Sign in

DuskRoute

Privacy policy

Last updated: 6 September 2026

Who we are

DuskRoute is the happy-hour discovery service at duskroute.com. It is operated by skorulis.com.

This page describes how data is handled today based on how the product is built and operated. It is not legal advice.

What we collect

Depending on how you use DuskRoute, we may process:

  • Account data — name, email address, hashed password (for email/password accounts), email verification status, whether you have completed profile setup, your optional marketing-email preference, and optional admin email-digest notification preferences (stored on your account when you use the site admin notifications settings). Email/password accounts choose a display name after email verification. For Google sign-in, we prefill that step with the name Google provides and let you change it before continuing.
  • Session data — session tokens, expiry, IP address, and user agent stored with your signed-in session.
  • Favorites — deal, venue, and route IDs you save while signed in, stored on our servers and linked to your account. We also keep a copy of those IDs in your browser so the site can show your favourites quickly. Favouriting requires an account. Aggregate favorite counts on routes (not who favorited them) are shown next to the favourite button and used to surface popular routes.
  • Saved routes— when you save a crawl while signed in, we store the route name, day and start time, stop count and total duration, the first venue and suburb, a shareable public id, a view count, and a JSON copy of the crawl (starting point and ordered stops with stay times, optional notes, and deal filters), linked to your account. You can edit or delete crawls you created; deleting a route also removes everyone's favorite of it.
  • Specials — deal details you submit (title, description, conditions, schedules, dates) and any deal images you upload, linked to your account for moderation.
  • Reports — category and free-text details about a deal. You can report while logged in or anonymously; if signed in, the report may be linked to your account.
  • Ratings — a star rating (0.5–5) and optional note you leave on a deal, linked to your account. The star rating, optional note, and your display name are shown publicly on the deal. Your email is not shown.
  • Venue ownership — a link between your account and a venue when you are authorized as a venue admin for that venue.
  • Venue claim requests — when you claim a venue, we store the venue, your user account, the business or work email address you verify against, a one-time verification code, and created/expiry timestamps (codes expire after about 10 minutes). Venue contact emails may also be stored on venue records when available from venue data sync.
  • Analytics device ID — a random ID stored in your browser and sent with product analytics events to Amplitude, Google Analytics (as the Google Analytics client_id), and PostHog (as $device_id, and as distinct_id when you are not signed in). If you are signed in, events may also include your user ID.
  • Account analytics — when you log in or create an account (email/password or Google), we may record whether the attempt succeeded, the method used, and a generic error code on failure. We do not send your email address, name, or password with these events. If you are signed in after a successful attempt, the event may also include your user ID.
  • Search analytics — when you run a home page, nearby, suburb, or region deal search, we may store the search type, selected or nearest suburb (for suburb searches, the suburb you chose; for nearby searches, the closest suburb centre within about 20 km of your location when one is available), selected region (for region searches), selected day of week (when exactly one day is chosen), selected products, and an arrival source for the visit (this site, Google, a referring website domain without subdomains, a campaign source from a utm_source parameter, or no referrer). We do not store the full referring URL or search-engine query terms. Home page searches are recorded when you change day, time, or product filters on the home page. If you are signed in, the record may be linked to your user ID; otherwise it is anonymous. We do not store your precise GPS coordinates in this table.
  • Venue-open analytics — when you open a venue from search results (list, map, or home hero), we may store the venue, the surface you opened it from, and a random per-search identifier that links the open to the search that produced those results. If you are signed in, the record may be linked to your user ID; otherwise it is anonymous. Opens that are not preceded by a recorded search in that browsing session are stored without that link.
  • Route views — when you open a saved route page, we increment a view count stored on that route. Your browser keeps the public ids of routes you have already counted (dr_viewed_routes) so refreshing the same page does not keep incrementing. This is a best-effort per-browser check, not a unique-visitor system. The count is not linked to your account. Aggregate view counts are shown next to the favourite button on route list and detail pages.
  • Approximate location — only if you use “near me” and grant browser geolocation permission. Coordinates are used for nearby search and are not saved as a personal location history on your account.

How we use data

  • Create and manage accounts, sessions, and email verification.
  • Power search, map views, and nearby results.
  • Sync and display your favorites.
  • Rank public popular routes by how many people have favorited them, and show favourite and view counts next to the favourite button on a route.
  • Save crawls you create so you can keep them on your account and share them via a public link id, and count visits to those public route pages (shown as a view count on the route).
  • Authorize venue admins to access venue-specific admin tools when ownership is recorded for their account, including verifying venue-claim requests via one-time email codes.
  • Moderate user-submitted deals and reports (including showing submitter or reporter email to site admins and to venue admins for reports on their venues).
  • Store deal ratings you submit so we can display the average and individual reviews on deals, and so you can view and manage them on your profile.
  • Understand product usage via analytics (for example page views, searches, search-bar filter selections, map interactions, venue opens, clicks from a venue page to an external source such as website, maps, Instagram, Facebook, menus, or more information, deal ratings views, and login or signup outcomes), including first-party search and venue-open analytics stored in our application database to improve search and the product, and the same product usage events plus website traffic reports via Google Analytics and PostHog. We aim to exclude automated or bot traffic from product analytics.
  • Diagnose errors and reliability issues via error monitoring.
  • Optionally extract deal details from content you provide using a language-model provider when you use deal extraction.

We use email for account verification (one-time codes and links), password reset links, venue-claim verification codes (which may be sent to a venue business or work email address you nominate, not only your account email), notices when you are added as a venue admin, and optional site-admin digest emails summarizing new deal reports and newly posted specials awaiting review (only when those notification preferences are enabled). If you opt in to marketing emails during profile setup or from your profile, we may also use your account email for occasional DuskRoute news, product updates, and offers. You can change that preference from your profile.

Where data is stored

  • Application database — Postgres hosted on a DigitalOcean droplet in Sydney (accounts, sessions, favorites, saved routes (including route view counts), venue ownership, venue claim verification codes, deals, reports, ratings, first-party search and venue-open analytics, and related app data).
  • Uploaded images — Cloudflare R2, served publicly via images.duskroute.com.
  • Your browser — localStorage and sessionStorage for device ID, analytics session ID, a cache of your signed-in favorites, which saved routes you have already counted as a view, in-progress route drafts, and temporary map navigation state.
  • Analytics and errors — Amplitude (product analytics), Google Analytics (product usage and website traffic), PostHog (product analytics, EU Cloud), Ahrefs (website traffic analytics), and Sentry (error monitoring).

Third parties

We rely on these services in the course of running DuskRoute:

  • Google — optional OAuth sign-in; Google Maps JavaScript API in the browser for map features; Google Analytics 4 for product usage and website traffic as described below. Venue data may include Google Places identifiers.
  • Resend — transactional verification, password-reset, venue-claim verification, venue-admin notification, and optional site-admin digest emails.
  • Amplitude — product analytics (filtered to exclude likely automated traffic).
  • Google Analytics (GA4) — product usage events (the same catalog sent to Amplitude, such as page views, searches, filter selections, map interactions, venue opens, deal ratings views, and login or signup outcomes) and website traffic (sessions, landing pages, and approximate source/geo). Events are sent from our servers via Measurement Protocol using the first-party device ID as client_id. We do not load the Google Analytics browser tag or set Google Analytics cookies. Your IP address may be forwarded so Google can estimate region and is not used by us as a personal identifier.
  • PostHog — product usage events (the same catalog sent to Amplitude and Google Analytics, such as page views, searches, filter selections, map interactions, venue opens, deal ratings views, and login or signup outcomes). Events are sent from our servers via PostHog’s capture API to PostHog EU Cloud. We do not load the PostHog browser SDK or set PostHog cookies. Your IP address may be forwarded so PostHog can estimate region and is not used by us as a personal identifier.
  • Ahrefs — website traffic analytics (page views and related visit metrics via a browser script; cookieless per Ahrefs).
  • Sentry — error and performance monitoring.
  • Cloudflare — DNS/CDN and R2 object storage for images.
  • OpenRouter — language models used when extracting deal information from user-provided images or text.
  • DigitalOcean — hosting for the app and database.

Cookies and local storage

  • Session cookies — used by our authentication system to keep you signed in.
  • localStorage — analytics device ID (dr_device_id), public ids of saved routes whose views you have already counted (dr_viewed_routes), and a cache of your favorite deal, venue, and route IDs while you are signed in.
  • sessionStorage — temporary map entry state used while navigating between list and map views, an in-progress new-route draft (name, starting point, day, time, chosen stops with optional notes, and current bar search) so leaving the page and coming back in the same tab can restore it until you start over or close the tab, an analytics session ID (dr_ga_session_id) used to group page views and other analytics events in Google Analytics, with a last-active timestamp so the session expires after about 30 minutes, and a search arrival source (dr_search_referrer) stamped once per tab so we can tell whether a visit started on this site, from Google, from another website domain (without subdomains) or campaign source, or with no referrer.

There is no separate cookie-consent banner in the product today. Analytics and error monitoring may run for visitors as described above.

Location

If you choose “near me”, your browser may ask for location permission. Coordinates are used to find nearby deals via our API and to show your position on the map. We may log that a nearby search occurred and attribute it to the closest suburb centre within about 20 km (without storing those coordinates) for product analytics. We do not keep a history of your precise location on your user profile.

Retention and your choices

  • Creating an account or signing in shows a notice that by continuing you agree to our Terms of Service and this Privacy Policy.
  • You can sign out to end your current session.
  • You can remove favorites at any time.
  • You can edit or delete crawls you created from the route page. Deleting a route cannot be undone and also removes it from everyone's favorites, along with its view count.
  • You can edit or delete your deal ratings from your profile ratings area.
  • You can withdraw your own open deal reports from your profile reports area.
  • There is currently no in-product account deletion or data-export flow. If you want an account removed, contact us using the details below and we will handle the request manually, including search and venue-open analytics rows linked to your user ID when applicable.

First-party search and venue-open analytics remain in our application database until we purge them operationally or remove them as part of a manual account-removal request. Route view counts stay on the saved route until that route is deleted. Amplitude, Google Analytics, PostHog, Ahrefs, and Sentry retention is controlled by their product settings. Uploaded deal images may remain publicly reachable by URL while they exist in our storage.

Contact

For privacy questions or account removal requests, email [email protected].

Back to DuskRoute