Back to UniBites

Privacy Policy

Last updated: 7 September 2026

This Privacy Policy explains how UniBites (“UniBites”, “we”, “us”, or “our”) collects, uses, discloses, and protects your personal information when you use our website and mobile application (the “Service”). By accessing or using UniBites, you agree to the practices described in this policy. If you do not agree, you should not use the Service. For details about how we use cookies and similar technologies, see our separate Cookie Policy.

1. Controller and contact

UniBites is the data controller responsible for your personal information under applicable UK and EU data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any question about this policy or how we handle your data, you can contact us through the Contact page or by writing to hello@unibites.co.uk.

2. Information we collect

Information you provide directly. When you register an account, we collect your email address, display name, username, and a password (stored only as a cryptographically secure hash). You may optionally add a profile photo and banner image, short bio, pronouns, university, graduation year, and a phone number for account security and support. Any recipe, review, reaction, comment, bookmark, message, SnackSnap post, or other content you create is also stored and associated with your account.

Information collected automatically. When you use UniBites we automatically collect limited technical and usage data, including device type, operating system, approximate region derived from your IP address, and aggregate statistics about which features and pages you interact with. We use this solely to operate, secure, and improve the Service.

Information from payment processing. If you subscribe to UniBites Unlimited, payment is handled by our payment provider, Stripe. We receive the minimum details needed to confirm and manage your subscription (for example subscription status and renewal date). We never receive or store your full card number or other sensitive cardholder data — that information is collected and processed directly by Stripe.

Information from support and communications. When you contact our support team, we may record internal notes about your enquiry and any actions taken on your account. If you use our in-app voice calling features (WebRTC), call metadata and voicemail messages may be stored to help us resolve support issues. We also assign you a customer reference number for internal administration. Transactional and marketing emails sent to you are logged (subject, date, and click-tracking data) so we can measure engagement and improve our communications — we track whether links in our emails are clicked, not whether the email was opened.

Biometric and security data. If you choose to enable biometric login (such as Face ID or fingerprint), we store a WebAuthn public-key credential on your account that allows your device to authenticate you. This credential never leaves your device and we cannot use it to access your biometric data. If you enable email-based two-factor authentication (2FA), we store a flag on your account indicating that 2FA is active. You can disable biometric login or 2FA at any time from your settings, and we can remove stored biometric credentials from your account on request.

Credits and rewards data. We store your bite-point credit balance and transaction history (including credits granted, used, or deducted) to manage recipe unlocks, promotional rewards, and ambassador payouts calculations.

3. Lawful basis for processing

We process your personal information only where we have a lawful basis under the UK GDPR. In particular, we rely on:

  • Performance of a contract — to provide your account and the features you signed up for, including recipes, reviews, messaging, and subscriptions.
  • Legitimate interests — to keep the platform secure, prevent fraud and abuse, and improve the Service, where these interests are not overridden by your rights.
  • Consent — for any optional processing that is not strictly necessary to run the Service, such as optional profile details you choose to add.
  • Legal obligation — where we are required to retain or disclose information to comply with the law.

4. How we use your information

We use your personal information to: create and manage your account; display the recipes, reviews, reactions, and bookmarks you create; power social features such as following, direct messaging, group chats, and university-based groups; recommend trending and relevant content; process and administer subscriptions and renewals; send service-related notifications such as follow requests and group invitations; investigate, prevent, and respond to misuse, reports, and security issues; and comply with our legal obligations.

5. Cookies and local storage

UniBites uses essential cookies and local storage to keep you signed in, remember your preferences (such as theme and cookie choice), and display the Service correctly. These are strictly necessary for the Service to function and cannot be switched off in our systems. For non-subscribers, we display advertising through Google AdSense, which may set its own cookies and similar technologies to serve and measure ads based on your activity and interests; UniBites Unlimited subscribers do not see advertisements. You can manage or disable advertising cookies through your browser settings or Google's Ads Settings (ads.google.com). We do not use additional third-party analytics or tracking cookies beyond what is described here. You can clear stored data at any time through your browser settings, although some features may stop working as a result. Full details, including how to manage cookies and the advertising cookies used by Google AdSense, are set out in our Cookie Policy at https://getunibites.com/cookie-policy.

6. Sharing and disclosure

We do not sell your personal information. We share information only in the following limited circumstances:

  • With service providers — such as Stripe for payment processing, Google AdSense for advertising (shown to non-subscribers only), and our hosting and infrastructure providers, who process data on our behalf and under our instructions.
  • To keep the Service safe — where necessary to enforce our Community Guidelines, investigate reports, prevent fraud, or protect the rights, property, or safety of UniBites, our users, or others.
  • To comply with the law — where we are required to respond to lawful requests from public authorities, or to establish, exercise, or defend legal claims.
  • In connection with a transfer — in the event of a merger, acquisition, or sale of all or part of our business, information may be transferred subject to the protections in this policy.

7. Visibility of your content

Your public profile, recipes, reviews, reactions, bookmarks, and SnackSnap posts are visible to other UniBites members. You can control your account privacy from Settings to limit who can see your saved items and personal details. Direct messages and group chats are visible only to the members of that conversation. Reviews and content you submit may remain visible to the community even after you delete your account, in an anonymised form where appropriate, as part of the shared cookbook.

8. International data transfers

Your information may be processed in countries outside the UK or European Economic Area that may have different data protection standards. Where this happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or standard contractual clauses, and we take steps to ensure your information remains protected to a standard consistent with UK data protection law.

9. Data retention

We keep your personal information for as long as your account is active, or for as long as we need it to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we remove your profile and personal data within a reasonable period, although some information may be retained in anonymised or aggregated form, or where we are legally required to keep it. Specifically:

  • Active account data — retained for as long as your account is active.
  • Recipes, reviews, and community content — retained indefinitely under an anonymised account after deletion, so other students can continue to benefit.
  • Complaints and support records — retained for 7 years from account deletion or complaint closure for audit and legal purposes, then permanently deleted.
  • Payment records — retained as required by tax and financial regulations.
  • Biometric credentials — retained until you disable biometric login or request removal. Deleting your account also clears all stored WebAuthn credentials.

10. Your rights

Under UK and EU data protection law you have the following rights, subject to certain exceptions:

  • Access — to a copy of the personal information we hold about you.
  • Rectification — to have inaccurate information corrected.
  • Erasure — to request deletion of your personal information.
  • Restriction and objection — to ask us to limit or stop certain processing.
  • Portability — to receive certain information in a structured, machine-readable format.
  • Withdrawal of consent — where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal.

You can exercise most of these rights directly from your Settings page, including downloading a copy of your data via the in-app data export feature. To make a formal request, contact us through the Contact page. If you are unsatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

11. Children

UniBites is intended for students and individuals aged 16 and over. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

12. Security

We take reasonable technical and organisational measures to protect your information, including encrypted password storage, access controls, and regular review of our systems. We offer optional email-based two-factor authentication (2FA) and biometric login (via WebAuthn) to help you secure your account. However, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials and biometric devices secure.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. We will indicate the “Last updated” date at the top of this page and, where changes are significant, provide a more prominent notice. Your continued use of UniBites after a change takes effect constitutes acceptance of the updated policy.

14. Contact

If you have any questions, requests, or concerns about this Privacy Policy or your personal information, you can reach us through the Contact page or by writing to hello@unibites.co.uk. We will respond in accordance with applicable data protection law.

We use essential cookies

UniBites uses essential storage to keep you signed in and remember your preferences. Free users may see ads served by Google AdSense, which can use cookies; subscribers don't. See our Cookie Policy and our Privacy Policy.