←Back to Rezza

Privacy Policy

Last updated July 1, 2026

Rezza is a curated guide to restaurants and bars in Philadelphia, operated at getrezza.com. We built it to be useful without demanding your data. You don’t need an account to use it, and we collect the minimum needed to keep the site working and improving.

What we collect

When you browse getrezza.com:

  • Anonymous usage data — page views, referrers, device type, and performance metrics collected via Vercel Analytics and Vercel Speed Insights. These services are cookieless and do not use fingerprinting or cross-site tracking.
  • Standard server logs — IP address, user agent, and request path, retained by our hosting provider (Vercel) for operational and security purposes.

When you submit feedback:

  • The content you submit — your message, category, and any details you choose to include. If you provide an email, we use it only to reply.
  • A hashed IP address — we store a one-way SHA-256 hash of your IP (salted, not the raw address) so we can rate-limit abuse. We cannot recover the original IP from the hash.

We do not sell your data. We do not run advertising. We do not create user profiles.

Cookies

Rezza does not set tracking, advertising, or analytics cookies.

Local browser storage

We use your browser’s local storage to remember non-sensitive preferences (such as recently viewed restaurants and whether you’ve seen the site tutorial). This data stays on your device and is never transmitted to us.

Third-party services we use

Rezza is built on services that process limited data on our behalf:

  • Vercel — hosting, analytics, and speed insights.
  • Supabase — database and file storage for restaurant data and feedback.
  • Cloudinary — image delivery and optimization.
  • Mapbox — interactive map tiles. Mapbox may collect anonymized request telemetry per its own privacy policy.
  • Google Places — restaurant search and reference data.
  • Anthropic — feedback categorization via Claude. Only the text you submit is sent, and it is not used to train models.

Each of these providers has its own privacy policy governing how they handle data on our behalf.

How long we keep data

  • Feedback submissions are kept until they’re resolved or you ask us to delete them.
  • Rate-limit records are automatically deleted on a weekly schedule.
  • Analytics data is retained according to Vercel’s default retention.

Your rights

Regardless of where you live, you can ask us to:

  • Tell you what data we have that’s associated with you.
  • Delete or correct that data.
  • Stop processing it.

Because we don’t require accounts, most requests come down to deleting a specific feedback submission — send the URL or a brief description and we’ll handle it. Residents of California (CCPA/CPRA), the EEA/UK (GDPR), and other jurisdictions with privacy laws are entitled to these same rights.

Security

We use industry-standard measures to protect the data we hold, including encryption in transit (HTTPS), hashed IP addresses for rate limiting, and access controls on our admin surface. No system is perfectly secure — if you spot a vulnerability, please report it via the form on our contact page.

Changes to this policy

If we make material changes, we’ll update the “last updated” date at the top of this page. Substantive changes will be noted on the site.

Contact

Questions, requests, or corrections? Use the report form at the bottom of our contact page — it reaches our team directly.