The short version
- Alcohol Ltd operates Bars.co.uk and is responsible for the personal information described here.
- We do not sell personal information, build advertising profiles, or use private reports to rank venues.
- Private mediation content stays separate from public venue pages.
- We do not use personal information or Private Material to train, test or improve any Alcohol Ltd or third-party artificial-intelligence model.
- Wider reuse of non-personal public content needs a separate, optional choice.
- Optional Google Analytics stays off until you actively allow it.
- You can contact us about your information or make a data-protection complaint.
1. Who controls your personal information
Alcohol Ltd, trading as Bars.co.uk, is the data controller for the processing described in this policy. Alcohol Ltd is registered in England and Wales under company number 04854930. Its registered office is The Limes, Bayshill Road, Cheltenham, England, GL50 3AW.
Email privacy@bars.co.uk for privacy questions, rights requests or complaints. The image-report link uses report@booze.co.uk, an Alcohol Ltd inbox used to check wrong or outdated venue images.
This policy applies to Bars.co.uk public pages, venue accounts, claims, certification and audits, community profiles, corrections and appeals, the venue page API, maps, reports, mediation, feedback, support and optional analytics. A short notice beside a form may give extra detail for that particular use.
We follow UK data protection law, including the UK GDPR and Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025.
2. The information we collect and where it comes from
Public venue and place information. Venue name, address, location, business type, food hygiene details and source dates from the Food Standards Agency, local authorities and other identified public sources. Place context and nearby locations may come from Wikipedia, OpenStreetMap and related licensed sources. Geograph may supply a licensed venue photo, photographer, date, location and image ID.
Venue accounts and claims. Name, work contact details, organisation, role, sign-in and security events, authority to represent a venue, claim evidence, communications and account choices.
Certification, audits and community profiles. Answers, declarations, supporting documents, review decisions, appeals, staff-count bands, community features, text, public captions, photos and videos. We keep private evidence separate from the reviewed public result.
Corrections, image reports and support. Your contact details, the page or record concerned, what you believe is wrong, supporting information, our checks, replies and outcome.
Reports and mediation. The selected venue; broad issue type; when it happened; whether it is ongoing; your description, steps already taken and outcome sought; name and email; optional phone number; whether you want to be unnamed to the venue; safety and access needs; messages, proposals, agreements, evidence visibility choices, feedback, delivery status and authorised staff-access records.
Optional nearby-area suggestion. If you select Use my location on the homepage, your browser provides temporary device coordinates to the page. The page compares them with published locations inside your browser. Alcohol Ltd's servers do not receive, log or store the coordinates, and the homepage does not load Google Analytics. Only the suggested place name is placed in the search box, and you decide whether to search.
Technical and service information. Network address, browser and device details, request time, page requested, security events, session and consent choices, API or map quota identifiers, and error records. If you allow analytics, Google also receives the limited information described below.
We receive information from you, another mediation participant, an authorised venue representative, our staff or reviewers, public bodies and public data sources, licensed media providers, service providers, and the systems used to deliver and protect the service. If someone gives us information about another person, they must have a lawful reason to do so.
3. Why we use information and our legal reasons
UK data protection law requires a lawful basis for each purpose. We do not rely on one basis for everything.
Provide an account or venue service you request — contract or steps at your request before a contract. We use account, venue claim, application and business-support information to create access, confirm authority, assess an application, communicate about the service and keep the record you need. If required information is not supplied, we may be unable to provide that feature.
Run a clear and reliable public venue service — legitimate interests. We use sourced venue information, correction records, public provenance and limited business-contact information to help people find venues and understand where facts came from. Our interests are operating an accurate, fair and useful public service, preventing misleading records and protecting editorial integrity. We balance these interests against the rights of people named in records, particularly sole traders and small operators.
Suggest a nearby covered area — legitimate interests. After you ask to use your location, the homepage compares it with published locations inside your browser. Our interest is helping you find relevant venue pages. Keeping the coordinates on your device, discarding them with the page and always offering town, postcode and city links limits the privacy impact.
Verify claims, moderate content and protect the service — legitimate interests. We use security logs, authority checks, rate limits, audit records, complaints and restricted evidence to prevent fraud, impersonation, misuse, unlawful content and unauthorised access. Our interests are protecting users, Alcohol Ltd, venues, data sources and the reliability of the service.
Handle eligible community reports and mediation — legitimate interests. We use report and case information to verify the reporter's email, match the correct venue, share only the material authorised for the other party, support a conversation, record proposals and apply safety rules. Our interests are providing a fair, secure and accountable way to resolve eligible community issues, protecting both parties and keeping a reliable record. We consider each participant's rights before using this basis. Consent to publish a short record is separate; it is not the basis for all private case processing.
Optional publication and analytics — consent. We rely on a clear choice for optional Google Analytics and for any public mediation summary or jointly approved public outcome that identifies or could reasonably relate to a person. You can withdraw consent for future use without affecting lawful processing that already happened.
Publish venue-supplied content — contract and legitimate interests. We use text, captions and media deliberately submitted for public display to review, moderate, make accessible and publish the venue profile requested. Our interests are maintaining useful, traceable public venue information and protecting its integrity. The intellectual-property licence in our Terms of service gives permission to use protected content; it is not, by itself, a data-protection lawful basis.
Optional research, internal tools and paid data products. These separate choices apply only to the selected Public Contribution after Personal Data and Private Material have been excluded. We record the exact choice and notice version. We do not treat an intellectual-property licence or a venue representative's permission as permission to reuse another person's personal information.
Use properly anonymised information. Information that has been effectively anonymised so nobody is identifiable is no longer personal information. We may use those anonymous totals for service improvement, research, business planning and automated tools. Pseudonymised information can still be personal information and is handled under this policy.
Meet legal duties and handle claims — legal obligation and legitimate interests. We may use information to answer a lawful request, protect legal rights, keep required company or tax records, investigate a data-protection complaint, or establish, exercise or defend legal claims.
Protect life and safety — vital interests or another lawful safety basis. In a genuine emergency, we may use or share the minimum information needed to protect someone's life or physical safety.
We do not use report content, private evidence or feedback to create a public or hidden complaint score. We do not sell personal information, use it for third-party advertising, or use Personal Data or Private Material to train, fine-tune, test, benchmark or improve any artificial-intelligence model, whether operated by Alcohol Ltd or a third party.
4. Sensitive information, alleged offences and children
A report or accessibility request can reveal health, disability, race, religion, sexual orientation or other special-category information. It can also include allegations about criminal behaviour, such as assault, drink spiking, theft or harassment.
We ask people not to provide sensitive information unless it is needed and the form requests it. Where we process special-category information, we identify both an Article 6 basis and an additional Article 9 condition. Depending on the situation, this may be explicit consent for an access need, protection of vital interests, or the establishment, exercise or defence of legal claims.
We process information about alleged or proven offences only where UK law authorises it and an applicable Data Protection Act 2018 condition is met. We restrict access, do not use it for venue scoring and do not publish it as part of public issue history.
For a safeguarding need or necessary work to prevent or address an unlawful act, we record the specific UK GDPR and Data Protection Act condition, why the use is necessary and why less sensitive information is not enough. Where the law requires it, we keep an appropriate policy document covering compliance, retention and deletion, and complete a data-protection impact assessment before high-risk production processing starts. If no valid condition applies, we do not keep or share the sensitive information.
Public venue pages can be viewed by people under 18, but venue accounts, reports and mediation participation are for adults. If you are under 18, ask a trusted adult to contact us for you. A report may still need to mention a child for safeguarding reasons. In that case we collect the minimum needed, restrict access and involve specialist or emergency services where appropriate. We do not knowingly use children's information for advertising or analytics profiles.
5. What can become public
Public pages may show official venue and location facts, source and update dates, information supplied by the venue, a chain or group relationship, broad staff-count bands, reviewed community text and media, a licensed Geograph photo, certification status, score-area totals, expiry, method version and a checked audit summary.
We label official-source, venue-supplied, licensed and Bars.co.uk information separately. Public pages can be indexed by search engines, quoted, archived or cached by other organisations. Removing information from Bars.co.uk cannot guarantee that every independent copy disappears immediately.
We do not publish venue-account contacts, claim evidence, individual certification answers, private audit proof, original private files, staff or customer identities, private mediation identities, case references, messages, offers, agreements, safety answers, feedback or staff notes. The free venue page API does not return this material or the public media, source datasets, scores or report history.
A venue can ask to withdraw venue-supplied public material and any optional wider-reuse permission for future releases or model-development runs. We may keep a restricted decision record, rights record or content fingerprint where reasonably needed. Removal cannot recall an independent cached copy, a dataset copy already lawfully supplied under an optional permission, a completed anonymous research result or information already incorporated into an existing trained model. Removing account-supplied content does not remove independent official data or a lawful editorial record.
6. Reports, mediation and public issue history
Choosing to be unnamed to the venue is not the same as being anonymous to Alcohol Ltd. We still need a working email and may need limited identity information to run the case safely. We do not reveal those identity fields to the venue unless you choose, the law requires it, or a serious safety need makes disclosure lawful and necessary. The venue may still work out who you are from the event or facts you choose to share.
Each party sees the shared case record intended for both sides and their own private submissions. They do not see the other party's private identity fields, private evidence, mediator-only notes or safety-only material. Assigned mediators and authorised specialist staff receive role-limited access that is logged.
A public record can show only a month, broad non-sensitive issue type and simple handling status after we verify the reporter's email, match the venue, notify the venue and complete safety and privacy checks. Choosing this is optional and separate from agreeing to share a case summary privately with the venue.
A public outcome appears only when both parties approve the exact same neutral wording and an authorised privacy reviewer approves it. If anyone edits the wording, both parties must approve it again. A person can withdraw permission for future public display through the private case route or by emailing privacy@bars.co.uk. This removes the Bars.co.uk record but cannot undo a copy someone already made.
A report is a request to resolve an issue. It is not a finding of fault, wrongdoing or legal liability. Unverified, unsafe, repeated, abusive, safeguarding or possible-crime reports stay private or are withheld. We do not publish feedback or use public issue activity to change certification or general ranking.
7. Cookies, device storage, maps, API limits and analytics
Essential access and security. A private mediation session uses a secure, host-bound, HTTP-only cookie for up to eight hours. Short-lived access tokens, security controls and same-origin checks protect private areas. Essential technologies do not require an analytics choice.
Saved drafts. Certification and some form progress can be stored in your browser so you can continue on that device. You can clear it by completing the form, using its reset control, or clearing site data in your browser. Private uploaded files are not placed in public storage merely because you preview them.
Request limits and security logs. Our trusted host provides the network address attached to a request. For the public venue page API and nearby-place map requests, we immediately turn it into a keyed code. The live shared limit keeps that code and short random request entries for about two minutes. Mediation search, verification, recovery, feedback and case actions use separate short-lived protected rate-limit codes. Hosting and security providers may keep limited request logs for their approved security period.
Homepage location choice. The homepage reads your location only after you select Use my location. Your browser asks for permission if it has not already recorded your choice for Bars.co.uk. You can refuse or remove permission in your browser. Coordinates are used only in the open page to suggest a covered area. They do not enter a URL, request, log, cookie, browser-storage record or analytics event, and are discarded when the page closes or reloads.
Maps. Venue and area maps do not use your device location. When a map comes near your screen, your browser contacts OpenFreeMap for map files. OpenFreeMap and its delivery provider receive a normal web request, including network and browser information. Bars.co.uk requests nearby OpenStreetMap places on the server using the published venue or area centre, so your browser does not contact the OpenStreetMap query service.
Optional Google Analytics. Google Analytics stays off until you choose Allow analytics. If you agree, Google receives a manual page view containing a clean public pathname and standard browser and device information. A normal request includes your network address. For UK users, Google says it uses this briefly to derive broad location and then discards it before logging. We remove query strings, fragments, page titles and referrers. We exclude the homepage, searches, reports, private mediation, certification applications, corrections, owner workspaces, staff pages, APIs, media delivery and embeds.
Advertising storage, advertising user data, advertising personalisation and Google Signals stay off. The bars_analytics_consent_v1 choice and accessible Google Analytics cookies last no more than 180 days. Change or withdraw your choice through Analytics choices in the footer; withdrawal stops future loading and removes accessible Google Analytics cookies from this site.
Google processes Analytics information for Alcohol Ltd under its data-processing terms where those terms apply. Google's support and processing systems may operate internationally, so the transfer safeguards described below also apply. Read Google's UK-focused Analytics privacy information.
Public Bars.co.uk widgets do not set cross-site tracking cookies or tell a venue who viewed the page containing a widget.
8. Who receives personal information
We share only what is reasonably needed with:
- the venue or other mediation participant, but only the case information marked for that party;
- authorised Alcohol Ltd staff, assigned mediators, auditors and specialist reviewers under role-based access and confidentiality duties;
- hosting, database, security, authentication, email, object-storage, malware-scanning, backup, monitoring and API-quota providers acting under contract;
- Vercel for website delivery and Upstash for the production public-request limit;
- OpenFreeMap when your browser loads a map and Google only after you allow optional analytics;
- professional advisers, insurers, auditors and potential business buyers where confidentiality and due diligence safeguards apply;
- API or data-product customers only for non-personal Public Contributions covered by the contributor's separate optional paid-data permission and the customer's product terms; and
- courts, regulators, police, safeguarding bodies or other public authorities where disclosure is required by law or is necessary and lawful to protect rights or safety.
Data sources such as the Food Standards Agency, local authorities, OpenStreetMap and Geograph usually supply information to us; we do not routinely send them private user submissions. If you follow an external link, the other site receives a normal web request under its own privacy policy.
We do not give an artificial-intelligence provider Personal Data or Private Material for model training, testing or improvement. A contracted provider may process non-personal Public Contributions for Alcohol Ltd's tools only where the contributor selected the separate research and model-development choice; the provider may not train its own general model with that content.
Key production providers and subprocessors are reviewed before use. If a provider or purpose changes materially, we update this policy and any point-of-collection notice before using personal information in the new way.
9. International transfers
Some providers or their support teams may process information outside the UK. Before a restricted transfer, we check the destination, provider, subprocessors and purpose.
We use a lawful transfer route, such as UK adequacy regulations or an approved safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment where required. We use a legal exception only in the limited circumstances allowed by law.
Email privacy@bars.co.uk to ask about the safeguard used for a particular provider or for information on how to obtain a copy. We may redact commercial or security-sensitive parts.
10. How long we keep information
We keep personal information only for its stated purpose, legal obligations, safety and dispute needs. Our standard schedule is:
- Public-source history: while needed to show provenance, corrections and dated public records, subject to licence and necessity reviews.
- Account details: while active, then direct identifiers are normally removed or separated within 30 days after a verified deletion request.
- Unverified forms and uploads: seven days after creation.
- Expired or used access-token metadata: 30 days after expiry; token plaintext is not retained.
- Private certification, audit, community-media or mediation evidence: 365 days after the relevant case or review closes.
- Closed mediation case content and private feedback: 730 days after final closure.
- Email delivery metadata: 365 days after the event.
- Public API and map quota codes: about two minutes after the last counted request.
- Security and decision audit records: up to 2,190 days, with direct identifiers reduced where possible.
- Google Analytics event data: two months in Google Analytics; consent and accessible analytics cookies last no more than 180 days.
- Encrypted rolling backups: up to 35 days before they age out.
Public Contributions are kept while published and then follow the restricted backup and rights-record periods above. If a contributor withdraws an optional reuse choice, we stop new releases and model-development runs within a reasonable operational period. The limits for content already lawfully supplied, completed anonymous research and existing trained models are shown before the choice is made. Personal information is never kept merely because an intellectual-property licence uses words such as “worldwide” or “royalty-free”.
Publication permissions and device-local drafts follow the rules described above. A legal claim, safeguarding need or documented legal hold may pause deletion for the affected information. We record the reason, owner and review date. When a backup is restored, deletion records are reapplied so expired data is not intentionally returned to live use.
11. Your data-protection rights
Depending on the information and legal basis, you can ask us to:
- give you a copy of your personal information;
- correct inaccurate or incomplete information;
- delete information;
- limit how we use it;
- provide information you gave us in a portable form;
- stop processing based on consent by withdrawing that consent;
- review a qualifying solely automated decision; or
- object to qualifying research, public venue, search, moderation or service-improvement uses based on our legitimate interests.
Your right to object
You may object to processing based on our legitimate interests, including public venue information, moderation, security and service-improvement uses. Tell us your situation and why you object. We will stop unless we have compelling lawful grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
These rights are not absolute. For example, deleting your part of a mediation case must not unlawfully erase the other party's record, and correcting an official-source fact may require the original provider to update it. We can restrict or pseudonymise information instead where that is the lawful response.
Email privacy@bars.co.uk. Say what you want and how the information relates to you. We may ask for proportionate proof of identity and will not disclose another person's private information, security secrets or confidential mediator notes.
We normally respond within one month. A complex or repeated request can take longer where the law allows; if so, we will explain why and when we expect to finish. Requests are normally free, although the law allows a reasonable fee or refusal in limited cases such as manifestly unfounded or excessive requests.
We do not currently make decisions based solely on automated processing that have legal or similarly significant effects on people. Venue scores follow published rules and search can use published relevance signals, but these do not decide a person's legal rights. Certification and moderation decisions have human review and appeal routes.
12. Security, data-protection complaints and contact
We use security measures chosen for the risk and the feature. These include separation between public and private data, encryption, short-lived access, role-based permissions, logged staff access, file checks, rate limits, backups and deletion controls where relevant. We review production providers and access before a private feature opens. No online service can promise absolute security. If a personal-data breach creates a legal duty to notify the Information Commissioner's Office or affected people, we will do so.
To make a data-protection complaint, email privacy@bars.co.uk with the subject “Data protection complaint”, or write to Alcohol Ltd at The Limes, Bayshill Road, Cheltenham, England, GL50 3AW. Tell us what happened, when, which information was involved and what you would like us to do. Do not send private evidence by ordinary email.
We will acknowledge a data-protection complaint within 30 days, investigate it appropriately, keep you informed and give an outcome without undue delay. You can also complain to the Information Commissioner's Office, the UK data protection regulator. You do not have to contact us first, but giving us a chance to resolve the issue may be quicker.
We review this policy when the service, law, providers or data uses change. We update the date above and give a prominent or direct notice before a material new use where required. Earlier versions remain in our policy record.