Privacy Notice

Last updated: 21 May 2026 ยท Applies to thedessertdetective.com

Summary: We collect only what we need to run The Dessert Detective. We never sell your data. You can delete your account and all associated data at any time. We store data in the UK/EU on Supabase (hosted on AWS EU). If you have questions, email us at [email protected].

1. Who We Are

The Dessert Detective ("we", "us", "our") is the operator of thedessertdetective.com โ€” a UK dessert shop discovery platform. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller.

Contact: [email protected]

We are not currently registered with the ICO as we fall below the fee threshold, but we comply fully with UK GDPR obligations.

2. What Data We Collect and Why

We only collect personal data that is necessary for the service. Here is a complete breakdown:

a) General User Accounts (optional โ€” you can browse without an account)

DataWhy we collect itLegal basis
Email addressAccount login and communicationsContract (account registration)
UsernameDisplay name on your accountContract
NamePersonalise your experienceContract
City / CountryShow relevant local contentContract
Phone numberOptional โ€” account recovery onlyLegitimate interests
Password (hashed)Authenticate you securely โ€” never stored in plain textContract
Marketing preferencesTo send or withhold marketing emailsConsent
Favourite shopsShow you saved venuesContract
Submitted eventsDisplay events you createdContract
Last login timestampSecurity โ€” inactive account detectionLegitimate interests

b) Business Accounts

DataWhy we collect itLegal basis
Business nameDisplay on the directoryContract
Contact nameAccount management communicationsContract
Email addressAccount login and business communicationsContract
Phone numberAccount verification and supportContract
Password (hashed)Authenticate you securelyContract
Messages sent to usCustomer support communicationsContract
Promotion requestsProcess paid promotionsContract

c) Non-account data we collect

DataWhy we collect itLegal basis
Email leads (newsletter)Send dessert updates if opted inConsent
Shop suggestionsImprove the directoryLegitimate interests
Shop claimsVerify business ownershipContract
Reactions (likes on shops)Community features โ€” not linked to your identity if not logged inLegitimate interests
PWA install/prompt eventsUnderstand how people use the app โ€” no personal identifiersLegitimate interests
Google Analytics dataUnderstand site usage via anonymised analyticsLegitimate interests
Location data (GPS)Show dessert shops near your current position โ€” only processed in your browser, never stored on our serversConsent (browser permission)

3. Where We Store Your Data

All personal data is stored on Supabase, hosted on Amazon Web Services (AWS) in the EU-West region. This keeps your data within the UK GDPR adequacy framework.

Our website is hosted on Netlify (US company with EU Standard Contractual Clauses in place). Static pages and CDN-cached content do not contain personal data.

Email notifications are sent via Resend (US company, SCCs in place). Emails are not stored permanently โ€” they are sent and discarded.

Analytics are processed by Google Analytics 4 with IP anonymisation enabled. We do not use Google Analytics for advertising targeting.

4. How Long We Keep Your Data

Data typeRetention period
User account dataUntil you delete your account, or 3 years of inactivity
Business account dataUntil you delete your account, or 3 years of inactivity
FavouritesUntil you delete them or your account
EventsUntil you delete them or your account
Messages to us2 years from the date sent
Email newsletter leadsUntil you unsubscribe
Reactions / likes90 days if not linked to an account; indefinitely if linked
Shop suggestions / claims2 years
PWA analytics events12 months
Google Analytics data14 months (GA4 default, configured by us)

5. Who We Share Your Data With

We do not sell, rent or trade your personal data to any third party, ever.

We share data with the following processors only to the extent necessary to run the service:

  • Supabase Inc. โ€” database hosting (EU-West, AWS)
  • Netlify Inc. โ€” website hosting (SCCs in place)
  • Resend Inc. โ€” transactional email delivery (SCCs in place)
  • Google LLC โ€” anonymised analytics via Google Analytics 4 (SCCs in place)

We may disclose data if required to do so by law, court order, or a regulatory authority. We would notify you of any such request unless legally prohibited from doing so.

6. Cookies and Tracking

We use the following cookies and local storage mechanisms:

Name / TypePurposeDuration
dd_user (localStorage)Keeps you logged in to your accountSession (1 hour)
dd_biz_account (localStorage)Keeps you logged in to your business account30 days
dd_shops_v3 (sessionStorage)Caches shop data for faster browsing โ€” no personal data5 minutes / tab close
dd_pwa_dismissed (localStorage)Remembers if you dismissed the install prompt7 days
_ga, _ga_* (cookies)Google Analytics โ€” anonymised usage data14 months

We do not use advertising cookies, tracking pixels or third-party remarketing tools.

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data. To exercise any of them, email us at [email protected] or use the options in your account settings.

RightWhat it meansHow to exercise it
Right of accessRequest a copy of all data we hold about youEmail us โ€” we respond within 30 days
Right to rectificationCorrect inaccurate dataEdit in your account settings, or email us
Right to erasure ("right to be forgotten")Delete your account and all personal dataDelete Account button in your account settings, or email us
Right to restrict processingAsk us to pause processing your dataEmail us
Right to data portabilityReceive your data in a machine-readable formatEmail us โ€” we will provide a JSON export
Right to objectObject to processing based on legitimate interestsEmail us
Right to withdraw consentWithdraw marketing consent at any timeAccount settings โ†’ Preferences, or email us

We aim to respond to all requests within 30 calendar days. If a request is particularly complex, we may extend this by up to a further two months โ€” we will inform you if this is the case.

8. Marketing Communications

We will only send you marketing emails if you have explicitly opted in (either at registration or in your account settings). You can withdraw consent at any time:

  • Go to Account โ†’ Preferences and toggle off "Email updates"
  • Click the unsubscribe link at the bottom of any marketing email
  • Email us at [email protected]

Withdrawing marketing consent does not affect transactional emails (e.g. password resets, account confirmations) which we send on the basis of contract performance.

9. Account Deletion

You can delete your account at any time from your Account page. When you delete your account:

  • Your profile information (name, email, city, phone) is permanently deleted
  • Your favourites list is deleted
  • Your submitted events are anonymised (we retain them for community purposes but remove your name and email)
  • Your messages to us are deleted after 30 days
  • We retain a deletion record for our legal audit trail for 12 months, containing only the date and account type โ€” no personal data

Deletion is irreversible. We cannot recover your account after deletion is processed.

10. Children's Privacy

The Dessert Detective is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Notice

We may update this privacy notice from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. We will notify registered users by email for significant changes.

12. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113

We would always appreciate the opportunity to address your concern directly before you contact the ICO โ€” please email us first at [email protected].