The Guinness Map Privacy Policy
This is the plain-English version of what we do with your data. We've tried to write it like a human rather than a lawyer, but everything here is accurate and complete. It covers both the website and The Guinness Map mobile apps.
The short version: we collect what we need to run a pub map, we don't sell it, and you can delete your account and everything in it from inside the app at any time.
Who we are
The Guinness Map is the data controller for the information described here. You can reach us at contact@theguinnessmap.com about anything on this page, including any of the rights listed further down.
What we collect
Your account
Your name, email address, and password (stored only as a hash, never as text we can read). If you sign in with Google or Apple instead, we receive your name and email from them and store the tokens that keep you signed in.
Optionally, if you choose to add them: a username, profile photo, short bio, your city and country, a personal website link, and Instagram or X handles. Your profile is private until you give yourself a username. Once you have one, your profile page and what you post are visible to anyone. Clearing your username in your profile makes it private again.
What you post
Reviews and ratings, photos you upload, pubs you add to the map, bar hops you build, and which pubs and people you follow. Photos have their embedded metadata stripped on upload, so any GPS coordinates your camera recorded are removed before we store the image.
Check-ins
When you check in, we record which pub and when. That builds up a history of places you've been, which is why we treat it carefully and why deleting your account removes it.
Location
In the mobile apps, if you grant location permission, we use your device's GPS to show pubs near you and to centre the map on bar hops. We only ask while you have the app open and we never track you in the background. Your coordinates stay on your device: they are not sent to us, not stored against your account, and not shared with anyone. You can refuse or revoke the permission in your device settings and the rest of the app keeps working.
Approximate location from your connection
Separately from GPS, our hosting provider tells us the rough city and country your connection comes from. We use this for two things: pub owners see which regions their listing is being viewed from, and the live globe on our marketing pages shows activity around the world. The globe data is coarse, rounded to roughly a kilometre, never tied to your account, and automatically deleted after seven days.
Notifications
If you turn on push notifications, we store the push token your device gives us so we can send them, along with your notification preferences. Switching off a notification type stops those sends; the token itself is deleted when you sign out or delete your account.
Analytics and technical data
Each time you sign in we record the IP address and browser or device the session came from, so we can investigate suspicious access. Our own application logs record only the request path, response code and how long it took, with no personal data attached. Our hosting providers keep their own access logs, as any web host does.
We also count how our features get used. On the website we use Fathom Analytics, which stores nothing at all on your device and cannot identify you. Alongside it we use PostHog for more detailed product analytics. In the EEA and UK, PostHog only runs if you agree to it when we ask, and we remember your answer.
PostHog also records session replays, which are playbacks of how a page or screen was used, to help us find bugs. This runs on both the website and the apps. Anything you type into a form is masked before it leaves your device, so we never see your password, email or draft review in a replay. In the EEA and UK this only happens if you agree when we ask.
We separately count views and clicks on pub listings and adverts so we can report accurate numbers to pub owners and advertisers. These counts use a pseudonymous identifier that our server works out from your connection and rotates every 24 hours. Nothing is stored on your device for this, and it cannot be traced back to you.
Payments and business accounts
If you buy an advertising campaign, Stripe handles the payment and we never see your card details. We keep a record of what was bought and when. If you claim a pub as its owner, we keep the contact email, your role there, and any message you send us so we can verify the claim.
Newsletter
If you subscribe, we store your email address and an unsubscribe token. Every newsletter has a one-click unsubscribe link.
Why we're allowed to use it
If you're in the UK or EEA, the law asks us to name a lawful basis for each use. Providing your account, your posts, check-ins and payments is performance of a contract, because it's the service you signed up for. Security logging, counting listing and advert views, fraud prevention and basic product improvement rest on our legitimate interests in running a working, honest service. Detailed analytics, screen replays, the newsletter and push notifications rely on your consent, and you can withdraw it at any time without losing access to anything else.
How we use it
- To run the map, your account, and the features you use.
- To reply to you and send service messages such as password resets or verification.
- To show pub owners and advertisers accurate view and click counts for their own listings.
- To promote The Guinness Map. We may feature your reviews and photos on social media. Your full name is not attached to your reviews when we do this.
- To keep the service safe, investigate abuse, and enforce our Terms of Service.
Who we share it with
We do not sell your personal information, and we never share it with third parties for their own marketing. We do use service providers who process data on our behalf under contract:
- Neon and Upstash for our database and caching
- Vercel, Render and Cloudflare for hosting, image storage and network security
- Fathom Analytics and PostHog for analytics
- Grafana for our application logs, which carry no personal data
- Resend for sending email
- Stripe for payments
- Google and Apple for sign-in, and Google for pub search data
- Mapbox for the map itself
- Expo for push notifications and app updates
- Shopify if you buy merchandise
If you post publicly, your reviews, photos, profile and check-ins are visible to others by design. We may also share information where the law requires it, or to protect our rights or someone's safety.
Where your data goes
We're hosted in the United States, so if you're in the UK or EEA your data is transferred there. Our providers are covered by Standard Contractual Clauses or the EU-US and UK-US Data Privacy Framework. Ask us if you'd like the detail for a specific one.
How long we keep it
Your account and what you post stay until you delete them. Deleting your account removes your profile, reviews, photos, check-ins and follows. Sign-in sessions expire on their own. Marketing-globe location pings are deleted after seven days. Listing and advert view counts are kept in aggregate for owner reporting, and the pseudonymous identifier attached to them rotates every 24 hours. We keep payment records for as long as tax and accounting law requires.
Your choices and rights
Delete your account. There's a Delete Account button in your profile on both the website and the apps. It removes your data, not just your login.
Remove individual content. You can edit a review at any time, and delete photos from it yourself. To delete a review outright, email us and we'll remove it. Deleting your account removes all of it. We also reserve the right to remove content that breaks our Terms.
Analytics. There's an Analytics switch in your profile on both the website and the apps. Turn it off at any time and detailed analytics and screen replays stop; turn it back on whenever you like. Fathom needs no such choice because it stores nothing on your device.
Notifications and email. Push notifications are controlled in your settings and your device. Every newsletter has an unsubscribe link.
If you're in the UK or EEA you also have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable format, and withdraw any consent you gave. Email us and we'll action it within one month. If you're unhappy with how we handle it you can complain to the Information Commissioner's Office in the UK, or your national data protection authority in the EEA. We'd rather you told us first so we can fix it.
Some US states give residents similar rights. We'll honour those requests on the same basis. We do not sell or share personal information as those laws define it.
Children
This is a service about alcohol. It's not for anyone under the legal drinking age where they live, and never for under-18s. We don't knowingly collect anything from children. If you believe a child has given us information, email us and we'll delete it.
Security
We take reasonable measures to protect your information. Passwords are hashed, traffic is encrypted, and access to production data is limited. No service can promise perfect security, and we won't pretend otherwise.
Changes to this policy
We may update this page. If a change materially affects how we use your data, we'll tell you in the app or by email rather than quietly editing this page.
Contact us
Questions, requests, or complaints: contact@theguinnessmap.com.
Effective Date: August 14, 2026