Legal

Privacy Policy

This policy explains what personal data Where's The Fish collects when you use the site, what we do with it, who we share it with, how long we keep it and the rights you have over it.

Effective from 6 September 2026

1. Who we are

Where's The Fish ("we", "us", "our") runs wheresthefish.uk. We are the data controller for the personal data described in this policy. You can reach us about anything in it at support@wheresthefish.uk or through the contact page.

2. What we collect

When you browse without an account

  • Technical data your browser sends with every request: IP address, browser and device type, the pages you visit and the page you came from. Our web server and error-monitoring keep this in logs.
  • Anonymous, aggregated usage measurements from a cookieless analytics service (see section 7). These do not identify you.
  • The map area you are looking at, sent to us so we can return the marks inside it. We do not store it against you.
  • If you use the contact form: your name, email address and message, plus a reCAPTCHA score from Google that helps us block spam.

When you create an account

  • Your email address and name. If you sign in with Google we also store the identifier Google gives us for your account so we can recognise you next time. We do not receive or store a password: sign-in links are emailed to you and each one expires after a short time.
  • Your angler profile: username, display name, bio, avatar, home county and the privacy defaults you choose. The username cannot be changed once set.
  • Preferences: the species and sea conditions you care about, forecast calendar settings and saved-spot alert settings.
  • Your saved spots ("My spots"), likes and the notifications the service sends you.
  • Everything you log: catches (species, weight, length, method, bait, time, location, notes and photos), trip plans and their outcomes, session write-ups and reports, comments and replies, and feedback on forecasts.
  • Usage events tied to your account (for example that you opened the planner or logged a catch) in our analytics, so we can see which features are used and fix what is not working.

When you subscribe to Premium

  • Payment is handled by Stripe. Stripe collects your card details and billing address directly; we never see the full card number. We store your Stripe customer reference, the card type and last four digits, your subscription status and dates, and the events Stripe sends us about payments and renewals.

We do not collect any special category data. Please do not put health information or other sensitive details in your bio, notes or reports.

3. Why we use it and our lawful basis

PurposeDataLawful basis
Signing you in and running your accountEmail, name, Google identifier, session dataPerforming our contract with you
Storing and showing your catches, trips, reports, comments and profileEverything you log or postPerforming our contract with you
Taking payment and managing your subscriptionStripe customer reference, subscription status, payment eventsPerforming our contract; legal obligation (tax and accounting records)
Emailing you sign-in links, receipts, and saved-spot forecast alerts you have turned onEmail address, saved spots, alert settingsPerforming our contract; alerts are sent only while you keep them switched on
Telling you about engagement on your content and material changes to the service or these termsEmail address, in-app notificationsLegitimate interests (running a community service); legal obligation for notice of changes
Suggesting a species from a photoThe photo you upload (nothing that identifies you)Performing our contract, at your request each time
Producing aggregated catch statistics for marks and speciesCatch records, anonymised in aggregateLegitimate interests (the aggregate is what makes the service useful to everyone)
Measuring how the site is used and fixing errorsTechnical data, usage events, error reportsLegitimate interests (improving and securing the service)
Preventing spam, abuse and fraud, and enforcing our termsTechnical data, account and content data, reCAPTCHA scoreLegitimate interests (protecting the service and its users)
Measuring whether our advertising leads to sign-ups or subscriptions, when we run campaignsGoogle Ads conversion eventsConsent, through the Google Ads tag described in section 7

We do not sell personal data, we do not use it for automated decisions with legal or similarly significant effects on you, and we do not send marketing email. The only emails you receive are the ones needed to sign in, run your subscription, deliver the alerts you have asked for and tell you about activity on your content.

4. What is public

The service is a community of anglers, so by default the things you log are visible to everyone, including people without an account and search engines:

  • your profile page (username, display name, bio, avatar, home county if set, and stats if you leave them on);
  • your public catches with their photos, species, weight, date and the location at the precision you chose;
  • your published trip reports and the comments you leave on other people's catches and reports;
  • your username next to anything you like or comment on.

Your email address, Google identifier, payment details, private catches, unpublished trips, private notes, exact GPS positions and forecast preferences are never public.

You control the audience of each catch and report, and the default for new ones, from your profile settings. Some audience and location-precision options are part of Premium; the Premium page lists which. A profile with only a handful of public catches is marked so that search engines do not index it, and you can make your whole profile private.

5. Photos, locations and AI species ID

Photo metadata

Photos often carry hidden metadata: the time they were taken and, on most phones, a GPS position. When you upload a catch photo we read that metadata in your browser and on our server to pre-fill the time of the catch and suggest the nearest mark, and then we re-encode the image so the stored and published copy carries no metadata at all. You can switch metadata reading off in your profile settings, in which case we never look at it. The original file is not kept.

Location precision

A catch is placed on a mark from our catalogue. When you publish it you choose whether other people see the mark, only the town, only the county, or no location. For session write-ups at a spot not in our catalogue you can drop a pin instead; the pin coordinate stays on our server and is never shown to anyone else, only the nearest town or the county at the precision you chose.

AI species identification

If you ask us to identify a species from a photo, we send the photo to OpenAI, a third-party AI provider, and show you its suggestion. We send only the image and a fixed instruction, never your name, email or location, and the photo is not used by the provider to train its models under the terms we hold with it. Use is limited to 5 identifications a UK calendar month on a free account and 50 on Premium, and we record how many you have used each month to enforce that.

6. Who we share data with

We share personal data only with the providers we need to run the service, each acting on our instructions:

  • Google (sign in with Google, reCAPTCHA on the contact form, and the Google Ads tag when we run campaigns).
  • Stripe (payments, subscriptions, invoices and the billing portal). Stripe is an independent controller for the payment data it collects.
  • Resend (sending our email: sign-in links, receipts, alerts and notifications).
  • OpenAI (photo species identification, as described in section 5, and the generation of our own site content, which involves no personal data).
  • Cloudflare (content delivery, image resizing and the object storage that holds catch photos and avatars).
  • Our hosting provider (the servers, database and backups the service runs on, located in the UK or EU).
  • Sentry (error monitoring, which receives technical details of a request when something goes wrong, including your user identifier if you were signed in).
  • PostHog, running on our own servers, and Umami (usage analytics, see section 7).

Our weather, sea-state and tide providers receive only mark coordinates, never anything about you. We may also disclose data where the law requires it, to enforce our terms, or to a buyer if the service changes hands, in which case this policy continues to apply to it.

7. Cookies, analytics and local storage

We keep cookies to the minimum the service needs to work:

  • Session and security cookies that keep you signed in, protect forms against forgery and remember flash messages. These are strictly necessary and last for your session or until you sign out.
  • Analytics. Umami measures page views without cookies or fingerprinting and cannot identify you. PostHog runs on our own infrastructure, so your usage data is not shared with a third party; it uses browser storage to recognise the same visitor across page views and, once you sign in, ties events to your account so we can understand how features are used. It does not record your screen.
  • Google Ads. Only while we are running an advertising campaign, a Google tag records whether a visit that came from one of our adverts led to a sign-up or subscription. This may set Google cookies, and you can block it with your browser's tracking protection without affecting the service.
  • Local storage in your browser keeps small conveniences on your device only: recent searches, which release announcement you have dismissed, and map preferences. Nothing in it is sent to us.
  • Stripe sets its own cookies on the checkout and billing portal pages for fraud prevention.

You can clear or block cookies and site data in your browser settings. Blocking the session cookie will stop you signing in.

8. How long we keep data

  • Account, profile and content data: for as long as you keep your account, then as described in section 9.
  • Sign-in links: each link is single-use and expires after a short time; used and expired links are removed.
  • Server sessions: expire after a period of inactivity.
  • Contact form messages: kept in our support mailbox for up to two years so we can follow up.
  • Payment and subscription records: kept for six years after the last payment, as UK tax law requires.
  • Server and error logs: up to 90 days.
  • Analytics events: up to 12 months in identifiable form; aggregated statistics are kept indefinitely.
  • Forecast data for marks is not personal data and is pruned on its own schedule.
  • Backups: overwritten on a rolling basis within 30 days.

9. Deleting your account

You can delete your account yourself, immediately, from the account page. This removes your profile, catches, photos, trips, reports, comments, likes, saved spots, notifications, preferences and sign-in identifiers from the live service, cancels any Premium subscription straight away, and stops your public pages resolving. Photo files are purged from storage and backup copies are overwritten within 30 days.

What we keep after deletion:

  • payment and invoice records at Stripe and in our accounts for the statutory period, because tax law requires it;
  • aggregated statistics your catches contributed to, which no longer identify you;
  • a minimal record (an email address or identifier) where an account was closed for breaking our terms, so the ban holds;
  • anything in server logs until those logs age out on the schedule above.

You can also delete or make private individual catches, trips, reports and comments at any time without deleting the account. Deleting a comment removes replies to it.

10. International transfers

Some of the providers in section 6 are based in, or process data in, the United States. Where personal data leaves the UK we rely on the UK's adequacy regulations, the UK extension to the EU–US Data Privacy Framework where the provider is certified, or the UK International Data Transfer Addendum to the EU standard contractual clauses, so that your data keeps the protection it has here.

11. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct anything inaccurate: most of it you can edit yourself from your profile and account pages;
  • erase your data, which you can do yourself by deleting your account;
  • restrict or object to processing that relies on our legitimate interests;
  • port the data you gave us to another service in a machine-readable format;
  • withdraw consent at any time where we rely on it, without affecting what was done before.

To use any of these rights that you cannot exercise yourself on the site, email support@wheresthefish.uk from the address on your account. We will respond within one month and will not charge you unless a request is clearly unfounded or excessive.

12. Security

Everything is served over HTTPS. Sign-in links are single-use and short-lived, and we hold no passwords that could leak. Card details never touch our servers. Uploaded images are re-encoded so they cannot carry hidden payloads or metadata, and free-text fields reject markup. Access to production systems is limited to the people who run the service. No system is perfectly secure, so if we learn of a breach that puts your rights at risk we will tell you and the Information Commissioner's Office as the law requires.

13. Children

The service is not aimed at children and you must be at least 16 to hold an account. We do not knowingly collect personal data from anyone younger. If you believe a child has created an account, email us and we will delete it. Photos of children in someone else's catch should only be posted with a parent's permission, and we will remove any that are reported to us.

14. Changes to this policy

We will update this policy when we add a feature that uses data in a new way, change a provider or the law changes. The date at the top shows the current version. For a material change we will tell you by email or with a notice on the site before it takes effect.

15. Contact and complaints

Questions, requests and complaints about personal data go to support@wheresthefish.uk or through the contact page. If you are not happy with how we handle a complaint you can contact the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113.