Privacy Policy for GFMapper
Last Updated: July 30, 2026
1. Introduction
Welcome to GFMapper ("we," "our," or "us"), operated by Bytesnack LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our mobile app.
We respect your privacy and are committed to protecting your personal data. Please read this Privacy Policy carefully to understand our practices regarding your personal information.
2. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@gfmapper.com
3. Information We Collect
3.1 Contact Information
We may collect personal information that you voluntarily provide to us when you contact us, such as your name, email address, and any information you include in your communications with us.
3.2 Public Content
Some of what you contribute to GFMapper is public by design. Your reviews, ratings, photos, check-ins, bookmarks, profile (including your username), and other content you choose to post are visible to anyone using our website or mobile apps. This content may also be surfaced beyond GFMapper itself — for example, on third-party sites and services that feature or link to our community's contributions. Please keep this in mind when deciding what to share. If you attach photos to a review, we access only the photos you select or capture. We do not scan your photo library.
3.3 Public Health Data
You can optionally note on your profile why you eat gluten-free - for example, celiac disease, non-celiac gluten sensitivity, or a wheat allergy. Sharing this is entirely your choice. If you do, that condition may be displayed as a badge alongside the reviews you write, so other diners can better weigh your experience against their own needs.
3.4 Reaction Tracking
To support our core functionality of mapping safe gluten-free dining experiences, if you have indicated on your profile that you have celiac disease or non-celiac gluten sensitivity, you may optionally report, when writing a review, whether you experienced a physical reaction after dining at a restaurant. You can choose from three options: no reaction, mild reaction, or significant reaction.
This information is public by design. When you submit a reaction report, it is displayed on your review so other users can see that a fellow diner with celiac disease had a reaction at that establishment. Reaction reports may also be aggregated and shown on restaurant listings (for example, as a warning indicator on the map or a filter for "no recent reactions") to help the community make informed dining choices. We do not attribute aggregated reaction data to your individual account.
Reaction reports are transmitted to our servers, stored in your account's review history, and retained for as long as the associated review remains on our platform. We implement appropriate technical and organizational security measures to protect this health-related data in transit and at rest, consistent with the measures described in section 8 of this policy.
3.5 Account Information
If you create an account, we may collect your name, email address, username, password, and other information necessary to set up and maintain your account.
3.6 Location Information
With your permission, our app uses your device's location to show gluten-free restaurants near you. Your coordinates are sent to our servers only to return nearby results. We do not store a history of your location or use it for advertising. You can decline location access and search by city or address instead, and you can withdraw permission at any time in your device settings.
3.7 Anonymous Usage Data (only with your consent)
With your consent — and only with your consent — our website and mobile app collect anonymous usage data: which pages or screens are opened and which features are used, so we can see what people find useful and what needs work. We use PostHog, Inc. as our analytics provider for this.
Until you say yes, nothing is collected and no analytics code runs at all. When you first visit the website or open the app, we ask; you can decline just as easily as accept, and either choice is remembered. You can change your answer at any time under Settings → "Share anonymous usage data".
If you do consent, the data is not linked to your account. We do not send your name, username, email address, or your gluten-free condition to our analytics provider, and no profile of you is created there. Events are attributed only to a random identifier stored on your device, which is reset when you sign out. We do not use your IP address to identify you, and it is not stored with analytics events.
3.8 Crash Reports
When our app or website crashes or hits an unexpected error, a report is sent to our error-tracking provider, Sentry, so we can find and fix the problem. A crash report contains the technical error, the point in our code where it happened, and your device model, operating system, and app version. It is not linked to your account: we never attach your name, username, email address, IP address, gluten-free condition, or anything you typed, and reports are scrubbed on your device before they are sent.
We send crash reports because we have a legitimate interest in keeping GFMapper working reliably, and we have deliberately limited them to the minimum needed for that purpose. You can turn them off at any time under Settings → "Send crash reports", in the app or on the website. Turning them off takes effect immediately.
3.9 Cookies and Local Storage
We keep our use of device storage to a minimum, and we never write analytics cookies before you consent:
- Strictly necessary: signing in stores the session credentials needed to keep you signed in, and your privacy choices themselves (the analytics consent record and the crash-report preference) are stored on your device so we can honour them.
- Analytics (consent only): if you consent to anonymous usage data, our analytics provider stores its random identifier in a cookie and local storage on the website, or in app storage on mobile. If you never consent — or when you withdraw consent — this storage is not created, or is deleted.
We do not use advertising cookies, third-party marketing trackers, or session-recording tools.
4. How We Use Your Information
We may use the information we collect for various purposes, including:
- To provide, operate, and maintain our website and app
- To improve, personalize, and expand our website and app
- To understand and analyze how you use our website and app
- To develop new products, services, features, and functionality
- To communicate with you about updates or changes to our website
- To detect, prevent, and address technical issues
5. Legal Bases for Processing
Where the GDPR or similar laws apply, we rely on the following legal bases:
- Contract — account information and the content you post, to provide the service you signed up for.
- Consent — anonymous usage data (section 3.7) and device location (section 3.5). You can withdraw either at any time, as easily as you gave it.
- Legitimate interest — crash reports (section 3.8), limited to the minimum needed to keep GFMapper working; you can object at any time via the Settings toggle.
- Legal obligation — where we must retain or disclose information to comply with law.
6. Sharing Your Information
We use PostHog, Inc. to process the anonymous usage data described in section 3.7, and Functional Software, Inc. (Sentry) to process the crash reports described in section 3.8. These providers act as data processors on our behalf and are contractually required to protect the data to the same standard set out in this policy and to use it only for the purposes we specify. We do not sell your data, and we do not share it with advertisers or data brokers.
We may also share information in the following situations:
- With service providers who perform services for us
- To comply with legal obligations
- To protect and defend our rights and property
- With your consent or at your direction
- Sensitive health data (including health conditions and reaction reports) is never used for serving advertising, nor is it shared with advertisers, data brokers, or any third party not involved in operating GFMapper.
7. International Transfers
We are a US company and our service providers process data in the United States. Where data of EU/EEA, UK, or Swiss users is transferred, we rely on our processors' compliance with recognized transfer mechanisms (such as the EU-U.S. Data Privacy Framework and Standard Contractual Clauses).
8. Data Security
We have implemented appropriate technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
9. Data Retention and Deletion
How long we keep your data. We keep your account information for as long as your account is active. Anonymous usage data (section 3.7) is retained for one year and then deleted. Crash reports (section 3.8) are retained only as long as needed to diagnose and fix the underlying problem, and at most 90 days.
Deleting your account. You can delete your account at any time from within the app: open your Profile, scroll to the Danger Zone, and choose "Delete Account". This immediately removes your personal information — your name, email address, gluten-free condition, home location, bio, and profile picture. The reviews and photos you contributed remain visible so the community keeps the benefit of them, but they are anonymized and can no longer be linked to you.
Backups. Deleted data may persist in our encrypted database backups for up to 7 days after deletion, after which those backups expire and the data is gone.
Withdrawing consent for analytics. You can withdraw at any time under Settings → "Share anonymous usage data", in the app or on the website. This takes effect immediately, requires no request to us, and also removes the analytics identifier stored on your device.
Objecting to crash reports. You can stop crash reports at any time under Settings → "Send crash reports", in the app or on the website. This also takes effect immediately.
10. Your Rights
Depending on your location, you may have certain rights regarding your personal information, such as:
- The right to access your personal data
- The right to correct inaccurate personal data
- The right to request deletion of your personal data
- The right to restrict or object to processing of your personal data
- The right to data portability
- The right to withdraw consent where we rely on it
Section 9 explains how to exercise each of these. You will never be treated differently for exercising a right. You also have the right to lodge a complaint with your local data protection authority.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. If a change expands what we collect under your consent, we will ask for your consent again.
12. Acceptance of This Policy
By using our website or app, you acknowledge that you have read and understand this Privacy Policy and agree to be bound by it.