Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how Bites & Sparks ("we", "our", "us") collects, uses, and shares personal data when you use the Bites & Sparks mobile application (the "App"). It also describes your rights and how to exercise them.

1. Who We Are (Data Controller)

The data controller responsible for your personal data is Bites & Sparks, operated by Yontem Technology Consultancy Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. You can reach us at privacy@bitesandsparks.com for any privacy matter.

2. Information We Collect

3. How We Use Your Information

4. Legal Bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the App and matching); consent (for location access, push notifications, and product analytics, which you can withdraw at any time); legitimate interests (to keep the service safe and to diagnose crashes); and legal obligation (to comply with applicable law).

5. Analytics & Consent

We use Mixpanel for product analytics. Analytics are off by default: no analytics events are sent to Mixpanel unless you explicitly opt in via the in-app consent prompt. You can withdraw consent at any time in the App, after which analytics collection stops. We use Sentry for crash and error diagnostics; crash reports may include a limited history of recent in-app actions attached to an error, which we treat as service-essential debugging under legitimate interests.

6. Data Sharing

We do not sell your personal data. We share information only with:

7. International Transfers

Your data is primarily stored on AWS infrastructure in the EU (eu-west-1). Some processors (e.g., Mixpanel, Sentry, Apple) may process data outside the EEA/UK. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Data Retention

We keep your personal data for as long as your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements.

9. Data Storage & Security

We use encryption in transit (TLS) and at rest (AES-256). Access is restricted via AWS IAM and Cognito authentication. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.

10. Your Rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. You can delete your account and data from within the App settings, or contact us at privacy@bitesandsparks.com. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

11. California Privacy Rights

If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to not be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under California law. To exercise these rights, contact us at privacy@bitesandsparks.com.

12. Photos & Camera

We request access to your camera and photo library solely to let you upload profile and date photos. Photos are stored securely and are only visible to other users as part of your profile or date plans.

13. Children

Bites & Sparks is intended only for people aged 18 and over. We do not knowingly collect data from anyone under 18.

14. Changes

We may update this Privacy Policy from time to time. We will post the new policy on this page and update the "Last updated" date above.

15. Contact

If you have questions about this Privacy Policy, contact us at privacy@bitesandsparks.com.