Privacy Policy
Last updated July 2026
Who we are (data controller)
queer.bar is a map-first platform for queer nightlife and community, including an optional adults-only layer ("Underground"). The data controller is [LEGAL ENTITY NAME AND REGISTERED ADDRESS — to be completed]. Privacy contact: privacy@queer.bar.
If we are established outside the UK/EEA but offer the service to people there, our UK/EU Article 27 representative is [REPRESENTATIVE NAME AND ADDRESS — to be completed if required].
What we collect
Account: you can browse anonymously (identified only by a random key in a signed, http-only cookie · no email or name required). If you create a full account we store your email, a securely hashed password (scrypt · we never store the plaintext), and any display name, handle, pronouns, bio and photos you add.
Age data: your date of birth and an "age-verified" flag, used solely to gate 18+ content. Your date of birth is never shown to other users and is never returned by our public APIs.
Underground (adults-only) profile — SPECIAL-CATEGORY DATA: if, and only if, you choose to create an Underground profile, we store the details you enter there, which can include your sexual orientation, gender identity, sexual preferences, roles and positions, relationship status, and similar data. Under GDPR Article 9 this is special-category data and we process it only with your explicit consent (see Legal basis).
Location: only if you opt in. Precise coordinates are used to show nearby venues and, if you enable it, to appear on the map — where your position is deliberately fuzzed/approximated for other users. You can switch location sharing off at any time.
Content & social graph: posts, stories, comments, reactions, lists, follows, check-ins, event/ticket activity, and direct messages. Direct-message content is encrypted at rest (AES-256-GCM).
Payments: if you buy a subscription, ticket or item, Stripe processes your payment. We receive the transaction result and a customer reference; we do not receive or store your full card number.
Device/log data: our hosting and infrastructure providers record standard request logs (IP address, user-agent, timestamps) for security and operations.
Legal basis (GDPR / UK GDPR)
Providing your account and the core service: performance of a contract with you (Art. 6(1)(b)).
Location, analytics, and other optional features: your consent (Art. 6(1)(a)), which you can withdraw at any time.
Special-category data in your Underground profile (sexual orientation, sexual preferences, etc.): your EXPLICIT consent (Art. 9(2)(a)); we also rely on Art. 9(2)(e) where you have manifestly made such data public. You can withdraw consent by editing/clearing that profile or deleting your account.
Security, abuse prevention, moderation and running the service: our legitimate interests (Art. 6(1)(f)).
Payment and transaction records: contract (Art. 6(1)(b)) and our legal obligations, e.g. tax/accounting (Art. 6(1)(c)).
Who we share data with (processors)
Vercel — hosting and content delivery. Neon — managed Postgres database. Stripe — payments and, where enabled, document-based age/identity verification (Stripe Identity), acting as an independent controller for the ID check. Resend — transactional email (e.g. email verification). CARTO / OpenStreetMap — map tiles (loading a tile shares your IP with them). Google Analytics — only if you consent (IP-anonymised, no ad personalisation or Google Signals).
We do not sell your personal data. We do not use it for third-party advertising.
International transfers
Some processors above are based in, or process data in, the United States and other countries outside the UK/EEA. Where personal data is transferred internationally we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the EU-US / UK-US Data Privacy Framework where a provider is certified.
Retention
Account data (including your Underground profile, date of birth and age-verified flag) is kept until you delete your account, after which it is erased. Hen-party/safety reports auto-expire after a short window. Server logs follow each provider's retention schedule. Stripe and Resend retain transaction and delivery records under their own schedules and applicable legal obligations.
Your rights
Under the GDPR / UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent at any time. You can download all your data (including your Underground profile) or permanently delete your account and its data from Privacy Settings, or by emailing privacy@queer.bar.
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your local Data Protection Authority.
US residents (e.g. under the CCPA/CPRA and similar state laws) have rights to know, access, delete, correct, and opt out of "sale"/"sharing" of personal information; we do not sell or share it for cross-context behavioural advertising. Exercise these the same way, via Privacy Settings or privacy@queer.bar.
We do not make decisions producing legal or similarly significant effects about you by solely automated means.
Children
queer.bar is for adults (18+) and is not directed to children. See our Children's Privacy and Age Verification policies.
These documents are provided in good faith and describe how queer.bar actually works today. They are drafts, not legal advice; have them reviewed by a qualified lawyer and complete the bracketed operator details before relying on them. Compliance with the EU GDPR, UK GDPR / Data Protection Act 2018, the US state privacy laws (incl. CCPA/CPRA) and other applicable regimes is an ongoing organisational responsibility, not something software alone establishes.