🌤️ Good morning, guest
GU
‹ Back

Privacy & Data Security

Last updated · Mar 9, 2026 · applies to Hong Kong

How we protect your data

Ourspot is built so that your account, saved spots, and group activity stay private and under your control. This page summarizes what we store, how it's secured, and the choices you have.

What we collect

  • Account basics — nickname, email, home/work area, language.
  • Activity — saved spots, reviews, visits, group membership, meetups you join.
  • Optional — profile photo, FoodiLog clips you upload (stored in access-controlled buckets).
  • Location — only with your permission, used for nearby spots; no background tracking.

How it's secured

  • Encrypted in transit (HTTPS) and at rest.
  • Row-level security — you can only read/write your own data; group data is scoped to members.
  • Uploaded media (profile photos, clips) sit in private storage with per-user access policies.
  • Trust-based gates limit sensitive actions (hosting meetups, becoming a Foodist).
🔒 We never sell your personal data. Spot information may be enriched by AI and third-party sources — see the AI disclaimer.

Data sharing

  • Supabase — backend for authentication, database, and file storage.
  • Google — Maps + Places APIs for spot information; Google Sign-In.
  • Apple — Apple Sign-In.
  • Law enforcement — only when required by law or to protect our rights.

Your controls

  • Edit or remove your profile, saved spots, reviews and clips anytime.
  • Leave a group to stop sharing with it.
  • Delete your account (below).

Data retention & account deletion

You can delete your account any time from Settings. Deletion follows a 30-day grace period, during which you can cancel by signing back in. After that:

  • Permanently erased — your profile and personal information (nickname, photo, bio, location), saved spots, lists, blocks and group memberships. Your login is closed and your email removed.
  • Kept but anonymized— content you shared with the community (reviews and ratings, FoodiLog clips, shared photos, chat messages) is retained in anonymized form, permanently unlinked from you and shown as “Deleted user.” It is no longer personal data, and it keeps aggregate ratings and shared group history intact for other members.

We honor deletion, access and correction requests for all users regardless of location. This meets the EU GDPR (Art. 17), the Hong Kong PDPO (DPP2 retention limitation) and the Republic of Korea PIPA. Limited data may be kept longer only where the law requires it (e.g. transaction records), and only for as long as required.

Delete your account

Starts the 30-day deletion process described above. You can cancel by signing back in.

Go to Settings →

Questions about your data? Contact security@ospot.io.

✦ Some content on Ourspot is generated or enriched by AI. Information may be inaccurate or outdated.AI Disclaimer →