What we collect

Account data: your name, email address, and a securely hashed password when you create an account. Activity you choose to record: favourites, private notes, visits, reviews, taste preferences, trip plans, and Bites Club activity (check-ins, points earned and spent, rewards redeemed).

Location, only at the moment you use it: when you check in at a venue or search "near me," your device sends its coordinates once, to verify presence or sort results. We store the check-in coordinates as part of that check-in record. We never track your location in the background, and the website and app work fully without location access.

Usage signals: anonymous, session-based interactions (viewing a listing, tapping directions) that tune our recommendation engine. These are tied to a random session identifier, not to your name.

What we don't do

We don't sell your data. We don't share it with advertisers. We don't track you across other websites or apps. The app carries no third-party analytics or advertising SDK. On the website, Google Analytics runs only if you accept cookies.

Third parties involved

Google Places supplies public venue information (addresses, ratings, photos), nothing about you is sent to Google. OpenStreetMap supplies the map data and CARTO renders and serves the map images on our map pages; your IP address reaches their tile servers as with any image on the internet. Stripe / Revolut process payments for business owners, card details go directly to them and never touch our servers. Emails we send you go through our own mail server.

Messages and reports you send us

When you write to us through the contact page, we keep your name, email and messages in our support system so we can answer you.

When you report content, we keep your name, email, what you reported, your explanation and our decision, so we can handle the report, confirm that we received it, tell you what we decided and deal with any legal claim. The EU Digital Services Act requires us to handle reports this way. We do not tell the member whose content you reported who you are, unless the law requires it.

When we decline or take down a review, we keep a record of the decision and the reason we sent the member.

Where your data lives, and for how long

On our servers in the EU, for as long as you keep your account. Newsletter addresses stay until you unsubscribe (one click, in every email).

Reports of content, and our decisions on them, are kept for five years after we decide, so we can answer an authority or a legal claim. They are then deleted.

Deleting your account

In the app: You → Delete account, everything listed above is erased immediately and permanently. On the web, email us and we delete it the same way. Aggregated statistics that contain nothing personal (e.g. "this venue had 14 check-ins in June") may survive as counts.

Your rights & contact

Under GDPR you can request a copy of your data, correct it, or erase it at any time. Write to legal@cyprusbites.com, a human answers.

You can also complain to the Commissioner for Personal Data Protection in Cyprus.