Your information, your choice.
We store your private account email, authentication records, tamale maker submissions and revisions, ratings, reports, and moderation audit records. We use email codes to establish inbox control and send necessary account and listing notifications. Account email is never shown publicly.
You choose the public tamale maker name, city, kitchen type, flavors, description, price, pickup notes, contact methods and optional photo. An exact public pickup address requires consent and pin confirmation. City-only listings do not collect a street address.
Public ratings show only an average and count. No customer email, public profile, written reviews or customer photos are displayed. Administrators can inspect ratings to investigate abuse.
Tamale maker photos are converted to optimized WebP and metadata is removed. Only publish photos you have permission to share. Hidden or removed photos cannot be retrieved publicly, including by their old URL.
Map tiles and approved-for-public address lookup use Geoapify. Map requests disclose network information to that provider. Bot protection uses Cloudflare Turnstile when configured. Email delivery uses Resend. Application data uses Cloudflare D1 and R2.
We count listing views, contact clicks, completed submissions, ratings and sponsor clicks as daily aggregates. Event records contain a listing ID and event type, never private email, contact details or email codes. Abuse controls store keyed hashes of network identifiers and recipient addresses temporarily.
Authentication cookies support sign-in. Cookies are secure on production HTTPS. Email codes expire in five minutes and are stored hashed; the isolated local test inbox contains plaintext delivery messages for development only.
Delete your account in Account settings after verifying a fresh email code. Administrators also confirm an authenticator code. Deletion revokes sessions and hides listings immediately; photo and database cleanup retries after failures. Administrator deletion waits for removal from the access allowlist. A minimal keyed deletion ledger prevents deleted administrator accounts from automatically registering again and supports deletion after backup restoration. Daily maintenance removes expired codes and sessions within 24 hours after expiry, sent mail after 7 days, pending or failed mail after 30 days, unattached uploads after 7 days, and superseded or rejected revisions, resolved reports and redacted audit records after 90 days. Active account email remains until deletion. Local development inbox messages expire after 24 hours. Production storage encryption is provided by Cloudflare; local SQLite is not encrypted.
Explore tamales