website and contact with the controller. The current app is free, without advertising or purchases. I do not sell users' data or use it for advertising tracking.

2. Data processed

  • Account and sign-in. When you sign in with Google or Apple, the app receives an identity token and passes it to Supabase, which manages the account and session. Data includes account and provider identifiers, the email supplied, any available name, profile image URL and technical authentication information, such as address verification, sign-in time, organisation domain or use of a relay address. The scope depends on the provider and account. Apple may supply a relay address and your full name on first authorisation; the app does not separately save that name in Supabase. BeBartender does not receive your Google or Apple account password.
  • Bar, favourites and ratings. I store selected ingredients, saved cocktails and ratings from 1 to 5 stars, linked to an account and timestamps. Your bar helps match recipes and identify missing ingredients; matching happens on your device. It does not record remaining bottle quantities or consumption history. Ratings contribute to aggregate scores, counts and rankings, including activity during the past seven days. Other users see aggregate results, rather than a list of people and their ratings.
  • Feedback. A problem report or suggestion contains its message, kind, date and account link. A bug report includes the available app version, platform, operating system version and language; a feature suggestion does not include this context. Authorised people handling feedback also see the sender's available email or account identifier. After account deletion, the link and lookup of the account email disappear, but the text may still contain data entered by the sender.
  • Session diagnostics. A report contains the outcome of a session recovery attempt, the event time and the time the server received it. It does not contain a user identifier, although sending it requires an authenticated session. Unsent reports wait on the device. A separate abuse-prevention counter stores the account identifier, UTC day and number of reports. Feedback limits use linked reports, their dates and a technical account-identifier record that prevents concurrent requests from exceeding the limit.
  • Logs and technical data. Supabase records authentication events, such as sign-in, session refresh and sign-out. Logs may include the account identifier, time, event type, IP address, client information and sign-in provider. Additional audit storage in the BeBartender database is disabled. Infrastructure providers also handle request data, such as IP address, time, resource address, method, response result and browser or app information, to deliver resources, investigate faults and protect services.
  • Website visits. Reading the website does not require an account. The site has no advertising, form or additional visitor analytics; fonts and images are served from its own domain. Its code does not set cookies or store data in the browser. Hosting and traffic protection process the technical data described above. Clicking an email address opens your email app; I receive the message only after you send it.
  • Correspondence. I receive the sender's address, message, attachments and other information you choose to send. Since 14 September 2026, the contact mailbox uses OVHcloud Zimbra. Earlier messages were forwarded through Cloudflare to consumer Gmail; changing providers did not delete earlier correspondence.
  • On-device data. The app stores language, units and the names of up to six cocktails opened from search results. The initial language comes from system settings. Queries and filters work locally against the downloaded catalogue. You can clear recent result names. These preferences and history are not synchronised as separate account records; language may be included in a bug report. The session, with user data and account metadata, uses the operating system's secure storage. A random installation marker supports its operation. Images are cached.
  • Sharing a recipe. The app creates a local image with the photo, ingredients, instructions and any available aggregate rating, in your chosen language and units. It is sent to the app or recipient you select in the system sharing menu. It does not include your account identifier, email, bar, favourites or individual rating.

3. Purposes and legal bases

Purpose Legal basis
Account, sign-in, bar, favourites and ratings Performance of the agreement to use the app — GDPR Article 6(1)(b), for data necessary for these features.
Handling voluntary feedback and correspondence, diagnosing faults and preventing abuse Legitimate interests in maintaining a functional, secure app and handling users' enquiries — GDPR Article 6(1)(f). This includes reviewing feedback after removing its account link, subject to the retention limits and rights below.
Fulfilling and necessarily documenting data protection requests Obligations under the GDPR — Article 6(1)(c).
Establishing, exercising or defending specific claims, if needed The legitimate interest in protecting the controller's rights — GDPR Article 6(1)(f), limited to necessary data.
Delivering and protecting the public website Legitimate interests in providing BeBartender information and maintaining availability and security — GDPR Article 6(1)(f), without advertising tracking.

Authentication data is necessary for features requiring an account. You decide whether to populate your bar, save favourites, rate a cocktail, submit feedback or send an email. Do not include other people's data or sensitive data in a report unless necessary for the matter.

The app matches and orders recipes using your bar, filters and aggregate ratings. I do not use this to make decisions producing legal or similarly significant effects on you.

4. Recipients and service providers

People authorised to operate the app have access within their responsibilities. I use these services:

Provider Scope
Supabase Pte. Ltd., Singapore Accounts, sessions, the database and app files: account data, bar, favourites, ratings, feedback, diagnostics and technical data. It processes entrusted data on my behalf. Supabase policy.
Netlify, Inc., USA Hosting the admin panel. The panel retrieves from Supabase data including feedback content, kind and date, context, and the sender's identifier and available email. It processes entrusted data on my behalf. Netlify policy.
Vercel Inc., USA Hosting a second running copy of the panel, with access to the same data categories. Vercel policy.
OVH Sp. z o.o., Poland (OVHcloud) Zimbra contact mailbox: addresses, content, attachments and technical delivery and security data, including spam and virus filtering. It processes entrusted data on my behalf. OVH DPA, Zimbra terms.
Cloudflare, Inc., USA Domain DNS and public website hosting on Cloudflare Pages, with technical visit data. It does not receive your bar, favourites, ratings or feedback content for this purpose. Historical email-routing events have separate retention; new email to contact@bebartender.com is not forwarded by Cloudflare. Cloudflare policy.
Google Ireland Limited, Ireland, for consumer services in the EEA Optional Google sign-in, historical email in consumer Gmail and messages sent to separate domain addresses still forwarded to Gmail. OVH handles new email to contact@bebartender.com. Google applies its own policy; consumer Gmail is not a processor service with a data processing agreement. Google policy, Gmail information.
Apple Distribution International Limited, Ireland, for Apple accounts in the EEA Optional Apple sign-in and a relay address. The relevant entity depends on the account's region. Apple operates its service under its own policies. Apple policy, Apple entities.

Supabase, Netlify and Cloudflare standard terms include agreements for processing on the customer's behalf, including free plans; OVH's agreement forms part of the purchased service terms. Providers separately determine their own purposes for customer accounts, billing and security. Supabase, Netlify, Cloudflare.

App connections to Supabase use HTTPS. The native session uses operating-system secure storage. Access rules link private bar, favourites and individual ratings to the account, and the feedback panel is available to authorised people.

5. Processing locations and transfers

The Supabase project database is in West EU (Paris), France, EU. Netlify admin functions run in Ohio, USA. A second panel copy runs on Vercel. Content delivery networks, email, support and providers' infrastructure may operate in other countries; the database region does not mean all processing is European.

Transfers outside the EEA may include the USA. Supabase terms provide European Commission Standard Contractual Clauses (SCCs). Netlify and Cloudflare provide the EU–US Data Privacy Framework (DPF) for covered transfers and SCCs in other applicable circumstances. OVH specifies location and subprocessor rules and SCCs for covered transfers to countries without a relevant adequacy decision. Supabase DPA, Netlify DPA, Cloudflare DPA, OVH DPA.

Google, Apple and Vercel describe international processing and safeguards in their own documents. These transfer descriptions do not establish a processor agreement for consumer Gmail or Vercel Hobby. Google, Apple, Vercel. You can request information about safeguards for BeBartender data and a copy through the contact address.

6. Retention

Data Retention period or criterion
Account, bar and favourites Until account deletion. You can delete an individual bar entry or favourite earlier. Inactivity alone does not delete an account.
Ratings While the account exists, you can change or delete a rating. Account deletion removes the link to its identifier but retains the rating, timestamps and cocktail identifier. The rating still contributes to aggregate results; it has no set expiry and remains until the cocktail is deleted. It is not linked to a new account.
Feedback No longer than 12 calendar months from the server originally receiving the report. Account deletion removes its identifier link but does not delete the message, kind, date or context or restart this period. Text may still contain personal data — removing the account link does not automatically make it anonymous. You can request earlier erasure under section 7.
Session diagnostics on the server No longer than 30 days from the server receiving the report.
Diagnostic counters The current and previous UTC day; daily cleanup removes older counters. They are also deleted with the account.
Technical feedback-limit record Account identifier, from the first report until account deletion; no additional report history.
Ordinary support correspondence No longer than 12 months after the matter is resolved, including historical Gmail correspondence. Changing providers does not restart this period.
Data-rights request records Only the minimum needed to fulfil and document obligations for the particular request. The need to retain records is assessed after the matter is resolved; they are erased when no longer needed for that purpose. A specific legal duty or dispute may justify retaining necessary data for the duration of that duty or for establishing, exercising or defending claims. This does not automatically cover all email.
Additional Auth audit in the BeBartender database Storage is disabled and the table contains no historical entries. Supabase's separate authentication service logs remain.
On-device recent searches Up to six names, until cleared, replaced by newer ones or successful in-app account deletion on that device.
On-device unsent diagnostics Until sent, replaced by newer entries or successful in-app account deletion on that device; up to 100 reports, without a separate time-based expiry. Signing out does not clear the queue.
Language and units Until changed or app data is removed. Signing out or deleting the account does not remove them.
On-device session While sign-in is maintained. Successful sign-out or account deletion ends the local session. Technical markers and encrypted remnants that the app does not use to restore sign-in may remain in system storage.
Photos and sharing images Cache or temporary files managed by libraries and the device system, without a separate app-set expiry. Signing out or deleting the account does not clear them. The recipient manages a copy passed to another app.

Daily cleanup of diagnostics and feedback may remove a record up to one day before the maximum deadline. The device clock and account deletion do not extend retention.

Provider logs and backups are separate categories. Plan documentation specifies a 1-day window for available Supabase Free API and database logs, 24 hours for Netlify Free function logs, and 1 hour for Vercel Hobby runtime logs. Cloudflare's earlier email-routing events, including sender, recipient, subject and routing decision data, have a 31-day period; routing was disabled on 14 September 2026. These windows do not mean all internal provider data is deleted. Supabase, Netlify, Vercel, Cloudflare.

I do not currently make my own database backups. Supabase Free does not provide a customer-accessible automatic backup feature; the provider describes its own technical backups. Database backups contain Storage metadata, not the image files themselves. Internal provider logs and backups follow criteria relating to service purposes, security and legal duties and deletion terms after services end. I do not assign them a single deadline or equate deleting a record with immediate deletion of every copy. Supabase backups and the provider policies in section 4 describe their scope.

OVH Zimbra describes recovery of messages for 30 days after deletion from Trash; other security data and backups have separate rules. Gmail keeps a message in Trash for up to 30 days unless permanently deleted earlier. Google describes a deletion process usually lasting around two months and encrypted backups for up to six months, with legal and security exceptions. These provider cycles do not extend BeBartender's ordinary use of correspondence. OVH Zimbra, Zimbra terms, Gmail, Google retention.

7. Your rights and account deletion

Subject to the GDPR's conditions, you can request access, rectification, erasure, restriction and data portability. You can object to legitimate-interest processing on grounds relating to your particular situation. If processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing.

In the app, open Profile → Delete account and confirm your decision. An internet connection is required. The server verifies the current session and deletes the account, bar, favourites and limit records. Once the server confirms, the app ends the local session and clears recent searches and unsent diagnostics on that device. There is no waiting period; deletion cannot be undone. If an error occurs, the app lets you retry. Language, units and cached public images remain. Signing out or uninstalling the app alone does not delete the server account. Signing in again after deletion creates a new, empty account.

Ratings and feedback remain without a link to the account identifier, under section 6. If feedback contains your personal data, you can request its erasure earlier. Provide only what is needed to locate the report, such as an approximate date and brief description. Removing the account link may make searching harder but does not remove rights concerning data that still identifies you. After verifying an applicable request, I erase that data or report unless a legal exception applies and explain the outcome.

Without installing the app, use the Account deletion page or email contact@bebartender.com. You do not need to give a reason. Where reasonably necessary, I will verify control of the account, including for an Apple relay address; do not send a password, token or identity-document scan.

Deleting your BeBartender account does not delete your Google or Apple account. On an iPhone or iPad, an account with an Apple identity requires confirmation again in Apple's system sheet so the server can revoke sign-in access. On Android and for email requests, the Apple connection may remain. For Google, the app attempts to disconnect access after deleting the BeBartender account. You can also check connections in your Apple settings and Google settings; this is not a condition for accepting a BeBartender account deletion request.

I provide information about action taken without undue delay and within one month of receiving a request. If its complexity or the number of requests justifies an extension by up to two further months, I will explain the reasons within the first month. If I refuse, I will explain the basis and available remedies. Straightforward erasure requests are handled without undue delay. You can complain to the competent supervisory authority, including the President of the Personal Data Protection Office in Poland.

8. Updates

When processing practices change, I update this policy and its date. The current version is available on the Privacy Policy page.

BeBartender

For adults aged 18 and over. Enjoy responsibly.

contact@bebartender.com
Privacy PolicyTerms of UseDelete account