Skip to content
← All legal documents

Data Protection Policy (UK DPA 2018 / EU GDPR)

Last updated July 2026

Principles

We follow the GDPR principles: lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, and accountability.

Data minimisation

Anonymous browsing requires no personal data. We only collect what a feature needs: an account needs an email; the Underground layer's special-category fields are entirely optional and stored only if you choose to add them.

Security

The service is served exclusively over HTTPS/TLS with HSTS. Passwords are hashed with scrypt (a memory-hard KDF) and never stored in plaintext. Session cookies are signed, http-only and secure. Direct-message content is encrypted at rest with AES-256-GCM. The database provider encrypts data at rest.

We apply least-privilege access to infrastructure, keep secrets out of source control, validate API input, and rate-limit the API. Baseline security response headers (nosniff, frame protections, referrer and permissions policies) are set on every response.

Processors & DPAs

Vercel (hosting/CDN), Neon (database), Stripe (payments + identity), Resend (email), CARTO/OpenStreetMap (map tiles) and Google (consent-gated analytics). A Data Processing Agreement should be in place with each; most offer a standard DPA.

International transfers

Where processors are outside the UK/EEA, transfers rely on Standard Contractual Clauses, the UK IDTA, or the EU-US/UK-US Data Privacy Framework as applicable.

DPIA

Because we process special-category data (sexual orientation/preferences) and location data at scale, a Data Protection Impact Assessment should be maintained for the Underground layer and location features.

Breach response

Any personal-data breach that risks individuals' rights will be assessed and, where required, reported to the relevant supervisory authority (e.g. the ICO) within 72 hours and to affected users without undue delay.

These documents are provided in good faith and describe how queer.bar actually works today. They are drafts, not legal advice; have them reviewed by a qualified lawyer and complete the bracketed operator details before relying on them. Compliance with the EU GDPR, UK GDPR / Data Protection Act 2018, the US state privacy laws (incl. CCPA/CPRA) and other applicable regimes is an ongoing organisational responsibility, not something software alone establishes.