Polityka Prywatności
Aplikacja mobilna i serwis www.chapaj.pl
Najważniejsze informacje
- Dokładna lokalizacja nie jest trwale zapisywana.
- Część profilu, opinie i liczba znajomych są publiczne, także dla osób niezalogowanych.
- Marketingowe profilowanie i komunikacja promocyjna mają osobne przełączniki.
- Konto można usunąć z 3-dniowym okresem na anulowanie.
1. O dokumencie
Niniejsza Polityka wyjaśnia, jak dane osobowe są przetwarzane w aplikacji Chapaj i serwisie www.chapaj.pl. Dotyczy użytkowników, osób przeglądających treści publiczne oraz restauratorów korzystających z przeznaczonych dla nich funkcji.
Polityka jest aktualizowana po istotnych zmianach funkcji, dostawców lub sposobów przetwarzania danych.
2. Administrator i kontakt
Administratorem danych osobowych jest Maciej Kuświk, działający jako osoba fizyczna, Warszawa, Polska.
E-mail w sprawach prywatności i realizacji praw: ppriv@chapaj.pl. Strona: www.chapaj.pl.
Administrator nie wyznaczył inspektora ochrony danych. W sprawach prywatności należy korzystać z powyższego adresu e-mail.
3. Jakie dane przetwarzamy
W zależności od sposobu korzystania z Chapaj mogą to być:
- dane konta i uwierzytelniania: adres e-mail, identyfikator konta, informacje o sesji, daty logowania i jednorazowe kody logowania ważne przez 10 minut;
- ustalenie nicku (nazwy wyświetlanej) jest wymagane przy tworzeniu konta.
- dane profilu: nick (nazwa wyświetlana), unikalny identyfikator (@), opcjonalne imię, avatar, wybrane miasto oraz ustawienia; nazwę wyświetlaną można zmienić najwyżej raz na 30 dni, a identyfikator (@) jest ustalany jednorazowo;
- dane społecznościowe: zaproszenia, zaakceptowane relacje i publiczna liczba znajomych;
- aktywność i preferencje: wyszukiwania, kliknięcia, czas oglądania, polubienia, zapisane restauracje, ulubione potrawy i kuchnie, deklarowane wizyty, oceny, tagi, aktywność znajomych oraz historia rekomendacji;
- treści: opinie, nazwa dania i restauracji, ocena, data, tagi i opcjonalne zdjęcie;
- lokalizacja: dokładne współrzędne przetwarzane chwilowo podczas używania aplikacji, ręcznie wybrane miasto oraz — gdy użytkownik włączy powiadomienia i zgodę na lokalizację — przybliżony obszar (dzielnica) wyznaczony z lokalizacji;
- dane techniczne i bezpieczeństwa: adres IP, urządzenie, system, wersja aplikacji, user-agent, identyfikatory sesji, znaczniki czasu, endpointy, token powiadomień push (gdy powiadomienia są włączone), błędy i nieudane próby logowania;
- ustawienia zgód, personalizacji i komunikacji oraz dowody ich udzielenia lub wycofania;
- dane moderacyjne: zgłoszenia treści (kto zgłosił, czego dotyczy i z jakiego powodu) oraz blokady użytkowników (kto kogo zablokował);
- dane restauracji i kont restauratorów: dane kontaktowe i konta oraz treści profilu restauracji, w tym nazwa, adres, godziny otwarcia, średnia cena, menu, zdjęcia i ustawienia sponsorowania.
4. Cele i podstawy prawne
Dane są przetwarzane w następujących celach:
- utworzenie i obsługa konta, logowanie, wyszukiwanie lokali, mapy, odległości, profile, znajomi, opinie, zapisane lokale i powiadomienia funkcjonalne – w celu wykonania umowy lub podjęcia działań na żądanie użytkownika (art. 6 ust. 1 lit. b RODO);
- dobrowolne funkcje wymagające zgody, w szczególności personalizacja marketingowa, spersonalizowane treści sponsorowane i komunikacja promocyjna – na podstawie zgody (art. 6 ust. 1 lit. a RODO), którą można wycofać w dowolnym momencie;
- bezpieczeństwo, zapobieganie nadużyciom, moderacja treści (obsługa zgłoszeń i blokad), diagnostyka, dochodzenie i obrona roszczeń, podstawowe statystyki oraz ulepszanie usługi – na podstawie prawnie uzasadnionych interesów administratora (art. 6 ust. 1 lit. f RODO);
- wykonanie obowiązków wynikających z prawa, w tym reagowanie na zgłoszenia treści bezprawnych, obsługa żądań i prowadzenie wymaganej dokumentacji – art. 6 ust. 1 lit. c RODO.
Gdy przetwarzanie jest konieczne do świadczenia funkcji, brak danych może uniemożliwić użycie tej funkcji. Lokalizacja, dostęp do zdjęć oraz powiadomienia push są opcjonalne; aplikacji można używać z miastem wybranym ręcznie.
5. Logowanie, profile i widoczność publiczna
Logowanie odbywa się za pomocą adresu e-mail i jednorazowego kodu przesyłanego przez Resend albo przez konto Google lub „Zaloguj się przez Apple”. Przy logowaniu Google lub Apple dostawca przekazuje nam adres e-mail i identyfikator konta; w opcji „Zaloguj się przez Apple” może to być adres przekazujący, jeśli użytkownik wybierze „Ukryj mój e-mail”. Adres e-mail i dane logowania nie są publiczne.
Część danych profilu publicznego, takich jak nick, imię, zdjęcie lub awatar, liczba znajomych oraz podstawowe statystyki, może być widoczna dla innych użytkowników aplikacji. Lista Twoich znajomych jest widoczna wyłącznie dla Twoich znajomych. Publicznie dostępna jest jedynie ich liczba, bez tożsamości. W przypadku profili publicznych wybrane informacje mogą być również widoczne dla osób, które nie są zalogowane do aplikacji, na przykład podczas przeglądania publicznych stron lub ekranów profilu.
Opinie i związane z nimi dane autora mogą być oglądane bez konta. Nie należy umieszczać w nicku, imieniu, avatarze, opinii ani zdjęciu informacji, których użytkownik nie chce ujawniać publicznie.
6. Znajomi i funkcje społecznościowe
Użytkownicy mogą wyszukiwać inne osoby po nicku, wysyłać i akceptować zaproszenia oraz przeglądać relacje społeczne. Bez zaakceptowania relacji profile nie mają bezpośredniego kanału kontaktu. Dane o znajomych mogą wpływać na zwykłe rekomendacje, lecz nie są przekazywane sponsorom jako dane jednostkowe ani używane do reklam sponsorowanych.
7. Lokalizacja i mapy
Po udzieleniu uprawnienia Chapaj pobiera dokładną lokalizację wyłącznie podczas używania aplikacji, aby wyszukiwać lokale w pobliżu i obliczać odległość. Współrzędne są przetwarzane tylko na czas zapytania lub sesji i nie powstaje trwała historia dokładnych współrzędnych.
Użytkownik może odmówić dostępu do GPS i wybrać miasto ręcznie. Aplikacja może przechowywać wybrane miasto, zapisane restauracje, deklarowane wizyty i moment wyszukiwania bez dokładnych współrzędnych.
Jeżeli użytkownik włączy powiadomienia i wyrazi zgodę na lokalizację, aplikacja wyznacza z jego lokalizacji przybliżony obszar (dzielnicę, np. „Mokotów”) i zapisuje go trwale, aby lepiej dobierać powiadomienia do okolicy. Nie zapisujemy przy tym surowych współrzędnych. Obszar jest usuwany po wycofaniu zgody na lokalizację lub wyłączeniu powiadomień.
Na iOS mapy obsługuje Apple Maps, a na Androidzie Google Maps. Dostawcy map mogą otrzymywać dane techniczne, adres IP i dane lokalizacyjne zgodnie z własnymi zasadami prywatności i ustawieniami urządzenia.
8. Opinie, oceny i zdjęcia
Opinia może obejmować ocenę dania, nazwę restauracji i dania, datę dodania, tagi (np. świeże, dobra cena, dobra temperatura, super obsługa, słaba obsługa, za drogo, nieświeże, zła temperatura) i opcjonalne zdjęcie. Przed wysłaniem zdjęcia automatycznie usuwamy metadane EXIF, w tym współrzędne GPS i model urządzenia — nie trafiają one na nasze serwery. Publikowane treści są publiczne i powiązane z nickiem oraz avatarem do czasu usunięcia konta.
Użytkownik może usunąć własną opinię lub zdjęcie. Dostęp do galerii jest potrzebny dopiero przy wyborze zdjęcia. Użytkownik powinien posiadać prawa do publikowanych materiałów i nie publikować wizerunku ani danych innych osób bez właściwej podstawy.
W aplikacji dostępne jest zgłaszanie opinii i zdjęć oraz blokowanie użytkowników — przy każdej opinii i na profilu. Zgłoszenia trafiają do moderacji; treść bezprawną lub naruszającą prawa albo regulamin usuwamy, a w uzasadnionych przypadkach blokujemy konto. Treści można też zgłaszać e-mailem na ppriv@chapaj.pl.
9. Profilowanie i rekomendacje
Chapaj tworzy profil preferencji na podstawie m.in. wyszukiwań, kliknięć, czasu oglądania, polubień, zapisanych lokali, ulubionych potraw i kuchni, ocen, tagów, deklarowanych wizyt i aktywności znajomych. Profil służy do porządkowania i dopasowywania restauracji, potraw i treści.
Rekomendacje nie wywołują skutków prawnych ani podobnie istotnych skutków dla użytkownika. Użytkownik może zarządzać ustawieniami personalizacji, wyłączyć marketingowe profilowanie i skontaktować się w sprawie sprzeciwu. Wyłączenie personalizacji może zmniejszyć dopasowanie wyników, lecz nie blokuje podstawowych funkcji.
10. Treści sponsorowane i marketing
Treści sponsorowane są widocznie oznaczane, w tym napisem „Sponsorowane” i wyróżnieniem wizualnym. Płatna ekspozycja nie powinna być przedstawiana jako wynik wyłącznie organiczny.
Spersonalizowane treści sponsorowane oraz powiadomienia promocyjne mają osobne przełączniki. Odmowa albo wycofanie zgody nie wpływa na dostęp do podstawowych funkcji. Bez zgody na personalizację mogą być wyświetlane treści sponsorowane kontekstowo, np. na podstawie wyszukiwanego dania lub ręcznie wybranego miasta.
Sponsorami mogą być restauracje, sieci, pośrednicy i przedstawiciele. Otrzymują wyłącznie dane zagregowane, np. liczbę wyświetleń, kliknięć, zapisów, zagregowane oceny i popularne tagi. Nie otrzymują danych konkretnych kont, nicków, danych poszczególnych znajomych ani dokładnej lokalizacji.
11. Powiadomienia i kalendarz
Obecnie Chapaj udostępnia powiadomienia wewnątrz aplikacji, m.in. o zaproszeniu do znajomych lub restauracji oraz o odznace. Planowaną funkcją jest wewnętrzny kalendarz Chapaj (np. zapisane wizyty i wydarzenia); po wdrożeniu nie będzie wymagał dostępu do kalendarza telefonu, a polityka zostanie w razie potrzeby zaktualizowana.
Komunikaty promocyjne, oferty sponsorowane i zachęty do powrotu są oddzielone od komunikatów niezbędnych do obsługi konta i podlegają ustawieniom użytkownika.
Systemowe powiadomienia push są funkcją opcjonalną, uruchamianą wyłącznie po wyrażeniu przez użytkownika zgody na powiadomienia. Po włączeniu aplikacja rejestruje token urządzenia za pośrednictwem usługi Expo (Expo Application Services), a dostarczanie odbywa się przez APNs (iOS) lub FCM (Android). Zgodę można w każdej chwili wycofać, co zatrzymuje wysyłkę i powoduje usunięcie tokenu. Resend nie jest wykorzystywany do marketingu.
Osobną kategorią są sponsorowane powiadomienia push — wymagają odrębnej zgody na sponsorowane powiadomienia (oddzielny przełącznik, domyślnie wyłączony) i są wysyłane tylko do użytkowników, którzy mają włączone powiadomienia w aplikacji. Odmowa lub wycofanie tej zgody nie wpływa na powiadomienia funkcjonalne ani podstawowe funkcje. Są wyraźnie oznaczone jako sponsorowane i można je w każdej chwili wyłączyć. Dopasowanie treści do gustu użytkownika następuje tylko przy dodatkowo aktywnej zgodzie na personalizację; w przeciwnym razie dobór jest co najwyżej kontekstowy (np. dzielnica).
12. Konta restauratorów
Restauratorzy mogą zarządzać profilem lokalu, w tym zdjęciem, nazwą, adresem, godzinami otwarcia, średnią ceną, menu i sponsorowaniem. Zdjęcia mogą być dodawane przez restauratorów lub administratora. Dane konta i historia zmian są przetwarzane w celu realizacji funkcji konta, bezpieczeństwa i rozliczalności. Profil restauracji oraz menu są przeznaczone do publicznego wyświetlania.
13. Odbiorcy, dostawcy i transfery
Dane mogą być ujawniane podmiotom obsługującym usługę wyłącznie w niezbędnym zakresie zapewniającym działanie aplikacji Chapaj:
- Supabase – infrastruktura backendowa, obsługa kont użytkowników oraz przechowywanie danych i treści związanych z korzystaniem z aplikacji. (UE/EOG);
- Resend – dostarczanie wiadomości e-mail związanych z kontem i logowaniem;
- Expo - infrastruktura wspierająca działanie aplikacji mobilnej;
- Google i Apple – usługi systemowe wykorzystywane m.in. do dostarczania powiadomień push;
- Apple Maps i Google Maps – wyświetlanie map oraz funkcje związane z lokalizacją i prezentowaniem miejsc;
- Ze względów bezpieczeństwa nie publikujemy szczegółów dotyczących wewnętrznej architektury systemu, konfiguracji infrastruktury, mechanizmów autoryzacji ani zabezpieczeń technicznych.
Niektórzy dostawcy lub ich podprocesorzy mogą przetwarzać dane poza EOG. W takich przypadkach administrator stosuje mechanizm wymagany przez RODO, np. decyzję stwierdzającą odpowiedni stopień ochrony, Ramy ochrony danych UE–USA dla certyfikowanych podmiotów lub standardowe klauzule umowne wraz z oceną transferu i środkami uzupełniającymi.
14. Retencja danych
| Rodzaj danych | Okres / kryterium |
|---|---|
| Konto, e-mail i profil | do usunięcia konta |
| Konto oczekujące na usunięcie | 3 dni |
| Dokładne współrzędne | wyłącznie na czas zapytania lub sesji; bez trwałej historii |
| Przybliżony obszar (dzielnica) | do wycofania zgody na lokalizację, wyłączenia powiadomień lub usunięcia konta |
| Historia wyszukiwań i personalizacji | 12 miesięcy od zdarzenia |
| Zapisane lokale i preferencje | do usunięcia przez użytkownika albo usunięcia konta |
| Relacje ze znajomymi | do usunięcia relacji lub konta |
| Zdjęcia użytkownika | do usunięcia zdjęcia, opinii lub konta |
| Zanonimizowane opinie po usunięciu konta | bezterminowo lub do usunięcia opinii |
| Logi bezpieczeństwa | co do zasady do 90 dni, z uwzględnieniem możliwości planu i potrzeb incydentowych |
| Zgłoszenia i blokady moderacyjne | do rozpatrzenia i przez okres konieczny dla bezpieczeństwa i rozliczalności; blokada — do jej cofnięcia lub usunięcia konta |
| Kopie zapasowe | obecnie brak własnego systemu backupów; jeśli zostanie wdrożony – maksymalnie 30 dni |
| Dowody zgód i ich wycofania | przez okres konieczny do wykazania zgodności lub obrony roszczeń |
Okresy mogą zostać wydłużone, gdy jest to niezbędne do ustalenia, dochodzenia lub obrony roszczeń albo wykonania obowiązku prawnego.
15. Usunięcie konta i anonimizacja
Konto można przeznaczyć do usunięcia w ustawieniach aplikacji lub zgłaszając żądanie na ppriv@chapaj.pl. Żądanie e-mail powinno pochodzić z adresu przypisanego do konta albo zostać dodatkowo potwierdzone kodem lub inną proporcjonalną metodą.
Po zleceniu usunięcia konto jest wygaszane przez 3 dni. W tym czasie użytkownik może anulować operację. Po upływie 3 dni konto, profil, e-mail, nick, avatar, relacje, preferencje, zdjęcia i inne dane powiązane z kontem są usuwane, z zastrzeżeniem obowiązków prawnych i danych niezbędnych do obrony roszczeń.
Opinie mogą pozostać jako treści anonimowe: identyfikatory wiążące je z kontem, nick, avatar i zdjęcia są usuwane, a autor jest oznaczany jako „Konto usunięte”. Jeżeli po anonimizacji nadal można rozsądnie ustalić autora, dane podlegają dalszemu usunięciu lub ograniczeniu.
16. Prawa użytkownika
Użytkownik może żądać dostępu do danych i ich kopii, sprostowania, usunięcia, ograniczenia przetwarzania i przeniesienia danych, a także wnieść sprzeciw wobec przetwarzania opartego na prawnie uzasadnionym interesie. Jeżeli podstawą jest zgoda, można ją wycofać w dowolnym momencie bez wpływu na zgodność wcześniejszego przetwarzania.
Wnioski i eksport danych są realizowane przez ppriv@chapaj.pl. Administrator może poprosić o informacje potrzebne do potwierdzenia tożsamości. Odpowiedź zostanie udzielona bez zbędnej zwłoki, zasadniczo w ciągu miesiąca, z możliwością przedłużenia zgodnie z RODO.
Użytkownik ma prawo wnieść skargę do Prezesa Urzędu Ochrony Danych Osobowych (UODO), w szczególności gdy uważa, że dane są przetwarzane niezgodnie z prawem.
17. Bezpieczeństwo
Administrator stosuje środki adekwatne do ryzyka, w tym szyfrowanie transmisji, kontrolę uprawnień, RLS tam, gdzie ma zastosowanie, ochronę sekretów po stronie serwera, 2FA, ograniczanie dostępu i monitoring zdarzeń. Żaden system nie gwarantuje pełnego bezpieczeństwa.
Użytkownik powinien chronić dostęp do skrzynki e-mail i urządzenia oraz nie przekazywać kodów logowania. Incydenty należy zgłaszać na ppriv@chapaj.pl.
18. Osoby poniżej 16 lat
Chapaj jest przeznaczony wyłącznie dla osób, które ukończyły 16 lat, i nie jest projektowany ani reklamowany specjalnie do dzieci. Aplikacja nie zbiera pełnej daty urodzenia; użytkownik potwierdza spełnienie wymogu wieku.
Po uzyskaniu wiarygodnej informacji, że konto należy do osoby poniżej 16 lat, administrator może je zablokować, wstrzymać profilowanie i marketing, zweryfikować sytuację oraz usunąć dane po krótkim okresie niezbędnym do wyjaśnienia.
19. Cookies i technologie mobilne
Strona www.chapaj.pl może wykorzystywać wyłącznie technologie niezbędne do działania, bezpieczeństwa i utrzymania sesji. Każde wdrożenie analityki, reklam, niekoniecznych cookies lub podobnych identyfikatorów wymaga aktualizacji tej polityki i, gdy jest to wymagane, uprzedniej zgody.
Aplikacja może używać pamięci lokalnej, identyfikatorów sesji, systemowych uprawnień lokalizacji i zdjęć oraz – przy włączonych powiadomieniach push – tokenu urządzenia. Uprawnieniami można zarządzać w ustawieniach urządzenia, a preferencjami marketingowymi w Chapaj.
20. Zmiany polityki
Polityka może być aktualizowana w razie zmian funkcji, dostawców, prawa lub sposobów przetwarzania. Nowa wersja zostanie opublikowana na www.chapaj.pl i w aplikacji z datą wejścia w życie. O istotnych zmianach użytkownicy mogą zostać poinformowani dodatkowym komunikatem.
21. Kontakt
Pytania, żądania i zgłoszenia dotyczące prywatności należy kierować na ppriv@chapaj.pl Data publikacji: 07.09.2026.
Privacy Policy
Mobile application and www.chapaj.pl website
Key information
- Precise location data is not stored permanently.
- Parts of your profile, your reviews, and the number of friends on your profile are publicly available, including to people who are not signed in.
- Marketing profiling and promotional communications have separate controls.
- You may delete your account, subject to a three-day cancellation period.
1. About this document
This Privacy Policy explains how personal data is processed in the Chapaj application and on the www.chapaj.pl website. It applies to users, people who browse public content, and restaurant operators who use features intended for them.
The Policy is updated following any material changes to the features, providers, or methods of processing personal data.
2. Controller and contact details
The controller of personal data is Maciej Kuświk, acting as a natural person and based in Warsaw, Poland.
For privacy matters and requests concerning your rights, contact ppriv@chapaj.pl. Website: www.chapaj.pl.
The controller has not appointed a Data Protection Officer. Please use the email address above for all privacy matters.
3. Personal data we process
Depending on how you use Chapaj, we may process the following data:
- account and authentication data: email address, account identifier, session information, login dates, and one-time login codes valid for 10 minutes;
- setting a nickname (display name) is required when creating an account;
- profile data: nickname (display name), unique identifier (@), optional first name, avatar, selected city, and settings; the display name may be changed no more than once every 30 days, while the identifier (@) is set only once;
- social data: invitations, accepted relationships, and the public number of friends;
- activity and preferences: searches, clicks, viewing time, likes, saved restaurants, favourite dishes and cuisines, declared visits, ratings, tags, friends' activity, and recommendation history;
- content: reviews, dish and restaurant names, ratings, dates, tags, and optional photographs;
- location data: precise coordinates processed temporarily while the application is in use, a manually selected city, and—when the user enables notifications and grants location permission—an approximate area (district) derived from the location;
- technical and security data: IP address, device, operating system, application version, user agent, session identifiers, timestamps, endpoints, push notification token (when notifications are enabled), errors, and failed login attempts;
- consent, personalisation, and communication settings, together with evidence that consent was given or withdrawn;
- moderation data: content reports (who submitted the report, what it concerns, and the reason for it) and user blocks (who blocked whom);
- restaurant and restaurant operator account data: contact and account details, as well as restaurant profile content, including the name, address, opening hours, average price, menu, photographs, and sponsorship settings.
4. Purposes and legal bases
Personal data is processed for the following purposes:
- creating and managing an account; enabling login, venue searches, maps, distance calculations, profiles, friends, reviews, saved venues, and functional notifications—to perform a contract or take steps at the user's request before entering into a contract (Article 6(1)(b) GDPR);
- providing optional features that require consent, in particular marketing personalisation, personalised sponsored content, and promotional communications—on the basis of consent (Article 6(1)(a) GDPR), which may be withdrawn at any time;
- ensuring security, preventing abuse, moderating content (handling reports and blocks), performing diagnostics, establishing, pursuing, and defending legal claims, compiling basic statistics, and improving the service—on the basis of the controller's legitimate interests (Article 6(1)(f) GDPR);
- complying with legal obligations, including responding to reports of unlawful content, handling requests, and maintaining required records—Article 6(1)(c) GDPR.
Where processing is necessary to provide a feature, failure to provide the relevant data may prevent you from using that feature. Location access, access to photographs, and push notifications are optional; you can use the application by selecting a city manually.
5. Login, profiles, and public visibility
You may sign in using your email address and a one-time code sent through Resend, or with a Google account or Sign in with Apple. When you sign in with Google or Apple, the provider supplies us with your email address and account identifier. If you use Sign in with Apple, this may be a relay address if you select Hide My Email. Your email address and login details are not public.
Certain public profile data, such as nickname, first name, photo or avatar, number of friends, and basic statistics, may be visible to other users of the Application. Your friends list is visible only to your friends. Only the number of your friends is publicly available, without their identities. For public profiles, selected information may also be visible to individuals who are not logged in to the Application, for example when viewing public pages or profile screens.
Reviews and the associated author information may be viewed without an account. Do not include any information in your nickname, first name, avatar, review, or photograph that you do not wish to disclose publicly.
6. Friends and social features
Users may search for other people by nickname, send and accept invitations, and view social connections. Users have no direct way to contact one another unless they have accepted the connection. Friends data may influence standard recommendations, but it is not disclosed to sponsors as individual-level data or used for sponsored advertising.
7. Location and maps
Once permission has been granted, Chapaj obtains your precise location only while you are using the application, in order to find nearby venues and calculate distances. Coordinates are processed only for the duration of the query or session, and no permanent history of precise coordinates is created.
You may refuse GPS access and select a city manually. The application may store the selected city, saved restaurants, declared visits, and the time of a search without storing precise coordinates.
If you enable notifications and grant location permission, the application derives an approximate area (district, such as “Mokotów”) from your location and stores it persistently to tailor notifications more closely to your area. We do not store raw coordinates for this purpose. The area is deleted when you withdraw location permission or disable notifications.
Maps are provided by Apple Maps on iOS and Google Maps on Android. Map providers may receive technical data, your IP address, and location data in accordance with their own privacy policies and your device settings.
8. Reviews, ratings, and photographs
A review may include a dish rating, restaurant and dish names, the date it was added, tags (such as fresh, good value, good temperature, excellent service, poor service, too expensive, not fresh, or wrong temperature), and an optional photograph. Before a photo is uploaded, we automatically remove EXIF metadata, including **GPS coordinates** and the device model, so this information is not sent to our servers. Published content is public and remains associated with your nickname and avatar until your account is deleted.
You may delete your own review or photograph. Access to your photo library is required only when you select a photograph. You should hold the necessary rights to any materials you publish and must not publish another person's image or personal data without an appropriate legal basis.
The application allows users to report reviews and photographs and to block users, both from each review and from a user's profile. Reports are referred for moderation. We remove content that is unlawful or infringes rights or the Terms of Service and, where justified, block the relevant account. Content may also be reported by email to ppriv@chapaj.pl.
9. Profiling and recommendations
Chapaj creates a preference profile based on information including searches, clicks, viewing time, likes, saved venues, favourite dishes and cuisines, ratings, tags, declared visits, and friends' activity. This profile is used to rank and tailor restaurants, dishes, and content.
Recommendations do not produce legal effects or similarly significant effects for the user. You may manage your personalisation settings, disable marketing profiling, and contact us to exercise your right to object. Disabling personalisation may make results less relevant, but it does not prevent you from using the application's core features.
10. Sponsored content and marketing
Sponsored content is clearly identified, including with a “Sponsored” label and visual highlighting. Paid placement should not be presented as a purely organic result.
Personalised sponsored content and promotional notifications have separate controls. Refusing or withdrawing consent does not affect access to the core features. Without consent to personalisation, sponsored content may be displayed contextually, for example based on the dish searched for or the city selected manually.
Sponsors may include restaurants, restaurant chains, intermediaries, and representatives. They receive aggregated data only, such as the number of impressions, clicks, and saves, aggregated ratings, and popular tags. They do not receive data relating to specific accounts, nicknames, individual friends data, or precise locations.
11. Notifications and calendar
Chapaj currently provides in-app notifications, including notifications about a friend request, a restaurant invitation, or a badge. A Chapaj in-app calendar is planned (for example, for saved visits and events). Once implemented, it will not require access to the device's calendar, and this Policy will be updated if necessary.
Promotional messages, sponsored offers, and re-engagement prompts are kept separate from communications necessary to manage your account and are subject to your settings.
System push notifications are optional and are enabled only after you grant notification permission. Once enabled, the application registers a device token through Expo (Expo Application Services), and notifications are delivered through APNs (iOS) or FCM (Android). You may withdraw permission at any time; this stops notifications from being sent and results in deletion of the token. Resend is not used for marketing.
Sponsored push notifications are a separate category. They require separate consent to sponsored notifications through a dedicated control that is disabled by default, and they are sent only to users who have enabled notifications in the application. Refusing or withdrawing this consent does not affect functional notifications or the core features. Sponsored notifications are clearly identified as such and may be disabled at any time. Content is tailored to your preferences only if you have also consented to personalisation; otherwise, selection is contextual at most (for example, based on your district).
12. Restaurant operator accounts
Restaurant operators may manage a venue profile, including its photograph, name, address, opening hours, average price, menu, and sponsorship settings. Photographs may be added by restaurant operators or by the controller. Account data and change history are processed to provide account features and ensure security and accountability. Restaurant profiles and menus are intended for public display.
13. Recipients, service providers, and international transfers
Personal data may be disclosed to entities that support the service only to the extent necessary to operate the Chapaj application:
- Supabase—backend infrastructure, user account management, and storage of data and content associated with use of the application (EU/EEA);
- Resend—delivery of emails relating to accounts and login;
- Expo—infrastructure supporting the operation of the mobile application;
- Google and Apple—system services used, among other things, to deliver push notifications;
- Apple Maps and Google Maps—displaying maps and providing features relating to location and the presentation of places;
- For security reasons, we do not publish details of the system's internal architecture, infrastructure configuration, authorisation mechanisms, or technical safeguards.
Some providers or their subprocessors may process personal data outside the EEA. In such cases, the controller uses a transfer mechanism required under the GDPR, such as an adequacy decision, the EU–U.S. Data Privacy Framework for certified organisations, or Standard Contractual Clauses together with a transfer assessment and supplementary measures.
14. Data retention
| Type of data | Period / criterion |
|---|---|
| Account, email address, and profile | until the account is deleted |
| Account pending deletion | 3 days |
| Precise coordinates | only for the duration of the query or session; no permanent history |
| Approximate area (district) | until location permission is withdrawn, notifications are disabled, or the account is deleted |
| Search and personalisation history | 12 months from the event |
| Saved venues and preferences | until deleted by the user or until the account is deleted |
| Friend connections | until the connection or account is deleted |
| User photographs | until the photograph, review, or account is deleted |
| Anonymised reviews retained after account deletion | indefinitely or until the review is deleted |
| Security logs | generally up to 90 days, subject to plan capabilities and incident-response needs |
| Moderation reports and blocks | until the matter is resolved and for as long as necessary for security and accountability; a block is retained until it is lifted or the account is deleted |
| Backups | no separate backup system is currently in place; if one is implemented, no more than 30 days |
| Records of consent and withdrawal | for as long as necessary to demonstrate compliance or defend legal claims |
Retention periods may be extended where necessary to establish, pursue, or defend legal claims or to comply with a legal obligation.
15. Account deletion and anonymisation
You may schedule your account for deletion in the application settings or by sending a request to ppriv@chapaj.pl. An email request should be sent from the address assigned to the account or additionally verified using a code or another proportionate method.
Once deletion has been requested, the account is deactivated for three days. You may cancel the operation during this period. After three days, the account, profile, email address, nickname, avatar, connections, preferences, photographs, and other data associated with the account are deleted, subject to legal obligations and the retention of data necessary to defend legal claims.
Reviews may remain as anonymous content: identifiers linking them to the account, as well as the nickname, avatar, and photographs, are deleted, and the author is identified as “Deleted account”. If the author can still reasonably be identified after anonymisation, the data will be deleted or further restricted.
16. Your rights
You may request access to and a copy of your personal data, rectification or erasure of your personal data, restriction of processing, and data portability. You may also object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before its withdrawal.
Requests and data exports are handled through ppriv@chapaj.pl. The controller may ask you to provide information needed to verify your identity. A response will be provided without undue delay, generally within one month, subject to any extension permitted under the GDPR.
You have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland (UODO), particularly if you believe that your personal data is being processed unlawfully.
17. Security
The controller implements measures appropriate to the level of risk, including encryption in transit, access controls, row-level security (RLS) where applicable, server-side protection of secrets, two-factor authentication (2FA), access restrictions, and event monitoring. No system can guarantee complete security.
You should secure access to your email account and device and must not share login codes. Please report incidents to ppriv@chapaj.pl.
18. Persons under the age of 16
Chapaj is intended solely for persons aged 16 or over and is not designed for or specifically marketed to children. The application does not collect a full date of birth; users confirm that they meet the age requirement.
If the controller receives credible information that an account belongs to a person under the age of 16, it may block the account, suspend profiling and marketing, investigate the matter, and delete the data after a short period necessary to clarify the situation.
19. Cookies and mobile technologies
The www.chapaj.pl website may use only technologies necessary for its operation, security, and session maintenance. Any implementation of analytics, advertising, non-essential cookies, or similar identifiers will require this Policy to be updated and, where required, prior consent to be obtained.
The application may use local storage, session identifiers, system permissions for location and photo access, and—when push notifications are enabled—a device token. Permissions may be managed in the device settings and marketing preferences in Chapaj.
20. Changes to this Policy
This Policy may be updated to reflect changes to features, providers, applicable law, or processing activities. A new version will be published at www.chapaj.pl and in the application, together with its effective date. Users may also be notified separately of material changes.
21. Contact
Please send privacy-related questions, requests, and reports to ppriv@chapaj.pl. Publication date: 07 September 2026.