Privacy Policy
The Best Tapa is a community guide to the best tapas, built on photos and votes from real people at real venues. This policy tells you what we collect, why we collect it, how long we keep it, and the rights you hold over it.
Last updated: July 2026
Who we are
Buenvest runs The Best Tapa and decides how your data gets used, so we are the data controller under the General Data Protection Regulation (GDPR).
Reach us about any privacy question or to exercise your rights at support@thebesttapa.com.
Account data
When you create an account, we store the basics that make it work:
- Your email address.
- Your display name, if you set one.
- Your language and an optional home city you choose.
- Your login method, such as Google or an email code.
We process this to give you an account, sign you in, and link your submissions and votes to you. The legal basis is the contract we form when you sign up. You can browse public discovery as a guest without an account.
Location access
We ask for your location only after you tap to vote or use Nearby, never in the background. Your browser shares your position in that moment so we can check you are close enough to the venue for the vote to count.
We do not store your exact coordinates long term, and we never put raw latitude or longitude into analytics. The legal basis is your consent, which your browser asks for and which you can withdraw in your browser settings at any time.
Photos
When you upload a tapa photo, we keep it private to you until a moderator approves it. Once approved, it appears on the public listing you attached it to.
Upload only photos you took or have the right to share, and keep recognizable people out of the frame unless they agreed. We process photos to run the guide, on the basis of our legitimate interest in showing real food from real venues. See our Moderation Policy for the full rules.
Analytics
We measure how people use the app so we can improve it, counting actions like discovery views, searches, the add-a-tapa flow, votes, and reports. We confirm an event only after the action succeeds.
We strip personal data before an event is recorded. Analytics never contains:
- Your email, name, or phone number.
- Raw latitude or longitude, or an exact address.
- Your raw search text, a photo URL, or a filename.
- Your IP address, tokens, or a precise device fingerprint.
We do this on the basis of our legitimate interest in understanding and improving the product. Admin and internal activity stays out of public analytics.
Marketing emails
We may email you about The Best Tapa, such as new features, city launches, or tips for finding good tapas. We send these only if you opt in, and the legal basis is your consent.
You can opt out at any time with the unsubscribe link in any marketing email, or by emailing support@thebesttapa.com. Opting out of marketing does not stop the service emails you need, such as a login code or a reply to a report. We send marketing through our email provider today and may add a customer relationship tool later, both bound by the same data-processing terms.
Who processes your data
We use a small set of trusted providers to run the service. They act on our instructions under data-processing agreements:
| Provider | What it does |
|---|---|
| Supabase | Database, account login, and photo storage. |
| Vercel | Hosts and serves the app. |
| Sign-in with Google, and place and map data. | |
| Resend | Sends account and notification emails. |
| Umami | Privacy-focused, anonymized usage analytics. |
Some providers sit outside the European Economic Area. When data moves there, we rely on the European Commission's Standard Contractual Clauses to protect it.
How long we keep your data
We keep your account data for as long as your account stays open. We keep published tapas, photos, and votes while they live in the guide, since they are part of a shared community record.
When you delete your account, we anonymize your contributions so the guide stays intact without pointing back to you, unless the law requires us to delete them outright. We keep moderation and admin logs for a limited period so we can review past decisions.
Your rights
The GDPR gives you control over your data. You can ask us to:
- Give you a copy of your data, which we call an export.
- Correct anything wrong in your account.
- Delete your account and anonymize your contributions.
- Restrict or object to how we use your data.
- Withdraw a consent you gave, such as location access.
Start an export or deletion from your account screen, or email support@thebesttapa.com and we will handle it.
Changes to this policy
We update this page when our data practices change, and we move the date at the top when we do. Check back now and then to see where things stand.