Privacy Notice
Yumma is a map of cheap meals built by the people who eat them. You can use almost all of it without telling us anything about yourself, and this notice is written to be read rather than to be survived.
It explains what we collect, why we collect it, who else sees it and what you can ask us to do about it. It applies to yumma.co.uk. Last updated 25 August 2026.
Last updated 25 August 2026.
The short version
- You can browse the map and Yum-vote without giving us a name, an email address or an account.
- Your browser is signed in anonymously the moment you arrive, using a random identifier that says nothing about who you are.
- We only ask for a scout name when you want to contribute something that will carry your name.
- We do not sell your data, and there are no advertising or analytics trackers on this site.
- What you contribute is published; your email address, your votes and anything you report to us are not.
Who we are
Yumma operates yumma.co.uk and is the data controller for the personal data described in this notice, under the UK GDPR and the Data Protection Act 2018.
You can reach us about anything in this notice at privacy@yumma.co.uk.
Anonymous scouts
The first time you open Yumma, your browser is signed in anonymously. That creates an account holding nothing but a random identifier — no name, no email address, no profile, and nothing that links it to you as a person. It exists so that the site can do the small number of things that need to tell one visitor from another.
Specifically, that identifier is what lets us:
- count one Yum per person per item, instead of one per click;
- attribute a contribution to the scout who made it;
- let you find your own votes and contributions again on your next visit;
- stop a single person flooding the moderation queue from a hundred identities.
The identifier is stored in your browser. If you clear your browser's site data, it is gone and cannot be recovered — your past votes and contributions stay where they are, but nothing connects them to your new session, and we have no way to reunite the two. Signing in with Google upgrades that same anonymous identifier in place, which is what makes your history survive.
Being anonymous to us is real, and it cuts both ways: if you write to us about an anonymous account, we usually cannot tell that it is yours. See “Your rights” below for what we can do instead.
What we collect
Without you doing anything:
- The anonymous account identifier described above, created by Google Firebase Authentication.
- Your IP address, processed by our hosting and content delivery providers to serve the site and to protect it from abuse. We do not use it to build a profile of you.
- Signals collected by Google reCAPTCHA, which Firebase App Check uses to tell a browser from a script. Without this check, the database refuses to answer at all.
- If a page fails, an error report: the error itself, the page it happened on and your browser type. We deliberately run no session replay and no performance tracing, because an error report does not need to watch you use the site.
Because the map has to be drawn:
- Map tiles are fetched from CARTO, built on OpenStreetMap data. Your IP address and the area you are looking at reach them, as they would with any map.
- If you drop a pin to add a place, the coordinates you chose are sent to OpenStreetMap's Nominatim service to turn them into an address.
Only when you choose to give it:
- A scout name, which you pick before contributing. It is public.
- Your email address, if you sign in with Google. It is stored on your own profile record and is never shown to other people.
- A social handle and follower count, if you connect a social account. These are the ones you type in.
- A business email address, if you claim a venue. It is checked against the venue's own domain and used to send a one-time verification code.
- What you contribute: venues, meals, prices, descriptions, photos and edits.
- What you report: corrections and reports are free text, plus the item they are about.
And as a result of using the site: your Yum votes, stored one per item against your account identifier, and counters for what you have contributed, which are what badges are awarded from.
What is public, and what is not
This distinction is the one worth being precise about, so here it is in full.
Public — visible to anyone, including search engines and AI crawlers:
- Your scout name, and the venues, meals, prices, descriptions and photos you contribute under it.
- Your badges and any city you are an ambassador for.
- The record that reserves your scout name. It ties that name to your account identifier and is readable by anyone, because that is what stops two people claiming the same name.
Not public — readable only by you and by site administrators:
- Your email address and the rest of your profile record.
- Which items you have Yum-voted for. Vote counts are public; who voted is not.
- Corrections and reports you file. These are free text written by a member of the public about a named business, so they go to moderators only — and, for a correction about a venue, to that venue's verified owner.
Contributions are meant to last. Once a price is on the map, other people rely on it, so removing your account does not remove what you contributed. We can detach your name from it — see “Your rights”.
Why we process it, and our legal basis
- To run the map, attribute contributions and keep voting to one vote per person — our legitimate interests in operating a community-built site that people can trust.
- To prevent spam, vote manipulation, fraud and abuse — our legitimate interests in keeping the map honest and available.
- To act on corrections and reports, and to keep a record of moderation decisions — our legitimate interests in a usable moderation process.
- To sign you in with Google, connect a social account, or verify a venue claim — your consent, given by choosing to do it. You can withdraw it by disconnecting or by asking us.
- To meet legal obligations where they apply to us.
Where we rely on legitimate interests, we have considered the effect on you: everything above is either strictly needed to make the feature work or is there to protect other people using the site, and none of it is used to profile or advertise to you.
Who else processes it
We use a small number of providers, and each one only gets what it needs:
- Google (Firebase Authentication, Cloud Firestore, Cloud Functions, App Check and reCAPTCHA) — accounts, the database itself, venue-claim verification and abuse prevention.
- Amazon Web Services — hosting and content delivery for the site.
- Sentry — error reports, when error reporting is enabled on a build.
- CARTO and the OpenStreetMap Foundation — map tiles and address lookups.
- An email delivery provider — the one-time codes sent to a venue's own address during a claim.
We do not sell personal data, and we do not share it with advertisers or data brokers. We may disclose information where the law requires it, or where it is necessary to investigate abuse of the site.
Some of these providers process data outside the UK. Where that happens, the transfer is covered by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
- The anonymous account identifier stays in your browser until you clear your site data.
- Your profile record and its counters are kept while your account exists, and deleted when you ask us to delete it.
- Contributions stay published, because the map depends on them. On request we replace the scout name attached to them with an anonymous credit.
- Corrections and reports are kept for twelve months after they are closed, so that repeated problems with the same venue can be recognised.
- Error reports are kept for ninety days.
- Server and delivery logs are kept for a short period by our providers, in line with their own retention settings.
Cookies and local storage
There are no advertising cookies and no analytics cookies on this site, which is why you are not being asked to consent to any.
What is stored in your browser is what the site cannot work without: your Firebase Authentication session, held in local storage so you are not signed out between visits, and storage set by Google reCAPTCHA for abuse prevention. Map tiles are cached by your browser in the ordinary way.
You can clear all of it through your browser's site-data controls. Doing so signs you out and, for an anonymous account, ends it permanently.
Your rights
Under UK data protection law you have the right to ask us for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we relied on it.
Write to privacy@yumma.co.uk and we will answer within one month.
One honest limitation: for an anonymous account we hold nothing that identifies you, so an email alone does not show that the account is yours. We will usually ask you to demonstrate control of it from the browser it lives in. We would rather ask you for that than hand somebody else your data on request.
If you think we have got this wrong, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to fix it first.
Children
Yumma is not aimed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us at privacy@yumma.co.uk and we will remove it.
Changes to this notice
When this notice changes, the date at the top changes with it. If a change materially affects how we handle your data, we will say so on the site rather than leaving you to notice.
Questions about any of this: privacy@yumma.co.uk.