Skip to content
ByLocals
Menu

Legal

ByLocals Privacy Notice

Draft — pending solicitor review. This document is published here so it can be read and checked. It has not been through legal sign-off, so please do not rely on it or quote it as our final position. It is deliberately kept out of our sitemap and out of the machine-readable index while that is true.

ByLocals Privacy Notice

Draft v1.2 for legal and implementation review — publish only after approval at bylocals.co.uk/privacy

Effective: [LAUNCH-DATE] · Last revised: 2 Sep 2026

In brief. ByLocals builds evidence-led records of independent organisations and their trading locations. Some information comes from public sources rather than the business. We show provenance, provide a visible correct/remove route and never sell personal data. Paid status cannot affect verification, corrections or organic discovery. Contact [PRIVACY-EMAIL].

1. Who we are

ByLocals is operated by Aceman Software Solutions Ltd, company no. 12928098, registered office 8 Holtdale Grove, Leeds, England, LS16 7RZ. Aceman is the controller for the processing described here. Its ICO registration status/reference remains [ICO-REG-NUMBER — CONFIRM BEFORE PUBLICATION]; do not state that registration is complete until checked.

Privacy contact: [PRIVACY-EMAIL] · postal contact: [POSTAL-PRIVACY-ADDRESS] · service/content support: [SUPPORT-EMAIL].

Some businesses receiving an Enquiry or data customer using a permitted Data Feed/API field may become a separate controller for their own later use. We identify that relationship at the point of transfer and restrict what we disclose.

2. Whose information we process

We do not knowingly offer contribution/account features to children under 16. A parent/guardian can contact us about a child’s information.

3. Organisation, location and fact records

We separate:

For a sole trader or partnership, business data can be personal data. We avoid publishing a home address unless the person clearly presents it as the public trading location and we have assessed publication; we do not publish private direct contacts, account emails, claim evidence or special-category data.

Sources include Companies House, Food Standards Agency/local-authority data, the organisation’s public website/channels, other licensed/lawfully accessible public sources and information supplied by an authorised representative. Automated tools may extract, normalize or draft facts, but their output is labelled and reviewed according to risk.

Where evidence is sufficient, Free Core may also publish a source-grounded About story prepared during the ordinary research flow. Objective assertions retain supporting provenance and authorised owners can correct or replace the story for free. A paid service is not required for narrative completeness.

Purpose/basis: to assess eligibility, build and publish the Free Core, answer local queries, maintain accuracy and prevent re-seeding after removal. We rely on legitimate interests (UK GDPR Article 6(1)(f)), subject to our LIA and the right to object. Identity evidence/account actions needed to provide a claimed service use contract/steps at request (Article 6(1)(b)); legal recordkeeping uses Article 6(1)(c) where applicable.

4. Privacy information when data did not come from you

Where Article 14 applies, we provide this notice within the legally required period and no later than the first relevant communication or disclosure. If we have a reliable business contact, we use a direct notice or claim invitation that identifies the source/categories and links here. The listing also carries provenance and a correct/remove link.

Where direct delivery is impossible or would involve disproportionate effort, we do not assume that a web notice alone is enough: we document the affected cohort, effort, risks and safeguards; minimize personal fields; make this notice prominent; maintain source/provenance; limit reuse; and re-assess on first contact or disclosure. This approach and any reliance on an exception require counsel approval before launch.

We process name, role, contact details, business/location association, verification evidence, single-use claim/authentication tokens, account/session records, edits, approvals and support activity. Purposes are to authenticate, prevent hijacking, provide Free Core/paid services, transfer ownership and preserve an audit trail. Basis: contract/steps at request, legitimate interests in security/accuracy and legal obligation where applicable.

Free Core business-image uploads may contain recognisable staff/customers and technical metadata. We process the private original, rights/licence and likeness/genuine-imagery attestation, alternative text, upload/processing attempts and moderation decision to scan/re-encode/strip metadata, assess safe publication and display only approved derivatives. Uploaders must avoid unnecessary personal or sensitive information and must have the required rights and permissions. Public pages expose only approved derivatives, moderated alternative text and order—not the uploader, original metadata, attestation or moderation record. Basis: contract/steps at the authorised owner’s request and legitimate interests in platform security, accurate presentation and rights handling.

We do not obtain a public “Companies House registered email”; claim routes use a domain/public business contact plus secondary evidence, post to a confirmed trading location or proportionate manual evidence. Authentication providers process only the fields configured in the processor register.

Service/transactional messages are limited to the requested service, security, material terms/privacy changes, Enquiry delivery and billing. They are not used to disguise marketing.

Directory search and Concierge events may include query text, time, approximate area, filters, matched organisation/location IDs, result impressions, page views and separately counted outbound actions. We instruct users not to enter personal data; query text is filtered for it as the event is recorded, so detected email addresses, telephone numbers and full postcodes are removed before storage rather than after. Query text is readable only by our operators, is never shown to a business about its own listing, and is deleted after 90 days; the counts and the anonymous record of which listings were returned are kept after the text has gone. A business that has claimed its listing sees only thresholded counts against its own categories, never anything a person typed. We do not describe an impression as a customer or Enquiry.

Basic aggregate measurement supports service quality under legitimate interests and any confirmed PECR condition. A pseudonymous identifier for cross-session repeat measurement is optional and off by default; it is used only with an appropriate express choice, is not linked to owner ranking/pricing and can be withdrawn. Link measurement separates aggregate destination counts from any person-level history. See the Storage Technologies Notice.

7. Vouches, tips, reports and awards

A vouch requires a lightweight verified participant, usually an email magic link, plus one versioned confirmation covering age 16+, genuine recent first-hand use, no disqualifying connection or incentive and an honest/lawful contribution. We process the private contact, participant token, organisation/location, attestation/policy version, timestamp, optional pre-moderated tip, fraud/security signals, moderation, report, sanction and appeal records. The public display is pseudonymous. Basis: contract/steps at request for submission and legitimate interests in publishing trustworthy local experience and preventing fake reviews.

The limit is one vouch per participant per organisation per rolling 12 months. Agree/disagree reactions are not approved. If awards later launch, votes are separately collected under published rules and a refreshed notice; vouches are not silently converted into votes.

8. ByLocals Requests

The free beta and any later explicitly activated native service may process the sender’s name/contact route, message, request mode, requested category/location/time, delivery-consent/terms record, separate affirmative 16+ attestation wording/version/time (without date of birth), matched business/location, delivery/bounce status, business response status, fraud signals and qualification/challenge decision. Users must not include unnecessary sensitive data.

We use the information to deliver the user’s requested message, operate/secure the service and assess whether it meets the published “qualified Request” rule. Basis: contract/steps at the user’s request and legitimate interests in delivery, measurement, disputes and abuse prevention. The receiving business sees only the information the user is told will be sent and becomes responsible for its own use after receipt; its privacy notice should explain that use. A booking Request is not confirmed until the business accepts it; a product Request does not assert stock.

Request content is never sold, added to an institutional insight product, exposed through a Data Feed/API or used to market SocialPostxr. Aggregates use thresholds and disclosure controls. A business must explicitly approve its route; native paid capability is never activated automatically.

9. Later paid services and billing

For Connect, Grow, Growth Review, Verified Kit and Local Supporter if separately activated, we process order/service, price/tax, billing contact, invoice, payment status/token reference, renewal/cancellation/refund, fulfilment, communications and support records. The payment provider receives payment details; ByLocals should not store full card data. These payments are for ByLocals services only: we do not handle customer payments to the business. Basis: contract/steps at request, legal obligation for tax/accounting and legitimate interests for fraud/disputes.

For Growth Review we may process the location, public web sources, ByLocals record, action routes, stated business goal, assessment prompts/notes, human review, three-action deliverable and 30-day usefulness/action response through [AI-PROVIDER] and our operators. We minimise personal/confidential material, publish processor retention and do not use the review to alter public treatment.

For Connect we process owner-approved Request modes/labels, route recommendation evidence, destination verification/health, delivery and response history. For Grow we additionally process the location’s real aggregate activity and eligibility preview, privacy-safe themes above disclosure floors, public-source/action-route monitoring, private suggested revisions/actions, resulting ordinary fact-revision references, monthly interpretation/action notes and owner-visible history. New facts arise only after an authenticated owner separately hands selected changes to the ordinary Free Core review route. These records are never used to change ranking, freshness, correction priority or verification.

Owner product exports record the requester, current authorising membership/location scope, recent re-authentication, kind, manifest/format/checksum, generation attempts, download receipts and archive deletion receipt. Export archives are encrypted in private storage for at most 24 hours, are not emailed and use one-time links after a fresh access check; successful download destroys the archive. The free standard export covers current owner-managed business content; the Grow variant adds owner-visible history. Both exclude restricted third-party/internal classes. Data-protection access/portability requests remain available free through the rights route and are not conditioned on purchase.

Buying/supporting never changes eligibility, verification, fact status, correction/removal SLA, ranking, freshness, relevance, vouch weight, awards or editorial treatment.

10. Communications and SocialPostxr

Claim outreach to businesses is routed under the PECR SOP. Direct-marketing choices are separate from service messages and recorded with notice/version/time/source.

Newsletters and optional ByLocals promotions use separate consent where required, with an unsubscribe in every message. The owner service-value digest is off until separately requested in Settings, contains no promotion and can be stopped in one action. SocialPostxr marketing requires its own unbundled, affirmative consent. Claiming, purchasing, joining the newsletter, requesting the owner digest or consenting to ByLocals marketing does not provide it; controls are never pre-ticked and withdrawal is as easy as signup. We record purpose, channel, wording/notice version, source, time and withdrawal, and retain only minimal separate suppression/permission evidence so a withdrawal remains honoured.

Marketing pixels are disabled at launch. Any optional interaction tracking is disclosed and gated as described in the Storage Technologies Notice.

11. Institutional/data research and any later paid pilot

No institutional/data product is currently available. Buyer interviews and sample reviews use synthetic, public or sufficiently aggregated/minimised material and do not grant ongoing access. Any later approved pilot may provide thresholded aggregate patterns such as category demand, coverage or broad trends. It must not include raw query text, participant-level events, Enquiry content, private contacts or cells from which a person/small group can reasonably be singled out. We test and log disclosure risk; truly anonymised outputs fall outside UK GDPR, while inputs remain protected as described here.

A future feed/API, if separately approved after buyer and data gates, is limited to approved business/location facts, source/provenance and permitted aggregate fields. It excludes account/claim evidence, private contacts, participant-level vouches, user/query records and Enquiry content. Customers are vetted, contractually restricted from re-identification, unlawful direct marketing and prohibited onward sale, and logged so corrections/removals can be propagated where required. Its LIA/DPIA, Article 14 and licensing review must be approved before activation.

12. Security and storage technologies

We use role-based/least-privilege access, MFA for privileged users, encryption in transit and at rest, environment separation, secrets management, backups, audit logs, upload controls, magic-link expiry/replay protection and incident response appropriate to the confirmed stack. No system is completely secure.

Session, IP, user-agent, device/security and consent-preference data are described in the Storage Technologies Notice. Hashing/pseudonymisation reduces linkability but does not automatically make data anonymous.

13. Recipients, processors and transfers

Subject to final procurement, recipients/processors include:

We never sell personal data. Before use, each processor requires role/security/retention/sub-processor/training-purpose review and an appropriate contract. International transfers use a current UK adequacy regulation or appropriate safeguards such as the UK IDTA/Addendum plus transfer-risk assessment; details are available from [PRIVACY-EMAIL].

14. Retention

We keep information only for the recorded purpose. Key periods include: expired magic links only for short security logs; closed account data generally 30 days plus backups; raw concierge/link data up to 90 days; consented cohort/vouch enforcement data up to 13 months; Request content generally 12 months after delivery/closure; rejected tips 90 days; BusinessImage failed/rejected originals up to 30 days and removed originals/derivatives normally within seven days unless a dispute/legal hold applies; Grow convenience history for active service plus 12 months, with pending draft input removed 30 days after access ends; owner-export archives 24 hours and job/download audit 90 days; support/correction records 12 months after closure; invoices/order records six years where required; security logs normally 90 days; suppression/consent-withdrawal evidence while needed to honour the choice. Growth Review working material is deleted on the separately confirmed schedule. Truly anonymised aggregates may be retained without a personal identifier.

The internal Retention Schedule contains the authoritative triggers, exceptions and deletion actions; production jobs must implement it. Legal holds or active disputes may temporarily extend a period and are recorded/reviewed.

15. Your rights

Depending on context, you may have rights to access, correction, erasure, restriction, portability, objection to legitimate-interests processing and withdrawal of consent. You may object to a sole-trader listing and direct marketing at any time. There is no solely automated decision producing legal or similarly significant effects; ask for human review of an eligibility, moderation or Enquiry-qualification decision through the published appeal route.

Contact [PRIVACY-EMAIL]. We may verify identity proportionately and normally respond within one month, subject to lawful clarification/extension rules. If data has been disclosed to an Enquiry recipient or approved data customer, we handle notification/assistance duties and tell you what we can do; that recipient may also need to respond as a separate controller.

16. Complaints and changes

Use bylocals.co.uk/privacy-complaint or [PRIVACY-EMAIL]. We acknowledge a data-protection complaint within the applicable statutory period (our target is seven days and never later than 30 days) and respond without undue delay. You may complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113.

We version this notice. We notify account holders where a material change requires it and obtain a new choice where the purpose or consent changes.


Version 1.2 · 2 Sep 2026 · draft. Reconciles Requests, Connect, Grow, Growth Review and the no-merchant-payment rule. Replace placeholders and validate every statement against the deployed system before publication.

Privacy choices

Necessary site storage remains available. Optional Google Analytics is used only for aggregate public-page journeys and can be changed at any time.

Automatically collected: privacy-safe page groups and scroll depth. Chosen actions use a fixed vocabulary; field contents, search words and private routes are excluded.