Privacy Policy
This explains what Recko collects, why we collect it, and what you can do about it. We've kept it in plain English — if anything here isn't clear, ask us and we'll fix the wording.
Who we are
Recko is a London food and drink recommendation service. We’re the “data controller” for the information described here, which means we decide what’s collected and why. You can reach us at hi@myrecko.com, and we read everything that arrives there.
Add the operating company’s name and registered address once one exists — UK GDPR Art. 13(1)(a) expects the controller to be identifiable, and “Recko” alone doesn’t meet that. Also confirm ICO registration and the annual data protection fee, which usually apply to a service like this.
What we collect
When you create an account:
- Your email address, so you can sign in and we can send you the things you’ve asked for.
- A username, which is public — it appears on your reviews and lists.
- Whether your email is verified, whether you’ve finished onboarding, and whether your profile is private.
What you create:
- Reviews — your rating and any text you write. Reviews are public and shown with your username.
- Lists of places, which you can keep private or make public.
- Who you follow, and what you’ve liked or saved.
- Reports, blocks and mutes, if you use those.
What we work out about you:
- A taste profile— inferred from your reviews and what you interact with. This is how Recko scores places for you rather than showing everyone the same ranking. It’s a form of profiling under data protection law, so it’s worth being clear: it affects the order things appear in and the match percentages you see. Nothing else. It has no legal effect on you, and there’s no automated decision-making in the sense the law restricts.
- Searches you run and places you open, used to improve results and to spot what’s working.
Location — only if you ask:
- If you use “Near me”, your browser asks your permission and gives us approximate coordinates. We use them to centre that search. They’re stored in your browser only, for up to 30 minutes, and are never sent to our servers or stored in our database. Clearing the location chip deletes them immediately.
Automatically:
- Standard server logs from our hosting provider, including IP address, for security and reliability.
- Anonymous usage analytics — only if you accept analytics cookies. See the Cookie Policy.
Why we’re allowed to use it
Data protection law requires a lawful basis for each use. Ours are:
- Contract — running your account and showing you the service you signed up for.
- Legitimate interests — keeping Recko secure, preventing abuse, and improving how recommendations work. We’ve considered your interests here and limited what we collect accordingly.
- Consent — analytics cookies, optional emails, and location. You can withdraw any of these at any time, as easily as you gave them.
- Legal obligation — where we have to keep or disclose something by law.
Who we share it with
We don’t sell your data. We don’t share it for advertising. We use these processors to run the service:
- Supabase — our database and sign-in.
- Vercel — hosting.
- Anthropic (Claude) — interprets your search wording and helps write summaries. Your search text is sent for this. It isn’t used to train their models.
- Google Maps Platform — place data, maps and photos. Google sets its own terms for map use.
- PostHog — product analytics, on their EU servers, and only with your consent.
- Resend — sending account and digest emails.
Some of these operate outside the UK. Where that happens, transfers rely on the UK International Data Transfer Agreement or an adequacy decision. Confirm the mechanism for each processor and keep a record — this is the part of a transfer assessment that regulators actually ask to see.
What’s public
Worth being blunt about: your username, reviews, public lists, and who you followare visible to other people and to search engines. Your email address is never shown. If you set your profile to private, your activity is limited to people you approve — but reviews already published stay attached to the places they’re about.
How long we keep it
- Account data — while your account exists, and [X days] after you delete it, to handle accidental deletion and abuse investigations.
- Reviews and lists — until you delete them or close your account.
- Analytics — [X months].
- Server logs — [X days].
- Location — 30 minutes, in your browser only.
Set real numbers here before launch. “As long as necessary” isn’t a retention period and regulators treat it as a gap.
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of your data, or send it somewhere else in a portable format.
- Correct anything that’s wrong.
- Delete your account and data.
- Restrict or object to how we use it, including the taste profiling.
- Withdraw consent — for analytics, emails or location — at any time.
Email hi@myrecko.comand we’ll respond within one month. If you’re unhappy with how we’ve handled it, you can complain to the Information Commissioner’s Office, though we’d rather you gave us the chance to put it right first.
Before launch: add a self-serve account deletion route. Requiring an email for erasure is permitted but a button is what people expect, and it reduces the requests you handle by hand.
Children
Recko is for people aged 18 or over — it’s about pubs, bars and restaurants. We don’t knowingly collect data from children. If you believe a child has an account, tell us and we’ll remove it.
Security
Access to the database is restricted by row-level security so people can only reach their own data and what’s deliberately public. Traffic is encrypted in transit. No system is perfect; if there’s a breach that puts you at risk, we’ll tell you and the ICO within the required 72 hours.
Changes
If we change this materially we’ll say so in the app rather than quietly updating the date at the top.