Privacy Policy
This policy covers pleet.org and the Ocean Conscious Restaurants mobile app (together, "Pleet", "we", "us"). It explains what we collect, why, who else sees it, and how to have it removed.
We do not sell personal information.
What we collect
Account details. If you create an account we store a username, an email address, and a hashed password. We never store your password itself. Your username is shown publicly next to any comments you leave.
What you contribute. Ratings you submit, restaurants you add, comments you write, and restaurants you save. Ratings and comments are public. Saved restaurants are private to your account.
Location, only while you are using the app. If you allow it, the mobile app reads your device location to show restaurants near you and sort them by distance. It is requested only while the app is in the foreground, it is used to build the query and is not stored on our servers, and you can decline it — the directory still works, it just is not sorted by distance. On the website, location is read by your browser only if you press "Near me", and is subject to your browser's own permission prompt.
Technical information. Like any web service, our servers receive your IP address and browser or device user agent as part of each request. We use these to apply rate limits and to diagnose faults.
We do not collect payment details, precise background location, contacts, photographs, health data, or anything from your device beyond what is described here.
Advertising
The mobile app shows advertising through Google AdMob. The website does not show ads.
On iOS, the app asks for your permission before allowing tracking, using Apple's App Tracking Transparency prompt. If you decline, ads are still shown but are not personalised using your device's advertising identifier. You can change this at any time in your device settings.
Google acts as an independent controller of the data it collects for advertising. Their handling is covered by Google's privacy policy.
Who else sees your data
| Who | What they receive | Why |
|---|---|---|
| Google Places | The restaurant name and coordinates you search for when adding a restaurant | To look up the restaurant's official details |
| Google AdMob | Advertising identifiers and ad interaction data, in the mobile app only | To serve advertising |
| Our hosting provider | Everything above, as the operator of our servers | To run the service |
Restaurant certification data flows the other way: it is sourced from the Surfrider Foundation's Ocean Friendly Restaurants program. We do not send them your personal information.
We will disclose information if we are legally required to, or where it is necessary to protect someone's safety.
How long we keep it
Account details and contributions are kept while your account exists. Server logs containing IP addresses are kept for a short operational period and then discarded.
Deleting your account
You can delete your account yourself, at any time, without contacting us:
- In the app: You → About → Delete account
- On the website: Account → Delete account
Deleting removes your account and sign-in details, your saved restaurants, and your ratings and comments. Scores are recalculated without your ratings.
Restaurants you added stay in the directory so other people can still find them, but they are no longer linked to you. We keep them because they are factual records about a business rather than information about you, and removing them would degrade a shared public resource.
If you would rather we did it for you, or you want a copy of your data first, email us — see Support.
Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. The deletion route above covers most of this directly. For anything else, contact us and we will respond.
Children
PLEET is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has created an account, contact us and we will remove it.
Security
Traffic to our servers is encrypted in transit. Passwords are stored hashed. Access tokens issued to the website are held in a cookie that JavaScript cannot read, and are never exposed to the page.
No service can promise perfect security, and we do not.
Changes
If we change this policy we will update the date at the top of this page. Material changes will be announced in the app and on the website.
Contact
Questions about this policy, or a request about your data: see Support for how to reach us.