Legal
Privacy policy
Last updated: 2026-09-28
What we collect
- Account data: email, display name, optional avatar, and password (hashed with bcrypt).
- Activity: ratings, taste preferences, saved drinks, scan attempts, review photos.
- Maker data (if applicable): business name, KvK number, contact details, drink listings.
- Technical: IP address (for rate limiting + abuse), basic request logs (retained 30 days).
What we don't collect
- We don't track you across other sites. No third-party advertising cookies.
- We don't sell your data. Period.
- We don't read your scan photos for anything other than matching the drink and (optionally, with your consent) improving our recognition model.
Cookies
We set a small number of strictly-necessary cookies:
nada_at,nada_rt: your session (signed JWT + refresh token, HttpOnly).nada_csrf: CSRF token, readable by the JavaScript on this site only.
If you accept analytics, we also load Plausible — a privacy-focused analytics service that doesn't use cookies and doesn't track you across sites. You can decline; the site works identically either way.
Third parties
- Mapbox — renders the map of stockists. Mapbox sees your IP + tile requests (their privacy policy).
- Nomic + OpenRouter — process scan photos for label recognition. Photos are sent server-to-server; consent is required for them to enter our training corpus (Settings → Scan photo training).
- Mailer — sends transactional emails (verification, password reset, monthly digest). They see your email + the message body.
Your rights
Under GDPR you can:
- Access a copy of your data — email privacy@drinknada.nl.
- Correct what's wrong — most fields are editable in Settings.
- Delete your account — Settings → Delete account, or email privacy@drinknada.nl for a full hard-delete.
- Object to specific processing — opt out of training-data contribution in Settings → Scan photo training; opt out of analytics via the cookie banner.
Data retention
- Active accounts — kept while you use nada.
- Soft-deleted accounts — anonymized immediately, ratings + photos retained for catalog continuity.
- Hard-delete request — fully removed within 30 days, including all photos, ratings, and the corresponding training-data rows.
- Request logs — 30 days, then deleted.
Security
Passwords hashed with bcrypt (12 rounds). All traffic is HTTPS. Session cookies are HttpOnly + Secure + SameSite. Email-link verification + reset tokens are single-use and expire within 1–24 hours.
Contact
Privacy questions or requests: privacy@drinknada.nl.