Privacy Policy
Last updated 18 September 2026
In short
The full text is below. This is what actually happens.
- Your collection is yours. Export it whenever you like, from the app.
- You delete your account yourself in the app and it is gone straight away.
- Everything stays within the EU.
- We keep only what the app needs in order to work.
- No advertising and no profiling.
- No third-party analytics, no trackers and no cookies. Not on this site, and not in the app.
- We count views on public lists, without storing who you are. How that works is in section 4.
- We never sell or rent your data, to anyone.
- We do not look through your collection to make money from it.
1. Who is responsible
BackBeer is made and run by Dickies Brewing. For the purposes of this policy, Dickies Brewing is the data controller.
If you have a question about your data, or want to exercise one of your rights, write to that address. It is also the address for complaints.
2. What we process
Your account
- Your email address. Needed to sign in, to reset your password, and to reach you if something happens to your account.
- Your display name. You choose it, and it does not have to be your real name.
- Your password, hashed. See Security. We do not know your password and cannot read it.
- Your language preference and the moment you created the account.
Your collection
- The beers you add, with the batches, quantities, storage places, best-before dates and purchase prices you fill in.
- What you take out and when, so the app keeps your stock straight.
- Groups you create and trades you make with other people.
This lives on your phone and, once you are signed in, on our server too: otherwise your collection would vanish the moment you lost your phone.
Contributions to the catalog
The beer catalog is built by its users. When you add a beer or correct a detail, we record what you contributed and that it was you. That is needed to undo corrections, to see who is carrying the catalog, and for a possible reward for contributions later. You can switch this off in the app.
The beer data itself, meaning brewery, name, style and alcohol content, are facts about a product and not personal data. They are visible to everyone using the app. If you delete your account those facts stay, but the link to you is removed.
Technical data
- Session data, so you stay signed in: a token and the kind of device you signed in with.
- Server logs containing the IP address of the request. We use them to fix faults and to stop abuse, and they are overwritten after fourteen days.
3. What we use it for, and why we may
- To run the app: signing in, storing your collection and syncing it between your devices. Basis: performance of the agreement you enter into with us when you create an account (Art. 6(1)(b) GDPR).
- To reach you about your account: a verification code, a password reset. Same basis. We do not send you marketing.
- To keep things safe and standing up: logs, rate limits and stopping abuse. Basis: our legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).
- To maintain the catalog: reviewing contributions, merging duplicates, undoing mistakes. Same legitimate interest.
4. What we do not do
There is no analytics package in the app and no tracking pixel on this site, and nothing measures you across the web. We do not measure which screens you look at, we do not build a profile of you, and we do not show advertising. We do not sell, rent or trade your data, and we do not pass it to third parties for their own purposes.
This website sets no cookies. The app sets no cookies.
Counting views on public lists
We count views on public lists. To avoid counting the same person twice in a day, we store an irreversible token derived from the visitor’s IP address and the list, using a key that rotates daily. The token expires after 24 hours and cannot be linked to a person or across days. We store no IP addresses and use no third-party analytics.
The count is shown on the list itself, and it is what orders the public directory when you have not said where you are.
5. Security
How we store and secure your data is described separately, in plain language, on Security. In short: traffic is encrypted, passwords are hashed with argon2id, and a backup is taken every night and immediately read back to check that it is sound.
6. Who else processes your data
We use two kinds of supplier: one that provides our server and one that sends our email. Both are in the European Union and process only what they need in order to do their part. No data goes to countries outside the EU.
Beyond that, the app shares only what you share: if you make a collection visible to someone or trade a beer, the other person sees what you shared for that and nothing else.
When you choose a password we check whether it appears in a known breach. That happens without sending your password anywhere: five characters of a hashed form go across and nothing more. See Security.
7. How long we keep it
- Your account and your collection: until you delete them. We do not tidy anything away on our own and we keep nothing "just in case".
- Server logs: fourteen days, then overwritten.
- Backups: daily backups are kept for fourteen days, monthly ones for twelve months. That is the only place a deleted account can still appear for a while. See below.
8. Deleting your account
You do it yourself, in the app, under Settings. It takes two steps: first you delete your beers, then your account. That is deliberate: it means you see exactly what goes before it goes.
Once you confirm with your password, your account is gone immediately. Not flagged as deleted, not held pending, but deleted: your email address, your password, your collection, your groups and your trades leave our database at that moment. You are signed out and there is nothing to restore.
Two things remain, and it is fairer to say so here than to let you find out:
- Contributions to the shared catalog stay, without your name on them. They are facts about beers that other people rely on.
- A backup taken before your deletion still contains your data until that backup’s turn comes to be overwritten: fourteen days for the daily copies, at most twelve months for the monthly ones. We never restore a deleted account from a backup.
If you no longer have the app on your phone, you can also request deletion through this page.
9. Your rights
You have the right to see your data, to have it corrected, to have it deleted, to take it with you to another service, and to object to a processing operation.
Seeing it and taking it with you work straight away: the app has an export button that gives you your whole collection in a readable file. Correcting is done in the app, and so is deleting. If something will not work, or you want something else, write to cheers@back.beer; we answer within a month.
If you disagree with us, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We would rather hear it ourselves first, but the right is yours either way.
10. Age
BackBeer is about beer, so we ask you to use the app only if you are old enough to buy alcohol in your country. In the Netherlands that is eighteen.
Separately: if the app is meant for someone under sixteen, a parent or guardian has to consent before any data is processed. If we find that an account belongs to a child, we delete it.
11. Changes
If what we process changes, we update this policy and put a new date at the top. If it is something substantial, we say so in the app or by email. We keep older versions. Ask if you would like to see them.
This policy was written in Dutch. This English version is a translation provided for information. If the two differ, the Dutch text is the binding one.