Privacy Policy
Effective: 7 May 2026 · Last updated: 31 August 2026
This Privacy Policy describes how Be My Guest B.V. ("Be My Guest", "we", "us", or "our") collects, uses, and shares personal data when you use our website at bemyguest.community and related services (together, the "Service").
We respect your privacy. This document explains what we do with your data, why we do it, and what rights you have. If anything is unclear, write to [email protected].
1. Who we are
Be My Guest B.V. is a private limited company registered in the Netherlands.
- Company: Be My Guest B.V.
- Chamber of Commerce (KvK): 93859449
- Address: Marnixstraat 94-1, 1015 VZ Amsterdam, the Netherlands
- Privacy contact: [email protected]
- General contact: [email protected]
We are the data controller for personal data processed via the Service.
2. Data we collect
2.1 Data you give us
When you create an account or use the Service, we may collect:
- Account data: name, email address, profile photo (optional)
- Authentication data: if you sign in with Google (or Apple, when that option is enabled), we receive your name and email address from those providers
- Profile preferences: taste preferences, dietary requirements, favourite cuisines (optional, only if you provide them)
- Your city: the city you tell us you go out to eat in, stored as the city name and the coordinates of that city's centre. We use it to sort places by how far they are from you. It is a city, never a street address, and you can change or remove it in your settings at any time.
- User-generated content: venues you save to lists, recommendations, notes, and reviews you write
- Communications: messages you send us via email or feedback forms
- Waiting-list email address: if you join the waiting list before we open, we store the email address you enter, the language you were browsing in, and which page you signed up from. We use it for one thing — to tell you when Be My Guest opens — and for nothing else. You do not need an account for it. The address is also added to a waiting-list audience at Resend, the processor that sends the email on our behalf (see Section 5); we never sell it and we never share it with anyone else for their own marketing. You can ask us to delete it at any time at [email protected], and we delete the whole list once everyone on it has been invited.
2.2 Data we collect automatically
When you use the Service we automatically collect:
- Device and browser data: device type, operating system, browser type, screen size
- Usage data: pages visited, features used, time on the Service, referring pages
- Approximate location: derived from your IP address (city level only). Our network provider also tells us which country a request comes from, which we use to decide which country Discover opens on when you have not set a default area yourself. That country is used for that one decision and is not stored.
We do not track your device location in the background. Your precise location is only used when you ask for it — by pressing the locate button on a map, or by sorting a list by "nearest". Your browser then asks for your permission, and you can refuse or withdraw it at any time in your browser settings.
When you do grant it:
- the position is rounded to roughly 100 metres before it leaves your device;
- it is sent with that request so our server can work out which places are closest, and is not stored in our database;
- it is kept in your browser tab only, and is forgotten when you close it.
- Cookies and similar technologies: see Section 7 below
2.3 Data from third parties
- Authentication services: Google (and Apple, if that option is enabled) — if you sign in via these providers they share your name and email address with us
- Google Maps saved lists: if you choose to import your saved places, you authorise us (through Google's Data Portability API) to receive a copy of your Google Maps saved lists. We use this only to recreate those lists in Be My Guest and delete the exported copy once the import finishes. You can disconnect at any time in your Google account settings.
- Map services: interactive maps are powered by Protomaps; your IP address reaches Protomaps servers when map tiles are loaded. Map font glyphs are served from Cloudflare R2 (EU region).
2.4 Google user data (Google Data Portability API)
If you choose to import your Google Maps saved lists, Be My Guest accesses a limited part of your Google Account through Google's Data Portability API. This section describes that processing in full.
- What we access. With your explicit authorization, we access your Google
Maps saved lists (your saved places and collections) via the Data
Portability scope
https://www.googleapis.com/auth/dataportability.saved.collections. We access no other Google data — not your email, contacts, location history, or any other Maps activity. - How we use it. We use this data solely to recreate your saved lists inside Be My Guest: matching each saved place to a venue and adding it to a list on your account. We do not use your Google user data for advertising, we do not sell it, and we do not use it to develop, improve, or train generalised artificial-intelligence or machine-learning models.
- Who we share it with. We do not share, transfer, or disclose your Google user data to third parties, except: (a) the infrastructure providers that host the Service on our behalf — Hetzner (servers and database, Germany) and Cloudflare (encrypted database backups and photo storage, EU) — which process it only to run the Service; and (b) to match your saved places to venues, a place's name may be sent to the Google Places API. We never sell this data or share it for advertising.
- How we protect it. All data is transferred over encrypted connections (TLS/HTTPS). The temporary Google authorization token used to fetch your export is kept only for the duration of the import and deleted as soon as it completes or fails; any longer-lived authorization credential is encrypted at rest. Access is restricted to the systems that perform the import.
- Data retention and deletion. We do not keep a copy of the raw archive Google produces — it is processed only to create your import. The imported places (and any notes on them) become lists on your Be My Guest account and are kept as part of your account until you delete them or delete your account. Places in your export that are not food and drink are set aside during the import so that you can review them and correct us if we got one wrong; we delete them when you finish the import, and at the latest seven days after the check runs if you never come back to it. The only exception is a place you yourself tell us is not food and drink after we had kept it: we retain that correction so we can stop making the same mistake. We delete the Google authorization when the import finishes or fails, and you can revoke Be My Guest's access at any time in your Google Account at myaccount.google.com/connections.
- Limited Use. Be My Guest's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use your data
We use your personal data to:
- provide, maintain, and improve the Service,
- create and manage your account,
- personalise recommendations based on your preferences,
- send essential service emails (account confirmation, password reset, important updates),
- respond to your questions and provide support,
- analyse usage patterns to improve the Service,
- prevent fraud and abuse, and safeguard security,
- comply with legal obligations.
We do not sell your personal data. We do not use your data for third-party advertising.
4. Legal basis for processing (GDPR)
Under the General Data Protection Regulation (GDPR) we rely on the following legal bases:
- Performance of a contract: to deliver the Service you signed up for
- Legitimate interests: to improve the Service, prevent fraud, and analyse usage. Our interests are weighed against your rights.
- Consent: for marketing communications, certain cookies, and optional features. You can withdraw consent at any time.
- Legal obligation: where required under Dutch or EU law
5. Who we share your data with
We share your personal data only as described below:
Service providers (processors): companies that help us operate the Service. These include:
- BetterAuth (authentication and session management, runs within our own infrastructure)
- Hetzner Online GmbH (website hosting and database hosting) — servers in Germany. Both the application and the database run on infrastructure we operate ourselves at Hetzner.
- Cloudflare (encrypted database backups, photo storage, DNS) — database backups are stored in Cloudflare R2. They are encrypted by us before they leave our servers, so Cloudflare holds ciphertext it cannot read.
- Google (Google Sign-In, Google Places, Google Data Portability, Gemini API) — when you sign in with Google they process your account information; venue photos and place data come via the Google Places API. If you import your Google Maps saved lists, the Google Data Portability API delivers a copy of those lists to us at your request. We also use the Gemini API as an editorial tool to transcribe dish names off photos of restaurant menus that our team has curated; this processes business content (menus, dishes, prices) only — no user data is sent to Gemini. GDPR-compliant. Apple Sign-In is handled similarly when that option is enabled. If you import your Google Maps saved lists via the Google Data Portability API, that data is used only to build your lists and is not shared further — see Section 2.4.
- Protomaps (interactive maps) — map tiles are served by Protomaps; your IP address reaches Protomaps servers when you load a map. Protomaps's privacy policy applies to those requests.
- Cloudflare R2 (map font glyphs) — glyph assets used for map labels are served from Cloudflare's R2 object storage; your IP address reaches Cloudflare when map labels render.
- Image CDN (venue photos) — photos are hosted on a cloud storage provider (S3-compatible); your IP address reaches the CDN when photos load.
- Resend (transactional emails — account confirmation, password reset — and the pre-launch waiting-list audience) — GDPR-compliant
- Expo (EAS Update) (mobile app over-the-air updates) — when the mobile app
checks for and downloads app updates on launch, your device's IP address
reaches Expo's update servers (
u.expo.dev). Based in the United States.
Legal obligations: where required by law, court order, or to protect our rights, users, or the public.
Business transfers: if Be My Guest B.V. is acquired or merged, your data may be transferred to the new entity (you will be notified).
We do not share your data with third parties for their own marketing purposes.
6. International data transfers
Some of our service providers are based outside the European Economic Area (EEA), primarily in the United States. When we transfer personal data outside the EEA we ensure appropriate safeguards, including:
- Standard Contractual Clauses approved by the European Commission,
- service providers certified under recognised data protection frameworks,
- encryption in transit and at rest.
7. Cookies and similar technologies
We use cookies and similar technologies for:
- Strictly necessary: keep you signed in, remember your preferences (cannot be disabled)
- Analytics: understand how the Service is used (only with your consent)
- Functional: improve your experience (e.g. remember which filters you selected)
You can manage your cookie preferences via our cookie banner or your browser settings. Disabling certain cookies may affect functionality.
8. How long we keep your data
- Account data: as long as your account is active
- Usage logs: up to 24 months
- Marketing email subscribers: until you unsubscribe
- Imported Google data: the raw Google export is not retained; imported lists are kept as part of your account, and the Google authorization token is deleted as soon as the import finishes (see Section 2.4). Places set aside as not food and drink are deleted when you finish the import, and at the latest seven days after the check runs
- After account deletion: we erase your personal data within 30 days, except where we are legally required to retain certain data
9. Your rights under the GDPR
As a user in the European Union, you have the following rights:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): request deletion of your data
- Right to restriction: limit how we use your data
- Right to portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interest
- Right to withdraw consent: when processing is based on consent
- Right to lodge a complaint: with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl)
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. How to delete your account
You can delete your account at any time:
- Via the Service: Profile → Settings → Delete account
- By email: send a message to [email protected] with the subject "Delete account"
We will delete your account and personal data within 30 days. Some data may be retained where legally required or for legitimate business purposes (such as fraud prevention or tax reporting), but only for as long as necessary.
11. Children's privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal data from children under 16. If you discover that a child has provided us with personal data, please contact [email protected] and we will take steps to delete it.
12. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- encryption in transit (HTTPS/TLS) and at rest,
- secure authentication via BetterAuth (session tokens as HttpOnly cookies),
- access controls limiting who can view personal data,
- regular security reviews.
No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the competent authorities as required by law.
13. Third-party links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We recommend reading their privacy policies before providing personal information.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you at least 30 days before they take effect via email or a prominent in-app notice. The "Last updated" date at the top of this document indicates when the most recent changes were made.
15. Contact
For questions, concerns, or requests about this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- Postal: Be My Guest B.V., Marnixstraat 94-1, 1015 VZ Amsterdam, the Netherlands
You also have the right to lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.