Privacy policy
Draft, pending legal review.
Last updated on 26 September 2026. This text is not final yet.
sovl is the "best at" recommendation network on sovl.com and in the sovl bot on Telegram. This policy explains which personal data sovl processes, why, and what you can do about it. We describe what the system actually does today; what is announced but not built yet is in a separate section at the end.
Who is responsible
The controller is Memes BV, Rue Groeselenberg 180, 1180 Uccle, Belgium, company number 0478.554.250, VAT BE0478554250. For anything about your data, write to [email protected].
What we process
Your account in the bot. When you write to the bot we store your Telegram user id, the name you use on Telegram (first name, last name or username), which becomes your display name, when you last wrote to the bot and whether the bot can reach you. We store the language of the conversation, taken from your Telegram app, to answer in your language. On WhatsApp, once available, your WhatsApp number is your identity and your WhatsApp profile name is your display name.
Your phone number, only if you share it. When you tap "Share my number" in the bot, Telegram sends us your own number and we store it in full, in international format. It is how sovl makes one phone number count as one person, and it is required to claim a shop or hang a sticker on a place. It is never shown publicly. When you claim a shop, the person who reviews the claim sees only its last four digits. You can vote without sharing your number; the ranking then says it is verified by account rather than by phone. sovl sends no text messages and uses no SMS provider.
Your votes. For every vote: the category, the place (its Google place id and name), the level and area you chose (neighbourhood, town, country or world), when you cast it, whose vote you followed, the vote you originally followed when you cast it, how it arrived (directly, through a sticker, or through a campaign code), whether it came through a share link, and whether it still stands or moved, with the date of the move. Earlier votes stay in your history when you move. We use these to count the rankings, to keep "found by" and "best since" honest, and to apply the rate limits.
Challenges and messages. Who challenged which vote, the deadline, your answer and when you gave it. We also keep the notifications the bot sends you and the one-time buttons in them.
Share links. A share link carries the id of the vote it shares. When a share link first brings you to sovl, we record which vote brought you and when, once. Opening a share link on sovl.com itself records nothing.
Stickers and campaign codes. Per code we count scans, bot starts, phone shares and votes. Those counters say nothing about who scanned. A vote records the code it came through. When you hang a code on a place, we record that you did and when.
Shop owners. When you claim a place: which place, the status of the claim, who decided and when, the codes an approval took over, and the votes for your own place that an approval withdrew (so a revoke can restore them).
Conversation state. The step of the conversation you are in and what is needed to finish it, for example the place you picked or the code you scanned. If you send the bot a location, it is not stored.
Place searches. What you type to find a place is sent to Google Places to find it. The places themselves are businesses: we store their Google place id and, for places with votes, their address, town, Google Maps link and website. We also classify every voted place into its neighbourhood, town and country, and keep the names of those areas, as Google gives them, in our public list of areas.
Signing in on sovl.com. On the sign-in page Telegram's login widget is loaded from telegram.org. After you confirm in Telegram, we receive your Telegram id, name, username and profile photo link, and check Telegram's signature. We keep only the id and the name; the username and the photo link are not stored. We then store a fingerprint (a SHA-256 hash) of your session token with the date it was created, last used and expires. We store no IP address and no browser details with it.
Operations and security. When something fails, we log a technical event for 30 days. It carries ids (for example a person id or a Telegram chat id), never the text of your messages and never your phone number. Alerts about failures go to our own ops chat on Telegram and to a Slack channel; an error message can occasionally contain a display name or a place name. A daily summary contains counts only.
E-mail. If you write to [email protected], we keep the correspondence for as long as needed to handle it.
What is public
- Rankings, the places in them, their vote counts, "best since" and their history are public on sovl.com and in machine-readable form (JSON and schema.org).
- Your name is not public by default. On sovl.com you appear as "a voter" and are counted, not named. Only voters who have explicitly agreed to be named appear by name: on rankings, as the finder of a place, on their voter page and in the machine records. There is no setting for this in sovl yet; until there is, nobody is named on sovl.com without having agreed with us directly.
- Inside the bot, the people you deal with see your display name: the person who opens your share link, the voter you challenge or who challenges you, the people who followed your vote when you move it, and bot users looking at a ranking where you found the place.
- Link previews of sovl pages show a person's name only for voters who agreed to be named. The share link of such a voter gets a preview card with their name, kept in the edge cache for up to 5 minutes.
Why, and on which legal basis
- Running sovl for you (your account, votes, challenges, notifications, share links, signing in, shop claims): performance of the contract formed by our terms of use (article 6.1.b GDPR).
- One phone number, one person, and the rate limits: our legitimate interest, and that of every voter, in rankings that cannot simply be bought or stuffed (article 6.1.f).
- Showing your name publicly: your consent (article 6.1.a), which you can withdraw at any time.
- Security, error logs, abuse prevention and handling reports: legitimate interest (article 6.1.f).
- Aggregated statistics about how sovl is used, such as how many votes arrive through a share link or a sticker: legitimate interest (article 6.1.f). They are counts, never profiles of individuals.
- Answering authorities and keeping what the law requires: legal obligation (article 6.1.c).
Who else processes your data
We do not sell personal data and show no advertising. These providers process data for us, or because you use them:
- Supabase: our database and server functions, hosted in the EU region eu-west-1 (Ireland).
- Cloudflare: hosting of sovl.com and its network. Cloudflare sees technical data such as your IP address and the page you request, to deliver and protect the site.
- Telegram: the bot and the sign-in on sovl.com. Telegram's own privacy policy applies to your use of Telegram.
- Meta (WhatsApp), once the WhatsApp bot is available.
- Google: Google Places, for place search and place details. On pages with a place photo, your browser loads the photo from Google's servers (googleusercontent.com), so Google receives your IP address.
- Slack: internal alerts about failures (see above).
Transfers outside the EU
The database is stored in the EU. Several providers are companies based in the United States or elsewhere outside the EU, and Cloudflare serves the site from a worldwide network. Where data leaves the EU, we rely on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission's standard contractual clauses.
How long we keep it
- Your account, votes, vote history, challenges and shop claims: as long as your account exists. When you delete it, they are removed at once (see below).
- Notifications the bot sent you, and its one-time buttons once used or expired: removed at night once they are 90 days old, counted from when they were created. A button you can still press is kept until it expires.
- Conversation state: removed 30 days after your last step in a conversation with the bot; your next message starts afresh.
- Sessions on sovl.com: one year after you last used them; expired sessions are removed daily.
- Technical event logs: 30 days.
- The classification of a place into areas, and the names of those areas: no fixed limit; they describe places, not people.
- Place details from Google: refreshed at least every 25 days, and cleared after 29 days without a refresh. The link to a place photo and its credit are cached for at most 40 minutes.
- The logs of our hosting providers and the automatic backups of the database follow the provider's own, limited retention.
Deleting your account
Signed in on sovl.com, go to your account and choose delete account. In one step this removes you and everything linked to you: your channels, phone number, votes and their history, challenges by or against you, notifications, buttons, sessions, shop claims, conversation state, and the technical event logs linked to your id. A name that appears inside the text of an error message stays in the log until it is deleted after 30 days, and copies of alerts already sent to our ops chat on Telegram and to Slack are not removed. People who voted with you keep their own vote. Finder credit for a place passes to the next earliest voter. Rankings are recounted. If you write to the bot again later, you start as a new person.
No access to sovl.com? Write to [email protected] from the bot account in question, or tell us how to recognise it, and we will delete it for you.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to object to processing based on our legitimate interest, to receive your data in a portable form, and to withdraw your consent at any time. Write to [email protected]. We answer within one month and may ask you to show that the account is yours, for example with a message from the bot.
You can also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), www.dataprotectionauthority.be.
Cookies
sovl.com uses only cookies that are strictly necessary, so there is no cookie banner. There are no analytics, advertising or tracking cookies, and our fonts are hosted on sovl.com itself.
- sovl_session: keeps you signed in, one year.
- sovl_login_intent: protects the sign-in against forgery, 15 minutes, used once.
- sovl_lang: remembers your language during sign-in and on your account page, 10 minutes.
- sovl_next: brings you back to the page you came from after signing in, 15 minutes.
- sovl_initial: holds only the initial of your name, so the header can show it; set at sign-in and on your account page, removed when you sign out or delete your account, one year.
The sign-in page loads Telegram's login widget, which is Telegram's own and subject to Telegram's policy.
Age
sovl is meant for people aged 16 or older.
Automated decisions
A ranking is a count of standing votes, with fixed rules for ties. Rate limits apply automatically. sovl takes no decision about you that has legal or similarly significant effects.
Coming soon: profile fields
Not built yet. When these fields arrive, this policy will be updated before they go live.
- A username, unique and editable, which becomes the address of your voter page.
- Your real first and last name, optional, and public only if you choose so.
- Sex (male, female, prefer not to say), birth year, region, and country. Country will be required and prefilled from your phone number's country code; everything else is optional, asked once after your first vote and skippable.
- Children: a count per age band (0 to 3, 4 to 8, 9 to 12, 13 to 17). Never names or birth dates.
- Social media handles you type in yourself. Later, a real connection to those platforms, showing their follower count as the platform's number.
- Your primary language, which sets the language of the site and the bot.
- One privacy switch for your name and your voter page: everybody, your circle, or nobody.
- A short "why" text with a vote, optional. Visible only to signed-in viewers, never in the machine records. Per vote you choose everybody or your circle. Earlier versions are kept internally; only the latest is shown.
- A disclosure on a vote (sponsored or ambassador, and the brand), with the date it was added.
The profile fields will serve four purposes: filters for users (for example "best according to parents"), aggregated statistics for shops (never about an individual), our own analytics, and a personalised ranking. For the optional fields the legal basis will be your consent, which you can withdraw by clearing the field.
Changes
We will update this policy when sovl changes. The date at the top shows the latest version. We will tell you through the bot about changes that matter.
See also: Terms of use ยท Legal notice