Legal

Privacy Policy

Draft — last reviewed 2026-08-09

This page is a draft, pending legal review.

The sections below describe basilly's data handling as accurately as it's currently implemented in the codebase. Sections marked [owner/legal to complete] need input basilly's team hasn't supplied yet — a registered company name and address, full data-retention periods, and a formal legal basis for processing. This page is not indexed by search engines until that review is done.

Who we are

basilly (basilly.com) is a UK food platform. Data controller details — registered company name, company number, and registered address — [owner/legal to complete].

What we collect

  • Account data: the email address and password you register with. Passwords are stored hashed, never in plain text.
  • Content you submit: recipes, places, hotels, product reviews, and comments you choose to post, along with any name or contact details you include in a submission.
  • Saved items: recipes and places you save to your account.
  • Payment relationship: if you take out a paid membership, payments are handled by Stripe. basilly does not store your full card details.
  • Cookies: basilly currently uses a single session cookie to keep you signed in. No advertising or analytics cookies are set at this time.

Who your data is shared with

basilly uses the following technical service providers to run the site: Stripe (payments), Cloudinary (image hosting), Vercel (application hosting), and a managed PostgreSQL database provider. A complete sub-processor list, the legal basis for each transfer, and retention periods for each category of data are [owner/legal to complete].

Your rights

Under UK data protection law you can generally ask to access, correct, or delete your personal data. Until this page is finalised, please email hello@basilly.com for any of these requests and we'll handle it manually.

Retention

How long each category of data is kept — [owner/legal to complete].

Contact

Questions about this policy: see our contact page.