Privacy Policy
Last updated: July 2026
1. Overview
Hotspots Portugal ("we," "us," "our," or "Company") operates the Hotspots Portugal website and platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
Please read this policy carefully. By accessing or using Hotspots Portugal, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree, please do not use our services.
2. Who We Are
Data Controller: Hotspots Portugal
Data Protection Officer / Privacy Contact: hello@hotspotsportugal.com
Jurisdiction: This Privacy Policy is designed to comply with GDPR (EU Regulation 2016/679) and applicable Portuguese data protection law. We are committed to maintaining the privacy and security of all personal data we collect.
3. Data We Collect
3.1 Anonymous Visitors
What we collect:
- IP address (anonymized in analytics)
- Browser type and version
- Operating system
- Pages visited and time spent
- Referral source
- Search queries
Legal basis: Legitimate interest (website analytics and improvement)
Retention: 12 months (anonymized)
3.2 Insider Community Members
Account creation and profile:
- Email address (required)
- Password (hashed, never stored in plaintext)
- Display name
- Gender (optional — used for grammatically correct Portuguese notifications, e.g., "Obrigado" vs. "Obrigada")
- Avatar/profile photo (optional)
- Notification preferences
Review activity:
- Reviews you submit (text, rating, photos)
- Restaurants you mention or suggest
- Saved restaurants (your ♡ favorites list)
- Review edit history
- Community votes and comments
Legal basis: Consent (account creation); Contract (using the service)
Retention: For the duration of your account, plus 30 days after deletion (backup/audit purposes)
3.3 Restaurant Owners / Restaurant Insiders
Restaurant claim registration:
- Restaurant name and legal business name
- Restaurant owner or authorized representative email
- Phone number
- Restaurant address
- Business license number (for verification)
- Menu data (if uploaded)
- Opening hours
- Photos and description
Engagement data:
- Responses to reviews
- Menu updates and changes
- Restaurant statistics (views, reviews, ratings)
Legal basis: Consent (restaurant claim); Contract (using restaurant features)
Retention: For the duration of the restaurant listing, plus 12 months after removal (legal/audit purposes)
3.4 Community Choice Voting
What we collect:
- Your vote (restaurant ID, category, timestamp)
- Voting history (for fraud prevention and duplicate vote detection)
Legal basis: Legitimate interest (prevent vote manipulation)
Retention: Current year + 1 year (for annual award validation)
4. How We Use Your Data
4.1 General Use
- Service delivery: Create and manage your account, display your profile and reviews, process restaurant claims
- Communication: Send transactional emails (e.g., password reset, account alerts), newsletter (if opted in), account notifications
- Community moderation: Review content for policy violations, inappropriate language, or spam
- Analytics: Understand how you use the platform, improve features, identify technical issues
- Fraud prevention: Detect and prevent duplicate accounts, vote manipulation, fake reviews
4.2 Insider Rank System
We automatically calculate your rank based on your review count:
- First Bite: 0–4 reviews (initial status)
- Regular: 5–14 reviews
- Local Insider: 15–49 reviews
- Resident Critic: 50+ reviews
This ranking is public and displayed on your profile and reviews. We do not use this data for discriminatory purposes.
4.3 Gender Field (Insider Profiles)
The optional gender field is used solely for grammatically correct Portuguese in automated notifications and emails:
- If not provided: we use gender-neutral Portuguese ("Obrigado/a")
- If provided: we use the correct grammatical form
This field is not shared publicly. You can change or remove it at any time in Settings.
5. Legal Basis for Processing
Under GDPR, we rely on the following legal bases for processing your data:
- Consent: Account creation, location tracking opt-in, newsletter subscription
- Contract: Providing the service you've requested (reviews, saved places, restaurant management)
- Legal obligation: Complying with court orders, tax law, fraud prevention
- Legitimate interest: Improving the platform, preventing abuse, analytics, security
6. Data Retention
| Data Type |
Retention Period |
| Anonymous analytics |
12 months (automatically deleted) |
| Active account data |
Duration of account + 30 days after deletion |
| Reviews and profiles |
Can be deleted by user; retained for 30 days as backup |
| Location data (if enabled) |
Only while feature is active; deleted immediately upon opt-out |
| Voting data |
Current year + 12 months (for award validation) |
| Restaurant owner data |
Duration of restaurant listing + 12 months |
7. Location Recognition (Chapter 4.9) — Preparation & Future Implementation
7.1 What This Feature Will Do
In the future, Hotspots may offer an optional Location Recognition feature for Insider members. This feature is not yet active.
How it will work (when enabled):
- When you opt in, Hotspots can periodically check your device's location (via your browser or operating system permission)
- We compare your location to restaurants in our database
- If you are within a configurable radius (default: 500 meters) of a restaurant you or other Insiders have reviewed, you receive a push notification
- Example: "Are you at [Restaurant Name] right now? Don't forget to take photos for your review!"
7.2 Your Control (Before & After Opt-In)
Before enabling Location Recognition:
- You will see a full information screen explaining what data is collected and how it's used
- You must explicitly consent to location tracking
- Your device (iOS/Android/browser) will also ask for location permission
- We do not collect location data without both consents (ours + device OS)
After opting in:
- You can turn off Location Recognition at any time in Settings → Privacy
- Turning off is immediate — we stop collecting location data
- You can delete all stored location history with one click: Settings → Privacy → "Delete location history"
7.3 Data Collection Details
What we collect when Location Recognition is active:
- Your GPS coordinates (latitude, longitude)
- Accuracy estimate (±X meters)
- Timestamp
- Which restaurants triggered notifications
- NOT collected: Your full location history, movement patterns over time, or tracking outside our feature
What we do NOT collect:
- Continuous tracking of your movements throughout the day
- Your home address or personal locations
- Movement history across different days/weeks
- Your location outside of the restaurant-matching logic
7.4 Legal & Compliance Preparation
GDPR Compliance:
- Data subject rights: You have the right to access, correct, delete, or export your location data at any time (see section 8)
- Data transfer: Location data is stored only on our Supabase database (Portugal/EU servers). We do not transfer it outside the EU/EEA
- Processing Agreement: Our data processors (hosting provider, etc.) are bound by Data Processing Agreements
- Breach notification: In the unlikely event of unauthorized location data access, we will notify affected users within 72 hours
Before Location Recognition is activated, we will:
- Obtain legal review of this privacy policy
- Confirm compliance with Portuguese GDPR requirements
- Update our Data Processing Agreements with all vendors
- Establish a data breach response protocol
- Obtain explicit consent from all users before any location data collection begins
7.5 Retention & Deletion of Location Data
Automatic deletion:
- Location coordinates are retained for 7 days only while the feature is active
- After 7 days, coordinates are deleted automatically
- Notification history (which restaurants triggered alerts) is retained for 30 days
Manual deletion:
- You can request deletion of all location data at any time via Settings → Privacy → "Delete all location history"
- Deletion is immediate and cannot be undone
Upon account deletion:
- All location data is deleted immediately
- No location data is retained after account closure
7.6 Opting Out & Disabling the Feature
You can opt out at any time:
- Settings → Privacy → Location Recognition → "Turn off"
- Immediate effect — no location data collected after you turn it off
- You can re-enable it later if you change your mind
iOS/Android/Browser level:
- You can also revoke location permission at your device level (iOS Settings → Privacy → Location or Android Settings → Apps → Hotspots → Permissions)
- This prevents any app from accessing your location
8. Your Rights (GDPR & Portuguese Law)
You have the following rights regarding your personal data:
8.1 Right of Access
You can request a copy of all personal data we hold about you. Submit a request to hello@hotspotsportugal.com with the subject "Data Access Request." We will provide a complete, machine-readable copy within 30 days (extendable to 60 days for complex requests).
8.2 Right to Rectification
If your data is inaccurate or incomplete, you can request correction. You can also update most profile information directly in your account settings (name, avatar, notification preferences).
8.3 Right to Erasure ("Right to Be Forgotten")
You can request deletion of your account and associated data. To delete your account:
- Go to Settings → Account → "Delete my account"
- Enter your password to confirm
- Your account and data are deleted immediately
Exceptions (data we must retain):
- Transaction records (30 days for backup/audit)
- If you have an active restaurant claim, we retain business registration details for 12 months for legal purposes
- We may retain anonymized review data (stripped of your name/email) for statistical analysis
8.4 Right to Data Portability
You can request your data in a portable, machine-readable format (JSON, CSV). Submit a request to hello@hotspotsportugal.com with the subject "Data Portability Request." We will deliver it within 30 days.
8.5 Right to Restrict Processing
In certain circumstances, you can ask us to restrict how we use your data (e.g., during a dispute about accuracy). Contact hello@hotspotsportugal.com with details.
8.6 Right to Object
You can object to processing based on legitimate interest. For example, if you do not want your review visible on the platform (except in limited cases where we must retain it for legal reasons), contact us.
8.7 Right to Withdraw Consent
For data processing based on your consent (e.g., location tracking, newsletters), you can withdraw consent at any time. Go to Settings → Privacy to manage your preferences.
8.8 Lodging a Complaint
If you believe we have violated your data protection rights, you can lodge a complaint with your national data protection authority:
- Portugal: Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt
9. Third-Party Services
9.1 Data Processors We Use
- Supabase (database & authentication): Stores all account data, reviews, location data (if enabled). Hosted in EU (compliance: GDPR, Standard Contractual Clauses)
- Brevo (email marketing): Sends newsletters, transactional emails if opted in. Brevo is GDPR-compliant and EU-based
- Netlify (hosting): Serves the website and handles traffic. Analytics are anonymized
- Railway (backend API): Processes API requests for votes, notifications, restaurant data. EU-hosted
All processors have Data Processing Agreements in place ensuring GDPR compliance.
9.2 Do We Sell Your Data?
No. We do not sell, rent, or trade your personal data to third parties for marketing purposes. We only share data with processors listed above, and only to the extent necessary to provide our services.
9.3 Your Data & Restaurant Owners
When you write a review of a restaurant:
- The restaurant owner can see your review, rating, and profile name (but not your email or personal information)
- Restaurant owners cannot see your saved places, voting history, or other private activity
- You can request that a restaurant owner remove or redact your review (contact us with details)
10. Security
We take data security seriously. We implement:
- Encryption in transit: All data is transmitted via HTTPS/TLS (encrypted)
- Encryption at rest: Sensitive data (passwords, emails) is encrypted in the database
- Password security: Passwords are hashed using industry-standard algorithms; we never store plaintext passwords
- Access controls: Only authorized staff can access databases; access is logged and monitored
- Regular backups: Your data is backed up daily and can be recovered in the event of loss
- Penetration testing: We periodically conduct security audits
However, no system is 100% secure. If we discover a breach involving personal data, we will notify affected users within 72 hours and cooperate with authorities as required by law.
Questions about this Privacy Policy or your data?
Email: hello@hotspotsportugal.com
We aim to respond to all inquiries within 10 business days.
Data Protection Officer / Privacy Contact:
Hotspots Portugal
Email: hello@hotspotsportugal.com
This Privacy Policy is effective as of July 2026 and may be updated periodically. We will notify you of material changes via email or by posting a notice on our website. Continued use of Hotspots after such changes constitutes your acceptance of the updated policy.