Privacy Policy
Last updated: August 22, 2026
This Privacy Policy explains how Bites & Sparks ("we", "our", "us") collects, uses, and shares personal data when you use the Bites & Sparks mobile application (the "App"). It also describes your rights and how to exercise them.
1. Who We Are (Data Controller)
The data controller responsible for your personal data is Bites & Sparks, operated by Yontem Technology Consultancy Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. You can reach us at privacy@bitesandsparks.com for any privacy matter.
2. Information We Collect
- Account information: Email address, name, date of birth / age, gender, city, and the profile photos you provide.
- Profile & content: Your intent, vibe tags, date plans, messages, message reactions, swipe activity, and any content you report or block.
- Approximate location: With your permission, your device location is used to show nearby date plans and to calculate distance for matching. You can disable location access in your device settings.
- Purchase information: If you subscribe, Apple processes your payment and shares subscription status with us (we do not receive your full card details).
- Device & diagnostic data: Device type, operating system version, app version, push notification token, and crash/diagnostic data.
- Product analytics: If you consent, in-app events (such as screens viewed and actions taken) used to understand and improve the product.
3. How We Use Your Information
- To create and manage your account and review your profile.
- To display date plans, calculate distance, and facilitate matching.
- To enable messaging between matched users.
- To operate subscriptions and other paid features.
- To send transactional emails and push notifications (e.g., verification codes, matches, messages).
- To keep the service safe (moderation, verification, blocking, and reporting).
- To diagnose crashes and, where you consent, to measure and improve the product.
4. Legal Bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the App and matching); consent (for location access, push notifications, and product analytics, which you can withdraw at any time); legitimate interests (to keep the service safe and to diagnose crashes); and legal obligation (to comply with applicable law).
5. Analytics & Consent
We use Mixpanel for product analytics. Analytics are off by default: no analytics events are sent to Mixpanel unless you explicitly opt in via the in-app consent prompt. You can withdraw consent at any time in the App, after which analytics collection stops. We use Sentry for crash and error diagnostics; crash reports may include a limited history of recent in-app actions attached to an error, which we treat as service-essential debugging under legitimate interests.
6. Data Sharing
We do not sell your personal data. We share information only with:
- Other users: Your public profile, date plans, and messages are visible to relevant users as part of the service.
- Service providers (processors): Amazon Web Services (hosting and infrastructure), Apple (in-app purchases and push delivery), Mixpanel (product analytics, only with consent), and Sentry (crash diagnostics). Each acts under a data processing agreement.
- Third-party resources on our website: Our marketing website loads a hero image hosted by Unsplash; visiting the site may transmit your IP address to that provider.
- Legal requirements: When required by law or to protect the rights and safety of our users and us.
7. International Transfers
Your data is primarily stored on AWS infrastructure in the EU (eu-west-1). Some processors (e.g., Mixpanel, Sentry, Apple) may process data outside the EEA/UK. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. Data Retention
We keep your personal data for as long as your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements.
9. Data Storage & Security
We use encryption in transit (TLS) and at rest (AES-256). Access is restricted via AWS IAM and Cognito authentication. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.
10. Your Rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. You can delete your account and data from within the App settings, or contact us at privacy@bitesandsparks.com. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
11. California Privacy Rights
If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to not be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under California law. To exercise these rights, contact us at privacy@bitesandsparks.com.
12. Photos & Camera
We request access to your camera and photo library solely to let you upload profile and date photos. Photos are stored securely and are only visible to other users as part of your profile or date plans.
13. Children
Bites & Sparks is intended only for people aged 18 and over. We do not knowingly collect data from anyone under 18.
14. Changes
We may update this Privacy Policy from time to time. We will post the new policy on this page and update the "Last updated" date above.
15. Contact
If you have questions about this Privacy Policy, contact us at privacy@bitesandsparks.com.