Privacy Policy
Last updated: April 15, 2026
This Privacy Policy explains how Plots ("we," "our," or "us") collects, uses, and protects your personal information when you use our Service.
1. Information We Collect
Information you provide:
- Account information: Email address, display name, password
- Profile information: Optional bio, location, avatar
- Content: Reviews, catch logs, photos, notes you submit
- Communications: Messages you send to us
Information collected automatically:
- Usage data: Pages viewed, features used, timestamps
- Device information: Browser type, operating system
- Location data: Approximate location based on IP address (not precise GPS)
- Cookies: See our Cookie section below
2. How We Use Your Information
- Provide and improve the Service
- Create and manage your account
- Display your public content (reviews, catches marked as public)
- Send service-related communications
- Ensure security and prevent abuse
- Comply with legal obligations
3. Information Sharing
We do not sell your personal information. We may share information:
- Public content: Reviews and catches you mark as public are visible to all users
- Service providers: Hosting, analytics, and email services that help us operate
- Legal requirements: When required by law or to protect rights and safety
4. Cookies
We use cookies for:
| Cookie Type |
Purpose |
Duration |
| Essential |
Login sessions (PHP session cookie), CSRF security tokens |
Session / 24 hours |
| Preferences |
Theme preference (dark/light mode), cookie consent choice |
1 year |
| Analytics |
Google Analytics (measurement ID: G-ZQR0B8PZJW) — used to understand how visitors interact with our site |
Up to 2 years |
We use Google Analytics (measurement ID: G-ZQR0B8PZJW) to collect anonymous usage data such as pages visited, session duration, and general geographic region. Google Analytics sets cookies (e.g. _ga, _ga_*) to distinguish unique visitors and track sessions. This data is processed by Google in accordance with their Privacy Policy. We also use our own built-in analytics system for additional usage tracking stored on our servers.
When you select "Essential Only" on our cookie consent banner, preference cookies (theme choice) are not stored. Essential cookies (login session, security tokens) cannot be disabled as they are required for the Service to function.
You can also control cookies through your browser settings.
5. Data Retention
We retain your personal data while your account is active.
You can delete your account at any time through the self-service deletion tool in your account settings (Security tab > Delete My Account). Alternatively, you can request deletion by emailing admin@plots.phillowry.net.
Upon account deletion:
- All personal data (email, password, profile information, avatar, saved venues, private notes, check-ins, badges, and activity history) is permanently removed from our active systems within 24 hours.
- Anonymised, non-personal data (such as catch reports and reviews attributed to "Deleted User") is retained for community benefit. This data can no longer be linked to your identity.
- A confirmation email is sent to your registered email address before it is purged.
- Backup systems are purged within 30 days.
- A PII-free audit record of the deletion is retained for compliance purposes.
6. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data (you can edit your profile directly in account settings)
- Erasure: Delete your account and personal data using the self-service deletion tool in your account settings (Security tab), or by contacting us at the email below
- Portability: Receive your data in a portable format
- Object: Object to certain processing
- Withdraw consent: Where processing is based on consent
To exercise these rights, use the tools available in your account settings or contact us at admin@plots.phillowry.net. We will respond to all data rights requests within one month, as required by UK GDPR.
7. Legal Basis for Processing
Under UK GDPR Article 6, we process your personal data on the following lawful bases:
- Contract performance (Article 6(1)(b)): Processing your account information, profile data, and content is necessary to provide the Service you signed up for.
- Legitimate interest (Article 6(1)(f)): Our built-in analytics (page views, engagement tracking) are processed under our legitimate interest in understanding how the Service is used and improving it. You can object to this processing by contacting us.
- Legal obligation (Article 6(1)(c)): We may process data where required to comply with applicable laws.
- Consent (Article 6(1)(a)): Where we send any optional marketing or promotional communications, this is based on your explicit consent, which you can withdraw at any time.
8. Data Controller
Plots is operated by Phil Lowry as a sole operator. For data protection enquiries, contact admin@plots.phillowry.net.
9. International Data Transfers
Plots primarily serves users in the United Kingdom. Our hosting infrastructure processes and stores data on servers that may be located outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR Article 46. These safeguards include the use of hosting providers that participate in recognised data protection frameworks and maintain appropriate technical and organisational measures to protect your data.
If you have questions about how your data is transferred or the safeguards in place, please contact us.
10. Data Security
We implement appropriate security measures including:
- Encrypted passwords (bcrypt hashing — never stored in plain text)
- HTTPS encryption for all data in transit
- CSRF token protection on all forms
- Rate limiting on sensitive operations
- Regular security reviews
11. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect data from children under 13.
12. Changes to This Policy
We may update this policy. We will notify you of significant changes via email or notice on the Service.
13. Contact Us
For privacy questions or to exercise your data protection rights:
Email: admin@plots.phillowry.net