Privacy Policy

Last updated: 11 June 2026 •  Data Controller: Babewyn Ltd

This policy explains how Babewyn Ltd (“we”, “us”, “our”) collects, uses, and protects your personal data when you use The Local Network (thelocalnetwork.uk). It applies to all users regardless of location, and meets the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1

Who we are

The data controller is Babewyn Ltd, a company registered in England and Wales. Our ICO registration reference is pending.

You can contact our data team at info@thelocalnetwork.uk, or by using the contact form and selecting “GDPR” as the enquiry type.

2

What data we collect

Account data (if you register)

  • Email address
  • Display name (chosen by you)
  • Password (stored as a bcrypt hash, we never see the plaintext)
  • Profile avatar (if uploaded)
  • Date of registration and last login

Usage data

  • Pub crawl sessions you start and check-in records
  • Route plans you generate
  • Favourited pubs
  • Visit notes you write
  • Preferences (units of measurement, display settings)

Technical data

  • IP address (used for rate limiting and abuse prevention; not linked to your account in logs)
  • Browser user-agent string
  • Pages visited and time spent (no third-party analytics currently deployed)

Contact form submissions

  • Name and email address
  • Message content
  • IP address (for spam prevention)

Data we do NOT collect

  • Payment card details (we do not take payments)
  • Your real-time location (geolocation is browser-side only and never sent to our servers unless you explicitly share it)
  • Sensitive personal data (health, religion, ethnicity, etc.)
3

How we use your data

To provide the service

Account creation, authentication, route planning, session tracking, and displaying your history and favourites.

To improve the service

Aggregate, anonymised usage patterns (e.g. which maps are most popular) inform what we build next. We do not profile individual users for marketing.

To communicate with you

Transactional emails only: email verification, password reset, and replies to contact form submissions. We do not send marketing emails.

For safety and security

Rate limiting, abuse detection, and fraud prevention.

5

Cookies and local storage

We use no third-party tracking cookies. The Local Network uses browser storage for the following strictly-necessary purposes:

  • Authentication tokens, stored in memory during your session. Refresh tokens may be stored in localStorage to keep you logged in across sessions.
  • User preferences, display settings stored locally in your browser.

We do not use Google Analytics, Meta Pixel, or any other third-party analytics or advertising cookies. If this changes we will update this policy and seek your consent before deployment.

6

Sharing and third parties

We do not sell, rent, or share your personal data with third parties for commercial purposes.

Service providers

We use a small number of processors to operate the service:

  • Hosting, self-hosted infrastructure in the UK/EEA. No major cloud hyperscaler currently processes your data in transit.
  • Email delivery, transactional email via an SMTP provider. Only email address and message content are shared for delivery purposes.

Legal disclosure

We may disclose personal data if required to do so by law, court order, or to protect the safety of users or the public. We will notify you of any such disclosure unless prohibited by law.

7

How long we keep data

Data typeRetention period
Account data (active accounts)Until you delete your account
Account data (inactive accounts)3 years from last login, then anonymised
Crawl sessions and route historyUntil you delete them, or account deletion
Visit notesUntil you delete them, or account deletion
Contact form submissions2 years from submission
Server access logs90 days (then purged)
Authentication tokensAccess: 15 minutes; Refresh: 30 days
8

Your rights

Under the UK GDPR you have the following rights. To exercise any of them, use the contact form or email info@thelocalnetwork.uk. We will respond within 30 calendar days.

👁️Right of Access

Request a copy of all personal data we hold about you.

✏️Right to Rectification

Ask us to correct inaccurate or incomplete data.

🗑️Right to Erasure

Ask us to delete your data (the "right to be forgotten").

⏸️Right to Restriction

Ask us to restrict processing while a dispute is resolved.

📦Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

🤖Automated Decisions

We do not make automated decisions with legal effects. Not currently applicable.

↩️Withdraw Consent

Where processing is consent-based, withdraw it at any time.

9

Security

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Passwords are hashed with bcrypt (cost factor ≥ 12), we cannot recover plaintext passwords.
  • Authentication uses short-lived JWTs (15 minutes) with rotating refresh tokens.
  • Database access is restricted to application servers only; no public database endpoints are exposed.
  • Our infrastructure is self-hosted in UK/EEA data centres with full disk encryption.

If you believe you have found a security vulnerability, please report it responsibly to info@thelocalnetwork.uk before public disclosure. We aim to acknowledge reports within 72 hours.

10

Children

The Local Network is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with their personal data, please contact us immediately at info@thelocalnetwork.uk and we will delete it promptly.

The service depicts pubs and alcohol-related content. Users under 18 should not use the service.

11

International transfers

We do not currently transfer personal data outside the UK or EEA. All servers and primary processors operate within the UK or EEA.

If this changes, for example, if we engage a processor based outside the UK/EEA, we will update this policy and ensure adequate safeguards are in place (such as UK Standard Contractual Clauses or an adequacy decision).

12

Changes to this policy

We may update this policy from time to time. When we make material changes we will update the “Last updated” date at the top of the page and, where appropriate, notify registered users by email.

Continued use of the service after a policy update constitutes acceptance of the revised policy. We recommend reviewing this page periodically.

13

Contact & complaints

For any privacy-related query or to exercise your data rights, contact us at:

Babewyn Ltd

Email: info@thelocalnetwork.uk

Or use the contact form , select “GDPR” as the enquiry type.

Right to complain

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Website: ico.org.uk

Helpline: 0303 123 1113

Post: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

We would appreciate the opportunity to address your concerns directly before you contact the ICO, but you are under no obligation to do so.

This policy was last updated on 11 June 2026. ICO registration: pending. © Babewyn Ltd 2026.