Privacy policy
This showroom has no accounts, you cannot vote here and it sets no cookies. Below are the terms and privacy policy of the real sovl.com.
Draft, pending legal review.
Last updated on 30 September 2026. This text is not final yet.
sovl is the "best at" recommendation network on sovl.com and in the sovl bot on Telegram. This policy explains which personal data sovl processes, why, and what you can do about it. We describe what the system actually does today; what is announced but not built yet is in a separate section at the end.
Who is responsible
The controller is Memes BV, Rue Groeselenberg 180, 1180 Uccle, Belgium, company number 0478.554.250, VAT BE0478554250. For anything about your data, write to hello@memes.be.
What we process
Your account in the bot. When you write to the bot we store your Telegram user id, the name you use on Telegram (first name, last name or username), which becomes your display name, when you last wrote to the bot and whether the bot can reach you. We store the language of the conversation, taken from your Telegram app, to answer in your language. On WhatsApp, once available, your WhatsApp number is your identity and your WhatsApp profile name is your display name.
Your phone number, only if you share it. When you tap "Share my number" in the bot, Telegram sends us your own number and we store it in full, in international format. It is how sovl makes one phone number count as one person, and it is required to claim a shop or hang a sticker on a place. It is never shown publicly. When you claim a shop, the person who reviews the claim sees only its last four digits. You can vote without sharing your number; the ranking then says it is verified by account rather than by phone. sovl sends no text messages and uses no SMS provider.
Your votes. For every vote: the category, the place (its Google place id and name), the level and area you chose (neighbourhood, town, country or world), when you cast it, whose vote you followed, the vote you originally followed when you cast it, how it arrived (directly, through a sticker, or through a campaign code), whether it came through a share link, and whether it still stands or moved, with the date of the move. Earlier votes stay in your history when you move. We use these to count the rankings, to keep "found by" and "best since" honest, and to apply the rate limits.
The "why" with a vote, only if you write one. Its text (at most 200 characters), who may see it (everybody signed in, or your circle), and every earlier version of the text, kept internally; only the latest is shown. Your circle is the people one step away from you in the trust tree: whoever voted under one of your votes, and whoever you voted under, in any ranking. When a signed-in viewer reports a why, we store who reported which version, when, and the reason they gave, if any. Our admins get the report in the bot: the reported text, your display name (admins handling a report always see it, whatever your name setting), the place and the reason. We record which admin decided, when, and whether the text was kept or taken off the site.
Challenges and messages. Who challenged which vote, the deadline, your answer and when you gave it. We also keep the notifications the bot sends you and the one-time buttons in them.
Share links. A share link carries the id of the vote it shares. When a share link first brings you to sovl, we record which vote brought you and when, once. Opening a share link on sovl.com itself records nothing.
Stickers and campaign codes. Per code we count scans, bot starts, phone shares and votes. Those counters say nothing about who scanned. A vote records the code it came through. When you hang a code on a place, we record that you did and when.
Page views and taps on sovl.com. Per ranking page and per place page we count, per day, how often it was opened, and per place how often Directions or Website was tapped. Only the count is stored: no person, no IP address, no device, no time finer than the day. Requests from known crawlers and link previews are not counted.
Shop owners. When you claim a place: which place, the status of the claim, who decided and when, the codes an approval took over, and the votes for your own place that an approval withdrew (so a revoke can restore them).
Conversation state. The step of the conversation you are in and what is needed to finish it, for example the place you picked or the code you scanned. If you send the bot a location, it is not stored.
Place searches. What you type to find a place is sent to Google Places to find it. The places themselves are businesses: we store their Google place id and, for places with votes, their address, town, Google Maps link, website and position (the position of the place you pick in the bot is kept at once, for at most 30 days like the rest). We also classify every voted place into its neighbourhood, town and country, and keep the names of those areas, as Google gives them, in our public list of areas.
Your location on sovl.com, only if you allow it. When you tap "Show what is near", your browser asks whether sovl.com may use your location. If you allow it, the position stays in your browser: the page works out there which rankings are near you and how far each place is, and sends the position nowhere. sovl never receives it and stores no location of yours. Once you chose it, later visits use your location again without a new tap, for as long as your browser still allows it; "Not now", or withdrawing the permission in your browser, stops that. For that, the page uses the position of each place as Google gives it, kept for at most 30 days like the address.
Signing in on sovl.com. On the sign-in page Telegram's login widget is loaded from telegram.org. After you confirm in Telegram, we receive your Telegram id, name, username and profile photo link, and check Telegram's signature. We keep only the id and the name; the username and the photo link are not stored. We then store a fingerprint (a SHA-256 hash) of your session token with the date it was created, last used and expires. We store no IP address and no browser details with it.
Operations and security. When something fails, we log a technical event for 30 days. It carries ids (for example a person id or a Telegram chat id), never the text of your messages and never your phone number. Alerts about failures go to our own ops chat on Telegram and to a Slack channel; an error message can occasionally contain a display name or a place name. A daily summary contains counts only. A reported why is logged with ids only, never the text or a name, and raises no alert there.
E-mail. If you write to hello@memes.be, we keep the correspondence for as long as needed to handle it.
What is public
- Rankings, the places in them, their vote counts, "best since" and their history are public on sovl.com and in machine-readable form (JSON and schema.org).
- Who sees your name is your choice, with one privacy switch on your account page or with "privacy" in the bot, and it applies on sovl.com and in the bot alike. Everybody: your display name appears with your votes, as the finder of a place, on your person page and in the machine records, to anyone. My circle, where everyone starts: your name is shown only to your circle (the people who voted under one of your votes, and the people under whose vote you voted, in any ranking) and to whoever arrives through your share link, because sending your link is choosing to be known to that person; everyone else sees "a voter", and a person page exists only for signed-in people in your circle. Nobody: your name is never shown to anyone else, you have no person page, and you are counted as "a voter". Whatever you choose, your vote counts the same.
- In the bot the same switch decides whether your name appears when someone opens your share link, when you challenge someone or are challenged, when you move a vote others followed, and when someone looks at a ranking where you found the place. Pages that anyone can load, the machine records and link previews only ever show names of people who chose everybody.
- The hunters ranking (sovl.com/en/hunters) is public too: it lists people with at least three finds (a find is the first vote ever for a place or product in a ranking), with how many finds they made and how many of them became #1 (led while that ranking had at least three voters), per area and for all rankings together. It is worked out from your votes and follows the same switch: pages anyone can load list only people who chose everybody; a signed-in person also sees the people who chose my circle and show them their name, that is the people of their circle and the person whose share link brought them to sovl; and people who chose nobody are never listed. Anyone not shown is left out of the list, not counted as "a voter".
- Your username (generated from your display name plus four digits, and changeable) is the address of your person page, sovl.com/@username. After a change we keep your old username for 90 days, linked to your account, so old links keep working and nobody else can take it meanwhile; then it is released. At most five changes in 30 days. When you delete your account, your usernames stay reserved for 90 days without any link to you (only the bare name and the date), so nobody can take them and old links lead nowhere; then they are released too.
- A why is never public. Only people signed in on sovl.com see it, next to your vote on rankings, place pages and voter pages: everybody signed in, or only your circle, as you chose for that vote. It shows with your name only where your name is shown anyway; otherwise as "a voter". It is never in the machine records (JSON and schema.org), link previews or the sitemap, and visitors who are not signed in never see it.
Why, and on which legal basis
- Running sovl for you (your account, votes, challenges, notifications, share links, signing in, shop claims, the why text): performance of the contract formed by our terms of use (article 6.1.b GDPR).
- One phone number, one person, and the rate limits: our legitimate interest, and that of every voter, in rankings that cannot simply be bought or stuffed (article 6.1.f).
- Showing your name: your choice with the privacy switch, which is consent (article 6.1.a) for everybody, and for the circle setting the contract and our legitimate interest in the trust tree the service is built on (articles 6.1.b and 6.1.f): the people shown your name are the ones you voted with or sent your link to. You can change it to nobody at any time.
- Security, error logs, abuse prevention and handling reports: legitimate interest (article 6.1.f).
- Aggregated statistics about how sovl is used, such as how many votes arrive through a share link or a sticker: legitimate interest (article 6.1.f). They are counts, never profiles of individuals.
- Answering authorities and keeping what the law requires: legal obligation (article 6.1.c).
Who else processes your data
We do not sell personal data and show no advertising. These providers process data for us, or because you use them:
- Supabase: our database and server functions, hosted in the EU region eu-west-1 (Ireland).
- Cloudflare: hosting of sovl.com and its network. Cloudflare sees technical data such as your IP address and the page you request, to deliver and protect the site.
- Telegram: the bot and the sign-in on sovl.com. Telegram's own privacy policy applies to your use of Telegram.
- Meta (WhatsApp), once the WhatsApp bot is available.
- Google: Google Places, for place search and place details. On pages with a place photo, your browser loads the photo from Google's servers (googleusercontent.com), so Google receives your IP address.
- Slack: internal alerts about failures (see above).
Transfers outside the EU
The database is stored in the EU. Several providers are companies based in the United States or elsewhere outside the EU, and Cloudflare serves the site from a worldwide network. Where data leaves the EU, we rely on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission's standard contractual clauses.
How long we keep it
- Your account, votes, vote history, challenges and shop claims: as long as your account exists. When you delete it, they are removed at once (see below).
- Notifications the bot sent you, and its one-time buttons once used or expired: removed at night once they are 90 days old, counted from when they were created. A button you can still press is kept until it expires.
- Conversation state: removed 30 days after your last step in a conversation with the bot; your next message starts afresh.
- A why and its earlier versions: removed at once when you delete the why, when your vote moves to another place or is withdrawn, and when you delete your account. A version someone reported is the exception: it is kept as evidence until the report is handled, plus 90 days, and then removed at night; deleting your account removes it at once. A report you made is removed with the version it is about, and at once when you delete your account. The admins' message about a report goes with the version, and otherwise after 90 days like every bot message.
- Sessions on sovl.com: one year after you last used them; expired sessions are removed daily.
- Technical event logs: 30 days.
- The classification of a place into areas, and the names of those areas: no fixed limit; they describe places, not people.
- The name of a product as a voter typed it (a brand and a product name, such as a chocolate): no fixed limit. It stays when the account that typed it is deleted and when the nightly clean-up runs, because it names a product, not a person; once no vote points at it, nothing links it to anyone. So do not type anything about yourself or another person in it. A new product name is checked by an administrator before it is shown; until then it appears as "new product". A name the administrator rejects is deleted 90 days after that decision, together with the votes for it.
- Place details from Google: refreshed at least every 25 days, and cleared after 29 days without a refresh. The link to a place photo and its credit are cached for at most 40 minutes.
- The logs of our hosting providers and the automatic backups of the database follow the provider's own, limited retention.
Deleting your account
Signed in on sovl.com, go to your account and choose delete account. In one step this removes you and everything linked to you: your channels, phone number, votes and their history, your why texts with their earlier versions, the reports you made and the reports on your whys, challenges by or against you, notifications, buttons, sessions, shop claims, conversation state, and the technical event logs linked to your id. A name that appears inside the text of an error message stays in the log until it is deleted after 30 days, and copies of alerts already sent to our ops chat on Telegram and to Slack are not removed. People who voted with you keep their own vote. Finder credit for a place passes to the next earliest voter. Rankings are recounted. If you write to the bot again later, you start as a new person.
No access to sovl.com? Write to hello@memes.be from the bot account in question, or tell us how to recognise it, and we will delete it for you.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to object to processing based on our legitimate interest, to receive your data in a portable form, and to withdraw your consent at any time. Write to hello@memes.be. We answer within one month and may ask you to show that the account is yours, for example with a message from the bot.
You can also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), www.dataprotectionauthority.be.
Cookies
sovl.com uses only cookies that are strictly necessary, so there is no cookie banner. There are no analytics, advertising or tracking cookies, and our fonts are hosted on sovl.com itself.
- sovl_session: keeps you signed in, one year.
- sovl_login_intent: protects the sign-in against forgery, 15 minutes, used once.
- sovl_lang: remembers your language during sign-in and on your account page, 10 minutes.
- sovl_next: brings you back to the page you came from after signing in, 15 minutes.
- sovl_initial: holds only the initial of your name, so the header can show it; set at sign-in and on your account page, removed when you sign out or delete your account, one year.
- sovl_pref_lang: the primary language from your profile, so that sovl.com opens in it; set when you save your profile or open your account page with one chosen, one year.
- sovl_nearby: kept in your browser (local storage, never sent to sovl), it remembers only whether you chose "Show what is near" or "Not now", never a position; it stays until you clear your browser data.
The sign-in page loads Telegram's login widget, which is Telegram's own and subject to Telegram's policy.
Age
sovl is meant for people aged 16 or older.
Automated decisions
A ranking is a count of standing votes, with fixed rules for ties. Rate limits apply automatically. sovl takes no decision about you that has legal or similarly significant effects.
Your profile
On your account page, and once in the bot after your first vote, you can fill in a profile. Only your country is required; everything else is optional, and you can skip or clear any field at any time.
- Country (required): prefilled from the country code of the phone number you shared, when that code belongs to one country; otherwise we ask.
- Your real first and last name, optional. Shown on your person page only if you tick "show my real name", and only to the people your privacy switch lets see that page.
- Sex (male, female, prefer not to say), birth year (never a full date of birth), region or town, and your children as a number with how many are 0 to 3, 4 to 8, 9 to 12 and 13 to 17 years old. Never their names or birth dates. All optional. The children are asked on your account page only, not in the bot.
- Your primary language (Dutch, French or English), which sets the language of the bot, of its messages to you and of the site. The site remembers it in a cookie (see Cookies).
- Instagram, Facebook and TikTok handles that you type in yourself, checked only for their form. They appear on your person page, like your real name, to the people who may see that page. We do not connect to those platforms and do not show follower counts; a real connection may come later and will be described here first.
Purposes, all four: filters for users (for example "the best according to parents"), aggregated statistics for shops (never about an individual), our own analytics, and a personalised ranking. None of them is built yet: for now the fields are only stored. Sex, birth year, region, country and children are never public, never in the machine records and never shown to anyone but you.
Legal basis: your consent for the optional fields, which you withdraw by clearing the field; for the country, which the service asks of everyone, the contract. Kept as long as your account exists; deleting the account deletes them at once.
Coming soon
Not built yet. When these arrive, this policy will be updated before they go live.
- A disclosure on a vote (sponsored or ambassador, and the brand), with the date it was added.
Changes
We will update this policy when sovl changes. The date at the top shows the latest version. We will tell you through the bot about changes that matter.
See also: Terms of use ยท Legal notice