Version 2026-09-12-v3 · FishMap public beta · designed for the UK GDPR, Data Protection Act 2018 and PECR as amended by the Data (Use and Access) Act 2025.
The controller is William Thomas Kemsley, operating FishMap. Contact: fishappsupport@gmail.com, 36 Rowan Road, Houghton Conquest, MK45 3SG.
Depending on the features you use, FishMap may process your email address through authentication; username and profile fields; age band (13–17 or 18+); catches and sessions; favourites; custom fishing locations; account-scoped app preferences such as theme, map style and saved favourite details; optional precise coordinates attached to your own catch/session; profile photo and catch photos; posts, comments, reactions, follows, groups, blocks and reports; support/privacy requests; and security/technical logs produced by hosting providers.
FishMap deliberately separates precise catch/session coordinates from social content. Exact coordinates are private account data and are not included in community post records.
| Purpose | Typical lawful basis |
|---|---|
| Create and operate your account, automatically sync your journal/preferences while signed in, groups and features you request | Contract / steps at your request |
| Security, abuse prevention, service integrity and proportionate moderation | Legitimate interests; legal obligation where applicable |
| Age band and enhanced privacy safeguards for younger users | Legitimate interests in protecting users and complying with applicable child-data duties |
| Optional product marketing | Consent; off by default and withdrawable |
| Optional non-essential analytics if introduced | Consent where required; none enabled in this beta build |
| Responding to privacy/data-rights requests | Legal obligation and/or legitimate interests |
Device/browser permission to use geolocation is separate from the data-protection lawful basis. FishMap only requests device location when you use a location-related feature.
Profiles start private. Exact catch locations are hidden from social features. Users aged 13–17 receive enhanced privacy prompts and high-privacy defaults. FishMap does not include private messaging, targeted advertising, or behavioural advertising profiles.
FishMap uses local browser/device storage for essential app functionality, preferences, offline caching and authentication session handling. No third-party analytics service is enabled in this beta build. If non-essential analytics or advertising storage is added later, it must remain disabled until the required consent or other lawful PECR exemption applies, with an easy way to change the choice.
FishMap uses Supabase for authentication/database/storage and Netlify for hosting/server functions. Mapping, imagery, weather and location-search services may also receive normal network information such as your IP address when their resources are requested. The production service must maintain appropriate processor arrangements.
Where information is transferred outside the UK, FishMap will rely on an applicable UK adequacy regulation or another lawful safeguard, such as the UK International Data Transfer Agreement/Addendum, where required.
Account/journal data is kept while your account remains active unless you delete it or another retention rule applies. Resolved support and moderation records are configured for deletion after 12 months; resolved data-protection complaints after 24 months; notifications after 180 days. Active account deletion removes database records and private stored media; infrastructure backups may persist until the provider's normal backup cycle expires. Legal/security records may be retained longer where necessary and lawful.
Depending on the processing, UK data-protection law may give you rights to be informed, access information, correct it, erase it, restrict processing, object, and receive portable data. FishMap includes profile correction, machine-readable export and account-deletion tools. You can withdraw optional marketing/analytics consent as easily as you give it. Rights are not absolute in every circumstance.
FishMap does not permit account creation by children under 13. Because the service may be used by people under 18, it is designed around the ICO Children's Code: high privacy by default, minimised collection, no automatic social location disclosure and no nudges to weaken privacy. Parents/carers and younger users can use the support/privacy channel for questions.
FishMap administrators can access aggregate user counts, limited profile identifiers needed for administration, public community content, reports and information a user deliberately submits to support. The database does not give admins a blanket read policy for private catches, sessions, custom locations or precise catch coordinates. Passwords are handled by the authentication provider and are never readable by FishMap administrators.
Fishability, Catch Score and Session Score are recreational planning/statistics features. They are not used to make legal or similarly significant decisions about people.
You can make a data-protection complaint in the app under Profile & account → Privacy & support → Data protection complaint, or email fishappsupport@gmail.com. FishMap will investigate appropriately and communicate the outcome without undue delay. You also have the right to complain to the UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint/.
FishMap is currently a public beta. Beta status does not reduce your privacy rights. Material privacy changes will be presented clearly, and choices requiring consent will not be silently enabled after an update.