Privacy Policy
Last Updated: August 22, 2026
1. Introduction
Welcome to the PubCrawl App ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.
By using the PubCrawl App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Username and display name
- Profile photo (if you upload one)
- Hashed password (for email sign-up) or authentication tokens (for Google/Apple Sign-In)
2.2 Location Information
We collect your device's location data to provide core app functionality. This data is used to:
- Generate pub crawl routes based on your location
- Show nearby pubs and venues on the explore map
- Calculate walking distances between venues
- Confirm you are at a venue when you check in, so that check-in can count towards that venue’s public visitor count
- Show you which venues near you are busy right now
Location data is collected only when you are actively using the app and have granted location permissions. We do not track your location in the background, and we do not record a continuous location history. A location reading is taken only at the moment you check in or open a screen that needs one.
You can use the app without granting location access. Check-ins will still be recorded for you, but they cannot be confirmed as being at the venue and so will not count towards that venue’s public figures.
2.3 Check-ins and “out now”
When you check in at a venue we record which venue, the time, and whether the check-in was confirmed. If you have granted location access your device sends the coordinates it read at that moment; we compare them against the venue’s position to decide whether to confirm the check-in, and then we discard them. We do not keep a record of where you were — only of which pub you said you were in.
For a short period after a check-in (currently three hours, and never past 6am your local time) you are shown as out now at that venue. Who can see this is limited:
- Only people you have both added as friends can see that you are out, and where. A friendship requires both people to have accepted — following someone does not give them this.
- Nobody else can see where you are. People who are not your friends cannot see that you are out, which venue you are at, or the map of venues you have visited.
- Other people may see how many people are at a venue, with no names attached. We do not show this figure at all unless enough people are present that it cannot identify an individual.
You can stop being shown as out at any time using Heading home on your profile, which takes effect immediately. Presence also expires on its own; it is never indefinite.
The map of where you have checked in — the individual venues and their locations — is visible only to you and, where you have chosen to share your profile, to your friends.
Your profile also shows totals, separately from that map: how many pubs you have visited, how many towns or cities, and which city you have visited most, with a count. These totals contain no venue names and no locations, and they are visible to anyone signed in to the app. If you would rather they were not, turning on Private profile in Privacy settings hides them along with your posts, pubs and reviews.
2.4 User-Generated Content
We store content you create within the app, including:
- Pub crawl routes you create or save
- Posts — see below
- Photos taken during crawls, and photos you add to a pub’s page
- Reactions and comments you leave on your friends’ posts
- Game scores and progress
- Venue reviews and ratings
What a post is. When you check in somewhere you can share it as a post: the pub, the time, and optionally a photo and a caption. A post goes to your accepted friends and nobody else — not the public, not people who have only asked to be your friend. Your friends can react to it and leave comments, and those comments are visible to the same people the post is.
A post is a separate thing from a photo on a pub’s page, and the difference matters because the audiences are different. Putting a photo on a pub’s page is a second, explicit choice you make on the post itself — and that copy is public. See section 6.
2.5 Purchase Information
Premium subscriptions are processed through the Apple App Store or Google Play Store via RevenueCat. We receive confirmation of your subscription status but do not collect or store your payment card details.
2.6 Device and Usage Information
We may collect:
- Device type, operating system, and app version
- Push notification tokens (if you enable notifications)
- Basic activity on your account — when you last used the app, crawls started and completed — which we use to understand whether the app is working for people
2.7 Business Account Information
If you register on our business platform (business.thepubcrawlapp.com), we additionally collect:
- First name and last name
- Business email address (used for account verification and venue claiming)
- Business name, address, and description
- Business logo
- Team member email addresses (when you invite others to your business)
- Venue claim documentation (uploaded files to verify venue ownership)
- Payment information via Stripe (we store a Stripe customer ID; card details are held by Stripe)
Business accounts are entirely separate from app user accounts and use a dedicated authentication system.
3. How We Use Your Information
We use the information we collect to:
- Provide core app functionality: route generation, venue discovery, group crawls, and game features
- Manage your account and authenticate your identity
- Store and display your routes, photos, and game history
- Send push notifications about your active crawl (if enabled)
- Verify and manage your Premium subscription status
- Improve and optimise the app based on usage patterns
- Respond to support requests
4. Data Storage and Security
Your data is stored securely in the United Kingdom. We use industry-standard security measures including:
- Encrypted data transmission (HTTPS)
- Securely hashed passwords
- Encryption at rest
Some preferences (such as active game state) are also stored locally on your device using secure storage.
5. Third-Party Services
Our app uses the following third-party services, each with their own privacy policies:
5.1 Google Maps Platform
We use Google Maps APIs and Google Places to provide venue information, maps, and walking routes. When you use these features, data may be processed by Google subject to Google's Privacy Policy.
5.2 RevenueCat
We use RevenueCat to manage Premium subscriptions across iOS and Android. RevenueCat processes your subscription status but does not receive your payment details. See RevenueCat's Privacy Policy.
5.3 Apple and Google Sign-In
If you sign in with Apple or Google, we receive your name and email address (or a relay email in Apple's case) from the identity provider. We do not receive your password.
5.4 Stripe
We use Stripe to process payments on our business platform. Stripe collects and processes payment card details directly — we do not store your card information. See Stripe's Privacy Policy.
5.5 Google Analytics
Our website uses Google Analytics to understand visitor behaviour. Analytics cookies are only loaded after you consent via our cookie banner. This does not apply to the mobile app.
5.6 Google Cloud Vision
Photos uploaded to a venue are automatically checked by Google Cloud Vision before they are published, to detect adult, violent or otherwise unsuitable content. The image is sent to Google for analysis and is not retained by Google or used to train their models. We keep only the result of the check, not the analysis itself.
5.7 Google Cloud Natural Language
Comments you write on posts are automatically checked by Google Cloud Natural Language before other people can see them, to detect abusive, threatening or otherwise unsuitable text. The text of the comment is sent to Google for analysis and is not retained by Google or used to train their models. We keep only the result of the check, not the analysis itself. Captions and other short text are not sent.
5.8 Sentry (error tracking)
We use Sentry to record errors on our servers so we can find and fix bugs. Sentry is configured not to attach personal data to error reports — it receives the technical details of a failure, not your account information. The mobile app itself does not currently send crash reports.
5.9 Microsoft Azure Communication Services
We send email — address verification, password resets, notifications and, where you have not opted out, occasional updates — through Microsoft Azure Communication Services. Microsoft processes your email address and the contents of that message in order to deliver it.
5.10 Google Cloud (hosting and storage)
Our application, database and uploaded photos are hosted on Google Cloud in the United Kingdom (London region).
5.11 Google Vertex AI
We use Google Vertex AI to help build and tidy our venue listings — reading pub websites for opening hours, descriptions and menus. This processes information about venues, which are businesses, rather than information about you. It is not used to analyse your account, your reviews or your photos.
6. Photos and Public Content
Content you create has one of three audiences, and it is always your choice which:
- A post — your accepted friends, and nobody else.
- A photo taken during a crawl — the other people on that crawl, and nobody else.
- A photo you put on a pub’s page — public, including people who are not signed in, on pages that appear in search engines.
Nothing moves from the first two into the third, ever. A post cannot be added to a pub’s page at all. Photos reach a pub’s page only when you add them from that pub’s own page, where publishing is the entire purpose of the action — and anything you have put there, you can take down again, which deletes the public copies.
Photos taken during a crawl are visible to other participants in that crawl, and to nobody else. The crawl host may enable "Hide Photos" mode, which keeps photos hidden until the crawl ends.
If you separately add a photo to a venue’s page from that venue’s own page, that copy is publicly visible — including to people who are not signed in, and on venue pages that appear in search engines. Photos taken on a crawl do not move there on their own.
6.1 Automatic screening
Comments are checked before anyone else can see them. While that check is running the comment is visible to you alone, marked as still being checked. Comments that clearly breach our rules are removed; anything uncertain is held for a person to review.
Photos are treated differently depending on where they are going. A photo you put on a pub’s page is public, so it is checked before it is published and is not visible to anyone until that check completes. This usually takes a few seconds. Photos that clearly breach our rules are rejected; anything uncertain is held for a person to review. No one at PubCrawl looks at your photo unless it is held for review or somebody reports it.
6.2 Location data in photos
Photos from a phone often contain hidden metadata, including the exact GPS coordinates and the device that took them. Before a photo is published we create resized copies with that metadata removed, and it is those copies — never your original file — that are shown publicly.
Routes you mark as "public" are discoverable by other users. Your username and profile photo may be visible on public routes. Private routes are only visible to you.
7. Data Sharing and Disclosure
We do not sell your personal information in a way that identifies you as an individual. We may share data in the following circumstances:
- With other crawl participants: your username, profile photo, scores, and crawl photos are visible to others in your group
- Public routes: your username is shown as the creator of routes you make public
- With friends: people you have both added as friends can see when you are out and which venue you are at, and the venues you have checked in to. See Section 2.3
- Venue visitor counts: the number of people currently at a venue may be shown to other users without any names attached, and only where the number is large enough not to identify anyone
- With venue owners: if a venue owner claims their venue through our business platform, they may see reviews, ratings, photos, and aggregated check-in data associated with that venue, including your username on reviews you post
- Service providers: third-party services listed in Section 5, strictly for providing app functionality
- Data products: we may create and distribute aggregated, anonymised, or de-identified datasets derived from user activity (such as venue popularity, route trends, and photo datasets) for commercial purposes, including via APIs to third parties. These products will not identify you personally
- Legal requirements: when required by law, court order, or to protect our rights and safety
8. Your Rights and Choices
8.1 Account and Data
- Access and portability: You can request a copy of your personal data by contacting us at [email protected]. We will provide your data in a commonly used, machine-readable format
- Rectification: You can update your profile, username, and display name in the app settings
- Erasure: You can delete your account via Settings > Delete Account. This removes your personal data, photos, routes, and reviews. Anonymised records (e.g. "Deleted User" in multiplayer game history) may be retained
- Restriction and objection: You can contact us to request restriction of processing or to object to specific data uses
- Withdraw consent: Where processing is based on consent, you may withdraw at any time by adjusting your privacy settings or contacting us
8.2 Location Permissions
You can enable or disable location services through your device settings. Disabling location will limit route generation and venue discovery features.
8.3 Push Notifications
You can manage push notification permissions through your device settings at any time.
8.4 Blocking
You can block another account from their profile or from any of their posts. Blocking removes any existing connection between you, stops them finding you in search, seeing your posts or your profile, and stops them adding you again. They are not told that you have blocked them. We keep a record of the block for as long as it is in place, so that we can enforce it; you can undo it at any time from Settings → Blocked accounts.
8.5 Premium Subscriptions
Subscriptions are managed through your Apple App Store or Google Play account settings.
9. Data Retention
We retain your data only as long as necessary for its purpose:
- Account data: retained while your account is active. Deleted within 30 days of account deletion
- Game history and photos: retained while your account is active; removed on account deletion
- Temporary data: verification codes, session tokens, and similar short-lived data are automatically purged after expiry
- Anonymised data: aggregated, non-identifiable data may be retained indefinitely for analytics
10. Children's Privacy
The PubCrawl App is intended for users of legal drinking age (18+ in the UK, or the applicable age in your jurisdiction). We do not knowingly collect personal information from anyone under the legal drinking age. If we become aware that we have collected data from an underage user, we will delete it promptly.
11. International Data Transfers
Your data is primarily stored and processed in the United Kingdom. Some third-party services may process data outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place.
12. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract: processing necessary to provide the PubCrawl service (account management, route generation, game features)
- Consent: where you have given explicit consent, such as agreeing to our terms at registration, enabling location services, or accepting analytics cookies
- Legitimate interest: improving our service, preventing fraud, and ensuring security
- Legal obligation: where required by law
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date and, where appropriate, through in-app notifications. Continued use of the App after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at: