Legal
Privacy Policy
This policy describes which personal data House of Cocktails processes, based on the functionality that actually exists in the application today.
This document is a technical framework prepared for the House of Cocktails platform. It is not legal advice and should be reviewed by a qualified lawyer before public launch.
1. Controller / responsible entity
Controller within the meaning of the GDPR: [LEGAL NAME / COMPANY NAME], [LEGAL ADDRESS], [CONTACT EMAIL].
Data protection officer: [DPO — IF LEGALLY REQUIRED / APPOINTED]
2. Contact
For any question about this policy or your personal data, contact [PRIVACY CONTACT EMAIL].
3. Hosting and infrastructure
The website is delivered through the hosting and deployment platform used by the operator, and application data is stored in a managed PostgreSQL database with file storage and an authentication service provided by Supabase (used through Lovable Cloud). Processing locations, subprocessor lists and data-processing agreements must be documented by the operator: [HOSTING PROVIDER + REGION + DPA REFERENCE]
4. Account registration
Creating an account processes your email address, a username, a password (stored only in hashed form by the authentication provider) and the creation date. This is necessary to provide the member account (Art. 6(1)(b) GDPR).
5. Authentication
Sign-in is handled by the Supabase authentication service. You may sign in with email and password, or with Google. When you use Google sign-in, Google processes the sign-in request and transmits your email address and basic account identifiers to us. Session data is stored in your browser so you stay signed in.
6. User profiles
Your profile may contain a username, display name, biography, location text and an avatar image. Profile information you publish is visible to other visitors, including visitors who are not signed in.
7. User-generated content
Recipes you create are stored with their title, description, ingredients, quantities, method, tags and their publication status. Published recipes are publicly visible together with your profile name; drafts are visible only to you and to moderators.
8. Cocktail and avatar image uploads
Uploaded images are stored in the project's file storage. Images are resized and re-encoded before upload, which removes most embedded camera metadata. Do not upload images containing personal data of other people without their permission.
9. Likes, saves, ratings and follows
Likes, saved cocktails, ratings, collections and follow relationships are stored together with your user identifier so the features work across sessions. Aggregated counts are shown publicly; your individual saves and collections are not published unless you make a collection public.
10. Comments
Comments are stored with their text, your user identifier and a timestamp, and are publicly visible next to the recipe. Comments hidden by moderation remain stored for moderation records.
11. Notifications
In-app notifications (for example follows, likes, replies or moderation notices) are stored with the notification type, the acting member and a read status.
12. Reports and moderation
When you report content, we store the reason, your optional explanation, your user identifier, the reported content and the moderation status. Reports are visible only to the reporting member and to administrators — never to other members or to the reported member. The legal basis is our legitimate interest in a safe platform and compliance with platform obligations (Art. 6(1)(f), Art. 6(1)(c) GDPR).
13. Technical logs and security
The hosting and database providers create technical logs which can include IP address, request time, requested resource, user agent and error information. These are used for operation, troubleshooting and abuse prevention. Recipe views are counted using a random session key stored in your browser, not your IP address. Retention of provider logs: [PROVIDER LOG RETENTION — TO BE CONFIRMED]
14. Cookies and local storage
House of Cocktails currently uses only essential browser storage. No analytics, advertising or tracking technologies are active.
- sb-*-auth-token — Keeps you signed in (authentication session). Set by the authentication provider.
- cc_session — Anonymous key used to count a recipe view only once per session.
- hoc_consent — Remembers your cookie preferences.
to review or change your choice at any time.
15. Third-party services
Currently detected in the application: the Supabase platform (database, file storage, authentication), Google sign-in as an optional login method, and Google Fonts loaded from Google servers for typography. Any further services must be added here before they are activated: [ADDITIONAL PROCESSORS — IF INTRODUCED]
16. International data transfers
Where a provider processes data outside the European Economic Area, the transfer mechanism (for example EU standard contractual clauses) and the storage region must be documented by the operator: [TRANSFER MECHANISM + REGION PER PROVIDER]
17. Data retention
Account data is retained while the account exists. Deleting the account removes the account and directly linked records; published recipes may remain available in anonymised form without an author reference. Concrete retention periods per data category must be defined by the operator: [RETENTION PERIODS]
18. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw consent at any time with effect for the future. You may also lodge a complaint with a supervisory authority: [COMPETENT SUPERVISORY AUTHORITY]
19. Account deletion
You can delete your account yourself under Profile → Settings → Account. Deletion removes your profile, comments, likes, saves, ratings, follows, collections, notifications and preferences. Recipes you published may remain visible without an author reference so that other members' saves and comments are not destroyed.
20. Privacy contact
Requests regarding your data: [PRIVACY CONTACT EMAIL]
21. Changes to this policy
This policy is updated when the functionality of House of Cocktails changes. The current version always applies.
