Bitehood

Legal

Privacy Policy

This policy explains what personal data Bitehood processes, why, and what rights you have under the GDPR.

7 September 2026

⚠ Before launch

This policy describes what the application actually does today (verified against the code). Fill in the highlighted operator details, and have it reviewed by a lawyer before accepting real customers β€” this is a technical draft, not legal advice.

You also need a data processing agreement (DPA) with each processor listed below (Supabase, Vercel, Resend). All three offer one.

1. Controller

[Legal name / company], [address], email [datenschutz@bitehood.net]. Full details are in our Imprint.

2. What we collect and why

Account data β€” email address, password (stored only as a salted hash by our authentication provider) and display name. Purpose: creating and securing your account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Listings you publish β€” title, description, ingredients, allergens, price, availability, photos and the approximate location you set. This content is public. Purpose: operating the marketplace. Legal basis: Art. 6(1)(b) GDPR.

Location β€” either coordinates you provide via your browser's location permission, or a place you type in. Purpose: sorting listings by distance and placing them on the map. Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b). Your browser only shares precise location after you explicitly allow it.

Messages and reservations β€” the content of messages you send, and reservation details (quantity, pickup/delivery, price). Visible to you and the other party. Purpose: arranging a purchase. Legal basis: Art. 6(1)(b) GDPR.

Favourites β€” which listings you saved. Legal basis: Art. 6(1)(b) GDPR.

3. Storage on your device

Bitehood does not use tracking, advertising or analytics cookies. We store the following in your browser's local storage, all strictly necessary for the site to function (Β§ 25(2) TTDSG):

  • your login session, so you stay signed in;
  • your chosen location, so you don't have to re-enter it;
  • your language preference;
  • a flag recording that you dismissed the cookie notice.

You can clear these at any time in your browser settings; doing so signs you out.

4. Processors and third parties

Supabase β€” database, authentication and file storage. Region: [your Supabase project region]. Stores all account, listing, message and reservation data.

Vercel β€” hosting. Processes server logs including IP addresses for security and operations.

Resend β€” sends transactional email (account confirmation). Receives your email address.

OpenStreetMap Foundation β€” map tiles and, when you type a place name, geocoding via Nominatim. Your IP address and the search term reach OpenStreetMap servers when the map or location lookup is used.

Unsplash β€” supplies some placeholder imagery; your IP address reaches Unsplash when those images load.

Fonts are self-hosted and served from our own domain β€” no request is made to Google Fonts.

5. Transfers outside the EU/EEA

Some processors above may process data outside the EU/EEA. Where that happens, transfers are covered by the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework. Confirm the region and safeguards for your own Supabase and Vercel projects and state them here: [regions and safeguards].

6. Retention

Account, listing, message and reservation data is kept while your account exists. If you delete your account, associated data is deleted, except where we must retain records to comply with statutory commercial or tax retention periods.

7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on consent, you may withdraw it at any time with future effect.

To exercise any of these, contact [datenschutz@bitehood.net]. You also have the right to lodge a complaint with a supervisory authority β€” in Germany, the authority of your federal state.

8. Security

Traffic is encrypted in transit (HTTPS). Access to data is enforced at database level through row-level security rules, so users can only read and write their own records and publicly visible listings. Passwords are never stored in plain text.

This policy is provided in several languages for convenience. In case of discrepancies, the German version prevails.