This is an honest summary of current behaviour — not a law-firm policy. If anything here is unclear, see Contact.
Account
If you register, we store your email, optional display name, and a hashed password. Sign-in is invite-gated during this pilot. We also store the places you save, mark as been, or pass, plus any reviews or dish notes you submit.
Session cookie
After you sign in, the site sets an HTTP-only cookie named localbite_token so you stay signed in. It is marked Secure in production, SameSite=Lax, and lasts 14 days. It is not used for advertising. There are no third-party marketing cookies.
Contact form
If you write in via the contact form, we collect your name, email, and message so we can reply. That inquiry is emailed to the founder and is not used for marketing or shared with advertisers. Delivery currently goes through FormSubmit from your browser (or Resend, if we have configured it). Those providers see the same name, email, and message you send.
Location
Discover asks the browser for your location so we can estimate walk times. Coordinates are sent to our API for that recommendation request and stored on the recommendation session (with the mood, budget, and distance you chose) so we can improve picks and avoid immediate repeats. We do not track you in the background, and Browse does not require location.
Site analytics
We use Vercel Web Analytics to see which pages are visited. It is cookieless and is not used for advertising. Vercel processes those page views as our host.
Where it runs
The website is hosted on Vercel. The API and Postgres database are hosted on Railway. Venue maps use OpenStreetMap tiles.
What we don't do
We don't sell your data, show sponsored listings, or share accounts with advertisers. Reviews and saved places stay inside LocalBite.