← Home

Privacy Policy

DRAFT — this page has not been reviewed by a solicitor and is not yet in effect. It exists to establish the real structure and content this app needs before wider launch. Sections marked PLACEHOLDER below are business/legal decisions (exact retention periods, governing law, formal contact details) that need confirming; everything else describes what the app actually, concretely does today, verified against its real code.

Last updated: 25 August 2026

Sipwhich (“we”, “us”, “the app”) is operated by Joel Blomfield, trading as a sole trader, who is the data controller responsible for the personal data described in this policy. Sipwhich is a site for finding which cafes (across Manchester, Sheffield, and any other city we add) sell a specific drink, built from menus photographed and submitted by users. This policy explains what personal data we collect, why, how long we keep it, who else it's shared with, and how to have it deleted.

Who can use Sipwhich

You must be at least 13 years old to create an account or otherwise use Sipwhich. We do not knowingly collect personal data from anyone under that age; if we become aware that we have, we'll delete it.

What we collect

Account information

When you sign up: your email address, a display name you choose, and your password — never stored in plain text, only a one-way bcrypt hash of it, which cannot be reversed back into your actual password even by us. You can optionally add a profile picture at any time from your account settings, stored in Vercel Blob storage the same way as other photos in the app; it's shown next to your name wherever your activity is visible to other users (e.g. a photo you shared to Community), and removed if you delete it or your account.

Content you submit

Menu photos you upload (stored in Vercel Blob storage), the drink names/prices/categories automatically extracted from them, star ratings (1–5) you give a drink, whether you mark a rating “public” or keep it private to your own diary, Drink Quality/Food/Atmosphere/Value scores (1–10 each) you give a cafe as a whole, “still available at this price” confirmations, your “tried it” history, any cafe you suggest (name and address), and drinks you save to your own favourites list. If a drink isn't in our database, you can log it yourself instead (“Can't find it? Add it yourself”) — the drink name, and any price or cafe name/location you type, are stored as plain text exactly as you entered them, not verified or linked to any real cafe or menu record. This is never used to publish anything on your behalf, but the typed cafe name may be looked at internally when considering which real cafes to add to the app in future.

Community & cafe photos

You can optionally share a photo of a drink you tried to the public Community grid, or post a standalone photo of a cafe itself (its interior, exterior, or general atmosphere, not tied to any specific drink) — both stored in Vercel Blob storage. Every photo shared this way is automatically screened by Anthropic's Claude API (see “Who we share data with” below) for whether it plausibly shows a drink (Community photos only) and whether it could be inappropriate or harmful — this is advisory only and never auto-rejects anything; a human moderator still reviews and explicitly approves every photo before it's visible to anyone else. A photo a moderator rejects isn't deleted, just kept off the public grid/gallery — it remains part of your own private diary (for a Community photo) or is otherwise simply not shown (for a cafe photo).

Favourites & likes

Drinks you save to your favourites are shown on your own profile page — visible to yourself always, and to any other user you've accepted as a follower (see “Followers & following” below), never to anyone else as “you favourited this.” Separately, the aggregate count of how many people in total have favourited an item is shown publicly to everyone (e.g. a “♥ 3” next to a Community photo or on an item's page), but never who any of them are.

Followers & following

You can follow another user, and others can follow you; we store who follows whom and whether a request is still pending your approval. In your account settings you choose whether your account is public (a follow of you is accepted automatically) or private (it stays pending until you explicitly accept or decline it). Your own follower/following counts are shown on your profile to any visitor; the actual list of who you follow and who follows you is visible only to you. Being an accepted follower of someone is what unlocks seeing their tried-drinks diary and favourites (see those sections above) — it doesn't change any of the finer-grained choices already described, such as keeping a specific rating private or a diary caption unshared.

Location

If you use “Near me” sorting, your device's location is read once, in your browser, using the standard browser Geolocation API — after you're shown an explanation and asked to confirm. That location is used entirely on your own device to calculate distance to each cafe and plot your own position as a marker on the map, and is never sent to, or stored on, our servers.

Technical/usage data

Standard request metadata (IP address, timestamps) is processed transiently to enforce rate limits against abuse (e.g. repeated failed logins, scripted submissions) and is not retained as a separate log of your activity beyond what's needed for that.

Why we collect it

Who we share data with

We don't sell personal data. The following third-party services process data as part of running the app:

Cookies

We use one essential session cookie to keep you logged in — the app can't function without it, and it isn't a tracking cookie. Your accept/decline choice from the cookie banner is itself remembered in a second, non-essential cookie (plus your browser's local storage) purely so that choice can be honoured — it carries no tracking purpose of its own. If you accept, Sentry becomes active for crash reporting, in both your browser and on our servers; declining (or not yet choosing) keeps it off entirely, everywhere. You can change this choice at any time — see the banner shown on your first visit, or clear your browser's cookies/local storage to see it again.

How long we keep it

Account and content data is kept for as long as your account exists, or until you request its deletion (see below).

PLACEHOLDER — confirm with a solicitor before launch: exact retention periods for specific data types (e.g. should rejected/deleted menu submissions, or inactive accounts after N years of no login, be purged automatically on a schedule, rather than only on explicit request?).

Your rights, and deleting your data

You can delete your account and its personal data at any time from your account settings, with immediate effect — no need to email anyone. This permanently removes your account, display name, email, password, profile picture, favourites, followers/following relationships, notifications, tried-drinks diary (including any photo you shared to Community from it), and availability confirmations. Your star ratings, cafe ratings, any menu or cafe photos you posted, and the record of which cafes you suggested are kept but anonymized (disconnected from your account entirely) rather than deleted outright, so that the average rating shown to other users for a drink, a cafe's own Drink Quality/Food/Atmosphere/Value ratings, a cafe's menu/photo gallery, or an already-approved cafe listing doesn't change just because you closed your account — once anonymized, none of these can be traced back to you by us or anyone else.

If you can't access your account, contact us using the details below and we'll verify your identity and action the request manually.

PLACEHOLDER — confirm with a solicitor before launch: formal data-subject-rights language (access, rectification, portability, objection) and which specific data protection law(s) govern this (e.g. UK GDPR) — depends on where users are based and needs a solicitor's framing, not a developer's guess.

Changes to this policy

If this policy changes materially, we'll update this page and, where practical, notify account holders.

Contact

Sipwhich is operated by Joel Blomfield, trading as a sole trader.

PLACEHOLDER — confirm with a solicitor before launch: a real, monitored contact email/address for privacy requests goes here.

We use one essential cookie to keep you logged in — it can't be turned off. If you say yes, we also use Sentry to report errors when something breaks, so we can fix it. Privacy Policy