The essentials
BrewLeague uses only the data required to create your account, synchronize your groups, moderate user-generated content, and produce rankings and statistics. It does not sell your data, display ads, or request GPS location, contacts, or photographs.
1. Data controller
This policy applies to the BrewLeague mobile application, developed and operated by Mario Pajares.
- Application: BrewLeague / Liga Cervecera
- Package name:
com.mariopajares.brewleague - Contact: m.pajares96@gmail.com
2. Data we process
Account
Username, email address, internal identifier, role, account creation date, and, when you choose Google sign-in, the Google account subject identifier.
Groups
Group name, members, owner, invitations, and season start date.
Beer logs
Brand, country, style, serving size, alcohol percentage, points, player, and log date.
Local data
Language, active group, and a cached copy of groups and rankings on your device.
Push notifications
If you allow notifications, a device push token (Firebase Cloud Messaging) linked to your account, used only to notify you when someone in your group logs a beer.
Safety reports
Reporter identifier and name, group, reported user or player, report text, status, and submission date.
Limited technical data
If you choose Google sign-in, Google processes the account selection and provides BrewLeague with a verified email address and a stable account identifier. BrewLeague does not request access to Gmail, contacts, Drive, photographs, or other Google data.
Firebase Authentication automatically processes IP addresses, device and application metadata, Firebase identifiers, and user-agent information to authenticate accounts, maintain the service, and prevent abuse. Cloudflare also temporarily processes IP addresses and request metadata to deliver the relay and rate-limit abusive requests. BrewLeague does not add those IP addresses to its Firestore user profiles.
We do not request or collect precise GPS location, address-book contacts, photographs, camera or microphone data, advertising identifiers, or payment information. Network providers may infer an approximate area from an IP address for security. A ranking image is generated locally and sent to another app only when you choose to share it.
3. How we use the data
- Create and protect your account, sign you in, and recover or change your password.
- Create groups, manage members and invitations, and synchronize group information.
- Log beers and calculate rankings, seasons, records, and statistics.
- Send a push notification to your group when a member logs a beer, if you allow notifications.
- Send strictly transactional emails about account recovery or email changes.
- Prevent abuse, unauthorized access, and automated requests.
- Handle access, correction, and deletion requests.
The primary legal basis is performance of the service you request when you create and use an account (Article 6(1)(b) GDPR). Security and abuse-prevention measures rely on our legitimate interest in protecting the service and its users (Article 6(1)(f) GDPR). Where required by law, we will ask for your consent.
4. What members of your group can see
BrewLeague is a collaborative application. People in the same group can see member and player names, beer logs, and information derived from those logs, including points, positions, history, and statistics.
Groups are not publicly searchable. Access is provided through an invitation or when the owner adds someone they know. Do not include personal information in usernames, group names, player names, or brand fields if you do not want the rest of the group to see it.
5. Service providers that make BrewLeague possible
We use technical service providers solely to operate BrewLeague:
These providers may process information in different countries. Where an international transfer occurs, it is carried out using the mechanisms and safeguards required by applicable law. We do not sell personal data or disclose it for advertising purposes.
6. Data retention and deletion
We retain account data while the account remains active. Group logs are kept to preserve history, rankings, and statistics until they are deleted individually or the group is deleted.
- Deleting a beer or player removes that information from the group.
- Deleting a group removes its session, members, beers, and rankings.
- Leaving or being removed from a group revokes access and removes the player entry associated with that membership.
- Push notification tokens are automatically removed once they become invalid (for example, after uninstalling the app), and are deleted along with your account.
- Full account deletion removes sign-in credentials, the profile, memberships, and associated logs. Groups owned by that account are also deleted.
- Safety reports are retained while they are investigated and for no longer than 24 months unless a longer period is required to protect users or comply with law. Reports submitted by an account are deleted when that account is fully deleted.
To request full deletion of your account and associated data, email m.pajares96@gmail.com from the address linked to the account. We will verify the requester's identity and complete the request within 30 days, unless the law requires us to retain specific information.
7. How we protect your information
- Communications are encrypted using HTTPS/TLS.
- Passwords are managed by Firebase Authentication and are never visible to us.
- Sensitive changes require recent authentication or a server-verified token.
- Firestore access rules restrict data to authorized accounts and groups.
No system can be guaranteed to be completely secure. If you identify a potential security issue, please report it using our contact email.
8. Children's privacy
BrewLeague relates to logging alcoholic beverages and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us so that we can investigate and delete the information where appropriate.
Please also review our Child Safety Standards.
9. Your rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, or portability of your personal data, and you may withdraw consent previously given.
To exercise these rights, email us with your username and the specific request. We may request additional information solely to verify your identity. If you live in Spain, you may also lodge a complaint with the Spanish Data Protection Agency.
10. Changes to this policy
We will update this page when BrewLeague's features or data practices change. The effective date will always appear at the top. If a change is material, we will also make reasonable efforts to notify users within the application.
Have a question?
For questions about privacy, account deletion, or security:
Mario Pajares · BrewLeague Developer
m.pajares96@gmail.com