Syft

Privacy Policy

Last updated 23 September 2026 · Syft is operated from Dayton, Ohio

The short version

Syft holds your email address, a password nobody can read back, the food you say you like, and a record of the deals you have redeemed and how you rated them.

Restaurants never see your name or your email. They see a random code — something like SYF-K4T9QM — and nothing about you anywhere else.

Syft does not store your location, does not set a single cookie, and runs no analytics or advertising trackers of any kind. Nothing here is sold, and nothing is shared with advertisers.

1. What Syft holds

This is the whole list. It is written from the database itself rather than from a template, and there is an automated check in the codebase that fails if a new column appears that this page does not mention.

Your email address
How you sign in. Syft sends no email at all — there are no newsletters, no marketing, and no "reset your password" link, because no mail is ever sent.
Your password, as a one-way hash
Stored using bcrypt. It cannot be read back, by us or by anybody who obtained the database.
A display name, if you give one
Optional, and used only inside your own account.
Your Syft code
Six random characters after SYF-, generated at signup. This is the only thing about you a restaurant ever sees. It is not derived from your name or email — it is random.
Your food preferences
Cuisines you have picked, a price range, and how far you are willing to travel. Used to order the list of deals.
Deals you have saved
Just the deal and when you saved it.
Deals you have redeemed
Which deal, which restaurant, when it was scanned, whether it was approved or declined, and which member of staff scanned it.
Ratings and comments you leave
One to five stars overall — that part is required — plus optional ratings for food, service, wait and atmosphere, and an optional written comment.
Which deals you were shown and which you opened
Syft records that a deal was seen, opened, skipped or redeemed, so the ordering can get better at putting the right things near the top. It is about deals, not about where you were or what else you did.
Notification records, only if you turn notifications on
The address your phone's browser gave out so a notification can be delivered, and a log of which notifications were sent and which were opened. See section 4.
When your account was made and when it was last used
Two timestamps.

What is deliberately not here: no location history, no payment details, no card numbers, no phone number, no address, no contacts, no photos from your phone, no advertising identifier, and no record of anything you do outside Syft. Syft never sees your bill — the restaurant rings that up on their own till.

2. Location

Syft is a map of places near you, so distance has to come from somewhere. Here is exactly how it works, because "we care about your privacy" is worth nothing next to the actual mechanism.

When you open the app

Your phone asks whether you want to share your location. If you say yes, the coordinates your phone gives out are sent with the request that fetches the list of deals, so the server can work out which restaurants are closest and how far each one is. They are not written down. There is no column in the database that holds a customer's coordinates, and the automated checks fail if one is ever added.

If you say no

The app still works. It falls back to a fixed point in Dayton and shows you everything from there. You lose accurate distances, not the product.

Notifications never use live location

When Syft decides whether a deal is near enough to be worth telling you about, it measures from the average location of the restaurants you have actually redeemed at — places you chose to go. Your phone is never asked where you are for this, and nothing follows you around in the background.

One honest caveat. Coordinates are sent as part of the web address of the request that fetches your list. Web addresses are the sort of thing that can appear in a hosting provider's server logs. Syft does not keep such logs itself, and nothing writes coordinates to the database, but we would rather say this plainly than claim a cleanliness we cannot fully guarantee once a request leaves your phone.

3. What a restaurant sees

This is the part most people actually want to know, and it is the one Syft was designed around.

When you redeem a deal, the member of staff scanning your code sees two things: whether the code is valid, and what to ring in. Not your name. Not how often you come. Not what you spent last time. Not whether you have ever been in before.

When you rate the visit afterwards, the owner sees your rating, your comment if you wrote one, the date, and your Syft code. The review is stored against that code rather than against your account, which is the reason a name cannot appear there even by mistake.

An owner can see the history of reviews left under a particular Syft code at their own restaurant only. They cannot see where else you have eaten, what you thought of anywhere else, or anything you have done on Syft outside their four walls.

Reviews are never published. There is no public star rating on Syft, no review feed, and no profile page. A rating goes to the owner and stops there.

4. Notifications

Notifications are off until you switch them on, and you can switch them off again in the same place. Syft will never ask you to turn them on at the moment you open the app.

If you turn them on, your browser generates a delivery address and two encryption keys and hands them to Syft. Those are stored so a notification can reach your device.

A notification is encrypted before it leaves the server and can only be opened by your device. Apple's and Google's delivery services carry it but cannot read it — the deal, the restaurant and the wording are not theirs to see.

Syft also records which notifications were sent and which were opened. That is the only way to tell a useful reminder from an annoyance, and it is what the limits below are measured against: at most three notifications in any seven days, and never two in the same day.

5. Cookies and tracking

Syft sets no cookies. Not one, not even a "necessary" one — which is why you have never seen a cookie banner here.

When you sign in, your browser keeps a sign-in token in its own storage on your device. It is not sent to anyone but Syft, it cannot be read by other websites, and signing out removes it.

There are no analytics services, no tracking pixels, no advertising networks, no session recording and no fingerprinting. Syft has never had a Google Analytics tag, a Meta pixel, or anything like them, and adding one would be a change worth telling you about.

6. Other companies involved

Running a website means other companies are in the path. These are all of them.

Railway
Hosts the Syft server and the database. They hold the data described above on our behalf.
Cloudflare
Handles the syftdeals.com domain, and may pass web traffic through on its way to the server.
CARTO
Draws the map background. Your browser fetches map tiles from them directly, which means they can see your device's internet address and roughly which part of the map you are looking at. They are not told who you are, because Syft never tells them.
Google Fonts, cdnjs and jsDelivr
Serve two typefaces and two small pieces of map and QR code software. Your browser fetches these directly, so they can see your device's internet address.
Apple and Google push services
Only if you have turned notifications on, and only to deliver them. The contents are encrypted, as described above.

Nobody else. Syft does not sell your information, does not rent it, does not trade it, and does not hand it to advertisers or data brokers. If that ever changes it will be because the company was sold, and section 12 covers what happens then.

7. If you are a restaurant

A restaurant account is a business relationship rather than an anonymous one, so more is held: the business name, address and coordinates, contact details, the deals you post, your staff members' names and sign-in details, and the record of which days each deal ran, because that is what a bill is worked out from.

Addresses are looked up through Google's Places service when you register, so a pin lands on the right building. That lookup happens between Syft's server and Google — your browser does not contact Google, and no customer's information is ever involved.

Restaurant details are meant to be seen. Your name, address, deals and photographs are shown to customers. That is the point of the listing.

8. How it is kept

No system is perfectly safe, and anybody who tells you theirs is should not be believed. If information held by Syft is ever exposed, affected people will be told.

9. How long, and deleting it

Account information is kept while the account exists. Redemption and rating records are kept because they are what a restaurant's own reporting is built from — a review that vanishes takes an owner's history with it.

Deleting your account

In the app, under You, there is a row called Delete account. It opens where it sits, tells you exactly what is about to go, and asks you to type your own Syft code — not the word DELETE — because there is no undo behind it.

Deleting removes your email address and password, your food preferences, your saved deals and any deal you are holding, your visit history, your notification settings, and any make-good a restaurant had sent you. It happens immediately and it cannot be reversed.

Two things that do not simply vanish, and why.

Ratings you left stay with the restaurants you gave them to. An owner's own ratings history should not quietly lose rows because somebody left Syft months later. A review carries a random code, a date and a score and never carried your name, and on the way out it is moved to a fresh code so that nobody who signs up after you can ever be issued yours and inherit what you wrote.

A visit in progress is closed first. If you have been scanned at a restaurant and the bill has not been settled yet, that visit is recorded as approved before your account goes — the same way an unsettled visit already settles on its own. Otherwise a member of staff is left holding an open table, mid-service, that belongs to nobody.

One more thing survives and is not about you: a count of how many times a deal was seen or opened. Your account is removed from those records rather than the records being deleted, so "this deal was opened four hundred times" stays true and none of it points at anybody.

10. Your choices

Depending on where you live you may have further rights over your information, including under Ohio law and, for visitors from elsewhere, under laws such as the GDPR or the CCPA. Ask and they will be honoured rather than argued about.

11. Children

Syft is not intended for children under 13 and accounts are not knowingly created for them. If you believe a child has made an account, get in touch and it will be removed.

12. Changes

If this policy changes, the date at the top changes with it. If a change is significant — a new company in the list above, a new kind of information collected, a promise withdrawn — you will be told in the app rather than left to notice.

If Syft is ever sold or merged, information would transfer with it, and you would be told before that happened and given the chance to delete your account first.

13. Contact

Syft is a small operation in Dayton, Ohio, and mail reaches a person rather than a queue.

wrcreative1@gmail.com