Skip to content
ATXTopEatery

Legal

Privacy Policy

What ATX Top Eatery collects, why, how long it is kept, and the choices you have.

Last updated August 22, 2026

The short version

There are no accounts on this site, so there is no profile of you to build. We do not run advertising trackers today, we do not sell or share data with data brokers, and we do not store your IP address in a readable form. What we keep is the minimum needed to run the listing and to stop spam.

1. Who we are

ATX Top Eatery (atxtopeatery.com) is a personal side project that publishes a directory of Austin food and drink businesses. For the purposes of data protection law, we are the controller of the limited data described below. Contact: [email protected].

2. What we collect

a. Listings you submit

When you add an eatery, we store what you send us:

  • the website URL, the eatery name and the summary;
  • the logo or photo, whether uploaded by you or fetched from the website;
  • a salted, irreversible hash of your IP address, and your browser’s user-agent string.

We do not store your raw IP address alongside a submission. The hash exists so we can enforce the cooldown between submissions and trace abuse patterns; it cannot be turned back into an address.

b. Visits to listings

When you visit a business through a listing, we record the listing, the time, the referring page, your user-agent, and the same kind of salted hash of your IP. This is what tells us which listings people find useful — it is what the “trending right now” panel and the visit counts are built from — and the hash is what stops one person refreshing a page from inflating a count.

c. Server logs

Our web server keeps standard access logs (IP address, timestamp, requested URL, response status, user-agent) for a short period for security and debugging. These are ordinary operational logs, not analytics.

d. What we never collect

  • Names, email addresses or phone numbers of visitors.
  • Payment details — nothing on the Site costs money.
  • Precise location data.
  • Advertising identifiers or cross-site tracking profiles.

3. Cookies and local storage

We do not currently use advertising or analytics cookies, and there is no consent banner because there is nothing to consent to. The Site is free to use and free to submit to, and it may carry advertising in future to cover its costs — if that ever involves cookies or similar tracking technologies, this policy will say so and the appropriate consent controls will appear before they are used.

Your browser stores one item locally: your light/dark theme preference, saved under the key theme so the site does not flash the wrong colours on your next visit. It never leaves your device. Clearing your browser storage removes it.

The admin dashboard — which only site staff can reach — stores a session token locally to keep an administrator signed in. It is not set for ordinary visitors.

4. Why we process this data

  • To run the listing. Knowing which eateries people open is how we arrange the page and fill the “trending” panel.
  • To keep the Site usable. Rate limiting and de-duplication stop spam and inflated counts.
  • To understand aggregate usage. Daily visit totals tell us whether the Site is working; they are not tied to any individual.

Where the UK/EU GDPR applies, our lawful basis is legitimate interests (Article 6(1)(f)) — running and protecting a free public directory — balanced against the fact that the data is minimal and pseudonymous.

5. How long we keep it

  • Individual visit records: pruned automatically after a short retention window (14 days by default). They exist only to calculate “trending right now”.
  • Daily visit totals per listing: kept indefinitely. These are aggregate counts with no visitor data attached.
  • Listings and their hashed submitter data: kept for as long as the listing is published.
  • Server access logs: rotated on a short cycle, typically within 30 days.

6. Who we share it with

Nobody, in the sense that matters: we do not sell, rent, or trade data, and we do not share it for advertising. The Site runs on a virtual server rented from DigitalOcean, which necessarily processes traffic on our behalf as an infrastructure provider. We may disclose information if legally compelled to, or where necessary to investigate abuse or protect someone’s safety.

If we introduce advertising, an advertising provider may process data about your visit in order to serve it. We will name any such provider here, and describe what it receives, before it goes live — and we will not hand it the submission or visit records described above.

Under the California Consumer Privacy Act, we do not “sell” or “share” personal information as those terms are defined.

7. Links to other websites

Opening a listing takes you to a business’s own website, with a utm_source=atxtopeatery parameter attached so they can see where the visit came from. Once you land there, that site’s own privacy policy applies — we have no control over and no visibility into what they collect.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or restrict processing of your personal data, to object to processing, to data portability, and to lodge a complaint with a supervisory authority.

In practice, because we hold no identifiers that point back to you, there is usually nothing to retrieve or erase. The exception is a listing you submitted: email [email protected] with the URL and we will remove it. We do not discriminate against anyone for exercising these rights.

9. Children

The Site is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has submitted personal information, contact us and we will delete it.

10. International visitors

The Site is operated from the United States and hosted there. If you visit from outside the US, the limited data described above is processed in the US, which may have different data-protection rules than your home country.

11. Security

Traffic is served over HTTPS. IP addresses are hashed before storage. Access to the administrative dashboard requires a password and is rate limited. No system is perfectly secure, but the Site deliberately holds very little worth stealing.

12. Changes to this policy

If this policy changes, the “Last updated” date above changes with it. Material changes will be reflected on this page before they take effect.

13. Contact

Questions, corrections, or removal requests: [email protected]. See also our Terms & Conditions.