Privacy notice

Sessions, crews & settling up

When you use Divvy we store the crews you belong to, the sessions you take part in, the rounds and orders logged in them (which drinks, at which venue, when), who paid, and the settlement records — who owed whom and what was marked as paid.

This data is visible to the other people in your crew or session — that's what makes splitting the bill work. It is not public.

Lawful basis: this processing is necessary to provide Divvy to you (UK GDPR Article 6(1)(b)). For a copy of your data or to ask for deletion, email jason@divvy.pub.

Your bank details

If you save bank details so friends can pay you back, the account name, sort code and account number are stored encrypted, with the key held separately from the database (Google Cloud KMS). A copy of the database alone cannot reveal them. Only the bank’s name and the last four digits of the account number stay readable, so the app can show you what you’ve saved.

They are visible only to you — never to other members — and are only decrypted when you tap Change on the bank card in Edit Profile, or when you choose to include them in a settle-up message you share. You can remove them at any time from Profile → Edit.

Lawful basis: this processing is necessary to provide the settle-up feature you asked for by saving them (UK GDPR Article 6(1)(b)).

Added by a friend? (managed guests)

If a friend added you to a session without you having the app, Divvy holds the name they entered for you and the drinks and share recorded against it. If they also gave us your email address — which we only accept when they confirm you were happy for them to share it — we use it solely to send you a claim link, so you can take over the record and see your own history.

You don't have to claim anything. If you never claim the record, we automatically delete any saved contact details 90 days after they were added. If the record is never claimed and hasn't been part of a session for at least 24 months, we also replace the saved name with "Former guest" — the amounts stay, so everyone else's history still adds up. To see what's held under your name or to have it removed sooner — including any contact details — email jason@divvy.pub and we'll sort it. Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)) — keeping the group's bill accurate for the people splitting it.

Adding a guest? Only enter someone's email address if they've genuinely agreed — you'll be asked to confirm that when you add it.

Analytics — what we collect

We use Firebase Analytics (by Google) and Sentry (error and performance tracking) to understand how Divvy is used and to catch bugs before you hit them.

Events include things like: started a session, added an order, opened the settlement screen, and automated signals like slow interactions or rage clicks.

Analytics — what we don't

We never send your email, real name, display name, avatar, drink search text, payment data, or bank details to analytics or crash-reporting services.

The only identifier attached to analytics events is your internal Divvy user id. That lets us count unique users without knowing who they are.

Help, bugs & manage-venue requests

When you send us a bug report, help question, feature idea, or a request to manage a venue, your message is stored in Divvy's database. Only you and Divvy admins can read it.

Manage-venue requests collect a bit more: your legal name, your role at the venue, a business email address (which we verify by sending a one-time code via our email provider Resend), a business phone number, and a short statement about your role. We use this information to verify your affiliation with the venue, to inform our decision on your request, and to contact you about that request. We do not share it with the venue or with anyone else, and we do not use it for marketing.

Lawful basis: legitimate interests under UK GDPR Article 6(1)(f). To request a copy or deletion of your past submissions, email jason@divvy.pub.

Analytics processors & retention

When you scan a receipt or menu, we delete the photo automatically 90 days after it's uploaded.

How to opt out

Go to Profile → Edit → Privacy and untick Help us improve Divvy. This stops all analytics and crash reports immediately and remembers your choice across devices.

Opting out does not affect your sessions, crews, or any other Divvy feature.

Check-ins & your location

When you tap Check in, Divvy reads your device's location once, at that moment, to confirm you're at the pub (within 150m) and to record your visit. We use it only for this — it is not sent to our analytics providers.

We don't keep your precise coordinates. We use them only to check you're within 150m of the pub, then discard them — we record only the pub and the date of your visit.

Your location in a check-in is not shared with anyone at this step.

The legal basis is your consent, which you give the first time you check in. To have your check-in history deleted, contact us via the in-app feedback option.

Telling a crew you're out

Checking in is private by default — nobody is told. A separate, clearly-labelled action lets you tell one crew you choose that you're out right now. Only the people you confirm on that screen are told — later changes to the crew can't widen who sees it.

What's shared is the pub, not your exact location, and it disappears after a few hours — it never becomes a permanent record of where you've been. You can clear any active "I'm out" message immediately with Stop all active sharing.

The legal basis is your consent, given each time you tap to tell a crew. (Push notifications for these messages are a separate, opt-in feature.)