Privacy Policy: Fish & Chips
Last updated: 7 September 2026
1. Who we are
Fish & Chips is an independent app for finding and keeping a record of the fish & chip shops you visit across the UK. It is run from the United Kingdom by the Fish & Chips team (“we”, “us”). We are the data controller for the information described here.
Contact: hello@fishchips.org.uk, or the Feedback option on the app’s Home screen.
2. The short version
We collect what the app needs to work and nothing else. We do not sell or rent your data. We do not show ads. There are no third-party advertising or analytics kits in the app — no Facebook SDK, no Google Analytics, no advertising identifiers.
3. What we collect
Account information
- Your email address, username, and display name.
- Optional: a profile photo and a short bio.
- How you signed in: email and password, Sign in with Apple, or Sign in with Google. If you use Apple or Google, we receive your email address (or Apple’s private relay address) and nothing more.
Check-ins
- The shop, the date and time, and your device’s location at the moment you check in — we store those coordinates so a check-in can be verified.
- Optional photos you attach.
- Optional notes you write.
- An optional 1-5 star rating. Ratings are private: they are never shown next to your name, never shown to other users, and never displayed on a shop. We use them only in aggregate, to understand how the directory is performing.
Location
- With your permission, the app uses your device’s location to sort shops by distance, centre the map, and check that you are within 200 metres of a shop when you check in. The app never tracks your location in the background.
- You can turn location off in your device settings at any time. Most of the app still works without it; checking in does not.
- Optionally, you can save a home postcode so we can tell you about shops near you. We store the postcode and its approximate coordinates. UK postcodes are looked up through postcodes.io; free-text place searches use Google’s Geocoding API.
Photos
- Check-in photos and your profile picture are stored in our photo storage and shown to you in your own visit history.
- Shop photos you submit are reviewed by us before they are published, and once published they appear publicly on that shop’s page.
- Photo files are held at public web addresses, which means anyone who has the exact link to a file can open it. Please do not upload anything you would not want a stranger to see.
Your activity in the app
- Points, badges, challenges and leaderboard position.
- Lists you create, shops you like or follow, groups you join, and meet-ups you create or say you are attending.
- Your display preferences: theme, default filters and regions.
Notifications
- If you allow notifications, we store a push token for your device so we can send you news, group activity and shop alerts. Turning notifications off in your device settings stops them.
Usage information
- One row per day that you open the app, recording the date, how many times, the platform (iOS or Android) and the app version. This is linked to your account and is how we measure whether the app is being used.
- Screen views are counted anonymously in aggregate — a daily count per screen, with no user ID and no session attached.
Messages you send us
- Feedback, check-in problem reports and shop corrections, along with the account that sent them so we can reply.
Referrals
- On Android only, once at install, the app reads the Google Play install referrer so that a referral from a friend can be credited. It is read one time and not repeated.
Tips
- Tips are handled entirely by the App Store or Google Play. We never see your card details, your address, or any payment information — only that a tip was made.
4. What we do not collect
No advertising identifiers. No contact list. No background or continuous location. No health, biometric or financial data. If you use Face ID or a fingerprint to unlock the app, that check happens on your device and the result never reaches us.
5. Why we are allowed to use it (UK GDPR)
- To provide the app you asked for — your account, check-ins, points and lists: performance of our contract with you.
- To keep the app working, safe and honest — fixing bugs, preventing fake check-ins, moderating submitted content, and understanding overall usage: our legitimate interests.
- Location, camera, photo library, calendar and notifications: your consent, given through your device’s permission prompts and withdrawable at any time in your device settings.
- Where the law requires us to keep or disclose something: legal obligation.
6. Who else handles your data
We use a small number of service providers, and only to run the app:
- Supabase — database, sign-in, file storage and server functions. Our data is hosted in Supabase’s Ireland (eu-west-1) region.
- Expo — delivers push notifications and app updates.
- Apple and Google — app distribution, sign-in and in-app purchases, under their own privacy policies.
- Google Maps and postcodes.io — maps, directions and place search.
We do not share your data with advertisers, data brokers, or anyone else. We may disclose information if the law requires it.
7. What other people can see
- Public by default: your display name, profile photo, bio, points, badges, and your position on the leaderboards.
- Turning on a private profile in Settings keeps you off the public leaderboards.
- Shop photos you submit are public once approved. Your check-in notes, ratings and check-in photos are not shown to other users.
- Inside a group, other members can see that you are a member, your display name, and meet-ups you create or join.
8. Keeping and deleting your data
We keep your information while your account is open. You can delete your account at any time in Settings — this removes your profile, check-ins, photos, lists, likes and messages. Two things survive deletion, neither of which identifies you: anonymous aggregate counts (such as daily totals), and feedback you sent us, which stays on file with the account link removed, so it can no longer be traced back to you or replied to.
If you would rather we deleted your account for you, email hello@fishchips.org.uk from the address on the account.
9. Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Email hello@fishchips.org.ukand we will respond within one month. If you are unhappy with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk.
10. Children
The app is not intended for children under 13, and you must be 13 or over to create an account. If you believe a child under 13 has an account, email us and we will remove it.
11. Security
Data is encrypted in transit. Our database enforces row-level security, so one account cannot read another’s private data. Only a small number of named administrators can reach account data, and only to run the service.
12. International transfers
Our database and files are hosted in Ireland. Some of our providers (Expo, Apple, Google) may process data outside the UK and EEA; where they do, they rely on the safeguards required by UK data protection law, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
13. Changes to this policy
If we change anything significant we will update the date at the top and, where the change matters to you, tell you in the app.
14. Contact
hello@fishchips.org.uk, or the Feedback option on the Home screen.