Skip to content
foodfinder.
Explore♡Saved placesShare a place

Your information, explained

Privacy Policy

Last updated: October 6, 2026

FoodFinder is an independent community food directory maintained by MM. This policy explains the information used by this website, the services involved, and your choices. It applies to FoodFinder itself, not to restaurants or websites you visit through our links.

1. Browsing and searching

You can browse without creating an account. The bundled starter directory, category filters, food-name filtering as you type, and city-name search run in your browser. FoodFinder does not include advertising pixels or Google Analytics. Our hosting provider may process standard request information, such as your IP address, browser information, requested pages and timestamps, to deliver and protect the site.

2. Live city searches and location

When you choose a town, load nearby places, or change the radius for a selected location, your browser requests restaurant data from the configured public Overpass services. A backup provider may be tried if the first service fails. That service receives the search-center coordinates and ordinary connection information, including your IP address and referring site. The area request sends the selected radius and coordinates, not the food name, restaurant name or cuisine filter. Those filters run locally over the loaded collection. We keep a limited cache of recent searches on your device to reduce repeated requests.

Opening the directory requests your current location to load the default 3-mile area, subject to your browser permission. Near me updates this location. You can deny permission and choose a town instead. Your coordinates are rounded to four decimal places and used as the live search center, which is sent to the search provider. Nearby-search coordinates and results may remain in the local cache. We do not send them to the FoodFinder database. You can decline permission and select a city instead. Your browser or operating system may use its own location services, governed by its privacy settings.

3. Maps and outside links

Map tiles are loaded from OpenStreetMap only when you open the map. The tile provider receives your IP address and the map areas requested. Directions open Google Maps with the destination; the destination service may request your origin separately. Venue websites, telephone links, OpenStreetMap source pages, and Stripe support links operate under their own policies. We do not receive your card details. We do not control those services.

Choosing “Search this food in Google Maps” opens Google with the food term and selected search coordinates (or “near me” if no center is selected). Google handles that visit under its own privacy policy.

4. Local storage

Saved places and up to six recent location/radius collections are stored in your browser’s local storage. Search results are reused for up to 24 hours before a new request is needed, but the stored copy can remain until replaced or cleared. Favorites remain until you remove them or clear your browser data. These items are specific to this browser and do not sync to an account. FoodFinder does not use its own advertising or tracking cookies. Providers may use their own necessary storage when you sign in or visit their services.

5. Sign-in and private messages

Google sign-in is used for private messages and administrator access. Firebase Authentication processes account identifiers and sign-in information; your Google email and verification status are available to the authentication service. FoodFinder does not ask for or receive your Google password. The app keeps its sign-in session in memory in the current tab, rather than deliberately persisting it in browser storage. Your underlying Google sign-in may remain active separately.

A submitted note stores your Firebase user ID, subject, selected request type, city, optional link, message, timestamps and review status. It does not store your email in the note. Notes are readable only by their authenticated sender and approved administrators under our database rules. They go to the site’s private admin inbox, not to an email mailing list. You may have one pending note at a time. Please do not include financial information, passwords, identity documents, private home addresses or other sensitive information.

6. Public listings and images

Place information comes from attributed open data and administrator-reviewed entries. A suggestion is not published automatically. If the editor adds a listing, its business name, public address, coordinates, public contact details, description, menu link, listed dishes, hours and approved image become public. A business does not need a website to be listed. Submit only material you are entitled to share.

Administrator-uploaded images are converted locally to a small WebP before storage. Conversion normally removes embedded metadata; administrators should still inspect the visible image for personal information. Original uploads are not sent by this app. Image conversion does not make the pictured content anonymous.

Result cards may show editor-uploaded images or selected images hosted by the venue’s official website. Loading a website image sends an ordinary image request, including your IP address, to that website or its image host. These images use a no-referrer policy. Source links identify the venue website. If a photo fails, a decorative illustration appears instead.

7. Purposes and legal grounds

We use information to operate the directory, provide requested features, review corrections, prevent misuse and respond to privacy requests. Where a lawful basis is required, these activities may rely on our legitimate interests in operating a useful and secure directory, steps needed to provide a requested service, applicable legal obligations, or consent where appropriate, such as your choice to share device location. We do not sell personal information or use it for targeted advertising.

8. Retention and deletion

Public listings remain until corrected, archived or removed. There is no automatic expiry date. Notes remain until you delete them or an administrator removes them. Our intended administrative practice is to review and delete resolved notes within 90 days; this is a manual process, not an automatic deletion guarantee. Account records and provider security logs may remain under the providers’ retention settings and legal requirements. Local data can be cleared using the button above. Copies already made by third parties or search engines may not disappear immediately.

9. Access, correction and requests

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or to object to certain processing, withdraw consent, or complain to a relevant data protection authority. Use Contact / corrections and select “Privacy / data request.” You can also delete your own submitted note there. An editor may need reasonable information to verify a request. Deleting a note does not delete your Google account or automatically remove an already published business listing; identify that listing in your request.

If online submissions are temporarily unavailable, please return when the service is restored. This site does not expose administrators’ private email addresses. Privacy requests are handled by the directory operator through the private inbox.

10. Security and international processing

We use HTTPS, verified Google authentication, restricted database rules and short administrator sessions. No service can guarantee complete security. Hosting and authentication/database services are provided through Google Firebase and may involve international processing. OpenStreetMap/Overpass and Stripe are separate providers. Their terms, safeguards and infrastructure also apply.

11. Children and policy changes

The site is a general-audience directory and is not intended to collect personal information from children under 13 or the applicable minimum age for consent. A parent or guardian may request removal through the privacy form. We may update this policy when the site changes; the date above identifies the current version.

Related provider information: Firebase privacy and security, Google Privacy Policy, OpenStreetMap Foundation Privacy Policy, Stripe Privacy Policy. The configured Overpass operator may have its own policies.

foodfinder.

Good food brings us a little closer.
A small guide to your next delicious stop.

Like what’s on the menu?

Help keep this little project going.

☕ Coffee $5🍔 Burger $10🍲 Big meal $15♡ Donation / charity
Optional support via Stripe. Check the recipient and amount at checkout.
Made by MM ♥ · © 2026
PrivacyTermsContact / correctionsAdmin

Place data © OpenStreetMap contributors · ODbL · City data: GeoNames (CC BY 4.0). Download starter data. Illustrations are decorative, not venue photographs.