Last updated 24 September 2026
Privacy Policy
Supper Social Private Limited ("Supper Social", "we", "us") runs this website, a restaurant discovery platform with stories, guides and crowd-voted venue rankings. We are incorporated in Singapore and handle personal data under the Personal Data Protection Act 2012 (PDPA). If you visit from the UK or EU, we also follow the basic GDPR principles set out below.
What we collect
- Votes and matchups. Each vote you cast between two venues: which venue won, which lost, the time, and how long you took to choose.
- Device identifiers. A random ID stored in your browser and a signed cookie that identifies your device, not you. We use them to show your own top ten and to stop repeat or fraudulent voting. When you vote we also take a scrambled (hashed) summary of basic device settings, such as screen size, language and time zone, to link repeat devices. We never store those settings themselves.
- Network signals. A one-way scrambled (hashed) version of your IP address, stored with votes, notes and venue suggestions, so we can spot bursts of fake votes. We do not store your raw IP address with these records.
- Vote country. The country your connection comes from, stored with each vote, so we can spot click farms and VPN use.
- Account details. If you sign in (mainly our team and partners), your email address and the role on your account.
- Fan notes. Short notes you post about a venue, plus the time and your device ID.
- Enquiries. What you type into our forms (for example the claim, story, waitlist or Work with us forms): usually your name, venue, email or WhatsApp number and your message.
- WhatsApp taps. When you tap a button that opens WhatsApp to message us, we log the page and button, the venue if you were on a venue page, the referring page, any campaign tags in the link and your device ID. We do not see your phone number unless you then message us.
- Saved venues and preferences. Venues you save, your chosen city, recent searches and view settings. Most of these stay in your browser.
- Basic analytics. Pages viewed, device type, browser and country, collected by our hosting provider.
- Map diagnostics. If the map fails to load, the page address, browser details and the reason, so we can fix it.
Why we use it
- To run the rankings and show you your own votes.
- To detect and undo vote manipulation, bots and spam.
- To publish and moderate fan notes.
- To reply to enquiries and manage partnerships.
- To keep the site working and improve it.
We rely on your consent (which you give by using these features or sending us your details), on what is needed to provide the service you asked for, and on our legitimate interest in keeping the rankings fair and the site secure.
Who helps us run the site
- Lovable, for website hosting, the Lovable Cloud backend and basic visitor analytics.
- Supabase, for our database, file storage and sign-in, via Lovable Cloud.
- Cloudflare, the network the site is served through.
- Google, for Maps and Places venue data (addresses, hours, photos). Your browser does not send your votes to Google.
- Map tile providers OpenFreeMap, CARTO and Esri, which serve map images to your browser and see your IP address as any website would.
- WhatsApp (Meta), when you choose to message us. WhatsApp's own privacy policy applies to that chat.
- Notion, where our team keeps a record of partnership enquiries.
- Ghost, which hosts our stories, and Behold, which supplies our public Instagram posts.
- Instagram (Meta), if you play an embedded reel or follow a link to Instagram.
- AI text tools provided through Lovable, used to help draft venue and page descriptions. We do not send your personal data to them.
Some of these providers store data outside Singapore. Where that happens we rely on their contractual protections so your data is protected to a standard comparable to the PDPA.
We do not sell your personal data.
How long we keep it
Votes are kept for as long as the rankings run, because they make up the ranking history. Enquiries are kept while we are in touch with you and for up to two years after. Fan notes stay until you or we remove them. Technical logs are kept for a short time only. When we no longer need data, we delete it or make it anonymous.
Security
Data travels over encrypted connections, access to our database is restricted by role, and device and network identifiers are hashed or signed. No system is perfectly secure, so we will tell you and the authorities where the law requires if something goes wrong.
Your rights
You can ask to see the personal data we hold about you, correct it, delete it, or withdraw your consent. You can also clear your browser storage at any time, which removes your device ID and your saved list on that device. Because votes are tied to a device and not to a name, please tell us roughly when and from which device you voted so we can find them. Visitors covered by the GDPR can also object to or limit how we use their data, and complain to their local data protection authority.
Children
The site is not aimed at children under 13, and we do not knowingly collect their data.
Contact
For anything about your data, email our Data Protection Officer at hello@suppersocial.co. See also our Cookie notice and Terms of Use.
We may update this policy. The date at the top shows the latest version.