Privacy
What we collect, and what we don’t
You can browse the whole map, every price and every historic pub, without an account and without telling us anything about yourself. Everything below is what happens when you go further than that.
Last updated 29 July 2026
The short version
- No account needed to look. Browsing is anonymous. We don’t ask who you are to show you the price of a pint.
- Analytics are off until you switch them on. On your first visit we ask you to tap Allow or No thanks. We remember that choice, and you can change it later in your account settings.
- PUBMAXX never stores raw IP addresses in its own database. Where we need to tell one device from another (rate limits, stopping one person logging the same price twice) we store a salted hash of it, never the address itself.
- We don’t sell anything to anyone. No ads, no data sales, no ad networks, no advertising trackers on the site.
- Your nights are yours. Night Memories and private plans are not public unless you choose to share them.
Who’s responsible
PUBMAXXING is run by Karan Manoharan, an individual based in London, UK. There is no company behind it yet, so for UK GDPR purposes the data controller is that individual, reachable at karanszdy@gmail.com. We have not appointed a Data Protection Officer, because at this size the law doesn’t require one. Mail to that address reaches a person, not a queue.
What we collect
If you just browse
Nothing you type, and no account. Our hosting provider records the ordinary technical detail every web server sees when it serves a page: the request, the time, the browser type and the IP address it came from. That is how the site gets served and how abuse gets stopped. Map tiles are fetched by your browser directly from the tile hosts named below, so those hosts see your IP address the same way any website you visit does.
If you make an account
Sign-in is handled by Supabase, using either an emailed magic link or Google or Microsoft sign-in. That means we hold your email address, plus whatever you choose to put on your profile: a handle, a display name, an avatar, a home city, a short bio. If you connect an external social profile (X, Instagram, TikTok) we store the account details you connected and any provider tokens encrypted at rest.
If you use an invite link
Making an invite gives you an opaque link tied to your account. When someone follows it, the opaque code stays in the page address. We set no referral cookie and store no attribution record while they browse. If that person starts and completes account creation in the same sign-in journey, the completed callback submits the code and we record one private referral edge between the two account IDs. It is recorded once and is never shown on a public profile, contributor record, venue page or anywhere else public.
Attribution works only during that sign-up. A delayed return, a different browser or device, an invalid link, or signing into an existing account is not attributed. We don’t guess when the same-journey proof is absent.
A referral is not qualified by signup alone. It needs the new account to make its first accepted contribution. We keep append-only milestone records so later decisions can be explained. Those milestone records do not grant paid features today, because contributions are not yet tied to signed-in accounts strongly enough to stop one person using several accounts.
What you post
Pint Drops (a price, a note, sometimes a photo), plans and crawl routes, presence taps (“I’m here tonight”), ratings, messages to other people, Recommendations, and Night Memories. We keep these because they are the product. A price with no date and no source is worth nothing. Presence is always a deliberate tap; the app never tracks your location in the background.
A Recommendation is your short opinion that one pub suits one kind of weather, so it is posted under a name. We store your public PUBMAXX handle, the pub, the single condition you picked from warm, clear skies, raining, cold and windy, the reason you wrote, the time our server took it, and the same opaque device token described below. The handle is stored because the opinion is attributed to you and shown with your name on it. A visible Recommendation counts on the public contributor record only when that handle resolves to an existing public profile. A self-asserted name without that profile can remain visible on the Recommendation but is excluded from the ranking. The token is stored only to rate-limit writes and to keep one contributor to one Recommendation per pub and condition, so editing yours replaces it rather than stacking another. The weather never writes a Recommendation. It only decides which of the ones people wrote match right now.
Community price submissions
Anyone can log tonight’s price without an account. We store the venue, the drink category, the price and the time. If your browser already has a public PUBMAXX handle, the price form tells you and sends that handle with the price. When your signed-in account owns that identity, the server resolves any renamed handle to its current name and the log counts there. When ownership cannot be proved, the price still lands anonymously and does not enter the contributor record.
Every price also carries an opaque device token derived server-side by salted SHA-256 hashing of your IP address, never the address itself. That token exists so one device can replace its own earlier entry instead of stacking duplicates, and so a single device can’t repaint the map on its own. It can’t be reversed back into an IP address, and we don’t use it to build a profile of you.
Public contributor record
The public contributor record ranks existing public profiles by contributions tied to that identity: visible prices posted, Visit Reports written and Recommendations made, added together across all time. Named Visit Reports and Recommendations that do not resolve to an existing public profile can remain visible on their posts but are excluded from this identity-backed ranking. It shows the combined total and each of those three counts. Hidden or taken-down contributions do not count. Anonymous price logs never appear under a name.
We also keep whether a price was corroborated, whether a contribution survived moderation and whether a price was later contradicted. Those signals are kept so the record can be made more useful later without losing its history. They do not change today’s ranking, which is based only on how many identity-backed, visible contributions a profile has made.
Community venue reports
Anyone can also report what they saw about a pub: rough or posh character, entrance and toilet access separately, door policy, and whether people were eating. We store the venue, the answer and the time, plus the same opaque device token used for community prices. It lets your newer answer replace your older one, keeps one device from confirming itself, and does not enter the public contributor record. The token is not shown with the report and does not become a public name.
Location
“Find my pint” asks your browser for your location and ranks nearby pubs there, so those coordinates never leave your device. Other location features work like this:
- What’s on: sharing location on the map or Tonight sends the coordinates supplied by your browser, without rounding them first, to our
/api/whats-onroute so it can rank listings near you. - Conditions and getting home: Tonight rounds your point to three decimal places, roughly 70 to 110 metres in London, before sending it to our
/api/tonight-conditions,/api/last-trainand/api/tfl-disruptionroutes. Today uses the same rounding for last-train and disruption requests. These answer nearby conditions, your nearest station and relevant transport disruption. The last-train route passes the rounded point to Transport for London’s public StopPoint API. - Getting to a pub: sharing location for travel times in a map venue sheet rounds your point to three decimal places before posting it to our
/api/citymcp/journeyroute. Our server forwards that approximate origin to CityMCP for journey options. If you then tap Maps, your browser sends the same rounded origin to Google Maps for directions. - Buses near a pub: opening nearby bus departures sends the pub’s public map coordinates to our
/api/nearby-bus-departuresroute. Our server passes that pub location, not your location, to Transport for London’s public StopPoint API to find nearby stops and live departures. - Remembered areas: Tonight can turn an area choice saved in your browser into that public area’s coarse centre and send the centre to
/api/whats-on. Today rounds the same kind of centre before sending it to/api/tfl-disruption. The saved choice itself is not uploaded.
Say no and the app falls back to picking an area or lets you open a venue without your location.
Analytics, only with consent
Usage analytics are off by default. A small prompt asks on your first visit, with Allow and No thanks both one tap. The browser remembers that choice so the prompt does not return on every visit. If you allow analytics, you can turn them back off later under Anonymous usage analytics in your PUBMAXX account settings. While they’re on:
- We create a persistent device identifier in your browser so page loads and later visits from that browser count as the same device. PostHog uses it for unique-user and retention analysis and keeps pseudonymous person and device records. We do not identify that record with your PUBMAXX account, handle or email.
- Page visits and events include browser and version, operating system, device type, screen and viewport size, the referring page, recognised campaign parameters and coarse app paths. The browser SDK also sends Web Vitals so we can measure loading and interaction performance. No account, handle, email, message content, free text or precise location is attached.
- Product actions still come from a closed, named list, such as a plan being accepted, with allow-listed simple values. Our server re-checks every product event and its browser context against the same rules and drops anything it does not recognise.
- For crash reporting, the browser analytics SDK sends the crash type with the same standard device context. Error messages and stack traces are redacted before they leave your browser. Session recording, autocapture, heatmaps, click tracking and surveys are all disabled.
- Analytics requests go through pubmaxxing.com rather than straight to the provider. The first-party browser proxy does not forward cookies or sign-in headers. For named product events, the server passes the request user agent and raw IP address to PostHog along with the validated referrer and screen context. PUBMAXX does not put that raw IP address in its own logs or database; its own rate limit keeps only a salted hash.
- If your browser sends a Do Not Track signal we skip analytics regardless, and the server honours the same signal.
- Turning consent off deletes the browser analytics identifier and stops PostHog page visits, product events and the hosting provider’s pageview counter.
Things that aren’t about you
Pub locations, opening hours, heritage facts, scraped and sourced prices, and the weather all come from public data. None of it is personal data, and requests for it are made by our server, not by your browser.
Why we’re allowed to
In UK GDPR terms, in plain language:
- Because you asked us to (contract). Holding your account, your plans, your messages and your saved nights is the service you signed up for.
- Because it’s a fair thing to do (legitimate interests). Keeping community prices and venue reports with their dates and device tokens, rate-limiting writes, and keeping server logs is how the map stays honest and the site stays up. We’ve kept it to the minimum that works.
- Because you said yes (consent). Usage analytics, push notifications and the email digest are consent-only, and you can withdraw consent at any time without losing the rest of the app.
Cookies and what sits on your device
We don’t use advertising or cross-site tracking cookies, and there is no ad network on the site. What we do keep in your own browser storage:
- A sign-in session, if you signed in, so you stay signed in. It lives in your browser and refreshes in the background.
- Your analytics choice, either allowed or denied, so we do not ask on every visit. Until you tap Allow, no analytics identifier exists. After you allow it, the persistent device identifier is kept in browser storage and a first-party cookie so later visits remain one device. Withdrawing consent removes that local analytics identity and stops new collection.
- Preferences and app state: theme, your device night profile, your remembered area, what you’ve already been shown once. We don’t upload those stored values as a bundle. An area choice can be turned in your browser into a coarse centre used for the requests described under Location. Your device night profile stays on your device unless you sign in and choose to bring it to your account.
Because nothing non-essential is set before you agree to it, the first visit choice is a small prompt rather than a wall in front of the map. Your account keeps the later control.
Who else touches it
We keep the list short on purpose. Each of these acts as a processor for us, or is only reached when you actively use the feature.
- Supabase
- Database, sign-in and file storage, on their EU region. Holds your account, your posts and your community observation rows.
- Vercel
- Hosting and CDN. Serves every page, and keeps short-lived request logs that include IP addresses. Also provides the pageview counter that stays disabled until you consent to analytics.
- PostHog (EU)
- Product analytics, EU project, consent-gated, with pseudonymous person and device records for unique-user and retention analysis. It receives the analytics categories listed above, including the raw IP on named product events. There are no session recordings and no identify calls tying events to your account.
- Map tile hosts
- OpenFreeMap and CARTO serve the base map straight to your browser, so they see your IP address while you pan the map. Map data is © OpenStreetMap contributors.
- Transport for London
- When you ask for last-train help, our server sends your coordinates rounded to three decimal places to TfL’s public StopPoint API at
api.tfl.gov.ukto find your nearest station. It also fetches live arrivals, timetables and line-status information. Opening nearby buses on a pub sheet sends that pub’s public map coordinates, not your location, to find nearby stops and live departures. - CityMCP
- When you share location for travel times to a pub, our server sends your origin rounded to three decimal places, with the selected venue, to CityMCP London at
citymcp.comfor journey options. - Google Maps
- If you tap Maps after sharing location in a venue sheet, the directions link gives
google.comyour origin rounded to three decimal places and the selected venue. Other Google map links include the venue or search only, not your shared location. - AI features
- If you ask The Landlord about a pub, or talk to Pub Pal, the text or audio of that request goes to the model provider that answers it (OpenRouter, and ElevenLabs for voice) and nothing else about you goes with it.
- Email and push
- If you opt in to the weekly digest, your email address goes to our email provider. If you turn notifications on, PUBMAXX stores your browser’s push subscription, the endpoint plus its keys, so it can send you the notification; the subscription itself belongs to your own browser’s push service. We keep that stored row until the push service reports it dead or you ask us to remove it.
We don’t sell personal data, and we don’t share it with advertisers or data brokers. We’ll only hand something over to authorities if we’re legally required to.
How long we keep it
- Your account and what you posted: until you delete it, or ask us to. Ask, and we’ll delete the account and the personal content attached to it within 30 days.
- Community prices and venue reports: the report itself stays, so later readers can see what people said and when. A row is one observation: the venue, either a drink and its price or one venue answer from a fixed list, the date and an unreversible device token. A price logged without an attributed public handle stays anonymous. If a public handle was attached, that attribution stays with the price while it is up and counts on the public contributor record.
- Recommendations: a Recommendation keeps your handle on it for as long as it is up, because an opinion with no name on it is not one. Writing another for the same pub and condition replaces the one you already had. There is no one-tap delete for a single Recommendation yet, so ask us and we’ll take it down, the same as anything else you posted.
- Hidden or reported content: photos attached to a removed post are purged from storage when the post is taken down.
- Analytics events: PostHog deletes analytics events 12 months after collection. It deletes pseudonymous person and device records 12 months after their last activity. These records carry no account identity, so they can’t be traced back to you after the fact, which also means we can’t pick your events out to delete them individually.
- Rate-limit records: durable limiter rows are keyed to salted hashes, never raw IP addresses. Hit timestamps outside that window are pruned when the hashed key is next used; the key row remains.
- Push subscriptions: if you turned notifications on, the stored subscription row stays until your browser’s push service reports it dead or you ask us to remove it.
- Referral records: the private invite code, account-to-account edge, first accepted contribution marker and milestone records stay until either account is deleted. Ordinary product writes can only append that history. A verified account deletion removes the private referral data tied to that account. We retain only a one-way hash of the deleted account ID in the referral system so an existing session cannot recreate those records.
Your rights
Under UK GDPR you can ask us to show you what we hold about you, correct it, delete it, hand it over in a portable form, restrict what we do with it, or object to it. You can also withdraw analytics consent whenever you like, in the app, without asking us.
Email karanszdy@gmail.com and say what you want. We’ll reply within 30 days, and it doesn’t cost anything. If we can’t verify that the account is yours we’ll say so rather than hand your data to someone else.
If you think we’ve got it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk. We’d rather you told us first so we can fix it.
Age
PUBMAXX is for over-18s. We don’t knowingly hold data about anyone younger, and if you tell us we have, we’ll delete it.
If this changes
When what the app does changes, this page changes with it and the date at the top moves. If a change is significant, like a new processor or a new category of data, we’ll say so in the app rather than quietly editing the text.
Get in touch
Privacy questions, data requests, or anything you think this page gets wrong:
See also our terms of use and our story.