Legal & Community

Privacy Policy

How BeerHero collects, uses, shares, retains and protects personal data—and the choices available to you.

Effective: August 9, 2026 · Version 1.0

1. Scope and data controller

This Privacy Policy explains how BeerHero (the “Service,” “we,” “us”) processes personal data when you use the BeerHero mobile application, website, APIs, support channels, and community features.

Controller identification: BeerHero is the data controller/operator identified as the seller or provider on the applicable App Store product page. Before commercial release, the operator’s full legal name and registered notice address must also be inserted here. Privacy requests can already be sent to support@beerhero.app.

BeerHero is not an alcohol seller, delivery service, venue, or emergency service. The Service is intended only for adults who are at least 18 and meet the legal drinking age where they live.

2. Personal data we process

CategoryExamplesHow collected
Account and identityFirebase user ID, email address, display name, username, sign-in provider, provider profile photo, BeerHero avatar and moderator status.From you and, when chosen, Apple or Google sign-in.
Community contentBeer prices, brands and serving types, venue notes, comments, votes, reports, venue or beer suggestions, menu evidence, photos, badges and contribution history.From content and actions you submit.
Location and check-insDevice coordinates while nearby discovery or check-in is requested; map bounds; derived distance to a venue; location accuracy; venue and date of check-in. Raw check-in coordinates are used to verify proximity and are not stored in the check-in record.From your device only after the relevant operating-system permission.
Preferences and relationshipsFavorites, public/private check-in preference, notification preference, localization and onboarding state.From your settings and app activity.
Support and safetySupport ticket subject, message history, account contact details, reports, moderation decisions, appeals and account-deletion records.From you, moderators and system records.
Technical and securityAuthentication tokens, request time, API logs, IP address and device/app information normally transmitted with network requests. We do not use this information for cross-app advertising.Automatically when the Service communicates with our infrastructure.

Camera and photo-library access is used only when you choose to attach a menu, venue or evidence image. Notification access is used only if you enable venue updates. We currently do not collect payment-card data or sell personal data.

3. Purposes and legal bases

We process data only for defined purposes:

  • Provide the Service and perform our agreement: authenticate accounts, show nearby venues, save contributions and favorites, verify check-ins, calculate scores and badges, provide support and synchronize settings.
  • Legitimate interests: prevent fraud, protect community integrity, rank trusted information, secure APIs, diagnose failures, enforce rules and improve reliability—balanced against user rights.
  • Consent or device choice: precise location, camera, photo-library access and notifications are controlled through contextual prompts and device settings. Where applicable law requires consent, you may withdraw it at any time without affecting prior lawful processing.
  • Legal obligations and claims: respond to lawful requests, preserve narrowly required records and establish, exercise or defend legal rights.

For Türkiye, processing relies on the applicable conditions under Law No. 6698, including necessity for contract performance, legitimate interests that do not harm fundamental rights, legal obligations, establishment or protection of rights, information made public by the data subject where applicable, and explicit consent when required. These bases are distinct from this notice.

4. Information visible to others

Your username/avatar, published prices and notes, contribution score, badges and public leaderboard position may be visible to other users. A check-in is visible at a venue and on your public profile only when you choose “Public check-ins.” Your email, precise device location, support tickets and moderation history are not public.

Do not include another person’s personal data in a comment, photo, menu submission or report. Public content may be viewed, captured or reshared by others outside our control.

5. Service providers and international transfers

We disclose only what is necessary to operate a feature:

  • Google Firebase: authentication and Remote Config; Apple and Google: optional account sign-in.
  • Supabase: application database and submitted media storage.
  • Vercel: API and website hosting, delivery and operational logs.
  • Google Maps Platform / Places: maps, place details, venue photos, search and nearby discovery. Google may receive map interactions or location-related requests under its own privacy terms.
  • Google Gemini: analyzes a menu image only when you explicitly submit it for menu analysis; extracted results are returned to BeerHero.
  • Authorities or professional advisers: only when legally required or reasonably necessary for safety, fraud, legal claims or corporate transactions, subject to appropriate safeguards.

Providers may process data in countries other than yours, including the United States and European Economic Area. Where required, transfers rely on applicable adequacy decisions, standard contractual protections, explicit consent, or another lawful transfer mechanism. Providers must protect personal data consistently with their contracts and applicable law.

We do not rent or sell personal data and do not share it for third-party behavioral advertising.

6. Retention and deletion

  • Account information and active community data are retained while your account is active and as needed to provide the Service.
  • Raw device coordinates used for proximity verification are processed transiently; a successful check-in stores the venue, date, derived distance and accuracy, not the submitted latitude/longitude.
  • Submitted menu and evidence images are retained while needed for verification, moderation and the related contribution. Account deletion removes their account association and access references; storage objects and backups expire through restricted operational deletion and rotation schedules.
  • Open support and moderation records are retained while necessary to resolve the matter, prevent abuse and meet legal obligations.
  • Operational logs are retained for a limited security and troubleshooting period, normally no longer than 90 days unless an incident or legal duty requires longer.

You can delete your account in Profile → Delete my account. BeerHero deletes the authentication identity, email, provider identifiers, avatar, check-ins, favorites, votes, reports, support records and other private account data. Published prices, comments and happy-hour contributions may remain to preserve the integrity and usefulness of community information, attributed only to the username used when contributing; the deleted profile cannot be opened and is excluded from leaderboards. Contact Support to request removal of a specific retained contribution. Media objects and backups expire through the operational schedules described above. Narrow records may also be retained when required for security, fraud prevention, disputes or law, and are restricted from ordinary use.

7. Your choices and legal rights

Use Privacy Choices for practical instructions. You can:

  • change public check-ins and favorite-venue notifications in Profile;
  • revoke location, camera, photo-library or notification permission in device Settings;
  • edit your username/avatar, remove check-ins, unfavorite venues, report content and delete your account in-app;
  • request access, correction, deletion, restriction, objection, portability or withdrawal of consent where applicable;
  • ask how data was processed, recipients to whom it was disclosed, correction/deletion notifications, and compensation where rights under KVKK Article 11 or other applicable law provide them;
  • complain to the competent data-protection authority, including Türkiye’s Personal Data Protection Authority or your EEA/UK supervisory authority.

Send a request from the in-app Contact form or support@beerhero.app. We may verify your identity before acting. Authorized-agent requests require proof of authority. We will respond within the period required by applicable law.

8. Security, age and sensitive information

We use access controls, authenticated APIs, transport encryption, least-privilege service credentials, moderation tools and monitoring appropriate to the nature of the Service. No system is completely secure; contact us promptly if you suspect misuse.

BeerHero is not directed to children. Users must be at least 18 and of legal drinking age. We do not knowingly collect data from children; credible reports will be investigated and removed as appropriate. Do not submit government IDs, financial data, health information or other sensitive personal data in community fields.

9. Policy changes and contact

We may update this Policy when features, providers or laws change. Material changes will be presented through the Service or another reasonable notice before they take effect where required. The effective date above identifies the current version.

Privacy and data-rights contact: support@beerhero.app
In-app: Profile → Contact BeerHero
Controller notice address: to be completed with the operator’s registered legal address before commercial release.