LuxPints← Back to LuxPints

Privacy Policy

Last updated 14 May 2026

Who we are

LuxPints is operated by Lewis Downes as an independent project in Luxembourg. For any data-related questions, contact lewisdownes12@outlook.com.

What we collect

We only collect what we need to run the service:

  • Email address — to sign you in via a magic link.
  • Profile details — first name, last name, and phone number (required to leave a review). Optionally: age, employer, time in Luxembourg, and a profile photo.
  • Reviews you post — star rating, written comment, and the display name and avatar you chose. Reviews are public.
  • Anonymous usage stats — page views and referrers, via Vercel Analytics. No cookies, no personal identifiers.

We do notcollect payment information, location, advertising identifiers, or any data we don't actively use.

How we use it

  • To sign you in and keep your session active.
  • To display your reviews and profile name/avatar publicly on bar pages.
  • To get in touch with you about your account if needed (your phone number is never shown publicly — it's only for account recovery).
  • To understand which pages are popular so we can improve the site.

We do not sell, rent, or share your data with advertisers or data brokers.

Where your data lives

Your data is processed by these services, each acting as our processor:

  • Supabase — authentication, database, and photo storage. Data is hosted in the EU.
  • Vercel — hosts the website and provides anonymous analytics.
  • Apple MapKit JS — provides the map. Apple may receive your IP address when the map loads.

Cookies

We use a small number of strictly-necessary cookies:

  • Supabase auth cookies — keep you signed in after using a magic link.
  • An admin session cookie — only set if you're an admin and only on the admin area.

No marketing, advertising, or third-party tracking cookies are set.

How long we keep it

We keep your account data for as long as your account exists. You can ask us to delete it at any time (see below). Reviews you posted may remain visible (anonymised) even after account deletion if other users have engaged with them — let us know if you want them removed too.

Your rights

Under the GDPR, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and associated personal data.
  • Object to or restrict certain processing.
  • Lodge a complaintwith Luxembourg's data protection authority, the CNPD.

To exercise any of these rights, email lewisdownes12@outlook.com from the address linked to your account.

Changes to this policy

If we materially change how we handle your data, we'll update this page and the date at the top. For significant changes, we'll also let registered users know by email.