Who we are
The data controller is Babewyn Ltd, a company registered in England and Wales. Our ICO registration reference is pending.
You can contact our data team at info@thelocalnetwork.uk, or by using the contact form and selecting “GDPR” as the enquiry type.
What data we collect
Account data (if you register)
- Email address
- Display name (chosen by you)
- Password (stored as a bcrypt hash, we never see the plaintext)
- Profile avatar (if uploaded)
- Date of registration and last login
Usage data
- Pub crawl sessions you start and check-in records
- Route plans you generate
- Favourited pubs
- Visit notes you write
- Preferences (units of measurement, display settings)
Technical data
- IP address (used for rate limiting and abuse prevention; not linked to your account in logs)
- Browser user-agent string
- Pages visited and time spent (no third-party analytics currently deployed)
Contact form submissions
- Name and email address
- Message content
- IP address (for spam prevention)
Data we do NOT collect
- Payment card details (we do not take payments)
- Your real-time location (geolocation is browser-side only and never sent to our servers unless you explicitly share it)
- Sensitive personal data (health, religion, ethnicity, etc.)
How we use your data
To provide the service
Account creation, authentication, route planning, session tracking, and displaying your history and favourites.
To improve the service
Aggregate, anonymised usage patterns (e.g. which maps are most popular) inform what we build next. We do not profile individual users for marketing.
To communicate with you
Transactional emails only: email verification, password reset, and replies to contact form submissions. We do not send marketing emails.
For safety and security
Rate limiting, abuse detection, and fraud prevention.
Legal basis for processing
| Activity | Legal basis (UK GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of contract (Art. 6(1)(b)) |
| Sending verification and reset emails | Performance of contract (Art. 6(1)(b)) |
| Storing crawl sessions and favourites | Performance of contract (Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Improving the service via aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Responding to contact form enquiries | Legitimate interests (Art. 6(1)(f)) |
| Processing GDPR data rights requests | Legal obligation (Art. 6(1)(c)) |
How long we keep data
| Data type | Retention period |
|---|---|
| Account data (active accounts) | Until you delete your account |
| Account data (inactive accounts) | 3 years from last login, then anonymised |
| Crawl sessions and route history | Until you delete them, or account deletion |
| Visit notes | Until you delete them, or account deletion |
| Contact form submissions | 2 years from submission |
| Server access logs | 90 days (then purged) |
| Authentication tokens | Access: 15 minutes; Refresh: 30 days |
Your rights
Under the UK GDPR you have the following rights. To exercise any of them, use the contact form or email info@thelocalnetwork.uk. We will respond within 30 calendar days.
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Ask us to delete your data (the "right to be forgotten").
Ask us to restrict processing while a dispute is resolved.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
We do not make automated decisions with legal effects. Not currently applicable.
Where processing is consent-based, withdraw it at any time.
Security
- All data in transit is encrypted using TLS 1.2 or higher.
- Passwords are hashed with bcrypt (cost factor ≥ 12), we cannot recover plaintext passwords.
- Authentication uses short-lived JWTs (15 minutes) with rotating refresh tokens.
- Database access is restricted to application servers only; no public database endpoints are exposed.
- Our infrastructure is self-hosted in UK/EEA data centres with full disk encryption.
If you believe you have found a security vulnerability, please report it responsibly to info@thelocalnetwork.uk before public disclosure. We aim to acknowledge reports within 72 hours.
Children
The Local Network is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with their personal data, please contact us immediately at info@thelocalnetwork.uk and we will delete it promptly.
The service depicts pubs and alcohol-related content. Users under 18 should not use the service.
International transfers
We do not currently transfer personal data outside the UK or EEA. All servers and primary processors operate within the UK or EEA.
If this changes, for example, if we engage a processor based outside the UK/EEA, we will update this policy and ensure adequate safeguards are in place (such as UK Standard Contractual Clauses or an adequacy decision).
Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date at the top of the page and, where appropriate, notify registered users by email.
Continued use of the service after a policy update constitutes acceptance of the revised policy. We recommend reviewing this page periodically.
Contact & complaints
For any privacy-related query or to exercise your data rights, contact us at:
Babewyn Ltd
Email: info@thelocalnetwork.uk
Or use the contact form , select “GDPR” as the enquiry type.
Right to complain
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
Post: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We would appreciate the opportunity to address your concerns directly before you contact the ICO, but you are under no obligation to do so.